Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Security

Critical Pre-Auth RCE Vulnerabilities Found in SysAid On-Premise ITSM Solution

Cybersecurity research firm watchTowr has disclosed multiple critical vulnerabilities in SysAid's on-premises IT Service Management (ITSM) soluti…

LockBit Ransomware Gang Hacked, Negotiation Data Exposed

The notorious LockBit ransomware operation has experienced a serious security breach. Unknown actors have successfully hacked the group's dark we…

Android's May Update Fix Zero-Day Flaw Under Active Attack

Google has released its Android Security Bulletin for May 2025, fixing multiple security vulnerabilities affecting Android devices. The bulletin high…

Wormable Zero-Click RCE in Apple AirPlay Protocol Exposes Billions of Devices to Remote Attacks

Security researchers at Oligo Security have uncovered a concerning set of vulnerabilities in Apple's AirPlay protocol that could potentially impa…

Critical Vulnerabilities Actively Exploited in SonicWall SMA Appliances

Security researchers at watchTowr have published an analysis of two vulnerabilities currently being exploited in the wild against SonicWall's Sec…

Microsoft Uncovers Critical macOS Sandbox Escape Vulnerability

Microsoft security researchers have discovered a significant vulnerability in macOS that allowed attackers to bypass Apple's App Sandbox protecti…

Apache Tomcat Releases Security Updates for DoS and Bypass Vulnerabilities

The Apache Software Foundation has released important security updates addressing two vulnerabilities in Apache Tomcat, the popular open-source web s…

Critical SAP Zero-Day Vulnerability Under Active Exploitation

A critical zero-day vulnerability in SAP NetWeaver systems (CVE-2025-31324) is currently being actively exploited by threat actors, according to secu…

Critical React Router Flaws Affects Framework Mode Applications

Security researchers have identified two high-severity vulnerabilities in React Router, a popular routing library for React applications. The flaws a…

Critical RCE Vulnerability in Commvault Backup Software

Security researchers at watchTowr have disclosed a critical remote code execution (RCE) vulnerability in Commvault's backup and recovery software…

Researcher Expose Critical Gaps in Email Security Gateway Protection

IRONSCALES, the AI-powered email security leader, reveals that traditional Secure Email Gateways (SEGs) are failing to catch a concerning number of p…

Critical Ivanti Connect Secure Vulnerability Under Active Exploitation by Chinese Hackers

A critical security vulnerability in Ivanti Connect Secure VPN appliances ( CVE-2025-22457 ) is being actively exploited by suspected Chinese state-…

Europol Shuts Down Massive Child Exploitation Website "Kidflix"

In a sweeping international operation, law enforcement agencies across 35 countries have successfully dismantled Kidflix, one of the world’s largest …

Researchers Uncover Three Bypasses of Ubuntu's Namespace Restrictions

Security researchers at Qualys have identified three methods to bypass Ubuntu's unprivileged user namespace restrictions, a security feature intr…

Gmail's New End-to-End Encryption for Enterprise Users

In celebration of Gmail’s birthday , Google has announced a significant advancement in email security that democratizes end-to-end encryption (E2EE) …

Critical Authentication Bypass Vulnerability Discovered in CrushFTP

A severe authentication bypass vulnerability has been identified in CrushFTP, a popular multi-protocol file transfer server used by many organization…

BLASTPASS Explained: How NSO’s WebP Zero-Day Exploit Hacked iPhones Silently

In September 2023, Apple rushed to patch a critical vulnerability after researchers uncovered an alarming zero-click exploit chain attributed to…

Kaspersky Uncovers New Chrome 0-Day Actively Exploited

In the latest discovery, Kaspersky Lab exposed a highly sophisticated cyber attack, dubbed “ Operation ForumTroll ,” that leverages a critical zero-d…

IngressNightmare - Critical RCE Vulnerabilities Expose Kubernetes Clusters

Cybersecurity researchers at Wiz ( recently acquired by Google ) have uncovered multiple severe vulnerabilities in the Ingress NGINX Controller for K…

Oracle Cloud Security Breach Exposes 6 Million Records Affecting 140,000 Tenants

A significant security breach at Oracle Cloud has been reported, with a cybercriminal claiming to have stolen approximately 6 million records from Or…