Category: CyberSecurityNews

Over 390 Abandoned iCalendar Sync Domains Could Expose ~4 Million Devices to Security Risks
27
Nov
2025

Over 390 Abandoned iCalendar Sync Domains Could Expose ~4 Million Devices to Security Risks

Digital calendars have become indispensable tools for managing personal and professional schedules. Users frequently subscribe to external calendars for public…

NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks
27
Nov
2025

NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks

An urgent security update for its DGX Spark AI workstation after discovering 14 vulnerabilities in the system’s firmware that could…

Quttera Launches "Evidence-as-Code" API to Automate Security Compliance for SOC 2 and PCI DSS v4.0
27
Nov
2025

Quttera Launches “Evidence-as-Code” API to Automate Security Compliance for SOC 2 and PCI DSS v4.0

New API capabilities and AI-powered Threat Encyclopedia eliminate manual audit preparation, providing real-time compliance evidence and instant threat intelligence Quttera…

One Identity Safeguard Named a Visionary in the 2025 Gartner Magic Quadrant for PAM
27
Nov
2025

One Identity Safeguard Named a Visionary in the 2025 Gartner Magic Quadrant for PAM

Alisa Viejo, CA, USA, November 27th, 2025, CyberNewsWire Gartner has recognized One Identity as a Visionary in the 2025 Gartner Magic…

Shai Hulud v2 Exploits GitHub Actions Workflows as Attack Vector to Steal Secrets
27
Nov
2025

Shai Hulud v2 Exploits GitHub Actions Workflows as Attack Vector to Steal Secrets

The software supply chain is under siege from “Shai Hulud v2,” a sophisticated malware campaign that has compromised 834 packages…

Dead Man's Switch - Widespread npm Supply Chain Attack Driving Malware Attacks
27
Nov
2025

Dead Man’s Switch – Widespread npm Supply Chain Attack Driving Malware Attacks

GitLab’s Vulnerability Research team has uncovered a large-scale supply chain attack spreading a destructive malware variant through the npm ecosystem….

Qilin RaaS Exposed 1 Million Files and 2 TB of Data Linked to Korean MSP Breach
27
Nov
2025

Qilin RaaS Exposed 1 Million Files and 2 TB of Data Linked to Korean MSP Breach

The “Korean Leaks” campaign has emerged as one of the most sophisticated supply chain attacks targeting South Korea’s financial sector…

Free WormGPT Variant Leveraging DeepSeek, Gemini, and Kimi-K2 AI Models
27
Nov
2025

Free WormGPT Variant Leveraging DeepSeek, Gemini, and Kimi-K2 AI Models

KawaiiGPT emerges as an accessible, open-source tool that mimics the controversial WormGPT, providing unrestricted AI assistance via jailbroken large language…

North Korean Hackers Exploiting npm, GitHub, and Vercel to Deliver OtterCookie Malware
27
Nov
2025

North Korean Hackers Exploiting npm, GitHub, and Vercel to Deliver OtterCookie Malware

A major security threat has emerged targeting software developers worldwide. North Korean state-sponsored threat actors, operating under the “Contagious Interview”…

ByteToBreach Cybercriminal Selling Sensitive Global Data from Airlines, Banks, and Governments
27
Nov
2025

ByteToBreach Cybercriminal Selling Sensitive Global Data from Airlines, Banks, and Governments

A cybercriminal operating under the alias ByteToBreach has emerged as a notable threat actor in the underground market, actively selling…

Angular HTTP Client Vulnerability Exposes XSRF Token to an Attacker-Controlled Domain
27
Nov
2025

Angular HTTP Client Vulnerability Exposes XSRF Token to an Attacker-Controlled Domain

A critical security vulnerability has been discovered in the Angular framework that could allow attackers to steal sensitive user security…

Malicious Chrome Extension Silently Steal and Injects Hidden SOL Fees Into Solana Swaps
27
Nov
2025

Malicious Chrome Extension Silently Steal and Injects Hidden SOL Fees Into Solana Swaps

A new threat has emerged in the Solana trading community. Security researchers have discovered a malicious Chrome extension named Crypto…