Top 20 Most Exploited Vulnerabilities of 2025: A Comprehensive Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape of 2025 has been marked by an unprecedented surge in vulnerability exploitation, with threat actors leveraging critical flaws across enterprise software, cloud infrastructure, and industrial systems. This …

CyberVolk Hackers Group With New VolkLocker Payloads Attacks both Linux and Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CyberVolk, a pro-Russia hacktivist group, has reemerged with a new ransomware platform called VolkLocker following a period of dormancy in 2025. The group, first documented in late 2024 for conducting …

New ConsentFix Attack Let Attackers Hijack Microsoft Accounts by Leveraging Azure CLI

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing attack technique called “ConsentFix” that combines OAuth consent phishing with ClickFix-style prompts to compromise Microsoft accounts without requiring passwords or multi-factor authentication. The attack leverages the …

NANOREMOTE Malware Leverages Google Drive API for Command-and-Control (C2) to Attack Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Windows backdoor named NANOREMOTE emerged in October 2025, presenting a significant threat to enterprise environments by leveraging legitimate cloud infrastructure for malicious purposes. This fully-featured malware utilizes …

New BlackForce Phishing Kit Lets Attackers Steal Credentials Using MitB Attacks and Bypass MFA

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing tool called BlackForce has emerged as a serious threat to organizations worldwide. First observed in August 2025, this professional-grade kit allows criminals to steal login information and …

Beware of Fake Leonardo DiCaprio Movie Torrent File Drops Agent Tesla Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat is targeting movie lovers who search for the latest films online. Cybercriminals are now using the popularity of Leonardo DiCaprio’s new film, One Battle After Another, to …

MITRE Releases Top 25 Most Dangerous Software Weaknesses of 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MITRE has unveiled its 2025 Common Weakness Enumeration (CWE™) Top 25 Most Dangerous Software Weaknesses list, highlighting the root causes behind 39,080 Common Vulnerability and Exposure (CVE™) records this year. …

Windows Remote Access Connection Manager Vulnerabilities Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical privilege escalation flaws were disclosed in the Windows Remote Access Connection Manager on December 9, 2025. The vulnerabilities, tracked as CVE-2025-62472 and CVE-2025-62474, allow authorized attackers with low-level …

CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An urgent warning about a critical security flaw in OSGeo GeoServer, a widely used open-source geographic data-sharing server. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, …

New Vulnerabilities in React Server Components Allow DoS Attacks and Source Code Leaks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Less than a week after addressing a critical Remote Code Execution (RCE) vulnerability, the React team has disclosed three additional security flaws affecting React Server Components (RSC). Security researchers discovered …