Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Threat Intelligence Group (GTIG) has issued a warning regarding the widespread exploitation of a critical security flaw in React Server Components. Known as React2Shell (CVE-2025-55182), this vulnerability allows attackers to …

Empire 6.3.0 Launches With New Features for Red Teams and Penetration Testers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BC Security has announced the release of Empire 6.3.0, the latest iteration of the widely used post-exploitation and adversary emulation framework. This update reinforces Empire’s position as a premier tool for …

CISA Warns of Google Chromium 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical zero-day vulnerability in Google Chromium’s ANGLE graphics engine to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2025-14174, …

Rust-Based Luca Stealer Spreads Across Linux and Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are increasingly abandoning traditional languages like C and C++ in favor of modern alternatives such as Golang, Rust, and Nim. This strategic shift enables developers to compile malicious …

New Phantom Stealer Campaign Hits Windows Machines Through ISO Mounting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered a sophisticated phishing campaign originating in Russia that deploys the Phantom information-stealing malware via malicious ISO files. The attack, dubbed “Operation MoneyMount-ISO,” targets finance and accounting departments …

Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple patches two WebKit zero-day flaws actively exploited in sophisticated attacks targeting specific iPhone users running iOS versions prior to 26.​ The iOS 26.2 and iPadOS 26.2 updates, released December …

Kali Linux 2025.4 Released With 3 New Hacking Tools and Wifipumpkin3

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kali Linux 2025.4, released with substantial desktop environment improvements, full Wayland support across virtual machines, and three powerful new hacking tools, including the much-anticipated Wifipumpkin3.​ Released on December 12, 2025, …

Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Torrance, United States / California, December 12th, 2025, CyberNewsWire In December 2025, CVE-2025-55182 (React2Shell), a vulnerability in React Server Components (RSC) that enables remote code execution (RCE), was publicly disclosed. …

New JSCEAL Infostealer Malware Attacking Windows Systems to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

JSCEAL has emerged as a serious threat to Windows users, specifically targeting those who work with cryptocurrency applications and valuable accounts. First reported by Check Point Research in July 2025, …

New AiTM Attack Campaign That Bypasses MFA Targeting Microsoft 365 and Okta Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged that successfully bypasses multi-factor authentication, protecting Microsoft 365 and Okta users, representing a serious threat to organizations relying on these platforms for identity management. …