Category: CyberSecurityNews

Chinese Hackers Use Rootkit to Hide ToneShell Malware Activity
30
Dec
2025

Chinese Hackers Use Rootkit to Hide ToneShell Malware Activity

A Chinese-linked threat group tied to the HoneyMyte, also known as Mustang Panda or Bronze President, is using a new…

Critical Vulnerability in SmarterMail Let Attackers Execute Remote Code
30
Dec
2025

Critical Vulnerability in SmarterMail Let Attackers Execute Remote Code

SmarterTools has issued an urgent security advisory addressing a critical vulnerability in SmarterMail that could allow attackers to execute remote…

CISA Warns of MongoDB Server Vulnerability(CVE-2025-14847) Exploited in Attacks
30
Dec
2025

CISA Warns of MongoDB Server Vulnerability(CVE-2025-14847) Exploited in Attacks

CISA has added a critical MongoDB Server vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is…

Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts
30
Dec
2025

Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts

A critical zero-day vulnerability has been discovered in XSpeeder’s SXZOS firmware, affecting tens of thousands of SD-WAN appliances, edge routers,…

70,000+ MongoDB Servers Vulnerable to MongoBleed Exploit
30
Dec
2025

70,000+ MongoDB Servers Vulnerable to MongoBleed Exploit

A critical vulnerability in MongoDB Server is putting tens of thousands of databases worldwide at risk. Dubbed MongoBleed and tracked as CVE-2025-14847, this…

Hackers Exploit Copilot Studio’s New Connected Agents Feature to Gain Backdoor Access
30
Dec
2025

Hackers Exploit Copilot Studio’s New Connected Agents Feature to Gain Backdoor Access

Microsoft’s newly unveiled “Connected Agents” feature in Copilot Studio, announced at Build 2025, is creating a significant security vulnerability. Attackers…

EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack
30
Dec
2025

EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack

A major supply chain attack targeting EmEditor, a widely used text editor software, has exposed millions of users to sophisticated…

New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins
29
Dec
2025

New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins

A Spanish-speaking phishing operation targeting Microsoft Outlook users has been active since March 2025, using a sophisticated kit that shows…

Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures
29
Dec
2025

Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures

Chinese threat actors operating under the name Silver Fox are targeting Indian organizations through sophisticated phishing campaigns that impersonate legitimate…

Windows Event Logs Reveal the Messy Reality Behind 'Sophisticated' Cyberattacks
29
Dec
2025

Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks

Public reports about cyberattacks often present a polished picture—threat actors working methodically through a well-planned playbook with every action perfectly…

New Vulnerabilities in Bluetooth Headphones Let Hackers Hijack Connected Smartphone
29
Dec
2025

New Vulnerabilities in Bluetooth Headphones Let Hackers Hijack Connected Smartphone

Security researchers have disclosed critical vulnerabilities affecting widely used Bluetooth headphones and earbuds that could allow attackers to eavesdrop on…

2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers
29
Dec
2025

2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers

A coordinated exploitation campaign that generated more than 2.5 million malicious requests against Adobe ColdFusion servers and 47+ other technology…