- Citrix Patches Three NetScaler Flaws, Confirms Active Exploitation of CVE-2025-7775by info@thehackernews.com (The Hacker News) on 26/08/2025 at 17:29
Citrix has released fixes to address three security flaws in NetScaler ADC and NetScaler Gateway, including one that it said has been actively exploited in the wild. The vulnerabilities in question are listed below - CVE-2025-7775 (CVSS score: 9.2) - Memory overflow vulnerability leading to Remote Code Execution and/or Denial-of-Service CVE-2025-7776 (CVSS score: 8.8) - Memory overflow
- New Sni5Gect Attack Crashes Phones and Downgrades 5G to 4G without Rogue Base Stationby info@thehackernews.com (The Hacker News) on 26/08/2025 at 17:23
A team of academics has devised a novel attack that can be used to downgrade a 5G connection to a lower generation without relying on a rogue base station (gNB). The attack, per the ASSET (Automated Systems SEcuriTy) Research Group at the Singapore University of Technology and Design (SUTD), relies on a new open-source software toolkit named Sni5Gect (short for "Sniffing 5G Inject") that's
- MixShell Malware Delivered via Contact Forms Targets U.S. Supply Chain Manufacturersby info@thehackernews.com (The Hacker News) on 26/08/2025 at 13:30
Cybersecurity researchers are calling attention to a sophisticated social engineering campaign that's targeting supply chain-critical manufacturing companies with an in-memory malware dubbed MixShell. The activity has been codenamed ZipLine by Check Point Research. "Instead of sending unsolicited phishing emails, attackers initiate contact through a company's public 'Contact Us' form, tricking
- AI-Driven Trends in Endpoint Security: What the 2025 Gartner® Magic Quadrant™ Revealsby info@thehackernews.com (The Hacker News) on 26/08/2025 at 10:47
Cyber threats and attacks like ransomware continue to increase in volume and complexity with the endpoint typically being the most sought after and valued target. With the rapid expansion and adoption of AI, it is more critical than ever to ensure the endpoint is adequately secured by a platform capable of not just keeping pace, but staying ahead of an ever-evolving threat landscape.
- ShadowCaptcha Exploits WordPress Sites to Spread Ransomware, Info Stealers, and Crypto Minersby info@thehackernews.com (The Hacker News) on 26/08/2025 at 10:45
A new large-scale campaign has been observed exploiting over 100 compromised WordPress sites to direct site visitors to fake CAPTCHA verification pages that employ the ClickFix social engineering tactic to deliver information stealers, ransomware, and cryptocurrency miners. The large-scale cybercrime campaign, first detected in August 2025, has been codenamed ShadowCaptcha by the Israel National