Category: CyberSecurityNews

SonicWall Releases Firmware Update to Remove Rootkit Malware 'OVERSTEP' from SMA Devices
23
Sep
2025

SonicWall Releases Firmware Update to Remove Rootkit Malware ‘OVERSTEP’ from SMA Devices

SonicWall has issued an urgent firmware update, version 10.2.2.2-92sv, for its Secure Mobile Access (SMA) 100 series appliances to detect…

2/3 of Organizations Fear Identity Attacks, But Blind Spots Remain
23
Sep
2025

2/3 of Organizations Fear Identity Attacks, But Blind Spots Remain

Austin, Texas, USA, September 23rd, 2025, CyberNewsWire New SpyCloud 2025 Identity Threat Report reveals dangerous disconnect between perceived security readiness…

SolarWinds Web Help Desk Vulnerability Enables Unauthenticated RCE
23
Sep
2025

SolarWinds Web Help Desk Vulnerability Enables Unauthenticated RCE

SolarWinds has released an urgent security advisory for a critical vulnerability in its Web Help Desk software that could allow…

EV Charging Provider Confirm Data Breach
23
Sep
2025

EV Charging Provider Confirm Data Breach

Digital Charging Solutions GmbH (DCS), a leading provider of white-label charging services for automotive OEMs and fleet operators, has confirmed…

GitHub Enhances NPM’s Security with Strict Authentication, Granular Tokens, and  Trusted Publishing
23
Sep
2025

GitHub Enhances NPM’s Security with Strict Authentication, Granular Tokens, and  Trusted Publishing

Recent High-profile supply‐chain attacks have exposed critical weaknesses in package registry security, prompting GitHub to roll out a suite of…

Hackers Hijacking IIS Servers Using Malicious BadIIS Module to Serve Malicious Content
23
Sep
2025

Hackers Hijacking IIS Servers Using Malicious BadIIS Module to Serve Malicious Content

A sophisticated cyber campaign, dubbed “Operation Rewrite,” is actively hijacking Microsoft Internet Information Services (IIS) web servers to serve malicious…

Hackers Abusing GitHub Notifications to Deliver Phishing Emails
23
Sep
2025

Hackers Abusing GitHub Notifications to Deliver Phishing Emails

In recent weeks, security researchers have uncovered an elaborate phishing campaign that leverages legitimate GitHub notification mechanisms to deliver malicious…

European Airport Disruptions Caused by Sophisticated Ransomware Attack
23
Sep
2025

European Airport Disruptions Caused by Sophisticated Ransomware Attack

Over the weekend, a sophisticated ransomware attack compromised Collins Aerospace’s Muse check-in and boarding systems, forcing key hubs including Heathrow,…

Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands
23
Sep
2025

Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands

A critical security flaw in Libraesva ESG email security gateways has been identified and patched, allowing threat actors to execute…

22.2 Tbps DDoS Attack Breaks Internet With New World Record
23
Sep
2025

22.2 Tbps DDoS Attack Breaks Internet With New World Record

Cloudflare announced it had autonomously mitigated the largest distributed denial-of-service (DDoS) attack ever recorded. The hyper-volumetric attack peaked at an…

BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch
22
Sep
2025

BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch

A seemingly innocent patch update for the popular 2D platformer game BlockBlasters has transformed into a sophisticated malware campaign, exposing…

Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments
22
Sep
2025

Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments

In recent weeks, security researchers have observed a surge in attacks exploiting Oracle Database Scheduler’s External Jobs feature to gain…