New Gentlemen Ransomware Leverages Legitimate Drivers, Group Policies to Infiltrate Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security researchers have observed a surge in activity by a previously undocumented ransomware group known as The Gentlemen. This threat actor has rapidly distinguished itself through the …

GitLab Patches Multiple Vulnerabilities That Enables Denial Of Service and SSRF Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released urgent security patches for its Community (CE) and Enterprise (EE) editions, addressing multiple vulnerabilities, including two high-severity flaws that could lead to Server-Side Request Forgery (SSRF) and …

Top 10 Best Mobile Application Penetration Testing Companies in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-quality mobile application penetration testing company is essential for businesses that want to safeguard their digital assets and user data. These specialized firms employ ethical hackers who simulate real-world …

Google Drive Desktop for Windows Vulnerability Grants Full Access to Another User’s Drive

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability has been found in the Google Drive Desktop application for Windows. It allows a logged-in user on a shared machine to access another user’s Drive files completely …

Microsoft Warns of Active Directory Domain Services Vulnerability, Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an updated warning for a critical security vulnerability in Active Directory Domain Services, tracked as CVE-2025-21293. This flaw could permit an attacker who has already gained initial …

Critical Microsoft Office Vulnerabilities Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released patches for two significant vulnerabilities in Microsoft Office that could allow attackers to execute malicious code on affected systems. The flaws, tracked as CVE-2025-54910 and CVE-2025-54906, were …

HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HackerOne has confirmed it was among the companies affected by a recent data breach that provided unauthorized access to its Salesforce instance. The access was gained through a compromise of …

Sophos Wireless Access Points Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sophos has resolved an authentication bypass vulnerability in its AP6 Series Wireless Access Points that could allow attackers to gain administrator-level privileges. The company discovered the issue during internal security …

Windows BitLocker Vulnerability Let Attackers Elevate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed two significant elevation of privilege vulnerabilities affecting its Windows BitLocker encryption feature. The flaws, tracked as CVE-2025-54911 and CVE-2025-54912, were disclosed on September 9, 2025, and carry …

Critical SAP NetWeaver Vulnerability Let Attackers Execute Arbitrary Code And Compromise System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability CVE-2025-42922 has been discovered in SAP NetWeaver that allows an authenticated, low-privileged attacker to execute arbitrary code and achieve a full system compromise. The flaw resides in …