Redis Server Vulnerability use-after-free Vulnerability Enables Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical use-after-free vulnerability, identified as CVE-2025-49844, has been discovered in Redis servers, enabling authenticated attackers to achieve remote code execution. This high-severity flaw affects all versions of Redis that …

Hackers Weaponize AWS X-Ray Service to Work as Covert Command & Control Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated technique uncovered where threat actors abuse Amazon Web Services‘ X-Ray distributed tracing service to establish covert command and control (C2) communications, demonstrating how legitimate cloud infrastructure can be …

QNAP NetBak Replicator Vulnerability Let Attackers Execute Unauthorized Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP has released a security advisory detailing a vulnerability in its NetBak Replicator utility that could allow local attackers to execute unauthorized code. The flaw, identified as CVE-2025-57714, has been …

How Windows Command-line Utility PsExec Can Be Abused To Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PsExec represents one of the most contradictory tools in the cybersecurity landscape, a legitimate system administration utility that has become a cornerstone of malicious lateral movement campaigns. Recent threat intelligence …

PoC Exploit Released for Remotely Exploitable Oracle E-Business Suite 0-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in Oracle E-Business Suite has emerged as a significant threat to enterprise environments, with proof-of-concept (PoC) exploit code now publicly available.  CVE-2025-61882 presents a severe security …

Hackers Exploit Zimbra Vulnerability as 0-Day with Weaponized iCalendar Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A zero-day vulnerability in the Zimbra Collaboration Suite (ZCS) was actively exploited in targeted attacks earlier in 2025. The flaw, identified as CVE-2025-27915, is a stored cross-site scripting (XSS) vulnerability …

New WireTap Attack Break Server SGX To Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability, named the WireTap attack, allows attackers with physical access to break the security of Intel’s Software Guard eXtensions (SGX) on modern server processors and steal sensitive …

Unity Real-Time Development Platform Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Unity Technologies has issued a critical security advisory warning developers about a high-severity vulnerability affecting its widely used game development platform.  The flaw, designated CVE-2025-59489, exposes applications built with vulnerable …

Microsoft to Disable Inline SVG Images Display to Outlook for Web and Windows Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced a significant security enhancement for Outlook users, implementing the retirement of inline SVG image support across Outlook for Web and the new Outlook for Windows platforms.  This …

New CometJacking Attack Let Attackers Turn Perplexity Browser Against You in One Click

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A groundbreaking cybersecurity vulnerability has emerged that transforms Perplexity’s AI-powered Comet browser into an unintentional collaborator for data theft.  Security researchers at LayerX have discovered a sophisticated attack vector dubbed …