Cloudflare API Outage Linked to React useEffect Bug Causes Service Overload and Recovery Failure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare has published a detailed post-mortem explaining the significant outage on September 12, 2025, that made its dashboard and APIs unavailable for over an hour. The company traced the incident …

0-Click ChatGPT Agent Vulnerability Allows Sensitive Data Exfiltration from Gmail

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A zero-click vulnerability discovered in ChatGPT’s Deep Research agent allowed attackers to exfiltrate sensitive data from a user’s Gmail account without any user interaction. The flaw, which OpenAI has since …

Top 10 Best Model Context Protocol (MCP) Servers in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In 2025, the Model Context Protocol (MCP) revolutionizes AI agent integration, making it seamless for tools, databases, and workflows to work harmoniously in enterprises and developer workspaces. Top MCP servers …

Windows 11 Notepad to Get AI Support for Free to Generate and Summarize Text

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is integrating free, on-device artificial intelligence capabilities into the classic Notepad application for Windows 11 users with Copilot+ PCs. The update introduces powerful text generation and editing tools, including …

Hackers Injecting Malicious Code into GitHub Actions Workflows to Steal PyPI Publishing Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers injected malicious code into GitHub Actions workflows in a widespread campaign to steal Python Package Index (PyPI) publishing tokens. While some tokens stored as GitHub secrets were successfully exfiltrated, …

Critical Microsoft’s Entra ID Vulnerability Allows Attackers to Gain Complete Administrative Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Microsoft’s Entra ID could have allowed an attacker to gain complete administrative control over any tenant in Microsoft’s global cloud infrastructure. The flaw, now patched, was …

Palo Alto Networks Acknowledges SquareX Research on Limitations of SWGs Against Last Mile Reassembly Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SquareX first discovered and disclosed Last Mile Reassembly attacks at DEF CON 32 last year, warning the security community of 20+ attacks that allow attackers to bypass all major SASE/SSE …

New ‘shinysp1d3r’ Ransomware-as-a-service in Active Development to Encrypt VMware ESXi Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Emerging in mid-2025, the shinysp1d3r ransomware-as-a-service (RaaS) platform represents the next evolution of cloud-focused extortion tools. Unlike traditional ransomware that targets Windows endpoints or network file shares, shinysp1d3r is engineered …

PureVPN Vulnerability Exposes Users IPv6 Address While Toggling Wi-Fi

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PureVPN’s Linux clients leak users’ IPv6 addresses when Wi-Fi reconnections or system resumes occur, and also obliterate host firewall rules without restoring them upon disconnect.  This undermines privacy guarantees and …

SonicWall Urges Customers to Reset Login Credentials After Configuration Backup Files Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has issued an urgent advisory urging all customers to perform an Essential Credential Reset after security researchers discovered that MySonicWall configuration backup files were inadvertently exposed on public storage.  …