Apache Struts Vulnerability Let Attackers Trigger Disk Exhaustion Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in Apache Struts could allow attackers to trigger disk exhaustion attacks, rendering affected systems unusable. The vulnerability, tracked as CVE-2025-64775, stems from a file leak in …

Sonesta International Hotels Implements Industry-Leading Cloud Security Through AccuKnox Collaboration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Travel and hospitality industry leader Sonesta International Hotels partners with AccuKnox to deploy Zero Trust Integrated Application and Cloud Security [ASPM and CNAPP (Cloud Native Application Protection Platform)] for Microsoft …

Google Patches Android 0-Day Vulnerabilities Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released critical security updates to address multiple zero-day vulnerabilities affecting Android devices worldwide. The December 2025 security bulletin reveals that threat actors are actively exploiting at least two …

OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenVPN has released critical security updates for its 2.6 stable and 2.7 development branches, addressing three vulnerabilities that could lead to local denial-of-service (DoS), security bypasses, and buffer over-reads. The …

India Mandates ‘Undeletable’ Government Cybersecurity App for All Smartphones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

India’s Department of Telecommunications (DoT) has ordered smartphone manufacturers to preload a government-backed cybersecurity app, “Sanchar Saathi,” on all new devices sold in the country. The order, issued privately on …

Malicious VS Code Extension as Icon Theme Attacking Windows and macOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious Visual Studio Code extension posing as the popular “Material Icon Theme” has been used to attack Windows and macOS users, turning the add-on into a hidden backdoor. The …

Chinese Front Companies Providing Advanced Steganography Solutions for APT Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Advanced steganography techniques are becoming increasingly central to state-sponsored cyber operations. Recent analysis has exposed two Chinese technology companies, BIETA and CIII, that allegedly provide sophisticated steganography solutions to support …

KimJongRAT Attacking Windows Users via Weaponized .hta Files to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new remote access trojan dubbed KimJongRAT has surfaced, posing a severe threat to Windows users. This sophisticated malware is believed to be orchestrated by the Kimsuky group, a threat …

Hackers Registered 2,000+ Fake Holiday-Themed Online Stores to Steal User Payments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With the holiday shopping season kicking into high gear, a massive cybersecurity threat has emerged, putting online shoppers at significant risk. A coordinated campaign has been discovered, involving the registration …

BreachLock Named a Leader in 2025 GigaOm Radar Report for Penetration Testing as a Service (PTaaS) for Third Consecutive Year

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, New York, December 1st, 2025, CyberNewswire BreachLock, the global leader in Penetration Testing as a Service (PTaaS), has been named a Leader and Fast Mover in the 2025 GigaOm …