Category: CyberSecurityNews

Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands
23
Sep
2025

Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands

A critical security flaw in Libraesva ESG email security gateways has been identified and patched, allowing threat actors to execute…

22.2 Tbps DDoS Attack Breaks Internet With New World Record
23
Sep
2025

22.2 Tbps DDoS Attack Breaks Internet With New World Record

Cloudflare announced it had autonomously mitigated the largest distributed denial-of-service (DDoS) attack ever recorded. The hyper-volumetric attack peaked at an…

BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch
22
Sep
2025

BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch

A seemingly innocent patch update for the popular 2D platformer game BlockBlasters has transformed into a sophisticated malware campaign, exposing…

Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments
22
Sep
2025

Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments

In recent weeks, security researchers have observed a surge in attacks exploiting Oracle Database Scheduler’s External Jobs feature to gain…

New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evade Detection
22
Sep
2025

New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evade Detection

Attackers increasingly exploit Microsoft Exchange inbox rules to maintain persistence and exfiltrate data within enterprise environments.  A newly released tool,…

Subtle Snail Mimic as HR Representatives to Engage Employees and Steal Login Credentials
22
Sep
2025

Subtle Snail Mimic as HR Representatives to Engage Employees and Steal Login Credentials

A sophisticated Iran-nexus espionage group known as Subtle Snail has emerged as a significant threat to European telecommunications, aerospace, and…

Kawa4096 Ransomware Attacking Multinational Organizations to Exfiltrate Sensitive Data
22
Sep
2025

Kawa4096 Ransomware Attacking Multinational Organizations to Exfiltrate Sensitive Data

A sophisticated new ransomware group has emerged from the shadows, targeting multinational organizations across diverse sectors with precision and systematic…

Lucid PhaaS With 17,500 Phishing Domains Mimics 316 Brands From 74 Countries
22
Sep
2025

Lucid PhaaS With 17,500 Phishing Domains Mimics 316 Brands From 74 Countries

The cybersecurity landscape faces a growing threat from sophisticated Phishing-as-a-Service (PhaaS) platforms that are democratizing cybercrime by lowering technical barriers…

Microsoft, SentinelOne, and Palo Alto Networks Withdraw from 2026 MITRE ATT&CK Evaluations
22
Sep
2025

Microsoft, SentinelOne, and Palo Alto Networks Withdraw from 2026 MITRE ATT&CK Evaluations

Three of the cybersecurity industry’s most prominent vendors, Microsoft, SentinelOne, and Palo Alto Networks, have announced they will not participate…

Windows 11 24H2 Update KB5064081 Breaks Video Content Playback
22
Sep
2025

Windows 11 24H2 Update KB5064081 Breaks Video Content Playback

A recent optional update for Windows 11 version 24H2 is causing significant video playback issues for users with certain media…

Stellantis, the Maker of Citroën, FIAT, Jeep, and Other Cars, Confirms Data Breach
22
Sep
2025

Stellantis, the Maker of Citroën, FIAT, Jeep, and Other Cars, Confirms Data Breach

Automotive giant Stellantis, the parent company of major brands including Citroën, FIAT, Jeep, Chrysler, and Peugeot, has confirmed a data…

Chrome Type Confusion 0-Day Vulnerability Code Analysis Released
22
Sep
2025

Chrome Type Confusion 0-Day Vulnerability Code Analysis Released

Google Chrome’s V8 JavaScript engine has been compromised by a critical type confusion zero-day vulnerability, designated CVE-2025-10585, marking the sixth…