Category: CyberSecurityNews

Windows 0-Day Vulnerability Exploited in Wild to Deploy Play ransomware
07
May
2025

Windows 0-Day Vulnerability Exploited in Wild to Deploy Play ransomware

Threat actors linked to the Play ransomware operation exploited a zero-day vulnerability in Microsoft Windows prior to its patching on…

CISA Warns of Langflow Missing Authentication Vulnerability Exploited in Attacks
06
May
2025

CISA Warns of Langflow Missing Authentication Vulnerability Exploited in Attacks

CISA has added a critical Langflow vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in…

UDP Vulnerability in Windows Deployment Services Allows 0-Click System Crashes
06
May
2025

UDP Vulnerability in Windows Deployment Services Allows 0-Click System Crashes

A newly discovered vulnerability in Microsoft’s Windows Deployment Services (WDS) allows attackers to remotely crash servers with zero user interaction…

Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide
06
May
2025

Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide

Security researchers have uncovered one of the largest credit card theft operations in recent history, with a sophisticated Phishing-as-a-Service (PhaaS)…

The New Breed Of Layer 7 Attacks And How SMEs
06
May
2025

The New Breed Of Layer 7 Attacks And How SMEs

When most people think of DDoS attacks, they envision tsunami-like floods of traffic overwhelming servers. That’s the classic Layer 3/4…

PCI Compliance Is Not Just A Checkbox It’s A Live-Fire Security Test 
06
May
2025

PCI Compliance Is Not Just A Checkbox It’s A Live-Fire Security Test 

Most executives still treat PCI DSS like paperwork something to file away after a quarterly scan. But that mindset is…

New T1555.003 Technique Let Attackers Steal Passwords From Web Browsers
06
May
2025

New T1555.003 Technique Let Attackers Steal Passwords From Web Browsers

A sophisticated credential theft technique, identified as T1555.003 in the MITRE ATT&CK framework, has emerged as a significant threat to…

Ransomware Groups Allegedly Breach IT Networks, Stealing Data from UK Retailers
06
May
2025

Ransomware Groups Allegedly Breach IT Networks, Stealing Data from UK Retailers

A notorious ransomware group dubbed DragonForce has claimed responsibility for a series of cyber attacks targeting major UK retailers, with…

RomCom RAT Attacking UK Organizations Via Customer Feedback Portals
06
May
2025

RomCom RAT Attacking UK Organizations Via Customer Feedback Portals

A sophisticated Remote Access Trojan (RAT) dubbed “RomCom” has emerged as a significant threat targeting UK organizations through their customer…

Hackers Attacking HR Departments with Fake Resumes That Drop More_eggs Malware
06
May
2025

Hackers Attacking HR Departments with Fake Resumes That Drop More_eggs Malware

A sophisticated cyber campaign targeting corporate human resources departments has been uncovered, with attackers exploiting the routine practice of opening…

Hackers Weaponized 21 Apps to Gain Full Control of Ecommerce Servers
06
May
2025

Hackers Weaponized 21 Apps to Gain Full Control of Ecommerce Servers

Security researchers have recently uncovered a sophisticated supply chain attack targeting ecommerce platforms through 21 widely-used applications. The backdoor, which…

Critical Microsoft Telnet 0-Click Vulnerability Exposes Windows Credentials
06
May
2025

Critical Microsoft Telnet 0-Click Vulnerability Exposes Windows Credentials

A critical vulnerability in Microsoft Telnet Server enables attackers to bypass authentication completely, potentially gaining administrator access without valid credentials….