Windows BitLocker Vulnerability Let Attackers Elevate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed two significant elevation of privilege vulnerabilities affecting its Windows BitLocker encryption feature. The flaws, tracked as CVE-2025-54911 and CVE-2025-54912, were disclosed on September 9, 2025, and carry …

Critical SAP NetWeaver Vulnerability Let Attackers Execute Arbitrary Code And Compromise System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability CVE-2025-42922 has been discovered in SAP NetWeaver that allows an authenticated, low-privileged attacker to execute arbitrary code and achieve a full system compromise. The flaw resides in …

Microsoft To Introduce New AI Actions In Windows File Explorer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is set to enhance the Windows user experience by integrating new AI-powered capabilities directly into File Explorer. This upcoming feature, named “AI actions in File Explorer,” will allow users …

Workday Confirms Data Breach – Hackers Accessed Customers Data and Case Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Workday has confirmed it suffered a data breach after a security incident involving a third-party application that compromised customer information. The breach originated from Salesloft’s Drift application, which connects to …

Chrome Security Update Patches Critical Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has issued an urgent security update for the Chrome browser on Windows, Mac, and Linux, addressing a critical vulnerability that could allow attackers to execute arbitrary code remotely. Users …

How to Enrich Alerts with Live Attack Data From 15K SOCs 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every SOC analyst knows the frustration. Your SIEM generates hundreds, sometimes thousands of alerts daily. Each alert demands attention, but with limited time and resources, how do you prioritize effectively? …

Microsoft September 2025 Patch Tuesday – 81 Vulnerabilities Fixed Including 22 RCE

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released its September 2025 Patch Tuesday updates, addressing a total of 81 security vulnerabilities across its product suite. The security patches cover a wide range of software, including …

Salat Stealer Exfiltrates Browser Credentials Via Sophisticated C2 Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Salat Stealer has emerged as a pervasive threat targeting Windows endpoints with a focus on harvesting browser-stored credentials and cryptocurrency wallet data. First detected in August 2025, this Go-based infostealer …

FortiDDoS OS Command Injection Vulnerability Let Attackers Execute Unauthorized Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has disclosed a medium-severity vulnerability in its FortiDDoS-F product line that could allow a privileged attacker to execute unauthorized commands. Tracked as CVE-2024-45325, the flaw is an OS command …