Magento Input Validation Vulnerability Exploited In Wild To Hijack Session And Execute Malicious Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Magento, the popular e-commerce platform, is now rebranded as Adobe Commerce. Dubbed SessionReaper and tracked as CVE-2025-54236, this improper input validation flaw allows attackers to hijack …

Microsoft Details ASP.NET Vulnerability That Enables Attackers To Smuggle HTTP Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued a critical security update for ASP.NET Core to address CVE-2025-55315, a high-severity flaw that enables HTTP request smuggling and could allow attackers to bypass key security controls. …

Docker Compose Vulnerability Allow Attacks To Overwrite Arbitrary Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Docker Compose, a cornerstone tool for developers managing containerized application harbors a high-severity vulnerability that lets attackers overwrite files anywhere on a host system. Discovered in early October 2025 by …

New Android Malware Herodotus Mimic Human Behaviour to Bypass Biometrics Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android banking trojan named Herodotus has emerged on the mobile threat landscape, introducing groundbreaking techniques to evade detection systems. During routine monitoring of malicious distribution channels, the Mobile …

New Phishing Attack Using Invisible Characters Hidden in Subject Line Using MIME Encoding

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have developed a sophisticated phishing technique that exploits invisible characters embedded within email subject lines to evade automated security filters. This attack method leverages MIME encoding combined with Unicode …

Tata Motors Data Leak – 70+ TB of Sensitive Info and Test Drive Data Exposed via AWS Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researcher Eaton Zveare has disclosed critical vulnerabilities in Tata Motors’ systems that exposed over 70 terabytes of sensitive data, including customer personal information, financial reports, and fleet management details. …

Pentest Copilot – AI-based Ethical Hacking Tool to Streamline Penetration Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pentest Copilot is an innovative open-source tool that leverages AI to help ethical hackers streamline penetration testing workflows. This browser-based assistant integrates large language models to automate tasks while preserving …

Aisuru Botnet Shifts from DDoS to Residential Proxies

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Aisuru, the botnet responsible for a series of record-smashing distributed denial-of-service (DDoS) attacks this year, recently was overhauled to support a more low-key, lucrative and sustainable business: Renting hundreds of …

Threat Actors Advertising Anivia Stealer Malware on Dark Web bypassing UAC Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated information-stealing malware named Anivia Stealer has emerged on underground forums, marketed by a threat actor known as ZeroTrace. The malware represents a dangerous evolution in credential theft operations, …

Threat Actors Merging FileFix and Cache Smuggling Attacks to Evade Security Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated phishing campaign that combines two emerging attack techniques to bypass conventional security defenses. The hybrid approach merges FileFix social engineering tactics with cache smuggling …