Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability, tracked as CVE-2025-14847, that could allow attackers to extract uninitialized heap memory from database servers without authentication. The flaw resides in MongoDB’s zlib compression implementation and affects …

One Year Of Zero-Click Exploits: What 2025 Taught Us About Modern Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The year 2025 represents a pivotal moment in cybersecurity, showcasing a remarkable evolution in zero-click exploitation techniques that significantly challenges our understanding of digital security. Unlike traditional attacks that require …

WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign has surfaced that uses GitHub repositories to spread the WebRAT malware by disguising it as proof-of-concept exploits and gaming utilities. The malware targets users searching for …

Ransomware Attack on Romanian Waters Authority – 1,000+ IT Systems Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Romania’s National Administration “Apele Române” (Romanian Waters) disclosed a severe ransomware attack on December 20, 2025. That compromised approximately 1,000 IT systems across the agency and 10 of its 11 …

Interpol Taken Down 6 Ransomware Variants and Arrested 500+ Suspects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Law enforcement agencies across 19 African nations have achieved a landmark victory against cybercrime. Arresting 574 suspects and dismantling six ransomware variants during Operation Sentinel, a month-long coordinated crackdown that …

Operation PCPcat Hacked 59,000+ Next.js/React Servers Within 48 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive credential-theft campaign dubbed PCPcat compromised 59,128 Next.js servers in under 48 hours. The operation exploits critical vulnerabilities CVE-2025-29927 and CVE-2025-66478, achieving a 64.6% success rate across 91,505 scanned …

Microsoft Teams to Enforce Messaging Safety Defaults Starting January 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is strengthening the security posture of enterprise collaboration by automatically enabling critical messaging safety features in Microsoft Teams. According to a new administrative update, the company will switch several …

HardBit 4.0 Ransomware Actors Attack Open RDP and SMB Services to Persist Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HardBit ransomware continues to evolve as a serious threat to organizations worldwide. The latest version, HardBit 4.0, emerged as an upgraded variant of a strain that has been active since …

Indian Income Tax-Themed Attacking Businesses with a Multi-Stage Infection Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have increasingly weaponized the Income Tax Return (ITR) filing season to orchestrate sophisticated phishing campaigns targeting Indian businesses. By exploiting public anxiety surrounding tax compliance and refund timelines, attackers …

University of Phoenix Data Breach – 3.5 Million+ Individuals Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

University of Phoenix, one of the largest for-profit educational institutions in the United States, disclosed a significant data breach affecting approximately 3.5 million individuals on December 22, 2025. The breach …