Shannon – AI Pentesting Tool that Autonomously Checks for Code Vulnerabilities and Executes Real Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Shannon is a fully autonomous AI pentesting tool for web applications that identifies attack vectors via code analysis and validates them with live browser exploits. Unlike traditional static analysis tools …

Storm-0249 Abusing EDR Process Via Sideloading to Hide Malicious Activity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Storm-0249, once known primarily as a mass phishing group, has undergone a significant transformation into a sophisticated initial access broker specializing in precision attacks. This evolution marks a critical shift …

Microsoft December 2025 Security Updates Breaking Message Queuing (MSMQ) Functionality Affects IIS Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s December 2025 security updates have unleashed an unexpected headache for enterprise admins relying on Message Queuing (MSMQ). Installed via KB5071546 on December 9, the patch targeting OS Build 19045.6691 …

New Gentlemen Ransomware Breaching Corporate Networks to Exfiltrate and Encrypt Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Gentlemen ransomware, first identified in August 2025, has rapidly evolved into a significant threat targeting corporate networks globally. Operating on a double extortion model, this group exfiltrates sensitive data before …

Windows Remote Access Connection Manager Vulnerability Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security issue involving the Windows Remote Access Connection Manager (RasMan) that allows local attackers to execute arbitrary code with System privileges. While investigating CVE-2025-59230, the vulnerability that Microsoft addressed …

CISA Adds Sierra Router Vulnerability to KEV Catalogue Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting Sierra Wireless routers has been added to its Known Exploited Vulnerabilities (KEV) catalog. This decision comes after evidence emerged that the flaw is being actively exploited …

CISA Releases Guidance for Managing UEFI Secure Boot on Enterprise Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in coordination with the National Security Agency (NSA), has issued new guidance urging enterprises to verify and manage UEFI Secure Boot configurations …

Cybersecurity News Weekly Newsletter – Windows, Chrome, and Apple 0-days, Kali Linux 2025.4, and MITRE Top 25

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As 2025 nears its close, the cybersecurity landscape shows no signs of slowing down. This week’s developments highlight how rapidly the threat environment continues to evolve with major zero-day vulnerabilities …

CISA Warns of Windows Cloud Files Mini Filter 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical alert regarding an active zero-day vulnerability affecting the Microsoft Windows Cloud Files Mini Filter The vulnerability poses a significant risk to organizations running affected Windows systems and requires …

7 Best Security Awareness Training Platforms For MSPs in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Managed service providers (MSPs) are increasingly popular cyberattack targets. These entities often have numerous endpoints and distributed networks that create many opportunities for adversaries seeking weaknesses to exploit. Security awareness …