Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Industrial Video & Control’s Longwatch video surveillance system, allowing attackers to execute malicious code with elevated privileges remotely. The flaw, tracked as CVE-2025-13658, …

Hackers Can Weaponize Claude Skills to Execute MedusaLocker Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new feature in Anthropic’s Claude AI, known as Claude Skills, has been identified as a potential vector for ransomware attacks. This feature, designed to extend the AI’s capabilities through …

Hackers Exploit Critical Yearn Finance’s yETH Pool Vulnerability to Steal $9 Million in Ethereum

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The decentralized finance sector witnessed a devastating breach targeting Yearn Finance’s yETH pool, resulting in the theft of approximately $9 million on November 30, 2025. The attacker executed a highly …

29.7 Tbps DDoS Attack Via Aisuru Botnet Breaks Internet With New World Record

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new 29.7 Tbps distributed denial-of-service (DDoS) blast from the Aisuru botnet has set a new world record for attack volume, underscoring how fragile core internet infrastructure remains under extreme …

Hackers Using Calendly-Themed Phishing Attack to Steal Google Workspace Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged targeting business professionals with Calendly-themed emails, combining social engineering with advanced credential theft techniques. The attack specifically focuses on Google Workspace and Facebook Business …

K7 Antivirus Vulnerability Allows Attackers Gain SYSTEM-level Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious privilege escalation vulnerability in K7 Ultimate Security, an antivirus product from K7 Computing, was found by abusing named pipes with overly permissive access control lists. This flaw enables …

Shai-Hulud 2.0 Malware Attack Compromised 30,000 Repositories and Stolen 500 GitHub Usernames and Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant supply chain security breach has emerged with the discovery of Shai-Hulud 2.0, a sophisticated malware that has compromised over 30,000 GitHub repositories since its emergence on November 24, …

Malicious Rust Evm-Units Mimic as EVM Version Silently Executes OS-specific Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The open-source software supply chain recently encountered a deceptive threat in the form of evm-units, a malicious Rust crate published by the author ablerust. Masquerading as a standard utility for …

Storm-0900 Hackers Leveraging Parking Ticket and Medical Test Themes in Massive Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On Thanksgiving eve, a sophisticated threat actor known as Storm-0900 launched a high-volume phishing campaign targeting users across the United States. Microsoft Threat Intelligence security analysts detected and blocked this …

Microsoft Patched Windows LNK Vulnerability Abused by Hackers to Hide Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has silently patched a Windows shortcut vulnerability that threat actors have been exploiting since 2017 to hide malicious commands from users inspecting file properties. The flaw, tracked as CVE-2025-9491, …