Critical Vulnerability in Azure Bastion Let Attackers Bypass Authentication and Escalate privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Azure Bastion (CVE-2025-49752) allows remote attackers to bypass authentication mechanisms and escalate privileges to administrative levels. The flaw, categorized as an authentication bypass vulnerability, poses an …

Microsoft Confirms Windows 11 24H2 Update Broken Multiple Core Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially acknowledged a significant disruption affecting Windows 11 version 24H2 users, specifically after installing the cumulative update KB5062553 released in July 2025. The issue primarily affects environments using …

ShinyHunters Claims Data Theft from 200+ Companies via Salesforce Gainsight Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has reportedly compromised data across hundreds of organizations, linking the breach to a critical integration between customer success platform Gainsight and CRM giant Salesforce. The …

Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code …

Fired Techie Admits Hacking Employer’s Network in Retaliation for Termination

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A former IT contractor from Ohio has admitted to launching a cyberattack against his employer’s network in retaliation for being terminated, federal prosecutors announced this week. Maxwell Schultz, 35, of …

CrowdStrike Fires Insider for Sharing Internal System Details with Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity giant CrowdStrike has confirmed the termination of an insider who allegedly provided sensitive internal system details to a notorious hacking collective. The incident, which came to light late Thursday …

AI-Based Obfuscated Malicious Apps Evading AV Detection to Deploy Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of malicious Android applications impersonating a well-known Korean delivery service has emerged, featuring advanced obfuscation techniques powered by artificial intelligence. These apps work to bypass traditional antivirus …

Xillen Stealer With New Advanced Features Evade AI Detection and Steal Sensitive Data from Password Managers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Xillen Stealer, a sophisticated Python-based information stealer, has emerged as a significant threat in the cybercriminal landscape. Originally identified by Cyfirma in September 2025, this cross-platform malware has recently evolved …

Dark Web Job Market Evolved – Prioritizes Practical Skills Over Formal Education

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The dark web has transformed into a functioning parallel labor market where cyber specialists find employment through unconventional channels. Unlike traditional job boards, this shadow economy operates with distinct recruitment …