OpenAI Codex CLI Command Injection Vulnerability Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has patched a command injection flaw in its Codex CLI tool that allowed attackers to execute arbitrary commands on developers’ machines simply by getting a malicious configuration file into …

Microsoft Azure API Management Flaw Enables Cross-Tenant Account Creation, Bypassing Admin Restrictions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Microsoft Azure API Management (APIM) Developer Portal enables attackers to register accounts across different tenant instances, even when administrators have explicitly disabled user signup through …

Tomiris Hacker Group Added New Tools and Techniques to Attack Organizations Globally

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Tomiris hacker group has resurfaced with a sophisticated campaign targeting foreign ministries and government entities worldwide. Beginning in early 2025, this advanced persistent threat (APT) actor shifted its operational …

Mystery OAST With Exploit for 200 CVEs Leveraging Google Cloud to Launch Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat has emerged in the cybersecurity landscape as security experts discover a private Out-of-Band Application Security Testing (OAST) service operating on Google Cloud infrastructure. This mystery operation stands …

APT36 Hackers Used Python-Based ELF Malware to Target Indian Government Entities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pakistan-based threat actor APT36, also known as Transparent Tribe, has launched a sophisticated cyber-espionage campaign against Indian government institutions using a newly developed Python-based ELF malware. The attack marks a …

Kevin Lancaster Joins the usecure Board to Accelerate North American Channel Growth

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claymont, Delaware, December 1st, 2025, CyberNewsWire Lancaster’s arrival brings significant North American channel experience and expertise, supporting usecure’s ambition to cement its position as the market-leading human risk management solution …

Critical Apache bRPC Framework Vulnerability Let Attackers Crash the Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the Apache bRPC framework that could allow remote attackers to crash servers by sending specially crafted JSON data. The flaw, tracked as CVE-2025-59789, …

Linux 6.18 Released With Enhanced Hardware Support, Updated Drivers and File Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Linus Torvalds has officially announced the release of Linux kernel 6.18 on November 30, 2025, marking another significant milestone in the open-source operating system’s development. The new kernel version brings …

Windows 11 24H2 Update Hides the Password Icon in the Sign-in Options on the Lock Screen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed a bizarre user interface bug affecting Windows 11 version 24H2 devices that renders the password sign-in icon invisible on the lock screen. The issue, stemming from the …

PoC Exploit Released for Critical Outlook 0-Click Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Proof-of-Concept (PoC) exploit code has been released for a critical remote code execution (RCE) vulnerability in Microsoft Outlook, identified as CVE-2024-21413. Dubbed “MonikerLink,” this flaw allows attackers to bypass …