TECHZONE™
Open in Telegram
TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news
Show more596
Subscribers
-124 hours
-37 days
-1130 days
Posts Archive
596
New React RSC Vulnerabilities Enable DoS and Source Code Exposure
https://thehackernews.com/2025/12/new-react-rsc-vulnerabilities-enable.html
The React team has released fixes for two new types of flaws in React Server Components (RSC) that, if successfully exploited, could result in denial-of-service (DoS) or source code exposure.
The team said the issues were found by the security community while attempting to exploit the patches released for CVE-2025-55182 (CVSS score: 10.0), a critical bug in RSC that has since been weaponized in
596
React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation
https://thehackernews.com/2025/12/react2shell-exploitation-escalates-into.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged federal agencies to patch the recent React2Shell vulnerability by December 12, 2025, amid reports of widespread exploitation.
The critical vulnerability, tracked as CVE-2025-55182 (CVSS score: 10.0), affects the React Server Components (RSC) Flight protocol. The underlying cause of the issue is an unsafe deserialization
596
Black Hat Europe 2025: Reputation matters – even in the ransomware economy
https://www.welivesecurity.com/en/business-security/black-hat-europe-2025-reputation-ransomware/
Being seen as reliable is good for ‘business’ and ransomware groups care about 'brand reputation' just as much as their victims
596
Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity
https://www.welivesecurity.com/en/business-security/locks-socs-cat-box-what-schrodinger-can-teach-us-about-cybersecurity/
If you don’t look inside your environment, you can’t know its true state – and attackers count on that
596
CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
https://thehackernews.com/2025/12/cisa-flags-actively-exploited-geoserver.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw impacting OSGeo GeoServer to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild.
The vulnerability in question is CVE-2025-58360 (CVSS score: 8.2), an unauthenticated XML External Entity (XXE) flaw that affects all versions prior to
596
Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw
https://thehackernews.com/2025/12/chrome-targeted-by-active-in-wild.html
Google on Wednesday shipped security updates for its Chrome browser to address three security flaws, including one it said has come under active exploitation in the wild.
The vulnerability, rated high in severity, is being tracked under the Chromium issue tracker ID "466192044." Unlike other disclosures, Google has opted to keep information about the CVE identifier, the affected component, and
596
Active Attacks Exploit Gladinet's Hard-Coded Keys for Unauthorized Access and Code Execution
https://thehackernews.com/2025/12/hard-coded-gladinet-keys-let-attackers.html
Huntress is warning of a new actively exploited vulnerability in Gladinet's CentreStack and Triofox products stemming from the use of hard-coded cryptographic keys that have affected nine organizations so far.
"Threat actors can potentially abuse this as a way to access the web.config file, opening the door for deserialization and remote code execution," security researcher Bryan Masters said.
596
Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece
https://www.welivesecurity.com/en/business-security/seeking-symmetry-attck-season-harness-todays-diverse-analyst-tester-landscape-paint-security-masterpiece/
Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.
596
React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors
https://thehackernews.com/2025/12/react2shell-exploitation-delivers.html
React2Shell continues to witness heavy exploitation, with threat actors leveraging the maximum-severity security flaw in React Server Components (RSC) to deliver cryptocurrency miners and an array of previously undocumented malware families, according to new findings from Huntress.
This includes a Linux backdoor called PeerBlight, a reverse proxy tunnel named CowTunnel, and a Go-based
596
.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL
https://thehackernews.com/2025/12/net-soapwn-flaw-opens-door-for-file.html
New research has uncovered exploitation primitives in the .NET Framework that could be leveraged against enterprise-grade applications to achieve remote code execution.
WatchTowr Labs, which has codenamed the "invalid cast vulnerability" SOAPwn, said the issue impacts Barracuda Service Center RMM, Ivanti Endpoint Manager (EPM), and Umbraco 8. But the number of affected vendors is likely to be
596
Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling
https://thehackernews.com/2025/12/three-pcie-encryption-weaknesses-expose.html
Three security vulnerabilities have been disclosed in the Peripheral Component Interconnect Express (PCIe) Integrity and Data Encryption (IDE) protocol specification that could expose a local attacker to serious risks.
The flaws impact PCIe Base Specification Revision 5.0 and onwards in the protocol mechanism introduced by the IDE Engineering Change Notice (ECN), according to the PCI Special
596
Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups
https://thehackernews.com/2025/12/warning-winrar-vulnerability-cve-2025.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a security flaw impacting the WinRAR file archiver and compression utility to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2025-6218 (CVSS score: 7.8), is a path traversal bug that could enable code execution. However, for exploitation
596
Webinar: How Attackers Exploit Cloud Misconfigurations Across AWS, AI Models, and Kubernetes
https://thehackernews.com/2025/12/webinar-how-attackers-exploit-cloud.html
Cloud security is changing. Attackers are no longer just breaking down the door; they are finding unlocked windows in your configurations, your identities, and your code.
Standard security tools often miss these threats because they look like normal activity. To stop them, you need to see exactly how these attacks happen in the real world.
Next week, the Cortex Cloud team at Palo Alto Networks
596
The big catch: How whaling attacks target top executives
https://www.welivesecurity.com/en/business-security/big-catch-how-whaling-attacks-target-top-executives/
Is your organization’s senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe.
596
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days
https://thehackernews.com/2025/12/microsoft-issues-security-fixes-for-56.html
Microsoft closed out 2025 with patches for 56 security flaws in various products across the Windows platform, including one vulnerability that has been actively exploited in the wild.
Of the 56 flaws, three are rated Critical, and 53 are rated Important in severity. Two other defects are listed as publicly known at the time of the release. These include 29 privilege escalation, 18 remote code
596
Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws
https://thehackernews.com/2025/12/fortinet-ivanti-and-sap-issue-urgent.html
Fortinet, Ivanti, and SAP have moved to address critical security flaws in their products that, if successfully exploited, could result in an authentication bypass and code execution.
The Fortinet vulnerabilities affect FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager and relate to a case of improper verification of a cryptographic signature. They are tracked as CVE-2025-59718 and
596
North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware
https://thehackernews.com/2025/12/north-korea-linked-actors-exploit.html
Threat actors with ties to North Korea have likely become the latest to exploit the recently disclosed critical security React2Shell flaw in React Server Components (RSC) to deliver a previously undocumented remote access trojan dubbed EtherRAT.
"EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution, deploys five independent Linux persistence mechanisms, and
596
Four Threat Clusters Using CastleLoader as GrayBravo Expands Its Malware Service Infrastructure
https://thehackernews.com/2025/12/four-threat-clusters-using-castleloader.html
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
The threat actor behind CastleLoader has been assigned the name GrayBravo by Recorded Future's Insikt Group, which was previously tracking it as TAG-150.
596
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading
https://thehackernews.com/2025/12/storm-0249-escalates-ransomware-attacks.html
The threat actor known as Storm-0249 is likely shifting from its role as an initial access broker to adopt a combination of more advanced tactics like domain spoofing, DLL side-loading, and fileless PowerShell execution to facilitate ransomware attacks.
"These methods allow them to bypass defenses, infiltrate networks, maintain persistence, and operate undetected, raising serious concerns for
596
How to Streamline Zero Trust Using the Shared Signals Framework
https://thehackernews.com/2025/12/how-to-streamline-zero-trust-using.html
Zero Trust helps organizations shrink their attack surface and respond to threats faster, but many still struggle to implement it because their security tools don’t share signals reliably. 88% of organizations admit they’ve suffered significant challenges in trying to implement such approaches, according to Accenture. When products can’t communicate, real-time access decisions break down.
The
Available now! Telegram Research 2025 — the year's key insights 
