DHS Asks OpenAI To Share Information on ChatGPT Prompts Used By Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Department of Homeland Security (DHS) has issued the first known federal search warrant compelling OpenAI to disclose user data tied to ChatGPT prompts. The warrant, unsealed last week in …

TARmageddon Vulnerability In Rust Library Let Attackers Replace Config Files And Execute Remote Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in the async-tar Rust library and its popular forks, including the widely used tokio-tar. Dubbed TARmageddon and tracked as CVE-2025-62518, the bug carries a CVSS score of …

Multiple Oracle VM VirtualBox Vulnerabilities Enables Complete Takeover Of VirtualBox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has disclosed multiple critical vulnerabilities in its Oracle VM VirtualBox virtualization software, potentially allowing attackers to achieve complete control over the VirtualBox environment. These flaws, detailed in the October …

Multiple BIND 9 DNS Vulnerabilities Enable Cache Poisoning and Denial Of Service Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Internet Systems Consortium (ISC) disclosed three high-severity vulnerabilities in BIND 9 on October 22, 2025, potentially allowing remote attackers to conduct cache poisoning attacks or cause denial-of-service (DoS) conditions …

Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloud account takeover attacks have evolved into a sophisticated threat as cybercriminals and state-sponsored actors increasingly weaponize OAuth applications to establish persistent access within compromised environments. These malicious actors are …

Critical Vulnerability in MCP Server Platform Exposes 3,000+ Servers and Thousands of API Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Smithery.ai, a popular registry for Model Context Protocol (MCP) servers. This issue could have allowed attackers to steal from over 3,000 AI servers and take API …

Canada Fines Cybercrime Friendly Cryptomus $176M

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Financial regulators in Canada this week levied $176 million in fines against Cryptomus, a digital payments platform that supports dozens of Russian cryptocurrency exchanges and websites hawking cybercrime services. The …

Critical Argument Injection Vulnerability in Popular AI Agents Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical argument injection flaw in three unnamed popular AI agent platforms enables attackers to bypass human approval safeguards and achieve remote code execution (RCE) through seemingly innocuous prompts. According …

SOCs Have a Quishing Problem: Here’s How to Solve It 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QR codes used to be harmless, now they’re one of the sneakiest ways attackers slip past defenses. Quishing, or QR code phishing, hides malicious links inside innocent-looking images that filters can’t read.  One scan, and the …

New PassiveNeuron Attacking Servers of High-Profile Organizations to Implant Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberespionage campaign dubbed PassiveNeuron has resurfaced with infections targeting government, financial, and industrial organizations across Asia, Africa, and Latin America. First detected in 2024, the campaign remained dormant …