IPVanish VPN for macOS Vulnerability Let Attackers Escalate Privilege and Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical privilege escalation vulnerability has been discovered in the IPVanish VPN application for macOS. This flaw allows any unprivileged local user to execute arbitrary code as root without requiring …

Critical XSS Vulnerability in Angular i18n Enables Malicious Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

XSS Vulnerability in Angular i18n A high-severity Cross-Site Scripting (XSS) vulnerability, designated as CVE-2026-27970, has been discovered in Angular’s internationalization (i18n) pipeline. The vulnerability allows attackers to execute malicious JavaScript …

MS-Agent Vulnerability Let Attackers Hijack AI Agent to Gain Full System Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in a lightweight framework designed to enable AI agents to perform autonomous tasks. According to a vulnerability note published by the CERT/CC, this flaw …

HPE AutoPass Vulnerability Let Attackers Bypass Authentication Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HPE AutoPass Vulnerability A security bulletin has been issued regarding a vulnerability in the AutoPass License Server (APLS) that could allow attackers to remotely bypass authentication controls. The issue is …

CISA Warns of VMware Aria Operations Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware Aria Operations Vulnerability A critical vulnerability affecting VMware Aria Operations has been added to the Known Exploited Vulnerabilities (KEV) catalog. Broadcom recently issued a security advisory detailing a flaw …

Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT and Enables Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A supply chain attack targeting the PHP developer community has surfaced through Packagist, the official package repository for PHP and Laravel projects. Threat actor nhattuanbl published several packages that disguised a fully …

Windows 11 23H2 to 25H2 Upgrade Allegedly Breaking Internet Connectivity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows 11 23H2 to 25H2 Upgrade A persistent bug in Windows 11 in-place upgrades is reportedly wiping critical 802.1X wired authentication configurations, leaving enterprise workstations completely offline until manual intervention …

Coruna Exploit Kit With 23 Exploits Hacked Thousands of iPhones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Coruna iOS Exploit Kit Google’s Threat Intelligence Group (GTIG) has uncovered Coruna, a sophisticated iOS exploit kit containing 23 exploits across five full exploit chains that compromised thousands of iPhones …

SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A suspected India-aligned threat group known as SloppyLemming has been conducting a sustained espionage campaign against government agencies, defense organizations, nuclear oversight bodies, and critical infrastructure operators in Pakistan and …

Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor tracked as D-Shortiez has been running a persistent malvertising campaign that turns a WebKit browser behavior into a trap, forcing iOS Safari users into scam pages with …