Saturday, May 2, 2026
HomeCyber News

Cyber News

Critical Grafana Vulnerabilities Allow Malicious Redirects and Arbitrary Code Execution

Grafana Labs has released critical security patches addressing two significant vulnerabilities that could allow attackers to redirect users to malicious websites and execute arbitrary JavaScript code. The company issued fixes for CVE-2025-6023 (high severity) and CVE-2025-6197 (medium severity) across multiple versions of the popular...

Ubiquiti UniFi Device Vulnerability Enables Remote Command Injection by Attackers

Ubiquiti Networks has disclosed a critical security vulnerability affecting multiple UniFi Access devices that could enable malicious actors to execute arbitrary commands through improper input validation. The vulnerability, assigned CVE-2025-27212 and discovered by security researchers Bongeun Koo and Junhyung Cho, carries a maximum CVSS...

June 2025 Sees Surge in Infostealer Attacks via Cracked Apps

A new report from AhnLab Security Intelligence Center (ASEC) reveals a significant uptick in Infostealer malware campaigns throughout June 2025, with cybercriminals increasingly exploiting cracked applications and illegal software downloads as their primary distribution method. Using advanced SEO poisoning tactics, threat actors have been...

Lenovo Protection Driver Vulnerability Allows Privilege Escalation and Remote Code Execution

A critical buffer overflow vulnerability has been identified in Lenovo’s Protection Driver, exposing users of various Lenovo applications to potential local privilege escalation and remote code execution. Lenovo has cautioned affected users to update key applications immediately to mitigate exploitation risks. Lenovo Security Advisory LEN-195370...

Microsoft Defender for Office 365 Unveils Enhanced Dashboard with Comprehensive Threat Insights

Microsoft has announced two major initiatives aimed at increasing transparency in email security effectiveness, addressing the growing challenge faced by chief information security officers (CISOs) in making data-driven cybersecurity decisions. The company is launching a new customer-facing dashboard for Microsoft Defender for Office 365...

WAFFLED: Exploiting Web Application Firewalls via Parsing Inconsistencies

Web Application Firewalls (WAFs) are the first line of defense for countless online services, yet a new approach—dubbed WAFFLED—demonstrates how subtle parsing mismatches can let malicious traffic slip through. Researchers at Northeastern University and Dartmouth College have unveiled a systematic method that exploits differences...