Category: CyberSecurityNews

Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls
25
Dec
2025

Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls

Cybercriminals are actively abusing a long-patched Fortinet FortiGate flaw from July 2020, slipping past two-factor authentication (2FA) on firewalls and…

Microsoft Unveils Hardware-Accelerated BitLocker to Enhance Performance and Security
25
Dec
2025

Microsoft Unveils Hardware-Accelerated BitLocker to Enhance Performance and Security

Microsoft has announced hardware-accelerated BitLocker, a significant security enhancement designed to eliminate performance bottlenecks caused by encryption on modern high-speed…

Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware
24
Dec
2025

Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware

The Evasive Panda APT group, also known as Bronze Highland, Daggerfly, and StormBamboo, has been running targeted campaigns since November…

Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations
24
Dec
2025

Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations

Security researchers at Seqrite Labs have identified a campaign called Operation IconCat, targeting Israeli organizations with weaponized documents designed to…

Threat Actors Advertised NtKiller Malware on Dark Web Claiming Terminate Antivirus and EDR Bypass
24
Dec
2025

Threat Actors Advertised NtKiller Malware on Dark Web Claiming Terminate Antivirus and EDR Bypass

A malicious actor known as AlphaGhoul has begun promoting a tool called NtKiller, designed to silently shut down antivirus software…

Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression
24
Dec
2025

Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression

A critical security vulnerability, tracked as CVE-2025-14847, that could allow attackers to extract uninitialized heap memory from database servers without authentication….

What 2025 Taught Us About Modern Malware
24
Dec
2025

What 2025 Taught Us About Modern Malware

The year 2025 represents a pivotal moment in cybersecurity, showcasing a remarkable evolution in zero-click exploitation techniques that significantly challenges…

WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users
24
Dec
2025

WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users

A new malware campaign has surfaced that uses GitHub repositories to spread the WebRAT malware by disguising it as proof-of-concept…

Interpol Taken Down 6 Ransomware Variants and Arrested 500+ Suspects
24
Dec
2025

Interpol Taken Down 6 Ransomware Variants and Arrested 500+ Suspects

Law enforcement agencies across 19 African nations have achieved a landmark victory against cybercrime. Arresting 574 suspects and dismantling six…

Ransomware Attack on Romanian Waters Authority
24
Dec
2025

Ransomware Attack on Romanian Waters Authority

Romania’s National Administration “Apele Române” (Romanian Waters) disclosed a severe ransomware attack on December 20, 2025. That compromised approximately 1,000…

Operation PCPcat Hacked 59,000+ Next.js/React Servers Within 48 Hours
24
Dec
2025

Operation PCPcat Hacked 59,000+ Next.js/React Servers Within 48 Hours

A massive credential-theft campaign dubbed PCPcat compromised 59,128 Next.js servers in under 48 hours. The operation exploits critical vulnerabilities CVE-2025-29927…

Microsoft Teams to Enforce Messaging Safety Defaults Starting January 2026
23
Dec
2025

Microsoft Teams to Enforce Messaging Safety Defaults Starting January 2026

Microsoft is strengthening the security posture of enterprise collaboration by automatically enabling critical messaging safety features in Microsoft Teams. According…