Category: CyberSecurityNews

15
Nov
2025

Formbook Malware Delivered Using Weaponized Zip Files and Multiple Scripts

A new wave of Formbook malware attacks has appeared, using weaponized ZIP archives and multiple script layers to bypass security…

Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments – New CISA Report
15
Nov
2025

Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments – New CISA Report

A new advisory from the Cybersecurity and Infrastructure Security Agency reveals that Akira ransomware has become one of the most…

Lumma Stealer Uses Browser Fingerprinting to Collect Data and for Stealthy C&C Server Communications
15
Nov
2025

Lumma Stealer Uses Browser Fingerprinting to Collect Data and for Stealthy C&C Server Communications

Lumma Stealer has emerged as a serious threat in the cybercrime world, targeting users through fake software updates and cracked…

Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover
15
Nov
2025

Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover

Fortinet has issued an urgent advisory warning of a critical vulnerability in its FortiWeb web application firewall (WAF) product, which…

Beware of Phishing Emails as Spam Filter Alerts Steal Your Email Logins in a Blink
14
Nov
2025

Beware of Phishing Emails as Spam Filter Alerts Steal Your Email Logins in a Blink

Cybercriminals have launched a new phishing campaign that tricks users by impersonating legitimate spam-filter notifications from their own company. These…

Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens
14
Nov
2025

Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens

On November 7th, security researchers discovered a dangerous malicious npm package called “@acitons/artifact” that had already been downloaded more than…

SmartApeSG Campaign Leverages ClickFix Technique to Deploy NetSupport RAT
14
Nov
2025

SmartApeSG Campaign Leverages ClickFix Technique to Deploy NetSupport RAT

The SmartApeSG campaign, also known as ZPHP or HANEY MANEY, continues to evolve its attack methods to compromise Windows systems…

NVIDIA NeMo Framework Vulnerabilities Allows Code Injection and Privilege Escalation
14
Nov
2025

NVIDIA NeMo Framework Vulnerabilities Allows Code Injection and Privilege Escalation

NVIDIA has issued a critical security update addressing two high-severity vulnerabilities in its NeMo Framework that could allow attackers to…

Threat Actors Leverage JSON Storage Services to Host and Deliver Malware Via Trojanized Code Projects
14
Nov
2025

Threat Actors Leverage JSON Storage Services to Host and Deliver Malware Via Trojanized Code Projects

Cybersecurity researchers have uncovered a sophisticated campaign where threat actors abuse legitimate JSON storage services to deliver malware to software…

Hackers Flooded npm Registry Over 43,000 Spam Packages Survived for Almost Two Years
14
Nov
2025

Hackers Flooded npm Registry Over 43,000 Spam Packages Survived for Almost Two Years

Security researcher Paul McCarty uncovered a significant coordinated spam campaign targeting the npm ecosystem. The IndonesianFoods worm, as it has…

Multiple vulnerabilities in Cisco Unified CCX Allow Attackers to Execute Arbitrary Commands
14
Nov
2025

Multiple vulnerabilities in Cisco Unified CCX Allow Attackers to Execute Arbitrary Commands

Cisco has released security updates to address two critical vulnerabilities in Unified Contact Center Express (Unified CCX) that could allow…

Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover
14
Nov
2025

Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover

A deceptive Chrome extension named Safery: Ethereum Wallet has emerged as a serious threat to cryptocurrency users. Published on the…