Category: CyberSecurityNews

EV Charging Provider Confirm Data Breach
23
Sep
2025

EV Charging Provider Confirm Data Breach

Digital Charging Solutions GmbH (DCS), a leading provider of white-label charging services for automotive OEMs and fleet operators, has confirmed…

GitHub Enhances NPM’s Security with Strict Authentication, Granular Tokens, and  Trusted Publishing
23
Sep
2025

GitHub Enhances NPM’s Security with Strict Authentication, Granular Tokens, and  Trusted Publishing

Recent High-profile supply‐chain attacks have exposed critical weaknesses in package registry security, prompting GitHub to roll out a suite of…

Hackers Hijacking IIS Servers Using Malicious BadIIS Module to Serve Malicious Content
23
Sep
2025

Hackers Hijacking IIS Servers Using Malicious BadIIS Module to Serve Malicious Content

A sophisticated cyber campaign, dubbed “Operation Rewrite,” is actively hijacking Microsoft Internet Information Services (IIS) web servers to serve malicious…

Hackers Abusing GitHub Notifications to Deliver Phishing Emails
23
Sep
2025

Hackers Abusing GitHub Notifications to Deliver Phishing Emails

In recent weeks, security researchers have uncovered an elaborate phishing campaign that leverages legitimate GitHub notification mechanisms to deliver malicious…

European Airport Disruptions Caused by Sophisticated Ransomware Attack
23
Sep
2025

European Airport Disruptions Caused by Sophisticated Ransomware Attack

Over the weekend, a sophisticated ransomware attack compromised Collins Aerospace’s Muse check-in and boarding systems, forcing key hubs including Heathrow,…

Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands
23
Sep
2025

Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands

A critical security flaw in Libraesva ESG email security gateways has been identified and patched, allowing threat actors to execute…

22.2 Tbps DDoS Attack Breaks Internet With New World Record
23
Sep
2025

22.2 Tbps DDoS Attack Breaks Internet With New World Record

Cloudflare announced it had autonomously mitigated the largest distributed denial-of-service (DDoS) attack ever recorded. The hyper-volumetric attack peaked at an…

BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch
22
Sep
2025

BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch

A seemingly innocent patch update for the popular 2D platformer game BlockBlasters has transformed into a sophisticated malware campaign, exposing…

Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments
22
Sep
2025

Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments

In recent weeks, security researchers have observed a surge in attacks exploiting Oracle Database Scheduler’s External Jobs feature to gain…

New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evade Detection
22
Sep
2025

New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evade Detection

Attackers increasingly exploit Microsoft Exchange inbox rules to maintain persistence and exfiltrate data within enterprise environments.  A newly released tool,…

Subtle Snail Mimic as HR Representatives to Engage Employees and Steal Login Credentials
22
Sep
2025

Subtle Snail Mimic as HR Representatives to Engage Employees and Steal Login Credentials

A sophisticated Iran-nexus espionage group known as Subtle Snail has emerged as a significant threat to European telecommunications, aerospace, and…

Kawa4096 Ransomware Attacking Multinational Organizations to Exfiltrate Sensitive Data
22
Sep
2025

Kawa4096 Ransomware Attacking Multinational Organizations to Exfiltrate Sensitive Data

A sophisticated new ransomware group has emerged from the shadows, targeting multinational organizations across diverse sectors with precision and systematic…