China-Nexus Hackers Actively Exploiting React2Shell Vulnerability in The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China-nexus threat groups are racing to weaponize the new React2Shell bug, tracked as CVE-2025-55182, only hours after its public disclosure. The flaw sits in React Server Components and lets an …

PoC Exploit Released for Critical React, Next.js RCE Vulnerability (CVE-2025-55182)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit for CVE-2025-55182, a maximum-severity remote code execution (RCE) flaw in React Server Components, surfaced publicly this week, heightening alarms for developers worldwide. Dubbed “React2Shell” by some …

CISA and NSA Warns of BRICKSTORM Malware Attacking VMware ESXi and Windows Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Canadian Centre for Cyber Security (Cyber Centre) issued a joint advisory today, warning of a sophisticated …

Prompt Injection Flaw in GitHub Actions Hits Fortune 500 Firms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new class of prompt injection vulnerabilities, dubbed “PromptPwnd,” has been uncovered by cybersecurity firm Aikido Security. The flaws affect GitHub Actions and GitLab CI/CD pipelines that are integrated with …

SpyCloud Data Shows Corporate Users 3x More Likely to Be Targeted by Phishing Than by Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Austin, TX, USA, December 4th, 2025, CyberNewsWire Phishing has surged 400% year-over-year, highlighting need for real-time visibility into identity exposures. SpyCloud, the leader in identity threat protection, today released new …

New SVG Clickjacking Attack Let Attackers Create Interactive Clickjacking Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Clickjacking has long been considered a “dumb” attack in the cybersecurity world. Traditionally, it involves placing an invisible frame over a legitimate website to trick a user into clicking a …

CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerability has been added to CISA’s Known Exploited Vulnerabilities list, warning organizations about a dangerous file-upload flaw in OpenPLC ScadaBR systems. The vulnerability allows remote authenticated users to upload …

Arizona Attorney General Suses Chinese E-commerce Retailer Temu Over Data Theft Claims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Arizona Attorney General Kris Mayes has announced a lawsuit against the popular Chinese e-commerce retailer Temu, accusing the company of stealing vast amounts of customer data. The lawsuit, filed Tuesday, …

Lazarus Group’s IT Workers Scheme Hacker Group Caught Live On Camera

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lazarus Group’s Famous Chollima unit has been caught “live on camera” running its remote IT worker scheme, after researchers funneled its operatives into fake laptops that were actually long‑running sandbox …