Sunday, April 26, 2026
HomeCyber News

Cyber News

Exploit of ArmouryLoader – Circumventing Security Measures to Inject Malicious Code

A sophisticated malware loader known as ArmouryLoader has emerged as a significant cybersecurity threat, demonstrating advanced techniques to bypass endpoint detection and response (EDR) systems while delivering malicious payloads. First discovered in 2024, this loader exploits legitimate ASUS Armoury Crate system management software to...

Apple Fixes Several Vulnerabilities, Including Safari Vulnerability Exploited as Chrome 0-Day

Apple released a comprehensive set of security updates on July 29, 2025, addressing vulnerabilities across its entire ecosystem of devices and operating systems. The latest updates include critical patches for iOS, iPadOS, macOS, watchOS, tvOS, and visionOS, with particular attention to Safari browser security...

Dropbox Passwords Closing – Export by October 28, 2025

Dropbox has announced the discontinuation of its password management service, Dropbox Passwords, effective October 28, 2025, as the company shifts focus toward enhancing core product features. The cloud storage giant is urging all users to export their stored password data before the final shutdown...

ToolShell – Unveiling Five Critical Vulnerabilities in Microsoft SharePoint

Security researchers and national Computer Emergency Response Teams (CERTs) worldwide issued urgent alerts on July 19-20, 2025, regarding active exploitation of critical vulnerabilities in on-premise SharePoint servers. The attack campaign, dubbed "ToolShell," exploits a chain of five interconnected vulnerabilities that allow attackers to gain...

WordPress Theme RCE Vulnerability Actively Exploited to take Full Site Control

A critical security vulnerability in the popular "Alone" WordPress theme has been actively exploited by cybercriminals to gain complete control of vulnerable websites. The vulnerability, which affects a theme with over 9,000 sales, allows unauthenticated attackers to upload malicious files and execute remote...

BeyondTrust Privilege Management for Windows Vulnerability Allows Attackers to Escalate Privileges

A critical security vulnerability has been discovered in BeyondTrust's Privilege Management for Windows software that enables local authenticated attackers to escalate their privileges to administrator level. The vulnerability, assigned CVE-2025-2297 and carrying a CVSSv4 score of 7.2, affects all versions prior to 25.4.270.0 and...