Category: CyberSecurityNews

New CrushFTP 0-Day Vulnerability Exploited in the Wild to Gain Access to Servers
19
Jul
2025

New CrushFTP 0-Day Vulnerability Exploited in the Wild to Gain Access to Servers

A critical zero-day flaw in the CrushFTP managed file-transfer platform was confirmed after vendor and threat-intelligence sources confirmed active exploitation…

New QR Code Attack Via PDFs Evades Detection Systems and Harvest Credentials
19
Jul
2025

New QR Code Attack Via PDFs Evades Detection Systems and Harvest Credentials

A sophisticated phishing campaign dubbed “Scanception” has emerged as a significant threat to enterprise security, leveraging QR codes embedded in…

Lumma Infostealer Steal All Data Stored in Browsers and Selling Them in Underground Markets as Logs
19
Jul
2025

Lumma Infostealer Steal All Data Stored in Browsers and Selling Them in Underground Markets as Logs

The cybersecurity landscape continues to face significant threats from sophisticated information stealers, with Lumma emerging as one of the most…

CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks
19
Jul
2025

CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiWeb vulnerability to its Known Exploited Vulnerabilities…

Google Sued BadBox 2.0 Malware Botnet Operators That Infects 10 Million+ Devices
18
Jul
2025

Google Sued BadBox 2.0 Malware Botnet Operators That Infects 10 Million+ Devices

Google has filed a lawsuit in New York federal court against the operators of the BadBox 2.0 botnet, marking a…

New Wave of Crypto-Hijacking Infects 3,500+ Websites
18
Jul
2025

New Wave of Crypto-Hijacking Infects 3,500+ Websites

A stealth Monero-mining campaign has quietly compromised more than 3,500 websites by embedding an innocuous-looking JavaScript file called karma.js. The…

Russian Vodka Producer Beluga Hit by Ransomware Attack
18
Jul
2025

Russian Vodka Producer Beluga Hit by Ransomware Attack

Russian premium vodka producer Beluga, owned by NovaBev Group, has fallen victim to a sophisticated ransomware attack that disrupted its…

Lenovo Protection Driver Vulnerability Let Attackers Escalate Privilege and Execute Arbitrary Code
18
Jul
2025

Lenovo Protection Driver Vulnerability Let Attackers Escalate Privilege and Execute Arbitrary Code

A buffer overflow vulnerability in Lenovo Protection Driver could allow local attackers with elevated privileges to execute arbitrary code on…

Microsoft Defender for Office 365 New Dashboard to Provide More Details Across a Range of Threat Vectors
18
Jul
2025

Microsoft Defender for Office 365 New Dashboard to Provide More Details Across a Range of Threat Vectors

Microsoft today announced the rollout of a revamped customer dashboard in Microsoft Defender for Office 365, designed to deliver unprecedented…

Sophos Intercept X for Windows Vulnerabilities Enable Arbitrary Code Execution
18
Jul
2025

Sophos Intercept X for Windows Vulnerabilities Enable Arbitrary Code Execution

Three critical vulnerabilities in the Sophos Intercept X for Windows product family could allow local attackers to achieve arbitrary code…

Fancy Bear Hackers Attacking Governments, Military Entities With New Sophisticated Tools
18
Jul
2025

Fancy Bear Hackers Attacking Governments, Military Entities With New Sophisticated Tools

The notorious Russian cyberespionage group Fancy Bear, also known as APT28, has intensified its operations against governments and military entities…

Threat Actors Exploiting Ivanti Connect Secure Vulnerabilities to Deploy Cobalt Strike Beacon
18
Jul
2025

Threat Actors Exploiting Ivanti Connect Secure Vulnerabilities to Deploy Cobalt Strike Beacon

A sophisticated malware campaign targeting Ivanti Connect Secure VPN devices has been actively exploiting critical vulnerabilities CVE-2025-0282 and CVE-2025-22457 since…