New VoidLink Cloud-Native Malware Attacking Linux Systems with Self-deletion Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new cloud-focused malware framework called VoidLink has emerged targeting Linux systems with advanced evasion techniques and self-deletion capabilities. Written in the Zig programming language, this malware represents a major …

Critical ServiceNow Vulnerability Enables Privilege Escalation Via Unauthenticated User Impersonation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security threat to ServiceNow AI Platform deployments, allowing unauthenticated attackers to impersonate legitimate users and execute unauthorized operations. The vulnerability, CVE-2025-12420, was discovered by AppOmni, a SaaS security …

CISA Warns of Gogs Path Traversal Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical warning about a path traversal vulnerability in Gogs, a self-hosted Git service, that is being actively exploited in the wild. The vulnerability, tracked as CVE-2025-8110, was added to …

DPRK’s Remote Workers Generating $600M Using Identity Theft to Gain Access to Sensitive Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has undergone a fundamental shift in recent years, as the definition of insider threats continues to evolve. For decades, organizations focused their security efforts on detecting disgruntled …

New Angular Vulnerability Enables an Attacker to Execute Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical Cross-Site Scripting (XSS) vulnerability has been discovered in Angular’s Template Compiler, affecting multiple versions of both @angular/compiler and @angular/core packages. Tracked as CVE-2026-22610, this vulnerability allows attackers to …

Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Facebook users are increasingly becoming targets of a sophisticated phishing technique that bypasses conventional security measures. With over three billion active users on the platform, Facebook represents an attractive target …

100,000+ n8n Instances Exposed to Internet Vulnerable to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting the popular n8n workflow automation platform has put over 100,000 internet-exposed instances at severe risk. Security researchers from The Shadowserver Foundation discovered that 105,753 unique n8n …

AsyncRAT Leveraging Cloudflare’s Free-Tier Services to Mask Malicious Activities and Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent AsyncRAT campaign is using Cloudflare’s free tier services and TryCloudflare tunnels to hide remote access activity inside normal looking cloud traffic. In these attacks, threat actors send phishing …

Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hikvision, a leading provider of surveillance and access control systems, faces serious security risks from two newly disclosed stack overflow vulnerabilities. These flaws, tracked as CVE-2025-66176 and CVE-2025-66177, allow attackers …

Malicious Chrome Extension Steals Wallet Login Credentials and Enables Automated Trading

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious Chrome extension called MEXC API Automator is abusing trust in browser add-ons to steal cryptocurrency trading access from MEXC users. Posed as a tool that helps automate trading …