Monsta web-based FTP Remote Code Execution Vulnerability Exploited

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability in Monsta FTP, a popular web-based FTP client used by financial institutions and enterprises worldwide. The flaw, now tracked as CVE-2025-34299, affects multiple versions of …

HackGPT: AI-Powered Penetration Testing Platform Includes GPT-4 and Other AI Engines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HackGPT Enterprise is a new tool made for security teams focuses on being scalable and compliant, meeting the growing need for effective vulnerability assessments. The platform supports multi-model AI, including …

Cybersecurity News Weekly Newsletter – Android and Cisco 0-Day, Teams Flaws, HackedGPT, and Whisper Leak

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Welcome to this week’s edition of the Cybersecurity News Weekly Newsletter, where we dissect the latest threats shaking the digital landscape. As cyber risks evolve faster than ever, staying ahead …

New Whisper Leak Toolkit Exposes User Prompts to Popular AI Agents within Encrypted Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated side-channel attack that exposes the topics of conversations with AI chatbots, even when traffic is protected by end-to-end encryption. Dubbed “Whisper Leak,” this vulnerability allows eavesdroppers such as …

Seven QNAP Zero-Day Vulnerabilities Exploited at Pwn2Own 2025 Now Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP has addressed seven critical zero-day vulnerabilities in its network-attached storage (NAS) operating systems, following their successful exploitation by security researchers at Pwn2Own Ireland 2025. These flaws, identified as CVE-2025-62847, …

Google Maps Adds Feature for Businesses to Report Ransom Demands for Removing Bad Reviews

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Scammers are targeting businesses with a new extortion scheme, and Google Maps is fighting back with a dedicated reporting tool. Google has introduced a feature that allows business owners to …

Hackers Hijack Samsung Galaxy Phones via 0-Day Exploit Using a Single WhatsApp Image

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated spyware operation targeting Samsung Galaxy devices, dubbed LANDFALL, which exploited a zero-day vulnerability to infiltrate phones through seemingly innocuous images shared on WhatsApp. This campaign, active since mid-2024, …

Threat Actors Leveraging RDP Credentials to Deploy Cephalus Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified ransomware group, Cephalus, has emerged as a significant threat to organizations worldwide, exploiting stolen Remote Desktop Protocol (RDP) credentials to gain access to networks and deploy powerful …

German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

German hosting provider aurologic GmbH has emerged as a central facilitator within the global malicious infrastructure ecosystem, providing upstream transit and data center services to numerous high-risk hosting networks. Operating …