HPE Warns of Aruba Hardcoded Credentials Allowing Attackers to Bypass Device Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Hewlett Packard Enterprise (HPE) Aruba Networking Instant On Access Points could allow attackers to bypass device authentication mechanisms completely.  The vulnerability, tracked as CVE-2025-37103, stems from …

Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an urgent security advisory addressing critical zero-day vulnerabilities in on-premises SharePoint Server that attackers are actively exploiting.  The vulnerabilities, assigned as CVE-2025-53770 and CVE-2025-53771, pose immediate risks …

New PoisonSeed Attack Let Attackers Trick Users into Scanning a QR Code with an MFA Authenticator

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new attack technique compromises Fast IDentity Online (FIDO) key authentication by exploiting cross-device sign-in features.  The PoisonSeed attack group has developed a method to downgrade FIDO key protections …

PoC Exploit Released for Critical NVIDIA AI Container Toolkit Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical container escape vulnerability has emerged in the NVIDIA Container Toolkit, threatening the security foundation of AI infrastructure worldwide. Dubbed “NVIDIAScape” and tracked as CVE-2025-23266, this flaw carries a …

New 7-Zip Vulnerability Enables Malicious RAR5 File to Crash Your System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical memory corruption vulnerability in the popular file archiver 7-Zip has been discovered that allows attackers to trigger denial of service conditions by crafting malicious RAR5 archive files. The …

Weekly Cybersecurity Newsletter: Chrome 0-Day, VMware Flaws Patched, Fortiweb Hack, Teams Abuse, and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

It’s been a busy seven days for security alerts. Google is addressing another actively exploited zero-day in Chrome, and VMware has rolled out key patches for its own set of …

Grafana Vulnerabilities Allow User Redirection to Malicious Sites and Code Execution in Dashboards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two significant Grafana vulnerabilities that could allow attackers to redirect users to malicious websites and execute arbitrary JavaScript code.  The vulnerabilities, identified as CVE-2025-6023 and CVE-2025-6197, affect multiple versions of …

SharePoint 0-Day RCE Vulnerability Actively Exploited in the Wild to Gain Full Server Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberattack campaign targeting Microsoft SharePoint servers has been discovered exploiting a newly weaponized vulnerability chain dubbed “ToolShell,” enabling attackers to gain complete remote control over vulnerable systems without …

Snake Keylogger Evades Windows Defender and Scheduled Tasks to Harvest Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targeting Turkish defense and aerospace enterprises has emerged, delivering a highly evasive variant of the Snake Keylogger malware through fraudulent emails impersonating TUSAŞ (Turkish Aerospace Industries). …

Chinese Threat Actors Using 2,800 Malicious Domains to Deliver Windows-Specific Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Chinese threat actor campaign has emerged as one of the most persistent malware distribution operations targeting Chinese-speaking communities worldwide. Since June 2023, this ongoing campaign has established an …