WhatsApp 0-Click Vulnerability Exploited Using Malicious DNG File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp 0-click remote code execution (RCE) vulnerability affecting Apple’s iOS, macOS, and iPadOS platforms, detailed with a proof of concept demonstration. The attack chain exploits two distinct vulnerabilities, identified as …

SUSE Rancher Vulnerabilities Let Attackers Lockout the Administrators Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw in SUSE Rancher’s user management module allows privileged users to disrupt administrative access by modifying usernames of other accounts.  Tracked as CVE-2024-58260, this vulnerability affects Rancher Manager …

ThreatBook Launches Best-of-Breed Advanced Threat Intelligence Solution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Singapore, Singapore, September 29th, 2025, CyberNewsWire Analyzing over 14 billion cyber-attack records daily, ThreatBook ATI is a global solution enriched with granular, local insights; and can offer organizations a truly …

Lesson From Cisco ASA 0-Day RCE Vulnerability That Actively Exploited In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape experienced a significant escalation in September 2025, when Cisco disclosed multiple critical zero-day vulnerabilities affecting its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) platforms. At …

Formbricks Signature Verification Vulnerability Let Attackers Reset User Passwords Without Authorization

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw discovered in Formbricks, an open-source experience management platform, demonstrates how missing JWT signature verification can lead to complete account takeovers.  The vulnerability tracked as CVE-2025-59934 affects …

Windows Heap Exploitation Vulnerability With Record’s Size Field Leads to Arbitrary R/W

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Windows heap management demonstrates how improper handling of record-size fields enables arbitrary memory read and write operations.  Suraj Malhotra shared a detailed exploitation technique leveraging the …

Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers are raising alarms about a growing threat vector as malicious actors increasingly exploit Dynamic DNS providers to establish robust command and control infrastructure. These publicly rentable subdomain services, …

Notepad++ DLL Hijacking Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered DLL hijacking vulnerability in Notepad++, the popular source code editor, could allow attackers to execute arbitrary code on a victim’s machine. Tracked as CVE-2025-56383, the flaw exists …

Cybersecurity Newsletter Weekly – Chrome 0-Day, 22.2 Tbps DDOS Attack, Kali Linux Release, Cisco IOS 0-Day and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

This week in cybersecurity was marked by a relentless pace of critical disclosures and unprecedented attack volumes, underscoring the escalating challenges facing defenders. At the forefront was Google’s emergency patch …