Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Security

Critical VM Escape Vulnerability Discovered in Oracle VirtualBox

Security researchers from Google's Security Research team have disclosed a high-severity vulnerability in Oracle's VirtualBox virtualization …

Google Unveils New Android Security and Privacy Features for 2025

Google has announced a comprehensive suite of new security and privacy features for Android devices in 2025, focusing on protecting users from sophis…

Coinbase Data Breach: Customer Information Stolen Through Insider Access

Cryptocurrency exchange giant Coinbase has disclosed a significant data breach involving customer information, according to a Form 8-K filing with th…

Ivanti EPMM Under Attack: Critical RCE Flaws Actively Exploited

Security researchers at watchTowr have published their analysis of two critical vulnerabilities in Ivanti's Endpoint Manager Mobile (EPMM) soluti…

Critical Security Vulnerabilities Impacting Core Microsoft Cloud Services

Microsoft has confirmed the discovery of four critical security vulnerabilities affecting its core cloud services, with one reaching the maximum poss…

Chinese Android Apps Found Using Insecure Encryption, Study Reveals

A new study from researchers at the Citizen Lab and Princeton University has exposed a troubling trend in the network security of Android apps, parti…

Critical Pre-Auth RCE Vulnerabilities Found in SysAid On-Premise ITSM Solution

Cybersecurity research firm watchTowr has disclosed multiple critical vulnerabilities in SysAid's on-premises IT Service Management (ITSM) soluti…

LockBit Ransomware Gang Hacked, Negotiation Data Exposed

The notorious LockBit ransomware operation has experienced a serious security breach. Unknown actors have successfully hacked the group's dark we…

Android's May Update Fix Zero-Day Flaw Under Active Attack

Google has released its Android Security Bulletin for May 2025, fixing multiple security vulnerabilities affecting Android devices. The bulletin high…

Wormable Zero-Click RCE in Apple AirPlay Protocol Exposes Billions of Devices to Remote Attacks

Security researchers at Oligo Security have uncovered a concerning set of vulnerabilities in Apple's AirPlay protocol that could potentially impa…

Critical Vulnerabilities Actively Exploited in SonicWall SMA Appliances

Security researchers at watchTowr have published an analysis of two vulnerabilities currently being exploited in the wild against SonicWall's Sec…

Microsoft Uncovers Critical macOS Sandbox Escape Vulnerability

Microsoft security researchers have discovered a significant vulnerability in macOS that allowed attackers to bypass Apple's App Sandbox protecti…

Apache Tomcat Releases Security Updates for DoS and Bypass Vulnerabilities

The Apache Software Foundation has released important security updates addressing two vulnerabilities in Apache Tomcat, the popular open-source web s…

Critical SAP Zero-Day Vulnerability Under Active Exploitation

A critical zero-day vulnerability in SAP NetWeaver systems (CVE-2025-31324) is currently being actively exploited by threat actors, according to secu…

Critical React Router Flaws Affects Framework Mode Applications

Security researchers have identified two high-severity vulnerabilities in React Router, a popular routing library for React applications. The flaws a…

Critical RCE Vulnerability in Commvault Backup Software

Security researchers at watchTowr have disclosed a critical remote code execution (RCE) vulnerability in Commvault's backup and recovery software…

Researcher Expose Critical Gaps in Email Security Gateway Protection

IRONSCALES, the AI-powered email security leader, reveals that traditional Secure Email Gateways (SEGs) are failing to catch a concerning number of p…

Critical Ivanti Connect Secure Vulnerability Under Active Exploitation by Chinese Hackers

A critical security vulnerability in Ivanti Connect Secure VPN appliances ( CVE-2025-22457 ) is being actively exploited by suspected Chinese state-…

Europol Shuts Down Massive Child Exploitation Website "Kidflix"

In a sweeping international operation, law enforcement agencies across 35 countries have successfully dismantled Kidflix, one of the world’s largest …

Researchers Uncover Three Bypasses of Ubuntu's Namespace Restrictions

Security researchers at Qualys have identified three methods to bypass Ubuntu's unprivileged user namespace restrictions, a security feature intr…