Critical AWS ClientVPN for macOS Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw in the AWS Client VPN for macOS has been disclosed, presenting a local privilege escalation risk to non-administrator users.  The vulnerability tracked as CVE-2025-11462 allows attackers to …

ASCII Smuggling Attack Lets Hackers Manipulate Gemini to Deliver Smuggled Data to Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers set out to test leading large language models (LLMs) for resilience against the long-standing ASCII Smuggling technique.  By embedding invisible control characters within seemingly harmless text, ASCII Smuggling abuses …

PoC Exploit Released for Critical Lua Engine Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three newly disclosed vulnerabilities have been identified in the Lua scripting engine of Redis 7.4.5, each presenting severe risks of remote code execution and privilege escalation.  Redrays has released a …

OpenAI Banned ChatGPT Accounts Used by Chinese Hackers to Develop Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI announced it has banned a series of ChatGPT accounts linked to Chinese state-affiliated hacking groups that used the AI models to refine malware and create phishing content. The October …

Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WordPress websites have become a prime target for threat actors seeking to monetize traffic and compromise visitor security. In recent months, a new malvertising campaign has emerged, leveraging silent PHP …

CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued a critical warning regarding a zero-day cross-site scripting (XSS) vulnerability in Synacor’s Zimbra Collaboration Suite (ZCS), designated as CVE-2025-27915.  This vulnerability has been actively exploited in attacks …

Attacks on Palo Alto PAN-OS Global Protect Login Portals Surge from 2,200 IPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive escalation in attacks targeting Palo Alto Networks PAN-OS GlobalProtect login portals, with over 2,200 unique IP addresses conducting reconnaissance operations as of October 7, 2025.  This represents a …

Multiple Chrome Vulnerabilities Expose Users to Arbitrary Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome version 141.0.7390.65/.66 for Windows and Mac, along with 141.0.7390.65 for Linux, addressing multiple critical security vulnerabilities that could allow attackers to execute arbitrary code on affected …

Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued a warning that both cybercriminals and state-sponsored threat actors are increasingly abusing the features and capabilities of Microsoft Teams throughout their attack chains. The platform’s extensive adoption …