WordPress Theme RCE Vulnerability Actively Exploited to Take Full Site Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution (RCE) vulnerability in the popular “Alone” WordPress theme is being actively exploited by attackers to gain complete control of vulnerable websites.  The vulnerability, assigned CVE-2025-5394 …

Lumma Password Stealer Attack Infection Chain and Its Escalation Tactics Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has witnessed a significant surge in information-stealing malware, with Lumma emerging as one of the most prevalent and sophisticated threats targeting Windows systems globally. This C++-based information …

BeyondTrust Privilege Management for Windows Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has been discovered in BeyondTrust’s Privilege Management for Windows solution, allowing local authenticated attackers to escalate their privileges to the administrator level.  The flaw, designated as …

Global Authorities Shared IoCs and TTPs of Scattered Spider Behind Major ESXi Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Joint international advisory warns of evolving social engineering tactics and new DragonForce ransomware deployment targeting commercial facilities A collaboration of international cybersecurity agencies issued an urgent updated advisory on July …

ChatGPT Agent Bypasses Cloudflare “I am not a robot” Verification Checks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ChatGPT agents demonstrate the ability to autonomously bypass Cloudflare’s CAPTCHA verification systems, specifically the ubiquitous “I am not a robot” checkbox.  This development, first documented in a viral Reddit post …

Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberattack targeting a US-based chemicals company has revealed the first observed pairing of SAP NetWeaver exploitation with Auto-Color malware, demonstrating how threat actors are leveraging critical vulnerabilities to …

Enterprise LLMs Under Risk: How Simple Prompts Can Lead to Major Breaches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Enterprise applications integrating Large Language Models (LLMs) face unprecedented security vulnerabilities that can be exploited through deceptively simple prompt injection attacks.  Recent security assessments reveal that attackers can bypass authentication …

Microsoft Details Defence Techniques Against Indirect Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has unveiled a comprehensive defense-in-depth strategy to combat indirect prompt injection attacks, one of the most significant security threats facing large language model (LLM) implementations in enterprise environments.  The …

Lionishackers Threat Actors Exfiltrating and Selling Corporate Databases on Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financially motivated threat actor known as Lionishackers has emerged as a significant player in the illicit marketplace for corporate data in recent months. Leveraging opportunistic targeting and a preference …