Yurei Ransomware Leverages SMB Shares and Removable Drives to Encrypt Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Yurei ransomware first emerged in early September 2025, targeting Windows environments with a sophisticated Go-based payload designed for rapid, large-scale encryption. Once executed, the malware enumerates all accessible local and …

ClamAV 1.5.0 Released with New MS Office and PDF Verification Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has announced the release of ClamAV 1.5.0, a significant update to the open-source antivirus engine that introduces major security enhancements, new document scanning capabilities, and extensive API improvements. This …

Critical AWS ClientVPN for macOS Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw in the AWS Client VPN for macOS has been disclosed, presenting a local privilege escalation risk to non-administrator users.  The vulnerability tracked as CVE-2025-11462 allows attackers to …

ASCII Smuggling Attack Lets Hackers Manipulate Gemini to Deliver Smuggled Data to Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers set out to test leading large language models (LLMs) for resilience against the long-standing ASCII Smuggling technique.  By embedding invisible control characters within seemingly harmless text, ASCII Smuggling abuses …

PoC Exploit Released for Critical Lua Engine Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three newly disclosed vulnerabilities have been identified in the Lua scripting engine of Redis 7.4.5, each presenting severe risks of remote code execution and privilege escalation.  Redrays has released a …

OpenAI Banned ChatGPT Accounts Used by Chinese Hackers to Develop Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI announced it has banned a series of ChatGPT accounts linked to Chinese state-affiliated hacking groups that used the AI models to refine malware and create phishing content. The October …

Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WordPress websites have become a prime target for threat actors seeking to monetize traffic and compromise visitor security. In recent months, a new malvertising campaign has emerged, leveraging silent PHP …

CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued a critical warning regarding a zero-day cross-site scripting (XSS) vulnerability in Synacor’s Zimbra Collaboration Suite (ZCS), designated as CVE-2025-27915.  This vulnerability has been actively exploited in attacks …

Attacks on Palo Alto PAN-OS Global Protect Login Portals Surge from 2,200 IPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive escalation in attacks targeting Palo Alto Networks PAN-OS GlobalProtect login portals, with over 2,200 unique IP addresses conducting reconnaissance operations as of October 7, 2025.  This represents a …

Multiple Chrome Vulnerabilities Expose Users to Arbitrary Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome version 141.0.7390.65/.66 for Windows and Mac, along with 141.0.7390.65 for Linux, addressing multiple critical security vulnerabilities that could allow attackers to execute arbitrary code on affected …