Category: CyberSecurityNews

700+ Malicious Android Apps Abusing NFC Relay to Exfiltrate Banking Login Credentials
30
Oct
2025

700+ Malicious Android Apps Abusing NFC Relay to Exfiltrate Banking Login Credentials

A sophisticated malware campaign exploiting Near Field Communication technology on Android devices has expanded dramatically since its emergence in April…

RediShell RCE Vulnerability Exposes 8,500+ Redis Instances to Code Execution Attacks
30
Oct
2025

RediShell RCE Vulnerability Exposes 8,500+ Redis Instances to Code Execution Attacks

The cybersecurity landscape faced a critical threat in early October 2025 with the public disclosure of RediShell, a severe use-after-free…

Critical Vulnerability In Chromium's Blink Let Attackers Crash Chromium-based Browsers Within Seconds
30
Oct
2025

Critical Vulnerability In Chromium’s Blink Let Attackers Crash Chromium-based Browsers Within Seconds

Security researcher Jofpin has disclosed “Brash,” a critical flaw in Google’s Blink rendering engine that enables attackers to crash Chromium-based…

CISA Releases Best Security Practices Guide for Hardening Microsoft Exchange Server
30
Oct
2025

CISA Releases Best Security Practices Guide for Hardening Microsoft Exchange Server

In a timely response to escalating threats against email infrastructure, the Cybersecurity and Infrastructure Security Agency (CISA), alongside the National…

New Malware Targeting WooCommerce Sites with Malicious Plugins Steals Credit Card Data
30
Oct
2025

New Malware Targeting WooCommerce Sites with Malicious Plugins Steals Credit Card Data

A sophisticated malware campaign has emerged targeting WordPress e-commerce sites, particularly those leveraging the WooCommerce plugin to process customer transactions….

12 Malicious Extension in VSCode Marketplace Steal Source Code and Exfiltrate Login Credentials
30
Oct
2025

12 Malicious Extension in VSCode Marketplace Steal Source Code and Exfiltrate Login Credentials

A recent discovery has shaken the Visual Studio Code (VSCode) ecosystem, unveiling a sophisticated supply chain attack targeting developers worldwide….

Multiple Jenkins Vulnerability SAML Authentication Bypass And MCP Server Plugin Permissions
30
Oct
2025

Multiple Jenkins Vulnerability SAML Authentication Bypass And MCP Server Plugin Permissions

The Jenkins project released Security Advisory 2025-10-29 on October 28, 2025, disclosing multiple vulnerabilities across 13 plugins that power the…

Microsoft Windows Cloud Files Minifilter Privilege Escalation Vulnerability Exploited
30
Oct
2025

Microsoft Windows Cloud Files Minifilter Privilege Escalation Vulnerability Exploited

Microsoft has patched a critical race condition vulnerability in its Windows Cloud Files Minifilter driver, known as CVE-2025-55680, which enables…

New Attack Combines Ghost SPNs and Kerberos Reflection to Elevate Privileges on SMB Servers
30
Oct
2025

New Attack Combines Ghost SPNs and Kerberos Reflection to Elevate Privileges on SMB Servers

A sophisticated privilege escalation vulnerability in Windows SMB servers, leveraging Ghost Service Principal Names (SPNs) and Kerberos authentication reflection to…

PhantomRaven Attack Involves 126 Malicious npm Packages with Over 86,000 Downloads Hiding Malicious Code
30
Oct
2025

PhantomRaven Attack Involves 126 Malicious npm Packages with Over 86,000 Downloads Hiding Malicious Code

A sophisticated malware campaign targeting developers has been operating since August 2025, deploying 126 malicious npm packages that have collectively…

PolarEdge Botnet Infected 25,000+ Devices and 140 C2 Servers Exploiting IoT Vulnerabilities
30
Oct
2025

PolarEdge Botnet Infected 25,000+ Devices and 140 C2 Servers Exploiting IoT Vulnerabilities

A sophisticated botnet campaign has compromised more than 25,000 IoT devices across 40 countries while establishing 140 command-and-control servers to…

Dentsu has Disclosed that its U.S.-based Subsidiary Merkle Suffers Cyberattack
30
Oct
2025

Dentsu has Disclosed that its U.S.-based Subsidiary Merkle Suffers Cyberattack

Global advertising and marketing giant Dentsu has confirmed that its U.S.-based subsidiary Merkle experienced a cyberattack, prompting immediate incident response…