• Security researchers have uncovered three significant vulnerabilities in OpenVPN, one of the world’s most trusted open-source virtual private network (VPN) solutions. The discovered flaws could allow attackers to crash VPN services, bypass essential security checks, or read sensitive memory data. The OpenVPN development team has released urgent updates to address these issues, and administrators are […]

    The post OpenVPN Flaws Allow Hackers to Launch DoS Attacks and Bypass Security Checks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Researchers have uncovered a sophisticated malware campaign where threat actors weaponize trojanized installers for popular productivity applications to deploy ValleyRat, a persistent remote access tool. The operation demonstrates advanced evasion techniques, including kernel-level driver abuse, endpoint security tampering, and multi-stage obfuscation designed to evade detection and establish long-term system compromise. The campaign has been attributed […]

    The post Hackers Exploit Telegram, WinSCP, Chrome, and Teams to Deliver ValleyRat Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Travel and hospitality industry leader Sonesta International Hotels partners with AccuKnox to deploy Zero Trust Integrated Application and Cloud Security [ASPM and CNAPP (Cloud Native Application Protection Platform)] for Microsoft Azure. AccuKnox, Inc., announced that Sonesta International Hotels has partnered with AccuKnox to deploy Zero Trust CNAPP. Gartner Group, in its 2024 findings, reported that […]

    The post Sonesta International Hotels Implements Industry-Leading Cloud Security Through AccuKnox Collaboration appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Travel and hospitality industry leader Sonesta International Hotels partners with AccuKnox to deploy Zero Trust Integrated Application and Cloud Security [ASPM and CNAPP (Cloud Native Application Protection Platform)] for Microsoft Azure.

    AccuKnox, Inc., announced that Sonesta International Hotels has partnered with AccuKnox to deploy Zero Trust CNAPP.

    Gartner Group, in its 2024 findings, reported that security leaders should:

    • Adopt CNAPP offerings to safeguard cloud-native applications and counter the growing attack surface. These solutions protect against threats in the runtime environment, mitigate misconfigurations in cloud infrastructure, and streamline security integration and collaboration throughout the overall development experience.
    • Leverage CNAPP to strengthen defenses against network attacks, compute, storage, identities, permissions, APIs, and the software supply chain, thereby mitigating potential risks and safeguarding critical assets.
    • Prioritize solutions that cater to the increasing operational responsibilities of developers and cloud architects.

    Furthermore, Gartner opined that enterprises that do not employ a unified CNAPP will lack extensive visibility into the cloud attack surface and consequently fail to achieve their desired zero-trust goals.

    In its 2024 report on Vulnerability Management, Gartner advised organizations to implement an RVBM (Risk-based Vulnerability Management) and conduct CTEM (Continuous Threat Exposure Management) to achieve actionability, risk control, security integration, and prioritization. 

    Sonesta Security Engineering and Cloud Platform DevOps leaders were focused on implementing an integrated application security and cloud security platform with the following goals/objectives:

    • Multi-Cloud misconfigurations with a focus on reducing Alert Deluge.
    • Compliance conformance against CIS, SOC2 Type II, NIST, MITRE, PCI across Multi-Cloud Infrastructure.
    • DevSecOps with SAST, DAST & IaC security integrations with Azure DevOps.
    • Automation of the Findings & Ticketing Lifecycle.

    Sonesta conducted an extensive POC (Proof of Concept) with multiple vendors and selected AccuKnox for the following reasons:

    • Multi-cloud misconfiguration detection.
    • Special focus on toxic combinations. 
    • Continuous Compliance visibility against cloud in CIS, SOC2 Type II, NIST, MITRE, PCI across Multi-Cloud Infrastructure.
    • Consolidated view of the DevSecOps with SAST, DAST & IaC security integrations with Azure DevOps pipeline.
    • 45% reduction in the Engineering efforts due to the Automation of Findings & Ticketing Lifecycle.

    Supporting Quotes

    “We are thrilled that an industry leader like Sonesta chose us for their integrated Zero Trust ASPM/CNAPP platform. Their vision and strategy are very well aligned with ours, and we look forward to a great partnership”,

    Nat Natraj, co-founder and CEO, AccuKnox.

    “We conducted an extensive evaluation of best-in-class vendors in the industry and selected AccuKnox based on their comprehensive features, ease of deployment, ease of use, 3rd party integrations, and real-time security to prevent advanced zero-day attacks. Their strong roadmap offerings in API Security, AI/LLM Security made AccuKnox the best choice for an integrated AppSec/CloudSec platform”

    David Billeter, Cybersecurity Leader, Sonesta International Hotels.

    About AccuKnox

    AccuKnox provides a Zero Trust CNAPP Security platform that secures public clouds, private clouds, edge/IoT & 5G assets. AccuKnox is funded by leading security investors like National Grid Partners, MDSV, Avanta Venture Partners, Dolby Family Ventures, DreamIT Ventures, 5G Open Innovation Lab, and Seedop. AccuKnox was formed in partnership with SRI International (previously Stanford Research Institute) and has seminal patents on different aspects of Zero Trust security. 

    About Sonesta International Hotels

    Sonesta is the 8th largest hotel company in the U.S., according to Smith Travel Research (STR), with approximately 1,100 properties totaling 100,000 guest rooms across 13 brands in eight countries. Sonesta owns, manages, and/or franchises under The Royal Sonesta; The James, Classico Collection by Sonesta, Sonesta Hotels, Resorts & Cruises; MOD Collection by Sonesta, Sonesta Select Hotels; Sonesta Essential Hotels, Sonesta ES Suites, Sonesta Simply Suites, Red Lion Hotels, Inns & Suites by Sonesta; Signature Inn by Sonesta; Americas Best Value Inn by Sonesta; and Canada’s Best Value Inn by Sonesta.

    Contact

    Syed Hadi
    AccuKnox
    syed.hadi@accuknox.com

    The post Sonesta International Hotels Implements Industry-Leading Cloud Security Through AccuKnox Collaboration appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has released critical security updates to address multiple zero-day vulnerabilities affecting Android devices worldwide.

    The December 2025 security bulletin reveals that threat actors are actively exploiting at least two of these vulnerabilities in real-world attacks, prompting urgent action from the tech giant.

    Critical Vulnerabilities Under Active Exploitation

    The two most concerning vulnerabilities being actively exploited are CVE-2025-48633 and CVE-2025-48572, both classified as information disclosure (ID) issues with high severity ratings.

    These vulnerabilities reside in Android’s Framework component and require immediate attention from device manufacturers and users.

    CVE-2025-48633 poses a significant risk by allowing unauthorized disclosure of information on affected versions of Android 13, 14, 15, and 16.

    Similarly, CVE-2025-48572 is classified as a privilege escalation vulnerability that could enable attackers to gain elevated access on vulnerable devices.

    AspectCVE-2025-48572CVE-2025-48633
    Vulnerability TypeElevation of Privilege (EoP)Information Disclosure (ID)
    Severity RatingHighHigh
    ComponentAndroid FrameworkAndroid Framework
    Affected VersionsAndroid 13, 14, 15, 16Android 13, 14, 15, 16
    Impact DescriptionAllows attacker to gain elevated system privileges without requiring additional permissionsEnables unauthorized access to sensitive device information and data

    Most Severe Threat: Remote Denial of Service

    While CVE-2025-48633 and CVE-2025-48572 represent the most actively exploited threats, the security bulletin identifies an even more critical vulnerability.

    CVE-2025-48631 stands out as the most severe issue in this month’s update, capable of causing remote denial-of-service attacks.

    What makes this vulnerability particularly dangerous is that attackers need no additional execution privileges to exploit it, meaning even unauthenticated attackers could trigger it.

    Google’s security response is comprehensive, addressing over 30 vulnerabilities across multiple Android components.

    Security patch levels resolve these issues, with source code patches to be released to the Android Open-Source Project within 48 hours of the bulletin’s publication.

    The Framework component dominates this month’s updates, with vulnerabilities including privilege escalation flaws (CVE-2025-22420, CVE-2025-48525).

    Denial-of-service issues and information disclosure vulnerabilities affecting Android versions 13 through 16. Google emphasizes that users can significantly reduce their risk through immediate action.

    The company has implemented multiple layers of protection through the Android security platform and Google Play Protect, which are enabled by default on devices with Google Mobile Services.

    Security experts advise users to install available updates immediately, particularly those using Android 13, 14, 15, or 16.

    Device manufacturers received advance notification at least one month before the public bulletin release, allowing them time to prepare patches for their specific devices.

    Android device owners should prioritize checking for available security updates in their device settings. Users can verify their current security patch level through their device’s About Phone section.

    Immediate installation of patches addressing the December 5, 2025, security level is strongly recommended, especially for devices that active exploits may target.

    Additionally, users should ensure Google Play Protect remains enabled and consider limiting app installation to the official Google Play Store, as the system actively monitors for potentially harmful applications that might exploit these vulnerabilities.

    The post Google Patches Android 0-Day Vulnerabilities Exploited in the Wild appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly discovered information-stealing malware called Arkanix is rapidly evolving to target sensitive user data, including VPN credentials, system information, and wireless network passwords. Security researchers have identified this emerging threat as a short-lived, profit-driven malware designed for quick financial exploitation through the sale of stolen data and direct credential compromise. The threat actors behind […]

    The post Arkanix Stealer Emerges as New Threat: Steals VPN Logins, Wi-Fi Credentials, and Screenshots appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated threat group operating under the name ShadyPanda has successfully compromised millions of browser users through a methodical seven-year campaign targeting popular Chrome and Edge extensions.

    The attack represents a significant breach of user trust, as the malicious extensions gained verified status from both Google and Microsoft, making them appear legitimate to unsuspecting users.

    Over this extended period, ShadyPanda infected 4.3 million devices while remaining largely undetected, demonstrating a patient and evolving approach to browser-based attacks.

    The campaign operates in two distinct but interconnected phases. The first involves a remote code execution (RCE) backdoor deployed through five weaponized extensions, including the well-known Clean Master application, which accumulated over 300,000 installations before activation.

    Clean Master - the malware that was featured by Google (Source - Koi)
    Clean Master – the malware that was featured by Google (Source – Koi)

    The second phase comprises a massive spyware operation spanning five additional extensions with over 4 million combined installs, particularly the WeTab New Tab Page extension with 3 million users alone.

    This dual-operation structure reveals the threat group’s ability to maintain multiple attack vectors simultaneously while evading detection for extended periods.

    Koi security analysts noted and identified that ShadyPanda’s success stems from weaponizing legitimate applications through quiet updates rather than malicious distribution methods.

    The group cultivated trust by allowing extensions to operate normally for years, collecting genuine user reviews and building installer counts.

    Cookie exfiltration (Source - Koi)
    Cookie exfiltration (Source – Koi)

    When vulnerable numbers were reached, a single update transformed these trusted tools into surveillance instruments, using Chrome and Edge’s automatic update mechanisms to instantly compromise millions of browsers without user interaction or visibility.

    Infection mechanism

    The infection mechanism operates with remarkable sophistication through several technical methods. Every infected browser contacts remote servers hourly to retrieve new instructions and execute arbitrary JavaScript code with full browser API access.

    This creates a persistent backdoor rather than static malware, enabling the threat group to adapt attacks dynamically.

    The malicious payload collects complete browsing histories, search queries, website navigation patterns, and precise mouse click coordinates, all encrypted with AES encryption before transmission to servers in China.

    To maintain effectiveness against security researchers, the malware employs advanced evasion techniques.

    When developer tools are opened, the extension immediately switches to benign behavior, preventing analysis and discovery.

    The code uses heavy obfuscation through shortened variable names and executes through a 158KB JavaScript interpreter to bypass security policies.

    Service workers enable man-in-the-middle capabilities, allowing traffic interception and modification of legitimate files, including credential harvesting from HTTPS connections.

    The threat landscape now extends beyond individual consumers to enterprise environments. Developer workstations running infected extensions represent entry points to corporate networks, potentially compromising repositories, API keys, and cloud infrastructure access.

    Security professionals must immediately audit installed extensions on critical systems and implement behavioral monitoring solutions to detect weaponization patterns that traditional static analysis cannot identify.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post 4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • OpenVPN has released critical security updates for its 2.6 stable and 2.7 development branches, addressing three vulnerabilities that could lead to local denial-of-service (DoS), security bypasses, and buffer over-reads.

    The patches, included in the newly released version 2.6.17 and 2.7_rc3, fix issues ranging from logic errors in HMAC verification to stability flaws in the Windows interactive service.

    Administrators are urged to upgrade immediately, particularly those running OpenVPN on Windows or utilizing the 2.7 release candidates.​

    Windows Interactive Service DoS (CVE-2025-13751)

    The most significant issue for Windows environments is CVE-2025-13751, a local denial-of-service vulnerability affecting the interactive service component.

    The flaw involves an erroneous exit routine where the service shuts down completely upon encountering specific error conditions, rather than logging the error and continuing operations.​

    This vulnerability can be triggered by any authenticated local user, making it a moderate risk for multi-user Windows systems.

    Once triggered, the OpenVPN service terminates, preventing any new VPN connections until the service is manually restarted or the system is rebooted. This issue affects OpenVPN versions 2.6.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2. It is resolved in 2.6.17 and 2.7_rc3.​

    HMAC Verification Bypass (CVE-2025-13086)

    A serious logic flaw, identified as CVE-2025-13086, was found in the HMAC verification check used during the 3-way handshake. Due to an inverted memcmp() call in the code, the system inadvertently accepted all HMAC cookies, effectively neutralizing source IP address validation.​

    This failure allows attackers to bypass the initial verification layer, potentially opening TLS sessions and consuming server state from IP addresses that did not initiate a legitimate connection.

    The update also enforces stricter timeslot checks, rejecting HMACs from future timestamps. This vulnerability affects versions 2.6.0 through 2.6.15 and is fixed in 2.6.16 (and included in 2.6.17).​

    IPv6 Buffer Over-Read (CVE-2025-12106)

    For users on the development branch (2.7 series), CVE-2025-12106 presents a high-severity memory safety issue. The vulnerability stems from a mismatched address family check in the get_addr_generic function, which can lead to a heap buffer over-read when parsing invalid IPv6 input.​

    While this flaw has been rated with a critical CVSS score of 9.1 in some reports due to its potential for memory corruption, it is strictly limited to the 2.7_alpha1 through 2.7_rc1 builds and does not affect the stable 2.6 branch.​

    The following table summarizes the vulnerabilities and the required versions to mitigate them. Users on the stable branch should target 2.6.17, while testing branch users must update to 2.7_rc3.

    CVE IDVulnerability TypeImpactAffected VersionsFixed In
    CVE-2025-13751Local DoSService crash on Windows2.6.0–2.6.16
    2.7_alpha1–2.7_rc2
    2.6.17
    2.7_rc3
    CVE-2025-13086Security BypassHMAC check failure2.6.0–2.6.15
    2.7_alpha1–2.7_rc1
    2.6.16
    2.7_rc2
    CVE-2025-12106Buffer Over-readInvalid IPv6 parsing2.7_alpha1–2.7_rc12.7_rc2

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google on Monday released monthly security updates for the Android operating system, including two vulnerabilities that it said have been exploited in the wild. The patch addresses a total of 107 security flaws spanning different components, including Framework, System, Kernel, as well as those from Arm, Imagination Technologies, MediaTek, Qualcomm, and Unison. The two high-severity shortcomings

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has released critical security patches addressing two high-severity zero-day vulnerabilities in Android that are currently being exploited in limited, targeted attacks. The vulnerabilities, disclosed in the December 2025 Android Security Bulletin, affect multiple Android versions and require immediate attention from device manufacturers and users. Active Exploitation Confirmed The two CVEs under active exploitation, CVE-2025-48633 […]

    The post Google Fixes Android Zero-Day Flaws Actively Exploited in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶