Thursday, April 16, 2026
HomeTagsCyber news

Tag: cyber news

Hackers Scanning Microsoft Remote Desktop Web Access From 1000+ IPs

A massive coordinated campaign targeting Microsoft Remote Desktop Protocol (RDP) services, with nearly 2,000 malicious IP addresses conducting simultaneous reconnaissance attacks against authentication portals. The unprecedented surge represents a 400-fold increase from normal baseline activity and signals potential preparations for large-scale credential-based attacks on...

CISA Alerts on Active Exploitation of Citrix Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on August 25, 2025, highlighting active exploitation of critical vulnerabilities affecting Citrix Session Recording and Git systems. The additions include CVE-2024-8069 and CVE-2024-8068 in Citrix...

Apple 0-Day RCE Vulnerability: PoC Exploit and Analysis Released

A detailed proof-of-concept exploit and vulnerability analysis for CVE-2025-43300, a critical zero-click remote code execution vulnerability affecting Apple devices. The vulnerability, which Apple acknowledges may have been exploited in sophisticated targeted attacks, represents one of the most dangerous iOS vulnerabilities discovered in recent years. CVE-2025-43300...

Kali Vagrant Rebuild Released – Preconfigured Command-Line VMs

Kali Vagrant Rebuilt, a streamlined toolchain for building and distributing pre-configured virtual machine (VM) images via HashiCorp Vagrant. By replacing Packer with an in-house DebOS-based solution, the Kali team has unified its VM build infrastructure, reduced external dependencies, and simplified cross-platform image creation. The...

Critical Mozilla Vulnerabilities Allow Remote Code Execution

Mozilla released Firefox 142 on August 19, 2025, addressing multiple critical security vulnerabilities that could enable remote code execution and sandbox escape attacks. The security update patches nine CVEs, with three classified as high-severity vulnerabilities that could allow attackers to execute arbitrary code on...

New QUIC-LEAK Vulnerability Exposes Servers to Memory Exhaustion and Denial-of-Service

A critical vulnerability in the widely-used LSQUIC QUIC implementation that allows attackers to crash servers through memory exhaustion before any connection handshake is established. The vulnerability, designated CVE-2025-54939 and dubbed "QUIC-LEAK," bypasses all standard QUIC protection mechanisms and affects the second most popular QUIC...