Category: CyberSecurityNews

Lazarus Group is No Longer Consider a Single APT Group, But Collection of Many Sub Groups
31
Mar
2025

Lazarus Group is No Longer Consider a Single APT Group, But Collection of Many Sub Groups

The cybersecurity landscape is witnessing a growing complexity in the attribution of Advanced Persistent Threat (APT) actors, particularly the North…

Multiple Dell Unity Vulnerabilities Let Attackers Compromise Affected System
31
Mar
2025

Multiple Dell Unity Vulnerabilities Let Attackers Compromise Affected System

Dell Technologies has released a critical security update addressing multiple severe vulnerabilities in its Unity enterprise storage systems that could…

CrushFTP Vulnerability Exploited to Bypass Authentication
31
Mar
2025

CrushFTP Vulnerability Exploited to Bypass Authentication

A critical vulnerability (CVE-2025-2825) in CrushFTP, a widely used enterprise file transfer solution, allows attackers to bypass authentication and gain…

Cannon Printer Vulnerability Let Attackers Execute Arbitrary Code
31
Mar
2025

Cannon Printer Vulnerability Let Attackers Execute Arbitrary Code

Canon has issued a critical security advisory regarding a severe vulnerability detected in several of its printer drivers that could…

Technical Analysis Published for OpenSSH's Agent Forwarding RCE Vulnerability
31
Mar
2025

Technical Analysis Published for OpenSSH’s Agent Forwarding RCE Vulnerability

Security researchers have published a detailed technical analysis of a critical remote code execution (RCE) vulnerability (CVE-2023-38408) in OpenSSH’s agent…

Critical PHP Vulnerability Let Hackers Bypass the Validation To Load Malicious Content 
31
Mar
2025

Critical PHP Vulnerability Let Hackers Bypass the Validation To Load Malicious Content 

A critical vulnerability in PHP’s libxml streams has been identified, potentially impacting web applications that rely on the DOM or…

Hackers Employ New ClickFix Captcha Technique to Deliver Ransomware
30
Mar
2025

Hackers Employ New ClickFix Captcha Technique to Deliver Ransomware

A sophisticated social engineering technique known as ClickFix has emerged, leveraging fake CAPTCHA verification processes to deceive users into executing…

TsarBot Android Malware Mimics 750 Banking & Finance Apps to Steal Credentials
30
Mar
2025

TsarBot Android Malware Mimics 750 Banking & Finance Apps to Steal Credentials

A newly discovered Android banking malware named TsarBot is targeting over 750 applications globally, including banking, finance, cryptocurrency, and e-commerce…

Apache Tomcat Vulnerability (CVE-2025-24813) Exploited to Execute Code on Servers
30
Mar
2025

Apache Tomcat Vulnerability (CVE-2025-24813) Exploited to Execute Code on Servers

A critical vulnerability in Apache Tomcat has been actively exploited by attackers to achieve remote code execution (RCE) on vulnerable…

Lotus Blossom APT Exploits WMI for Post-Exploitation Activities
29
Mar
2025

Lotus Blossom APT Exploits WMI for Post-Exploitation Activities

The Lotus Blossom Advanced Persistent Threat (APT) group, also known as Lotus Panda, Billbug, and Spring Dragon, has intensified its…

CISA Warns of ESURGE Malware Exploiting Ivanti RCE Vulnerability
29
Mar
2025

CISA Warns of ESURGE Malware Exploiting Ivanti RCE Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a Malware Analysis Report (MAR-25993211-r1.v1) detailing the exploitation of a critical…

Fake Snow White Movie Attacking Viewers Device With New Malware
29
Mar
2025

Fake Snow White Movie Attacking Viewers Device With New Malware

Disney’s latest release, Snow White (2025), has turned into a cybersecurity crisis for unsuspecting users. With a disappointing IMDb rating…