Wednesday, March 26, 2025

Cyber Security News

Windows MMC Framework

Windows MMC Framework Zero-Day Exploited to Execute Malicious Code

0
Trend Research has uncovered a sophisticated campaign by the Russian threat actor Water Gamayun, exploiting a zero-day vulnerability in the Microsoft Management Console (MMC)...

CrushFTP Warns of HTTP(S) Port Vulnerability Enabling Unauthorized Access

0
Both CrushFTP, a popular file transfer technology, and Next.js, a widely used React framework for building web applications, have come under scrutiny due to...

Windows 11 24H2 Update Disrupts Connection to Veeam Backup Server

0
Users of the Veeam Backup Server have encountered a significant issue following the Windows 11 24H2 update.Specifically, the update has disrupted the connection between...

Cloudflare Attributes Service Outage to Faulty Password Rotation

0
Cloudflare experienced a significant service outage that affected several of its key offerings, including R2 object storage, Cache Reserve, Images, Log Delivery, Stream, and...
APT Hackers

APT Hackers Exploit Google Chrome Zero-Day in Operation ForumTroll to Bypass Sandbox Protections

0
In mid-March 2025, Kaspersky researchers uncovered a sophisticated APT attack, dubbed Operation ForumTroll, which leveraged a previously unknown zero-day exploit in Google Chrome.This...
Linux Backdoor

New Sophisticated Linux Backdoor Targets OT Systems via 0-Day RCE Exploit

0
Researchers at QiAnXin XLab have uncovered a sophisticated Linux-based backdoor dubbed OrpaCrab, specifically targeting industrial systems associated with ORPAK, a company involved in gas...

New Chrome Installer Fails on Windows 10 & 11 With “This app can’t run...

0
A recent snag in Google's Chrome distribution process has left Windows users unable to install the browser on their Intel and AMD systems.The issue,...
SIEM as a Service

Recent News

Google Chrome Zero-Day Vulnerability Actively Exploited in the Wild

0
Google has released an urgent update for its Chrome browser to patch a zero-day vulnerability known as CVE-2025-2783.This vulnerability has been actively exploited in...
CYREBRO

Gartner Names CYREBRO in Emerging Tech Report for Detection & Response Startups

0
Ramat Gan, Israel, March 25th, 2025, CyberNewsWireCYREBRO, the AI-native Managed Detection and Response (MDR), today announced its recognition as a leading detection and response...
Malware Analysis

CAPE from Cuckoo v1 Enables Malware Analysis in a Secure Isolated Sandbox Environment

0
CAPE, derived from Cuckoo v1, is a sophisticated malware sandbox designed to execute malicious files in an isolated environment while capturing their dynamic behavior...
Raspberry Robin

Raspberry Robin Unveils 200 Unique Domains Used by Threat Actors

0
In a significant development, cybersecurity firm Silent Push has identified nearly 200 unique command and control (C2) domains associated with the Raspberry Robin malware....
ChatGPT

Malicious AI Tools See 200% Surge as ChatGPT Jailbreaking Talks Increase by 52%

0
The cybersecurity landscape in 2024 witnessed a significant escalation in AI-related threats, with malicious actors increasingly targeting and exploiting large language models (LLMs).According to...
Android Users

New Malware Targets Android Users by Abusing Cross-Platform Framework for Evasion

0
A recent discovery by the McAfee Mobile Research Team has highlighted a new wave of Android malware campaigns that utilize the .NET MAUI cross-platform...

New Windows Zero-Day Vulnerability Exposes NTLM Credentials – Unofficial Patch Available

0
A new zero-day vulnerability has been discovered in Windows, impacting all versions from Windows 7 and Server 2008 R2 to the latest Windows 11...

Kali Linux 2025.1a Released: New Tools and Desktop Environment Upgrades

0
Kali Linux, the renowned cybersecurity-focused Linux distribution, has just ushered in the new year with the release of Kali Linux 2025.1a.This update builds upon...

Tomcat RCE Vulnerability Exploited in the Wild – Mitigation Steps Outlined

0
A recent vulnerability in Apache Tomcat, identified as CVE-2025-24813, has sparked concerns among cybersecurity professionals due to its potential for exploitation in unauthenticated remote...

Windows MMC Framework Zero-Day Exploited to Execute Malicious Code

Trend Research has uncovered a sophisticated campaign by the Russian threat actor Water Gamayun, exploiting a zero-day vulnerability in the Microsoft Management Console (MMC)...

CrushFTP Warns of HTTP(S) Port Vulnerability Enabling Unauthorized Access

Both CrushFTP, a popular file transfer technology, and Next.js, a widely used React framework for building web applications, have come under scrutiny due to...

Windows 11 24H2 Update Disrupts Connection to Veeam Backup Server

Users of the Veeam Backup Server have encountered a significant issue following the Windows 11 24H2 update.Specifically, the update has disrupted the connection between...

Cloudflare Attributes Service Outage to Faulty Password Rotation

Cloudflare experienced a significant service outage that affected several of its key offerings, including R2 object storage, Cache Reserve, Images, Log Delivery, Stream, and...

APT Hackers Exploit Google Chrome Zero-Day in Operation ForumTroll to Bypass Sandbox Protections

In mid-March 2025, Kaspersky researchers uncovered a sophisticated APT attack, dubbed Operation ForumTroll, which leveraged a previously unknown zero-day exploit in Google Chrome.This...

New Sophisticated Linux Backdoor Targets OT Systems via 0-Day RCE Exploit

Researchers at QiAnXin XLab have uncovered a sophisticated Linux-based backdoor dubbed OrpaCrab, specifically targeting industrial systems associated with ORPAK, a company involved in gas...

New Chrome Installer Fails on Windows 10 & 11 With “This app can’t run on your PC” Error

A recent snag in Google's Chrome distribution process has left Windows users unable to install the browser on their Intel and AMD systems.The issue,...

North Korean Kimsuky Hackers Deploy New Tactics and Malicious Scripts in Recent Attacks

Security researchers have uncovered a new attack campaign by the North Korean state-sponsored APT group Kimsuky, also known as "Black Banshee."The group, active...

Critical NetApp SnapCenter Server Vulnerability Allows Attackers to Gain Admin Access

A critical vulnerability has been identified in NetApp's SnapCenter Server, affecting versions before 6.0.1P1 and 6.1P1.This flaw allows an authenticated SnapCenter Server user to...

Glossary