Hackers Can Manipulate BitLocker Registry Keys Via WMI to Execute Malicious Code as Interactive User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel lateral movement technique that exploits BitLocker’s Component Object Model (COM) functionality to execute malicious code on target systems. The technique, demonstrated through the BitLockMove proof-of-concept tool, represents a …

Critical HashiCorp Vulnerability Let Attackers Execute Arbitrary Code on Underlying Host

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical HashiCorp security vulnerability affecting Vault Community Edition and Enterprise versions could allow privileged operators to execute arbitrary code on underlying host systems.  The vulnerability, tracked as CVE-2025-6000, affects …

AI-Powered Code Editor Cursor IDE Vulnerability Enables Remote Code Without User Interaction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in the popular AI-powered code editor Cursor IDE, dubbed “CurXecute,” allows attackers to execute arbitrary code on developers’ machines without any user interaction.  The vulnerability, tracked as …

NestJS Framework Vulnerability Let Attackers Execute Arbitrary Code in Developers Machine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the NestJS framework’s development tools that enables remote code execution (RCE) attacks against JavaScript developers.  The flaw, identified as CVE-2025-54782, affects the …

Microsoft PlayReady DRM Used by Netflix, Amazon, and Disney+ Leaked Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security breach has compromised Microsoft’s PlayReady Digital Rights Management (DRM) system, exposing critical certificates that protect premium streaming content across major platforms including Netflix, Amazon Prime Video, and …

Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape continues to evolve as threat actors develop increasingly sophisticated methods to compromise Windows systems. A new ransomware variant known as Interlock has emerged as a significant threat, …

APT37 Hackers Weaponizes JPEG Files to Attack Windows System Leveraging “mspaint.exe” File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new wave of cyberattacks attributed to North Korea’s notorious APT37 (Reaper) group is leveraging advanced malware hidden within JPEG image files to compromise Microsoft Windows systems, signaling a …

Cybersecurity News Recap – Chrome, Gemini Vulnerabilities, Linux Malware, and Man-in-the-Prompt Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Welcome to this week’s edition of Cybersecurity News Recap! In this issue, we bring you the latest updates and critical developments across the threat landscape. Stay ahead of risks with key …

New Undectable Plague Malware Attacking Linux Servers to Gain Persistent SSH Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Linux backdoor dubbed Plague has emerged as an unprecedented threat to enterprise security, evading detection across all major antivirus engines while establishing persistent SSH access through manipulation of …