cyber news

SharePoint Deserialization Vulnerabilities Lets Hackers Steal IIS Machine Keys

Security researchers have revealed alarming details about how attackers are exploiting recently disclosed Microsoft SharePoint vulnerabilities to steal critical IIS…

8 months ago

SonicWall Gen 7 Firewalls Under Attack: Spike Reported

SonicWall has issued an urgent security warning following a dramatic surge in cyberattacks targeting Gen 7 firewalls with SSL VPN…

8 months ago

MediaTek Chipset Vulnerabilities Enable Unauthorized Access

MediaTek has disclosed three critical security vulnerabilities in its August 2025 Product Security Bulletin that affect a wide range of…

8 months ago

ADOdb SQLite3 Driver Vulnerability Enables Arbitrary SQL Statement Execution

A critical SQL injection vulnerability affecting the widely-used ADOdb PHP database abstraction library has been discovered and patched, posing significant…

8 months ago

New Streamlit Vulnerability Enables Cloud Account Takeover Attacks

A critical vulnerability in Streamlit's file upload feature that could enable attackers to execute cloud account takeover attacks on misconfigured…

8 months ago

WAF Evasion Using JavaScript Injection and Parameter Pollution for XSS

A sophisticated technique that can bypass most Web Application Firewalls (WAFs) to execute Cross-Site Scripting (XSS) attacks, revealing significant vulnerabilities…

9 months ago

LegalPwn Attack Exploits AI Tools Like Gemini and ChatGPT Using Disclaimers to Run Malicious Code

The attack, dubbed "LegalPwn," was revealed in groundbreaking research by AI security firm Pangea and represents a significant evolution in…

9 months ago

Claude AI Vulnerabilities Allow Attackers to Run Unauthorized Commands

Two critical security vulnerabilities discovered in Anthropic's Claude Code have demonstrated how artificial intelligence tools designed to enhance developer productivity…

9 months ago

Mozilla Warns of Targeted Phishing Campaign Against Add-on Developers

Mozilla has issued an urgent advisory to add-on developers, alerting them to a sophisticated phishing campaign aimed at compromising accounts…

9 months ago

FUJIFILM Printer Vulnerability Exposes Devices to Denial-of-Service Attacks

A newly disclosed vulnerability in FUJIFILM’s Internet Printing Protocol (IPP) and Line Printer Daemon (LPD) processing logic allows malicious actors…

9 months ago