New VanHelsing Ransomware RaaS Model Attacking Windows, Linux, BSD, ARM, and ESXi Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VanHelsing has emerged as a sophisticated ransomware-as-a-service operation that fundamentally changes the threat landscape for organizations worldwide. First observed on March 7, 2025, this multi-platform locker represents a significant escalation …

Ivanti Endpoint Manager Vulnerabilities Let Attackers Write Arbitrary Files to Disk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has rolled out security updates for its Endpoint Manager product, addressing three high-severity vulnerabilities that could let authenticated local attackers write arbitrary files anywhere on the system disk. The …

Android Remote Data-Wipe Malware Attacking Users Leveraging Google’s Find Hub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated remote data-wipe attack targeting Android devices has emerged, exploiting Google’s Find Hub service to execute destructive operations on smartphones and tablets across South Korea. This campaign represents the …

Synology BeeStation 0-Day Vulnerability Let Remote Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Synology has released an urgent security update addressing a critical remote code execution vulnerability in BeeStation OS that allows unauthenticated attackers to execute arbitrary code on affected devices. The vulnerability, …

Hackers Weaponizing Calendar Files as New Attack Vector Bypassing Traditional Email Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A surge in attacks exploiting iCalendar (.ics) files as a sophisticated threat vector that bypasses traditional email security defenses. These attacks leverage the trusted, plain-text nature of calendar invitations to …

Weaponized NuGet Packages Inject Time-Delayed Destructive Payloads to Attack ICS Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has emerged, targeting industrial control systems through compromised .NET packages. The threat landscape shifted on November 5, 2025, when researchers identified nine malicious NuGet packages …

Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability has been discovered in Zoom Workplace VDI Client for Windows that could allow attackers to gain elevated privileges on affected systems. The flaw, tracked as CVE-2025-64740, has …

Devolutions Server Vulnerability Let Attackers Impersonate Users Using Pre-MFA Cookie

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Devolutions Server could allow attackers with low-level access to impersonate other user accounts by exploiting how the application handles authentication cookies before multi-factor authentication is completed. …

65% of Leading AI Companies Exposes Verified Secrets Including Keys and Tokens on GitHub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security investigation reveals that 65% of prominent AI companies have leaked verified secrets on GitHub, exposing API keys, tokens, and sensitive credentials that could compromise their operations and …

WatchGuard Firebox Firewall Vulnerability Let Attackers Gain Unauthorized SSH Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in WatchGuard Firebox firewalls could allow attackers to gain complete administrative access to the devices without any authentication. The flaw, tracked as CVE-2025-59396, stems from insecure default …