Critical Argument Injection Vulnerability in Popular AI Agents Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical argument injection flaw in three unnamed popular AI agent platforms enables attackers to bypass human approval safeguards and achieve remote code execution (RCE) through seemingly innocuous prompts. According …

SOCs Have a Quishing Problem: Here’s How to Solve It 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QR codes used to be harmless, now they’re one of the sneakiest ways attackers slip past defenses. Quishing, or QR code phishing, hides malicious links inside innocent-looking images that filters can’t read.  One scan, and the …

New PassiveNeuron Attacking Servers of High-Profile Organizations to Implant Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberespionage campaign dubbed PassiveNeuron has resurfaced with infections targeting government, financial, and industrial organizations across Asia, Africa, and Latin America. First detected in 2024, the campaign remained dormant …

New Tykit Phishing Kit Mimics Microsoft 365 Login Pages to Steal Corporate Account Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing kit dubbed Tykit, which impersonates Microsoft 365 login pages to harvest corporate credentials. First detected in May 2025, the kit has surged in activity during September and …

Lumma Infostealer Malware Attacks Users to Steal Browser Cookies, Cryptocurrency Wallets and VPN/RDP Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since its emergence in August 2022, Lumma Infostealer has rapidly become a cornerstone of malware-as-a-service platforms, enabling even unskilled threat actors to harvest high-value credentials. Delivered primarily via phishing sites …

Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has urgently released patch versions 18.5.1, 18.4.3, and 18.3.5 for its Community Edition (CE) and Enterprise Edition (EE) to address multiple critical security flaws, including several high-severity denial-of-service (DoS) …

Decoding Microsoft 365 Audit Log Events Using Bitfield Mapping Technique – Investigation Report

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

When users authenticate to Microsoft cloud services, their activities generate authentication events recorded across multiple logging systems. Microsoft Entra sign-in logs and Microsoft 365 audit logs capture identical authentication events …

Chinese Hackers Using ToolShell Vulnerability To Compromise Networks Of Government Agencies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China-based threat actors have exploited the critical ToolShell vulnerability in Microsoft SharePoint servers to infiltrate networks across multiple continents, targeting government agencies and critical infrastructure in a suspected espionage campaign. …

Critical Vulnerability In Oracle E-Business Suite’s Marketing Product Allows Full Access To Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has disclosed two critical vulnerabilities in its E-Business Suite’s Marketing product that could hand full control to remote attackers. Dubbed CVE-2025-53072 and CVE-2025-62481, these flaws affect the Marketing Administration …

Azure Apps Vulnerability Lets Hackers Create Malicious Apps Mimicking Microsoft Teams

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security flaws in Microsoft’s Azure ecosystem enable cybercriminals to create deceptive applications that imitate official services like the “Azure Portal. Varonis found that Azure’s safeguards, designed to block reserved names …