TP-Link Network Video Recorder Vulnerability Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two high-severity vulnerabilities in TP-Link VIGI network video recorder (NVR) systems could allow attackers to execute arbitrary commands on affected devices.  The security flaws, identified as CVE-2025-7723 and CVE-2025-7724, impact …

SharePoint 0-day Vulnerability Exploited in Wild by All Sorts of Hacker Groups

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in Microsoft SharePoint servers has become a playground for threat actors across the cybercriminal spectrum, with attacks ranging from opportunistic hackers to sophisticated nation-state groups since …

First Known LLM-Powered Malware From APT28 Hackers Integrates AI Capabilities into Attack Methodology

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The newly revealed LAMEHUG campaign signals a watershed moment for cyber-def: Russian state-aligned APT28 has fused a large language model (LLM) directly into live malware, allowing each infected host to …

Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated malware campaign where threat actors are exploiting Hangul Word Processor (.hwp) documents to distribute the notorious RokRAT malware. This marks a significant shift from …

NoName057(16)’s Hackers Attacked 3,700 Unique Devices Over Last Thirteen Months

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The pro-Russian hacktivist group NoName057(16) has orchestrated a massive distributed denial-of-service campaign targeting over 3,700 unique hosts across thirteen months, according to new research published on July 22, 2025. The …

Splunk Details on How to Detect, Mitigate and Respond to CitrixBleed 2 Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CitrixBleed 2 (CVE-2025-5777) erupted in 2025 when researchers uncovered an out-of-bounds read in Citrix NetScaler ADC and Gateway that lets an unauthenticated request siphon memory straight from the appliance. The …

New AI-Powered Wi-Fi Biometrics WhoFi Tracks Humans Behind Walls with 95.5% Accuracy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhoFi surfaced last on the public repository ArXiv, stunning security teams with a proof-of-concept that turns ordinary 2.4 GHz routers into covert biometric scanners. Unlike camera-based systems, this neural pipeline …

Metasploit Module Released For Actively Exploited SharePoint 0-Day Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have developed a new Metasploit exploit module targeting critical zero-day vulnerabilities in Microsoft SharePoint Server that are being actively exploited in the wild.  The module, designated as pull request …

Chinese Hackers Attacking Windows Systems in Targeted Campaign to Deploy Ghost RAT and PhantomNet Malwares

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat researchers are warning of twin Chinese-nexus espionage operations—“Operation Chat” and “Operation PhantomPrayers”—that erupted in the weeks preceding the Dalai Lama’s 90th birthday, exploiting heightened traffic to Tibetan-themed websites to …

GitLab Security Update – Patch for Multiple Vulnerabilities in Community and Enterprise Edition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released critical security patches addressing multiple vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE) platforms, with versions 18.2.1, 18.1.3, and 18.0.5 now available for immediate deployment.  …