Category: CyberSecurityNews

New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data
29
Sep
2025

New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data

A sophisticated malware campaign has emerged that weaponizes seemingly legitimate productivity tools to infiltrate systems and steal sensitive information. The…

SVG Security Analysis Toolkit to Detect Malicious Scripts Hidden in SVG files
29
Sep
2025

SVG Security Analysis Toolkit to Detect Malicious Scripts Hidden in SVG files

As attackers increasingly leverage Scalable Vector Graphics (SVG) for stealthy code injection, security researchers face mounting challenges in detecting obfuscated…

New Spear-Phishing Attack Delivers DarkCloud Malware to Steal Keystrokes, FTP Credentials and Others
29
Sep
2025

New Spear-Phishing Attack Delivers DarkCloud Malware to Steal Keystrokes, FTP Credentials and Others

A newly observed spear-phishing campaign is leveraging sophisticated social engineering lures to distribute DarkCloud, a modular malware suite designed to…

JLR Confirms Phased Restart
29
Sep
2025

JLR Confirms Phased Restart of Operations Following Cyber Attack

Jaguar Land Rover (JLR) has confirmed it will begin a phased restart of its manufacturing operations in the coming days,…

SUSE Rancher Vulnerabilities Let Attackers Lockout the Administrators Account
29
Sep
2025

SUSE Rancher Vulnerabilities Let Attackers Lockout the Administrators Account

A critical flaw in SUSE Rancher’s user management module allows privileged users to disrupt administrative access by modifying usernames of…

Threat Actors Weaponizing Facebook and Google Ads as Financial Platforms to Steal Sensitive Data
29
Sep
2025

Threat Actors Weaponizing Facebook and Google Ads as Financial Platforms to Steal Sensitive Data

In recent months, cybersecurity teams have observed an alarming trend in which malicious actors exploit Facebook and Google advertising channels…

New ModStealer Evade Antivirus Detection to Attack macOS Users and Steal Sensitive Data
29
Sep
2025

New ModStealer Evade Antivirus Detection to Attack macOS Users and Steal Sensitive Data

A sophisticated new cross-platform information stealer known as ModStealer has emerged, targeting macOS users and demonstrating concerning capabilities to evade…

WhatsApp 0-Click Vulnerability Exploited Using Malicious DNG File
29
Sep
2025

WhatsApp 0-Click Vulnerability Exploited Using Malicious DNG File

WhatsApp 0-click remote code execution (RCE) vulnerability affecting Apple’s iOS, macOS, and iPadOS platforms, detailed with a proof of concept…

Hackers Weaponizing SVG Files to Deliver PureMiner Malware and Steal Sensitive Information
29
Sep
2025

Hackers Weaponizing SVG Files to Deliver PureMiner Malware and Steal Sensitive Information

In recent weeks, a sophisticated phishing campaign has emerged, targeting organizations in Ukraine with malicious Scalable Vector Graphics (SVG) files…

Windows Heap Exploitation Vulnerability With Record's Size Field Leads to Arbitrary R/W
29
Sep
2025

Windows Heap Exploitation Vulnerability With Record’s Size Field Leads to Arbitrary R/W

A critical vulnerability in Windows heap management demonstrates how improper handling of record-size fields enables arbitrary memory read and write…

Formbricks Signature Verification Vulnerability Let Attackers Reset User Passwords Without Authorization
29
Sep
2025

Formbricks Signature Verification Vulnerability Let Attackers Reset User Passwords Without Authorization

A critical security flaw discovered in Formbricks, an open-source experience management platform, demonstrates how missing JWT signature verification can lead…

DataCenter Fire Takes 600+ South Korean Government Websites Offline
29
Sep
2025

DataCenter Fire Takes 600+ South Korean Government Websites Offline

A fire caused by a lithium-ion battery explosion at a key government data center in South Korea has knocked more…