Microsoft IIS Web Deploy Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Microsoft Web Deploy tool could allow authenticated attackers to execute remote code on affected systems.  The vulnerability, tracked as CVE-2025-53772, was disclosed on August 12, …

New Gmail Phishing Attack With Weaponized Login Flow Steals Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing campaign targeting Gmail users through a multi-layered attack that uses legitimate Microsoft Dynamics infrastructure to bypass security measures and steal login credentials. The attack begins with …

Multiple ImageMagick Vulnerabilities Cause Memory Corruption and Integer Overflows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered four serious vulnerabilities in ImageMagick, one of the world’s most widely used open-source image processing software suites, potentially exposing millions of users to security risks. The …

F5 Fixes HTTP/2 Vulnerability Enabling Massive DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

F5 Networks has disclosed a new HTTP/2 vulnerability affecting multiple BIG-IP products that could allow remote attackers to launch denial-of-service attacks against corporate networks. The security flaw, designated CVE-2025-54500 and …

ERMAC v3.0 Banking Malware Source Code Exposed via Weak Password ‘changemeplease’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Hunt.io have made a significant discovery in the cybersecurity field by obtaining and analyzing the complete source code of ERMAC V3.0. This advanced Android banking trojan targets over 700 financial …

Hackers Mimic IT Teams to Exploit Microsoft Teams Request to Gain System Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated social engineering campaign by the EncryptHub threat group that combines impersonation tactics with technical exploitation to compromise corporate networks. The Russian-linked cybercriminals are posing as IT support staff …

Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) – Technical Details Revealed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers from watchTowr Labs have published a comprehensive technical analysis of a critical pre-authentication command injection vulnerability affecting Fortinet FortiSIEM systems, designated as CVE-2025-25256. The vulnerability carries a maximum …

Palo Alto Networks Released A Mega Malware Analysis Tutorials Useful for Every Malware Analyst

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks has published an extensive malware analysis tutorial detailing the dissection of a sophisticated .NET-based threat that delivers the Remcos remote access trojan (RAT). The malware’s emergence highlights …

Ransomware Actors Blending Legitimate Tools with Custom Malware to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape faces a new sophisticated threat as the Crypto24 ransomware group demonstrates an alarming evolution in attack methodology, seamlessly blending legitimate administrative tools with custom-developed malware to execute …