Category: CyberSecurityNews

Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets
28
Nov
2025

Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets

The Shai Hulud 2.0 worm, first detected on November 24, 2025, has compromised nearly 1,200 organizations, including major banks, government…

Scattered Lapsus$ Hunters Registered 40+ Domains Mimicking Zendesk Environments
28
Nov
2025

Scattered Lapsus$ Hunters Registered 40+ Domains Mimicking Zendesk Environments

A sophisticated, complex new cyber offensive has emerged from the “Scattered Lapsus$ Hunters,” a threat collective that has aggressively shifted…

Vulnerable Codes in Legacy Python Packages Enables Attacks on Python Package Index Via Domain Compromise
28
Nov
2025

Vulnerable Codes in Legacy Python Packages Enables Attacks on Python Package Index Via Domain Compromise

Hidden vulnerabilities in legacy code often create unseen risks for modern development environments. One such issue recently surfaced within the…

Gitlab Patches Multiple Vulnerabilities that Enable Authentication Bypass and DoS Attacks
27
Nov
2025

Gitlab Patches Multiple Vulnerabilities that Enable Authentication Bypass and DoS Attacks

GitLab has released critical security updates for its Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities….

Over 390 Abandoned iCalendar Sync Domains Could Expose ~4 Million Devices to Security Risks
27
Nov
2025

Over 390 Abandoned iCalendar Sync Domains Could Expose ~4 Million Devices to Security Risks

Digital calendars have become indispensable tools for managing personal and professional schedules. Users frequently subscribe to external calendars for public…

NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks
27
Nov
2025

NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks

An urgent security update for its DGX Spark AI workstation after discovering 14 vulnerabilities in the system’s firmware that could…

Quttera Launches "Evidence-as-Code" API to Automate Security Compliance for SOC 2 and PCI DSS v4.0
27
Nov
2025

Quttera Launches “Evidence-as-Code” API to Automate Security Compliance for SOC 2 and PCI DSS v4.0

New API capabilities and AI-powered Threat Encyclopedia eliminate manual audit preparation, providing real-time compliance evidence and instant threat intelligence Quttera…

One Identity Safeguard Named a Visionary in the 2025 Gartner Magic Quadrant for PAM
27
Nov
2025

One Identity Safeguard Named a Visionary in the 2025 Gartner Magic Quadrant for PAM

Alisa Viejo, CA, USA, November 27th, 2025, CyberNewsWire Gartner has recognized One Identity as a Visionary in the 2025 Gartner Magic…

Shai Hulud v2 Exploits GitHub Actions Workflows as Attack Vector to Steal Secrets
27
Nov
2025

Shai Hulud v2 Exploits GitHub Actions Workflows as Attack Vector to Steal Secrets

The software supply chain is under siege from “Shai Hulud v2,” a sophisticated malware campaign that has compromised 834 packages…

Dead Man's Switch - Widespread npm Supply Chain Attack Driving Malware Attacks
27
Nov
2025

Dead Man’s Switch – Widespread npm Supply Chain Attack Driving Malware Attacks

GitLab’s Vulnerability Research team has uncovered a large-scale supply chain attack spreading a destructive malware variant through the npm ecosystem….

Qilin RaaS Exposed 1 Million Files and 2 TB of Data Linked to Korean MSP Breach
27
Nov
2025

Qilin RaaS Exposed 1 Million Files and 2 TB of Data Linked to Korean MSP Breach

The “Korean Leaks” campaign has emerged as one of the most sophisticated supply chain attacks targeting South Korea’s financial sector…

Free WormGPT Variant Leveraging DeepSeek, Gemini, and Kimi-K2 AI Models
27
Nov
2025

Free WormGPT Variant Leveraging DeepSeek, Gemini, and Kimi-K2 AI Models

KawaiiGPT emerges as an accessible, open-source tool that mimics the controversial WormGPT, providing unrestricted AI assistance via jailbroken large language…