Hackers Actively Scanning to Exploit Palo Alto Networks PAN-OS Global Protect Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers are observing a significant increase in internet-wide scans targeting the critical PAN-OS GlobalProtect vulnerability (CVE-2024-3400).  Exploit attempts have surged as attackers seek to leverage an arbitrary file creation …

Linux 6.17 Released With Fix for use-after-free Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Linus Torvalds has announced the release of Linux Kernel 6.17, a new version focused on stability and incremental improvements rather than groundbreaking features. The update brings a host of bug …

Tesla’s Telematics Control Unit Vulnerability Let Attackers Gain Code Execution as Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability in Tesla’s Telematics Control Unit (TCU) allowed attackers with physical access to bypass security measures and gain full root-level code execution. The flaw stemmed from an incomplete …

Lunar Spider Infected Windows Machine in Single Click and Harvested Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lunar Spider, a newly observed malware strain, has emerged as a potent threat to Windows environments by compromising systems in a single click. First detected in mid-September 2025, its operators …

Beer Brewing Giant Asahi Halts Production Following Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Japanese beverage conglomerate Asahi Group Holdings has halted production at its domestic factories following a significant cyberattack that crippled its systems on Monday. A company spokesperson confirmed on Tuesday that …

Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious npm package masquerading as the official Postmark MCP Server has been exfiltrating user emails to an external server.  This fake “postmark-mcp” module, available on npm from versions 1.0.0 …

VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A zero-day local privilege escalation vulnerability in VMware Tools and VMware Aria Operations is being actively exploited in the wild. The flaw, tracked as CVE-2025-41244, allows an unprivileged local attacker …

VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware has released an advisory to address three high-severity vulnerabilities in VMware Aria Operations, VMware Tools, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.  Disclosed on …

Critical Western Digital My Cloud NAS Devices Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Western Digital has released security updates for a critical vulnerability affecting multiple My Cloud network-attached storage (NAS) devices. The flaw, tracked as CVE-2025-30247, could allow a remote attacker to execute …

Apple Font Parser Vulnerability Enables Malicious Fonts to Crash or Corrupt Process Memory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has rolled out security updates across its operating systems to address a vulnerability in the Font Parser component that could allow malicious fonts to crash applications or corrupt process …