Tag: cyber-security-news

  • Wikipedia Lost Legal Battle Against The UK’s Online Safety ACT Regulations

    Wikipedia Lost Legal Battle Against The UK’s Online Safety ACT Regulations Wikipedia has suffered a significant legal defeat in its attempt to avoid being classified under the UK’s stringent Online Safety Act regulations. The High Court ruled against the Wikimedia Foundation and a Wikipedia user, known only as “BLN,” who challenged the Secretary of State’s…

  • Scattered Spider With New Telegram Channel List Organizations It Attacked

    Scattered Spider With New Telegram Channel List Organizations It Attacked In early August 2025, a previously quiet cybercrime collective known as Scattered Spider resurfaced with a striking new Telegram channel that aggregates proof of its intrusions and data exfiltration operations. The channel name fuses ShinyHunters, Scattered Spider, and Lapsus$, signaling a collaboration—or at least a…

  • DarkBit Hackers Attacking VMware ESXi Servers to Deploy Ransomware and Encrypt VMDK Files

    DarkBit Hackers Attacking VMware ESXi Servers to Deploy Ransomware and Encrypt VMDK Files A newly discovered ransomware campaign has targeted enterprise VMware ESXi environments with military precision, deploying custom-built encryption tools that specifically hunt for virtual machine disk files across VMFS datastores.  Security researchers have successfully reverse-engineered the attack methodology and developed breakthrough decryption techniques,…

  • INE Named to Training Industry’s 2025 Top 20 Online Learning Library List

    INE Named to Training Industry’s 2025 Top 20 Online Learning Library List Cary, United States, August 11th, 2025, CyberNewsWire Hands-on cybersecurity and IT training leader recognized for innovation in practical, work-ready education INE has been selected for Training Industry’s 2025 Top 20 Online Learning Library Companies list, recognizing the company’s leadership in cybersecurity training, cybersecurity certifications,…

  • WinRAR 0-Day in Phishing Attacks to Deploy RomCom Malware

    WinRAR 0-Day in Phishing Attacks to Deploy RomCom Malware A critical zero-day vulnerability has been identified in WinRAR that cybercriminals are actively exploiting through sophisticated phishing campaigns to distribute RomCom malware.  The flaw, designated as CVE-2025-8088, represents a significant security threat with a CVSS v3.1 score of 8.4, enabling attackers to execute arbitrary code on…

  • GPT-5 Jailbreaked With Echo Chamber and Storytelling Attacks

    GPT-5 Jailbreaked With Echo Chamber and Storytelling Attacks Researchers have compromised OpenAI’s latest GPT-5 model using sophisticated echo chamber and storytelling attack vectors, revealing critical vulnerabilities in the company’s most advanced AI system.  The breakthrough demonstrates how adversarial prompt engineering can bypass even the most robust safety mechanisms, raising serious concerns about enterprise deployment readiness…

  • 7-Zip Arbitrary File Write Vulnerability Let Attackers Execute Arbitrary Code

    7-Zip Arbitrary File Write Vulnerability Let Attackers Execute Arbitrary Code A newly disclosed security vulnerability in the popular 7-Zip file compression software has raised significant concerns in the cybersecurity community. CVE-2025-55188, discovered and reported by security researcher Landon on August 9, 2025, allows attackers to perform arbitrary file writes during archive extraction, potentially leading to…

  • New ‘Win-DoS’ Zero-Click Vulnerabilities Turns Windows Server/Endpoint, Domain Controllers Into DDoS Botnet

    New ‘Win-DoS’ Zero-Click Vulnerabilities Turns Windows Server/Endpoint, Domain Controllers Into DDoS Botnet LAS VEGAS — At the DEF CON 33 security conference, researchers Yair and Shahak Morag of SafeBreach Labs unveiled a new class of denial-of-service (DoS) attacks, dubbed the “Win-DoS Epidemic.” The duo presented their findings, which include four new Windows DoS vulnerabilities and…

  • Google Confirms Data Breach – Notifying Users Affected By the Cyberattack

    Google Confirms Data Breach – Notifying Users Affected By the Cyberattack Tech giant Google has officially acknowledged a significant data breach affecting its corporate Salesforce database, with the company completing email notifications to affected users as of August 8, 2025. Google revealed on August 5 that one of its corporate Salesforce instances was compromised in…

  • Darknet Market Escrow Systems is Vulnerable to Administrator Exit Scams

    Darknet Market Escrow Systems is Vulnerable to Administrator Exit Scams Darknet markets, operating beyond the reach of traditional payment processors and legal systems, rely on escrow systems to secure cryptocurrency transactions between buyers and vendors.  These systems, using multisignature wallets and automated release mechanisms, aim to ensure transaction security and facilitate dispute resolution. However, vulnerabilities…

  • ChatGPT Connectors ‘0-click’ Vulnerability Let Attackers Exfiltrate Data From Google Drive

    ChatGPT Connectors ‘0-click’ Vulnerability Let Attackers Exfiltrate Data From Google Drive A critical vulnerability in OpenAI’s ChatGPT Connectors feature allows attackers to exfiltrate sensitive data from connected Google Drive accounts without any user interaction beyond the initial file sharing. The attack, dubbed “AgentFlayer,” represents a new class of zero-click exploits targeting AI-powered enterprise tools. The…

  • New Linux Kernel Vulnerability Directly Exploited from Chrome Renderer Sandbox Via Rare Linux Socket Feature

    New Linux Kernel Vulnerability Directly Exploited from Chrome Renderer Sandbox Via Rare Linux Socket Feature A critical vulnerability in the Linux kernel, identified as CVE-2025-38236, has exposed a flaw that could allow attackers to escalate privileges from within the Chrome renderer sandbox on Linux systems.  Google Project Zero researcher Jann Horn discovered the bug affects…

  • Threat Actors Using Typosquatted PyPI Packages to Steal Cryptocurrency from Bittensor Wallets

    Threat Actors Using Typosquatted PyPI Packages to Steal Cryptocurrency from Bittensor Wallets A sophisticated cryptocurrency theft campaign has emerged targeting the Bittensor ecosystem through malicious Python packages distributed via the Python Package Index (PyPI). The attack leverages typosquatting techniques to deceive developers and users into installing compromised versions of legitimate Bittensor packages, ultimately resulting in…

  • Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email

    Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email A sophisticated malware campaign dubbed “Efimer” has emerged as a significant threat to cryptocurrency users worldwide, employing a multi-vector approach that combines compromised WordPress websites, malicious torrents, and deceptive email campaigns. First detected in October 2024, this ClipBanker-type Trojan…

  • 5,000+ Fake Online Pharmacies Websites Selling Counterfeit Medicines

    5,000+ Fake Online Pharmacies Websites Selling Counterfeit Medicines A sophisticated cybercriminal enterprise operating over 5,000 fraudulent online pharmacy websites has been exposed in a comprehensive investigation, revealing one of the largest pharmaceutical fraud networks ever documented. This massive operation, orchestrated by a single threat actor group, targets vulnerable individuals seeking prescription medications through deceptive digital…

  • BitUnlocker – Multiple 0-days to Bypass BitLocker and Extract All Protected Data

    BitUnlocker – Multiple 0-days to Bypass BitLocker and Extract All Protected Data Researchers have disclosed a series of critical zero-day vulnerabilities that completely bypass Windows BitLocker encryption, allowing attackers with physical access to extract all protected data from encrypted devices in a matter of minutes. The research, conducted by Alon Leviev and Netanel Ben Simon…

  • DarkCloud Stealer Employs New Infection Chain and ConfuserEx-Based Obfuscation

    DarkCloud Stealer Employs New Infection Chain and ConfuserEx-Based Obfuscation A sophisticated information-stealing malware campaign has emerged, utilizing advanced obfuscation techniques and multiple infection vectors to evade traditional security controls. The DarkCloud Stealer, first documented in recent threat intelligence reports, represents a significant evolution in cybercriminal tactics, employing a complex multi-stage delivery mechanism that begins with…

  • ECScape: Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials

    ECScape: Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials A sophisticated technique dubbed “ECScape” that allows malicious containers running on Amazon Elastic Container Service (ECS) to steal AWS credentials from other containers sharing the same EC2 instance. The discovery highlights critical isolation weaknesses in multi-tenant ECS deployments and underscores the…

  • Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims

    Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims A sophisticated cybercriminal operation known as GreedyBear has orchestrated one of the most extensive cryptocurrency theft campaigns to date, deploying over 650 malicious tools across multiple attack vectors to steal more than $1 million from unsuspecting victims. Unlike traditional threat groups that…

  • ChatGPT-5 Released: What’s New With the Next-Generation AI Agent

    ChatGPT-5 Released: What’s New With the Next-Generation AI Agent OpenAI has officially launched ChatGPT-5, a new generation of its AI agent that introduces a sophisticated, unified system designed to be faster, more intelligent, and significantly more useful for real-world applications. This release marks a significant evolution from its predecessors, offering a suite of models tailored…

  • CISA Releases Emergency Advisory Urges Feds to Patch Exchange Server Vulnerability by Monday

    CISA Releases Emergency Advisory Urges Feds to Patch Exchange Server Vulnerability by Monday CISA has issued an emergency advisory directing all Federal Civilian Executive Branch agencies to mitigate a newly disclosed Microsoft Exchange urgently hybrid-joined vulnerability, tracked as CVE-2025-53786, by 9:00 AM EDT on Monday, August 11, 2025. The flaw enables attackers who have already…

  • Flipper Zero ‘DarkWeb’ Firmware Bypasses Rolling Code Security on Major Vehicle Brands

    Flipper Zero ‘DarkWeb’ Firmware Bypasses Rolling Code Security on Major Vehicle Brands A new and custom firmware for the popular Flipper Zero multi-tool device is reportedly capable of bypassing the rolling code security systems used in most modern vehicles, potentially putting millions of cars at risk of theft. Demonstrations by the YouTube channel “Talking Sasquach”…

  • HashiCorp Vault 0-Day Vulnerabilities Let Attackers Execute Remote Code

    HashiCorp Vault 0-Day Vulnerabilities Let Attackers Execute Remote Code Security researchers uncovered a series of critical zero-day vulnerabilities in HashiCorp Vault in early August 2025, the widely adopted secrets management solution. These flaws, spanning authentication bypasses, policy enforcement inconsistencies, and audit-log abuse, create end-to-end attack paths that culminate in remote code execution (RCE) on Vault…

  • 1.2 Million Healthcare Devices and Systems Data Leaked Online – Patient Records at Risk of Exposure

    1.2 Million Healthcare Devices and Systems Data Leaked Online – Patient Records at Risk of Exposure Over 1.2 million internet-connected healthcare devices and systems with exposure that endanger patient data shown in new research by European cybersecurity company Modat. Global findings showing Top 10 Regions (most results are across Europe, the USA, and South Africa):  United States…

  • HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover

    HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover A critical vulnerability in the HTTP/1.1 protocol threatens tens of millions of websites with potential hostile takeovers through sophisticated desynchronization attacks.  This fundamental flaw in the decades-old protocol creates extreme ambiguity about where one request ends and the next begins, enabling attackers to manipulate web…

  • Gemini Exploited via Prompt Injection in Google Calendar Invite to Steal Emails, and Control Smart Devices

    Gemini Exploited via Prompt Injection in Google Calendar Invite to Steal Emails, and Control Smart Devices A sophisticated attack method exploits Google’s Gemini AI assistant through seemingly innocent calendar invitations and emails.  The attack, dubbed “Targeted Promptware Attacks,” demonstrates how indirect prompt injection can compromise users’ digital privacy and even control physical devices in their…

  • Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds

    Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds Threat actors successfully compromised corporate systems within just five minutes using a combination of social engineering tactics and rapid PowerShell execution.  The incident, investigated by NCC Group’s Digital Forensics and Incident Response (DFIR) team, demonstrates how cybercriminals are weaponizing trusted business applications to…

  • Critical Trend Micro Apex One Management RCE Vulnerability Actively Exploited in the wild

    Critical Trend Micro Apex One Management RCE Vulnerability Actively Exploited in the wild Critical command injection remote code execution (RCE) vulnerabilities in Trend Micro Apex One Management Console are currently being actively exploited by threat actors.  The company confirmed observing at least one instance of attempted exploitation in production environments, prompting the immediate release of…

  • Threat Actors Weaponizing RMM Tools to Take Control of The Machine and Steal Data

    Threat Actors Weaponizing RMM Tools to Take Control of The Machine and Steal Data Cybercriminals are increasingly exploiting Remote Monitoring and Management (RMM) software to gain unauthorized access to corporate systems, with a sophisticated new attack campaign demonstrating how legitimate IT tools can become powerful weapons in the wrong hands. This emerging threat leverages the…

  • CISA Releases Two Advisories Covering Vulnerabilities, and Exploits Surrounding ICS

    CISA Releases Two Advisories Covering Vulnerabilities, and Exploits Surrounding ICS CISA released two urgent Industrial Control Systems (ICS) advisories on August 5, 2025, addressing significant security vulnerabilities in critical manufacturing and energy sector systems.  These advisories detail exploitable flaws that could compromise industrial operations and potentially disrupt essential services across multiple sectors. Key Takeaways1. CISA…

  • Bing Search Poisoned to Deliver Bumblebee Malware for ‘ManageEngine OpManager’ Searches

    Bing Search Poisoned to Deliver Bumblebee Malware for ‘ManageEngine OpManager’ Searches A sophisticated search engine optimization (SEO) poisoning campaign that exploited Bing search results to distribute Bumblebee malware, ultimately leading to devastating Akira ransomware attacks. The campaign, active throughout July 2025, specifically targeted users searching for legitimate IT management software, demonstrating how threat actors continue…

  • Millions of Dell Laptops Vulnerable to Device Takeover and Persistent Malware Attacks

    Millions of Dell Laptops Vulnerable to Device Takeover and Persistent Malware Attacks A wide range of vulnerabilities affects millions of Dell laptops used by government agencies, cybersecurity professionals, and enterprises worldwide. The vulnerabilities, collectively dubbed “ReVault,” target the Broadcom BCM5820X security chip embedded in Dell’s ControlVault3 firmware, creating opportunities for attackers to steal passwords, biometric…

  • Fashion Giant Chanel Hacked in Wave of Salesforce Attacks

    Fashion Giant Chanel Hacked in Wave of Salesforce Attacks French luxury fashion house Chanel has become the latest victim in a sophisticated cybercrime campaign targeting major corporations through their Salesforce customer relationship management systems. The company confirmed on July 25, 2025, that unauthorized threat actors had breached a database containing personal information of U.S. customers…

  • Critical Android System Component Vulnerability Allows Remote Code Execution Without User Interaction

    Critical Android System Component Vulnerability Allows Remote Code Execution Without User Interaction Google released its August 2025 Android Security Bulletin on August 4, revealing a critical vulnerability that poses significant risks to Android device users worldwide.  The most severe flaw, designated CVE-2025-48530, affects the core System component and could enable remote code execution without requiring…

  • New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data

    New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data A sophisticated new Android malware campaign has emerged targeting Indian banking customers through convincing impersonations of popular financial applications. The malicious software masquerades as legitimate apps from major Indian financial institutions, including SBI Card, Axis Bank, Indusind Bank, ICICI, and…

  • NVIDIA Triton Vulnerability Chain Let Attackers Take Over AI Server Control

    NVIDIA Triton Vulnerability Chain Let Attackers Take Over AI Server Control A critical vulnerability chain in NVIDIA’s Triton Inference Server that allows unauthenticated attackers to achieve complete remote code execution (RCE) and gain full control over AI servers.  The vulnerability chain, identified as CVE-2025-23319, CVE-2025-23320, and CVE-2025-23334, exploits the server’s Python backend through a sophisticated…

  • WAFs protection Bypassed to Execute XSS Payloads Using JS Injection with Parameter Pollution

    WAFs protection Bypassed to Execute XSS Payloads Using JS Injection with Parameter Pollution A sophisticated method to bypass Web Application Firewall (WAF) protections using HTTP Parameter Pollution techniques combined with JavaScript injection.  The research, conducted by Bruno Mendes across 17 different WAF configurations from major vendors including AWS, Google Cloud, Azure, and Cloudflare, revealed alarming…

  • AI-Powered Code Editor Cursor IDE Vulnerability Enables Remote Code Without User Interaction

    AI-Powered Code Editor Cursor IDE Vulnerability Enables Remote Code Without User Interaction A severe vulnerability in the popular AI-powered code editor Cursor IDE, dubbed “CurXecute,” allows attackers to execute arbitrary code on developers’ machines without any user interaction.  The vulnerability, tracked as CVE-2025-54135 with a high severity score of 8.6, affects all Cursor IDE versions prior to…

  • NestJS Framework Vulnerability Let Attackers Execute Arbitrary Code in Developers Machine

    NestJS Framework Vulnerability Let Attackers Execute Arbitrary Code in Developers Machine A critical security vulnerability has been discovered in the NestJS framework’s development tools that enables remote code execution (RCE) attacks against JavaScript developers.  The flaw, identified as CVE-2025-54782, affects the @nestjs/devtools-integration package and allows malicious websites to execute arbitrary code on developers’ local machines…

  • Microsoft PlayReady DRM Used by Netflix, Amazon, and Disney+ Leaked Online

    Microsoft PlayReady DRM Used by Netflix, Amazon, and Disney+ Leaked Online A significant security breach has compromised Microsoft’s PlayReady Digital Rights Management (DRM) system, exposing critical certificates that protect premium streaming content across major platforms including Netflix, Amazon Prime Video, and Disney+. The leak, which surfaced on GitHub through an account named “Widevineleak,” has triggered…

  • Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines

    Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines The cybersecurity landscape continues to evolve as threat actors develop increasingly sophisticated methods to compromise Windows systems. A new ransomware variant known as Interlock has emerged as a significant threat, leveraging the deceptive ClickFix social engineering technique to execute malicious commands on victim…

  • APT37 Hackers Weaponizes JPEG Files to Attack Windows Systems Leveraging “mspaint.exe”

    APT37 Hackers Weaponizes JPEG Files to Attack Windows Systems Leveraging “mspaint.exe” A sophisticated new wave of cyberattacks attributed to North Korea’s notorious APT37 (Reaper) group is leveraging advanced malware hidden within JPEG image files to compromise Microsoft Windows systems, signaling a dangerous evolution in evasion tactics and fileless attack techniques. Security researchers at Genians Security…

  • New Undectable Plague Malware Attacking Linux Servers to Gain Persistent SSH Access

    New Undectable Plague Malware Attacking Linux Servers to Gain Persistent SSH Access A sophisticated Linux backdoor dubbed Plague has emerged as an unprecedented threat to enterprise security, evading detection across all major antivirus engines while establishing persistent SSH access through manipulation of core authentication mechanisms. Discovered by cybersecurity researchers at Nextron Systems, this malware represents…

  • SonicWall Firewall Devices 0-day Vulnerability Actively Exploited by Akira Ransomware

    SonicWall Firewall Devices 0-day Vulnerability Actively Exploited by Akira Ransomware A suspected zero-day vulnerability in SonicWall firewall devices that the Akira ransomware group is actively exploiting. The flaw allows attackers to gain initial access to corporate networks through SonicWall’s SSL VPN feature, leading to subsequent ransomware deployment. In late July 2025, security researchers observed a…

  • Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers

    Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers A sophisticated cyber espionage campaign targeting software developers has infiltrated two of the world’s largest open source package repositories, with North Korea’s notorious Lazarus Group successfully deploying 234 malicious packages across npm and PyPI ecosystems. Between January and July 2025, this state-sponsored operation…

  • SafePay Ransomware Infected 260+ Victims Across Multiple Countries

    SafePay Ransomware Infected 260+ Victims Across Multiple Countries A new ransomware threat has emerged as one of the most aggressive cybercriminal operations of 2025, with SafePay ransomware claiming responsibility for over 265 successful attacks spanning multiple continents. The group, which first appeared in September 2024 with limited activity targeting just over 20 victims, has dramatically…

  • Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS

    Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS The ransomware landscape experienced a significant shift in the second quarter of 2025 as Qilin ransomware emerged as the dominant threat following the unexpected collapse of RansomHub, previously the most prolific ransomware-as-a-service operation. This transition has reshaped the cybercriminal ecosystem, with Qilin capitalizing on the…

  • LockBit Operators Using Stealthy DLL Sideloading Technique to Load Malicious App as Legitimate One

    LockBit Operators Using Stealthy DLL Sideloading Technique to Load Malicious App as Legitimate One LockBit ransomware operators have adopted an increasingly sophisticated approach to evade detection by leveraging DLL sideloading techniques that exploit the inherent trust placed in legitimate applications. This stealthy method involves tricking legitimate, digitally signed applications into loading malicious Dynamic Link Libraries…

  • Search Engines are Indexing ChatGPT Conversations! – Here is our OSINT Research

    Search Engines are Indexing ChatGPT Conversations! – Here is our OSINT Research ChatGPT shared conversations are being indexed by major search engines, effectively turning private exchanges into publicly discoverable content accessible to millions of users worldwide. The issue first came to light through investigative reporting by Fast Company, which revealed that nearly 4,500 ChatGPT conversations…

  • Hackers Weaponizing Free Trials of EDR to Disable Existing EDR Protections

    Hackers Weaponizing Free Trials of EDR to Disable Existing EDR Protections A sophisticated attack technique was uncovered where cybercriminals exploit free trials of Endpoint Detection and Response (EDR) software to disable existing security protections on compromised systems.  This method, dubbed BYOEDR (Bring Your Own EDR), represents a concerning evolution in defense evasion tactics that leverage…

  • Unit 42 Unveils Attribution Framework to Classify Threat Actors Based on Activity

    Unit 42 Unveils Attribution Framework to Classify Threat Actors Based on Activity Palo Alto Networks’ Unit 42 threat research team has introduced a groundbreaking systematic approach to threat actor attribution, addressing longstanding challenges in cybersecurity intelligence analysis. The Unit 42 Attribution Framework, unveiled on July 31, 2025, transforms what has traditionally been considered “more art…

  • Threat Actors Embed Malicious RMM Tools to Gain Silent Initial Access to Organizations

    Threat Actors Embed Malicious RMM Tools to Gain Silent Initial Access to Organizations A sophisticated cyber campaign leveraging legitimate Remote Monitoring and Management (RMM) tools has emerged as a significant threat to European organizations, particularly those in France and Luxembourg. Since November 2024, threat actors have been deploying carefully crafted PDF documents containing embedded links…

  • Navigating APTs – Singapore’s Cautious Response to State-Linked Cyber Attacks

    Navigating APTs – Singapore’s Cautious Response to State-Linked Cyber Attacks Singapore’s cybersecurity landscape faced a significant challenge in July 2025 when Coordinating Minister K. Shanmugam disclosed that the nation was actively defending against UNC3886, a highly sophisticated Advanced Persistent Threat (APT) group targeting critical infrastructure. The revelation, announced during the Cyber Security Agency’s 10th anniversary…

  • APT Hackers Attacking Maritime and Shipping Industry to Launch Ransomware Attacks

    APT Hackers Attacking Maritime and Shipping Industry to Launch Ransomware Attacks The maritime industry, which facilitates approximately 90% of global trade, has emerged as a critical battleground for advanced persistent threat (APT) groups deploying sophisticated ransomware campaigns. This surge in cyber warfare represents a paradigm shift where state-sponsored hackers and financially motivated threat actors are…

  • Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released

    Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released A significant zero-day vulnerability in CrushFTP has been disclosed, allowing unauthenticated attackers to achieve complete remote code execution on vulnerable servers.  The flaw, tracked as CVE-2025-54309 and scoring a critical 9.8 on the CVSS scale, stems from a fundamental breakdown in security checks within CrushFTP’s…

  • OAuth2-Proxy Vulnerability Enables Authentication Bypass by Manipulating Query Parameters

    OAuth2-Proxy Vulnerability Enables Authentication Bypass by Manipulating Query Parameters A critical security vulnerability has been identified in OAuth2-Proxy, a widely-used reverse proxy that provides authentication services for Google, Azure, OpenID Connect, and numerous other identity providers.  The vulnerability, designated as CVE-2025-54576, enables attackers to bypass authentication mechanisms by manipulating query parameters in crafted URLs, potentially…

  • Gunra Ransomware New Linux Variant Runs Up To 100 Encryption Threads With New Partial Encryption Feature

    Gunra Ransomware New Linux Variant Runs Up To 100 Encryption Threads With New Partial Encryption Feature A sophisticated new Linux variant of Gunra ransomware has emerged, marking a significant escalation in the threat group’s cross-platform capabilities since its initial discovery in April 2025. The ransomware, which drew inspiration from the notorious Conti ransomware techniques, has…

  • Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures

    Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures Cybercriminals have once again demonstrated their evolving sophistication by weaponizing an obscure Toshiba laptop driver to bypass endpoint detection and response systems. The Qilin ransomware operation, active since July 2022, has incorporated a previously unknown vulnerable driver called TPwSav.sys into their attack arsenal, enabling them…

  • ChatGPT Agent Bypasses Cloudflare “I am not a robot” Verification Checks

    ChatGPT Agent Bypasses Cloudflare “I am not a robot” Verification Checks ChatGPT agents demonstrate the ability to autonomously bypass Cloudflare’s CAPTCHA verification systems, specifically the ubiquitous “I am not a robot” checkbox.  This development, first documented in a viral Reddit post on the r/OpenAI community, showcases the evolving sophistication of AI agents in navigating web…

  • Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware

    Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware A sophisticated cyberattack targeting a US-based chemicals company has revealed the first observed pairing of SAP NetWeaver exploitation with Auto-Color malware, demonstrating how threat actors are leveraging critical vulnerabilities to deploy advanced persistent threats on Linux systems.  In April 2025, cybersecurity firm Darktrace successfully detected…

  • Enterprise LLMs Under Risk: How Simple Prompts Can Lead to Major Breaches

    Enterprise LLMs Under Risk: How Simple Prompts Can Lead to Major Breaches Enterprise applications integrating Large Language Models (LLMs) face unprecedented security vulnerabilities that can be exploited through deceptively simple prompt injection attacks.  Recent security assessments reveal that attackers can bypass authentication systems, extract sensitive data, and execute unauthorized commands using nothing more than carefully…

  • Microsoft Details Defence Techniques Against Indirect Prompt Injection Attacks

    Microsoft Details Defence Techniques Against Indirect Prompt Injection Attacks Microsoft has unveiled a comprehensive defense-in-depth strategy to combat indirect prompt injection attacks, one of the most significant security threats facing large language model (LLM) implementations in enterprise environments.  The company’s multi-layered approach combines preventative techniques, detection tools, and impact mitigation strategies to protect against attackers…

  • Lionishackers Threat Actors Exfiltrating and Selling Corporate Databases on Dark Web

    Lionishackers Threat Actors Exfiltrating and Selling Corporate Databases on Dark Web A financially motivated threat actor known as Lionishackers has emerged as a significant player in the illicit marketplace for corporate data in recent months. Leveraging opportunistic targeting and a preference for Asian-based victims, the group employs automated SQL injection tools to breach database servers,…

  • 10 Best Virtual Machine (VM) Monitoring Tools in 2025

    10 Best Virtual Machine (VM) Monitoring Tools in 2025 VM (Virtual Machine) monitoring tools are essential for maintaining the performance, availability, and security of virtualized environments. These tools provide real-time visibility into VM health and performance, enabling administrators to track key metrics such as CPU usage, memory utilization, disk I/O, and network traffic. VM monitoring…

  • CISA Warns of PaperCut RCE Vulnerability Exploited in Attacks

    CISA Warns of PaperCut RCE Vulnerability Exploited in Attacks CISA has issued an urgent warning regarding a critical vulnerability in PaperCut NG/MF print management software that threat actors are actively exploiting in ransomware campaigns.  The vulnerability, tracked as CVE-2023-2533, represents a significant security risk to organizations worldwide using the affected software versions. Key Takeaways1. CVE-2023-2533…

  • Apple’s New Containerization Feature Allows Kali Linux Integration on macOS

    Apple’s New Containerization Feature Allows Kali Linux Integration on macOS Apple quietly slipped a game-changing developer feature into its WWDC 25 announcements: a native containerization stack that lets Macs run Open Container Initiative (OCI) images inside ultra-lightweight virtual machines. In practice, that means you can launch a full Kali Linux environment on macOS “Sequoia” 15…

  • 10 Best Anti-Phishing Tools in 2025

    10 Best Anti-Phishing Tools in 2025 Anti-phishing tools are essential cybersecurity solutions designed to detect and prevent phishing attacks. These tools identify and block malicious emails, websites, and messages that attempt to deceive users into disclosing sensitive information such as passwords, credit card numbers, and personal details. They use advanced algorithms, machine learning, and threat…

  • Critical macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Private Data of Files Bypassing TCC

    Critical macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Private Data of Files Bypassing TCC A critical macOS vulnerability enables attackers to bypass Transparency, Consent, and Control (TCC) protections and steal sensitive user data, including files from protected directories and Apple Intelligence caches.  The vulnerability, dubbed “Sploitlight,” exploits Spotlight plugins to access normally protected information without user consent,…

  • LG Innotek Camera Vulnerabilities Let Attackers Gain Administrative Access

    LG Innotek Camera Vulnerabilities Let Attackers Gain Administrative Access A serious security vulnerability has been discovered in LG Innotek’s LNV5110R camera model that could allow cybercriminals to gain complete administrative control over affected devices.  The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory on July 24, 2025, warning of a remotely exploitable flaw…

  • 10 Best Cloud Monitoring Tools in 2025

    10 Best Cloud Monitoring Tools in 2025 Cloud monitoring tools are essential for maintaining cloud-based services and applications’ performance, availability, and security. These tools provide real-time visibility into cloud infrastructure, enabling monitoring metrics such as resource utilization, application performance, and network traffic. Cloud monitoring tools help identify and resolve issues quickly by offering customizable dashboards…

  • Arizona Woman Sentenced for Helping North Korean IT Workers by Operating Laptop Farm

    Arizona Woman Sentenced for Helping North Korean IT Workers by Operating Laptop Farm An Arizona woman received a significant federal prison sentence for orchestrating a sophisticated cybercrime operation that enabled North Korean Information Technology (IT) workers to infiltrate hundreds of American companies while generating millions in revenue for the Democratic People’s Republic of Korea (DPRK). …

  • Critical Salesforce Tableau Vulnerabilities Let Attackers Execute Code Remotely

    Critical Salesforce Tableau Vulnerabilities Let Attackers Execute Code Remotely Multiple critical security vulnerabilities affecting Salesforce’s Tableau Server that could allow attackers to execute remote code, bypass authorization controls, and access sensitive production databases.  The vulnerabilities, revealed through a security advisory published on June 26, 2025, impact Tableau Server versions before 2025.1.3, before 2024.2.12, and before…

  • Weekly Cybersecurity News Recap : Sharepoint 0-day, Vmware Exploitation, Threats and Cyber Attacks

    Weekly Cybersecurity News Recap : Sharepoint 0-day, Vmware Exploitation, Threats and Cyber Attacks Welcome to this week’s Cybersecurity Recap. We’re looking at important updates from July 21-27, 2025, in the world of digital threats and defenses. This week has seen significant developments that highlight the ongoing risks of cyber attacks and the need for constant…

  • Allianz Life Insurance Data Breach – 1.4 Million Customers Data at Risk

    Allianz Life Insurance Data Breach – 1.4 Million Customers Data at Risk Major U.S. insurance provider Allianz Life Insurance Company confirmed on Saturday that hackers compromised the personal information of the “majority” of its 1.4 million customers following a sophisticated cyberattack on July 16, 2025. The breach, disclosed in a mandatory filing with Maine’s attorney…

  • 15 Best Docker Monitoring Tools in 2025

    15 Best Docker Monitoring Tools in 2025 Docker monitoring is the process of keeping tabs on the functionality, state, and resource usage of Docker containers as well as the entire Docker ecosystem. With the help of the well-known containerization technology Docker, programmers may bundle their apps and their dependencies into independent, lightweight containers that can…

  • 20 Best SNMP Monitoring Tools in 2025

    20 Best SNMP Monitoring Tools in 2025 SNMP (Simple Network Management Protocol) monitoring tools are essential for managing and monitoring network devices. They collect and organize information from various network devices, such as routers, switches, servers, and printers. These tools provide real-time data on device performance, network traffic, and operational status, enabling network administrators to…

  • Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware

    Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware Gaming peripheral manufacturer Endgame Gear has confirmed that hackers successfully compromised its official software distribution system, using the company’s OP1w 4K V2 mouse configuration tool to spread dangerous Xred malware to unsuspecting customers for nearly two weeks. The security breach, which occurred between June…

  • Infamous BreachForums Is Back Online With All Old Accounts and Posts Restored

    Infamous BreachForums Is Back Online With All Old Accounts and Posts Restored BreachForums, the notorious cybercrime discussion board that vanished from the clearnet after a law-enforcement seizure in, quietly re-opened this week under its original administrators and with the entire historical archive of user accounts, posts, and private messages intact. The unexpected reemergence has alarmed…

  • Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities

    Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities Microsoft Corp. is investigating whether a leak from its Microsoft Active Protections Program (MAPP) enabled Chinese state-sponsored hackers to exploit critical SharePoint vulnerabilities before patches were fully deployed, according to a Bloomberg report. The investigation comes as cyber espionage attacks have compromised…

  • New VOIP-Based Botnet Attacking Routers Configured With Default Password

    New VOIP-Based Botnet Attacking Routers Configured With Default Password A sophisticated global botnet campaign targeting VOIP-enabled routers and devices configured with default credentials.  The discovery began when analysts noticed an unusual cluster of malicious IP addresses concentrated in rural New Mexico, leading to the identification of approximately 500 compromised devices worldwide. Key Takeaways1. Hackers are…

  • Web-to-App Funnels: Pros And Cons

    Web-to-App Funnels: Pros And Cons In today’s mobile-first world, companies often struggle to bridge the gap between their websites and mobile apps. This is where web-to-app funnels come into play. These funnels are designed to guide users from a web touchpoint (such as an ad or landing page) into a mobile application, where deeper engagement…

  • Microsoft 365 Admin Center Outage Blocks Access for Admins Worldwide

    Microsoft 365 Admin Center Outage Blocks Access for Admins Worldwide Microsoft is currently facing an outage that affects the Microsoft 365 Admin Center, preventing administrators from accessing essential management tools. The issue, which emerged prominently on July 24, 2025, has persisted into the following day, marking the second such incident this week and raising concerns…

  • 10 Best API Monitoring Tools in 2025

    10 Best API Monitoring Tools in 2025 API monitoring tools ensure the performance, availability, and reliability of application programming interfaces (APIs) that connect different software systems. These tools continuously track and analyze API requests and responses to detect slow response times, errors, and downtime. By providing real-time insights, alerts, and detailed analytics, API monitoring tools…

  • Malicious Android Apps Mimic as Popular Indian Banking Apps Steal Login Credentials

    Malicious Android Apps Mimic as Popular Indian Banking Apps Steal Login Credentials Attackers are weaponizing India’s appetite for mobile banking by circulating counterfeit Android apps that mimic the interfaces and icons of public-sector and private banks. Surfacing in telemetry logs on 3 April 2025, the impostors travel through smishing texts, QR codes and search-engine poisoning,…

  • Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations

    Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations A sophisticated espionage campaign dubbed “Fire Ant” demonstrates previously unknown capabilities in compromising VMware virtualization infrastructure.  Since early 2025, this threat actor has systematically targeted VMware ESXi hosts, vCenter servers, and network appliances using hypervisor-level techniques that evade traditional endpoint security solutions. …

  • New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer

    New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer A newly uncovered campaign is exploiting gamers’ enthusiasm for off-beat indie titles to plant credential-stealing malware on machines. Branded installers for nonexistent games such as “Baruda Quest,” “Warstorm Fire,” and “Dire Talon” are pushed through slick YouTube trailers and Discord download links…

  • xonPlus Launches Real-Time Breach Alerting Platform For Enterprise Credential Exposure

    xonPlus Launches Real-Time Breach Alerting Platform For Enterprise Credential Exposure Chennai, India, July 25th, 2025, CyberNewsWire xonPlus, a real-time digital risk alerting system, officially launches today to help security teams detect credential exposures before attackers exploit them. The platform detects data breaches and alerts teams and systems to respond instantly. Built by the team behind…

  • Hackers Exploiting Sharepoint 0-day Vulnerability to Deploy Warlock Ransomware

    Hackers Exploiting Sharepoint 0-day Vulnerability to Deploy Warlock Ransomware Microsoft has issued urgent warnings about active exploitation of critical SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 by multiple threat actors, including the China-based group Storm-2603, which has been deploying Warlock ransomware in compromised environments.  The vulnerabilities affect on-premises SharePoint Server 2016, 2019, and Subscription Edition, with exploitation…

  • Windows 11 Gets New Black Screen of Death With Auto Recovery Tool

    Windows 11 Gets New Black Screen of Death With Auto Recovery Tool Microsoft has unveiled significant improvements to Windows 11’s system recovery capabilities, introducing a redesigned Black Screen of Death restart screen alongside an automated Quick Machine Recovery (QMR) tool.  These enhancements are part of the broader Windows Resiliency Initiative (WRI), designed to minimize downtime…

  • CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild

    CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild CISA has issued an urgent warning regarding two critical Microsoft SharePoint vulnerabilities that threat actors are actively exploiting in the wild.  The vulnerabilities, designated as CVE-2025-49704 and CVE-2025-49706, pose significant risks to organizations running on-premises SharePoint servers and have been added to…

  • Kali Linux Unveils Two New Tools to Boost Wi-Fi Performance for Raspberry Pi Users

    Kali Linux Unveils Two New Tools to Boost Wi-Fi Performance for Raspberry Pi Users Kali Linux has announced the release of two groundbreaking packages that significantly enhance wireless penetration testing capabilities for Raspberry Pi users. The new brcmfmac-nexmon-dkms and firmware-nexmon packages, introduced in Kali Linux 2025.1, enable the onboard Wi-Fi interface on supported Raspberry Pi…

  • Chinese Hackers Actively Exploiting SharePoint Servers 0-Day Flaw in the Wild

    Chinese Hackers Actively Exploiting SharePoint Servers 0-Day Flaw in the Wild Microsoft has confirmed that Chinese state-sponsored threat actors are actively exploiting critical zero-day vulnerabilities in on-premises SharePoint servers, prompting urgent security warnings for organizations worldwide.  The tech giant’s Security Response Center reported coordinated attacks targeting internet-facing SharePoint installations using newly disclosed vulnerabilities that enable…

  • Chrome High-Severity Vulnerabilities Allow Attackers to Execute Arbitrary Code

    Chrome High-Severity Vulnerabilities Allow Attackers to Execute Arbitrary Code Google has released an urgent security update for its Chrome browser, addressing three critical vulnerabilities that could enable attackers to execute arbitrary code on users’ systems. The Stable channel update to version 138.0.7204.168/.169 for Windows and Mac, and 138.0.7204.168 for Linux, is currently rolling out to…

  • GLOBAL GROUP’s Golang Ransomware Attacks Windows, Linux, and macOS Environments

    GLOBAL GROUP’s Golang Ransomware Attacks Windows, Linux, and macOS Environments A sophisticated new ransomware threat has emerged from the cybercriminal underground, targeting organizations across multiple operating systems with advanced cross-platform capabilities. In June 2025, a ransomware actor operating under the alias “Dollar Dollar Dollar” introduced GLOBAL GROUP on the Ramp4u cybercrime forum, marketing it as…

  • Wireshark 4.4.8 Released With Bug Fixes and Updated Protocol Support

    Wireshark 4.4.8 Released With Bug Fixes and Updated Protocol Support Wireshark Foundation has announced the availability of Wireshark 4.4.8, the latest maintenance release of the world’s most widely used network-protocol analyzer. Although the update does not introduce brand-new protocols, it delivers a focused package of stability improvements, expanded dissector capabilities, and quality-of-life fixes that will…

  • Dior, a Louis Vuitton Brand, Alerts Customers Following Cyber Attack

    Dior, a Louis Vuitton Brand, Alerts Customers Following Cyber Attack Christian Dior Couture, the luxury fashion house owned by Louis Vuitton, has begun notifying customers of a major cybersecurity incident that exposed sensitive personal information of clients.  The breach, discovered in May 2025, involved unauthorized access to customer databases containing personal data including names, addresses,…

  • Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day

    Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day Thousands of organizations worldwide face active cyberattacks targeting Microsoft SharePoint servers through two critical vulnerabilities, prompting urgent government warnings and emergency patches. Microsoft confirmed over the weekend that threat actors are actively exploiting two zero-day vulnerabilities in on-premises SharePoint servers, designated CVE-2025-53770 and CVE-2025-53771. The…

  • Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT

    Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT A financially motivated threat group dubbed Greedy Sponge has been systematically targeting Mexican financial institutions and organizations since 2021 with a heavily modified version of the AllaKore remote access trojan (RAT). The campaign represents a sophisticated evolution of cybercriminal tactics, combining traditional social…

  • Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability

    Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability Microsoft has issued an urgent security advisory addressing critical zero-day vulnerabilities in on-premises SharePoint Server that attackers are actively exploiting.  The vulnerabilities, assigned as CVE-2025-53770 and CVE-2025-53771, pose immediate risks to organizations running SharePoint infrastructure and require immediate remediation. Key Takeaways1. Active zero-day attacks…

  • New PoisonSeed Attack Let Attackers Trick Users into Scanning a QR Code with an MFA Authenticator

    New PoisonSeed Attack Let Attackers Trick Users into Scanning a QR Code with an MFA Authenticator A sophisticated new attack technique compromises Fast IDentity Online (FIDO) key authentication by exploiting cross-device sign-in features.  The PoisonSeed attack group has developed a method to downgrade FIDO key protections through adversary-in-the-middle (AitM) phishing campaigns that trick users into…