Researchers Exploited Google kernelCTF Instances And Debian 12 With A 0-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers exploited CVE-2025-38001—a previously unknown Use-After-Free (UAF) vulnerability in the Linux HFSC queuing discipline—to compromise all Google kernelCTF instances (LTS, COS, and mitigation) as well as fully patched Debian 12 …

New Malware Attack Weaponizing LNK Files to Install The REMCOS Backdoor on Windows Machines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, cybersecurity teams have observed a surge in malicious campaigns exploiting Windows shortcut (LNK) files to deliver sophisticated backdoors. This new wave of attacks disguises LNK shortcuts as …

Threat Actors Exploitation Attempts Spikes as an Early Indicator of New Cyber Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a groundbreaking pattern that could revolutionize how organizations prepare for emerging threats. A comprehensive analysis reveals that spikes in malicious attacker activity against enterprise edge technologies …

Hackers Use AI to Create Malicious NPM Package that Drains Your Crypto Wallet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have escalated their attack sophistication by leveraging artificial intelligence to create a malicious NPM package that masquerades as a legitimate development tool while secretly draining cryptocurrency wallets. The package, …

Hackers Can Manipulate BitLocker Registry Keys Via WMI to Execute Malicious Code as Interactive User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel lateral movement technique that exploits BitLocker’s Component Object Model (COM) functionality to execute malicious code on target systems. The technique, demonstrated through the BitLockMove proof-of-concept tool, represents a …

Critical HashiCorp Vulnerability Let Attackers Execute Arbitrary Code on Underlying Host

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical HashiCorp security vulnerability affecting Vault Community Edition and Enterprise versions could allow privileged operators to execute arbitrary code on underlying host systems.  The vulnerability, tracked as CVE-2025-6000, affects …

AI-Powered Code Editor Cursor IDE Vulnerability Enables Remote Code Without User Interaction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in the popular AI-powered code editor Cursor IDE, dubbed “CurXecute,” allows attackers to execute arbitrary code on developers’ machines without any user interaction.  The vulnerability, tracked as …

NestJS Framework Vulnerability Let Attackers Execute Arbitrary Code in Developers Machine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the NestJS framework’s development tools that enables remote code execution (RCE) attacks against JavaScript developers.  The flaw, identified as CVE-2025-54782, affects the …