Akamai Patches HTTP Request Smuggling Vulnerability in Edge Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical HTTP request smuggling vulnerability in Akamai’s edge server infrastructure has been successfully fixed. The vulnerability, identified as CVE-2025-66373, stemmed from improper processing of HTTP requests containing invalid chunk-encoded …

CISA Releases Five ICS Advisories Covering Vulnerabilities, and Exploits Surrounding ICS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency released five critical Industrial Control Systems advisories on December 2, 2025, addressing significant security threats across industrial environments. These advisories cover vulnerabilities and active …

New Scanner Tool for Detecting Exposed ReactJS and Next.js RSC Endpoints (CVE-2025-55182)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security assessment tool has been released to help researchers and administrators identify React Server Components (RSC) endpoints potentially exposed to CVE-2025-55182. Developed as a lightweight by Pentester with …

New Report Warns of 68% Of Actively Serving Phishing Kits Protected by CloudFlare

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security report reveals a troubling reality about the state of online phishing operations. Recent research has uncovered over 42,000 validated URLs and domains actively serving phishing kits, command-and-control …

Operation DupeHike Attacking Employees Using Weaponized Documents DUPERUNNER Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack campaign known as Operation DupeHike has emerged as a significant threat to Russian corporate environments, specifically targeting employees within human resources, payroll, and administrative departments. The campaign, …

Critical React and Next.js Enables Remote Attackers to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in React and Next.js could let remote attackers run malicious code on servers without logging in. The issue affects React Server Components (RSC) and the “Flight” …

Threat Actors Using Malicious VSCode Extension to Deploy Anivia Loader and OctoRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fake Visual Studio Code extension has been used in a supply chain attack that targets developers through their editor. The rogue extension, named prettier-vscode-plus and posing as the trusted …

India’s New SIM-Binding Rule for WhatsApp, Signal, Telegram and Other Messaging Platforms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

India has implemented a mandatory SIM-binding requirement for messaging applications, including WhatsApp, Telegram, Signal, Snapchat, and others. The Department of Telecommunications issued a directive on November 28 requiring all app-based …

Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Industrial Video & Control’s Longwatch video surveillance system, allowing attackers to execute malicious code with elevated privileges remotely. The flaw, tracked as CVE-2025-13658, …

Hackers Can Weaponize Claude Skills to Execute MedusaLocker Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new feature in Anthropic’s Claude AI, known as Claude Skills, has been identified as a potential vector for ransomware attacks. This feature, designed to extend the AI’s capabilities through …