Microsoft Windows Cloud Files Minifilter Privilege Escalation Vulnerability Exploited

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has patched a critical race condition vulnerability in its Windows Cloud Files Minifilter driver, known as CVE-2025-55680, which enables local attackers to escalate privileges and create arbitrary files across …

Chrome 142 Released With Fix for 20 Vulnerabilities that Allows Malicious Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially promoted Chrome 142 to the stable channel, delivering critical security updates for Windows, Mac, and Linux users. The rollout begins immediately and will continue over the next …

CISA Shares New Threat Detections for Actively Exploited WSUS Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a critical update issued on October 29, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) has provided organizations with enhanced guidance on detecting and mitigating threat activity related to …

Russian Hackers Attacking Government Entity Using Stealthy Living-Off-the-Land Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ukrainian government organizations continue facing relentless cyber threats from Russian-backed threat actors employing sophisticated evasion techniques to maintain persistent network access. Recent investigations have uncovered coordinated campaigns targeting critical infrastructure …

Threat Actors Weaponizes Judicial Documents to Deliver PureHVNC RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Between August and October 2025, a sophisticated phishing campaign has emerged targeting Colombian and Spanish-speaking users through deceptive emails masquerading as official communications from Colombia’s Attorney General’s office. The campaign …

Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity experts at ANY.RUN recently unveiled alarming trends in how attackers are exploiting everyday technologies to bypass security operations centers (SOCs). They dissected tactics like QR code phishing, ClickFix social …

New Gentlemen’s RaaS Advertised on Hacking Forums Targeting Windows, Linux and ESXi Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered ransomware-as-a-service platform called Gentlemen’s RaaS has recently emerged on underground hacking forums, offering threat actors a sophisticated cross-platform attack capability. The service, advertised by the threat actor …

EY Data Leak – Massive 4TB SQL Server Backup Exposed Publicly on Microsoft Azure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive 4TB SQL Server backup file belonging to global accounting giant Ernst & Young (EY) was discovered publicly accessible on Microsoft Azure. The exposure, uncovered by cybersecurity firm Neo …

Huge Surge in Fake Investment Platforms Mimic Forex Exchanges Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fraudulent investment platforms impersonating cryptocurrency and forex exchanges have emerged as the predominant method used by financially motivated cybercriminals to defraud victims across Asia and beyond. These sophisticated scam operations …

Microsoft DNS Outage Disrupts Azure and Microsoft 365 Services Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft reported a DNS-related outage on October 29, 2025, affecting access to key services, including Microsoft Azure and Microsoft 365. The issue surfaced around 9:37 PM GMT+5:30, leaving users unable …