Category: CyberSecurityNews

Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover
15
Nov
2025

Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover

Fortinet has issued an urgent advisory warning of a critical vulnerability in its FortiWeb web application firewall (WAF) product, which…

Beware of Phishing Emails as Spam Filter Alerts Steal Your Email Logins in a Blink
14
Nov
2025

Beware of Phishing Emails as Spam Filter Alerts Steal Your Email Logins in a Blink

Cybercriminals have launched a new phishing campaign that tricks users by impersonating legitimate spam-filter notifications from their own company. These…

Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens
14
Nov
2025

Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens

On November 7th, security researchers discovered a dangerous malicious npm package called “@acitons/artifact” that had already been downloaded more than…

SmartApeSG Campaign Leverages ClickFix Technique to Deploy NetSupport RAT
14
Nov
2025

SmartApeSG Campaign Leverages ClickFix Technique to Deploy NetSupport RAT

The SmartApeSG campaign, also known as ZPHP or HANEY MANEY, continues to evolve its attack methods to compromise Windows systems…

NVIDIA NeMo Framework Vulnerabilities Allows Code Injection and Privilege Escalation
14
Nov
2025

NVIDIA NeMo Framework Vulnerabilities Allows Code Injection and Privilege Escalation

NVIDIA has issued a critical security update addressing two high-severity vulnerabilities in its NeMo Framework that could allow attackers to…

Threat Actors Leverage JSON Storage Services to Host and Deliver Malware Via Trojanized Code Projects
14
Nov
2025

Threat Actors Leverage JSON Storage Services to Host and Deliver Malware Via Trojanized Code Projects

Cybersecurity researchers have uncovered a sophisticated campaign where threat actors abuse legitimate JSON storage services to deliver malware to software…

Hackers Flooded npm Registry Over 43,000 Spam Packages Survived for Almost Two Years
14
Nov
2025

Hackers Flooded npm Registry Over 43,000 Spam Packages Survived for Almost Two Years

Security researcher Paul McCarty uncovered a significant coordinated spam campaign targeting the npm ecosystem. The IndonesianFoods worm, as it has…

Multiple vulnerabilities in Cisco Unified CCX Allow Attackers to Execute Arbitrary Commands
14
Nov
2025

Multiple vulnerabilities in Cisco Unified CCX Allow Attackers to Execute Arbitrary Commands

Cisco has released security updates to address two critical vulnerabilities in Unified Contact Center Express (Unified CCX) that could allow…

Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover
14
Nov
2025

Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover

A deceptive Chrome extension named Safery: Ethereum Wallet has emerged as a serious threat to cryptocurrency users. Published on the…

Washington Post Oracle E-Suite Hack Impacts 9K+ Employees and Contractors
14
Nov
2025

Washington Post Oracle E-Suite Hack Impacts 9K+ Employees and Contractors

The Washington Post has publicly disclosed a significant data breach involving external hacking of its Oracle E-Suite system, impacting over…

Critical Imunify360 AV Vulnerability Exposes 56 Million Linux-hosted Websites to Remote Code Execution Attacks
14
Nov
2025

Critical Imunify360 AV Vulnerability Exposes 56 Million Linux-hosted Websites to Remote Code Execution Attacks

A severe remote code execution (RCE) vulnerability has been discovered in Imunify360 AV, a widely used malware scanner protecting approximately…

Kraken Cross-Platform Ransomware Attacking Windows, Linux, and VMware ESXi Systems in Enterprise Environments
14
Nov
2025

Kraken Cross-Platform Ransomware Attacking Windows, Linux, and VMware ESXi Systems in Enterprise Environments

In August 2025, a new ransomware threat emerged with capabilities that fundamentally changed how organizations should approach enterprise security. Kraken,…