American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Envoy Air, a wholly owned subsidiary of American Airlines, has confirmed it fell victim to a hacking campaign exploiting vulnerabilities in Oracle’s E-Business Suite (EBS). The breach, first highlighted by the notorious Clop ransomware group, underscores the growing risks facing …

New Phishing Attack Leverages Azure Blob Storage to Impersonate Microsoft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are leveraging Microsoft Azure Blob Storage to craft highly convincing phishing sites that mimic legitimate Office 365 login portals, putting Microsoft 365 users at severe risk of credential theft. This method exploits trusted Microsoft infrastructure, making the attacks …

PoC Exploit Released for 7-Zip Vulnerabilities that Let Attackers Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept exploit for two critical vulnerabilities in the popular file archiver 7-Zip, potentially allowing attackers to execute arbitrary code remotely through malicious ZIP files. The flaws, tracked as CVE-2025-11001 and CVE-2025-11002, were disclosed by the Zero Day Initiative (ZDI) …

Authorities Dismantle Cybercrime-as-a-Service Platform, Seize 40,000 Active SIM Cards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An international law enforcement operation has dismantled a large-scale cybercrime-as-a-service network responsible for fueling thousands of online fraud cases across Europe. The operation, known as SIMCARTEL, took place on 10 October 2025 in Latvia and resulted in five arrests, the …

Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed Server-Side Request Forgery (SSRF) flaw in Zimbra Collaboration Suite has raised major security concerns, prompting administrators to patch systems immediately. The issue, identified in the chat proxy configuration component, could allow attackers to gain unauthorized access to …

Microsoft Windows 11 October Update Breaks Localhost (127.0.0.1) Connections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s October 2025 cumulative update for Windows 11 has disrupted localhost functionality, preventing developers and users from accessing local web applications and services via 127.0.0.1. The issue, tied to update KB5066835 released on October 14, affects builds like 26100.6899 and …

Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are exploiting TikTok’s massive user base to distribute sophisticated malware campaigns that promise free software activation but deliver dangerous payloads instead. The attack leverages social engineering tactics reminiscent of the ClickFix technique, where unsuspecting users are tricked into executing …

Threat Actors Leveraging ClickFake Interview Attack to Deploy OtterCandy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals associated with the North Korean threat group WaterPlum, also known as Famous Chollima or PurpleBravo, have escalated their activities with a sophisticated new malware strain called OtterCandy. This cross-platform RAT and information stealer represents a dangerous evolution in the …

Hackers Using AI to Automate Vulnerability Discovery and Malware Generation – Microsoft Report

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security teams around the world are grappling with a new breed of cyber threats that leverage advanced automation to identify software weaknesses and craft malicious payloads at unprecedented speed. Over the past year, adversaries have integrated machine-driven workflows into their …

New Tech Support Scam with Microsoft’s Logo Tricks Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new campaign has emerged that weaponizes Microsoft’s familiar branding to lure unsuspecting users into a sophisticated tech support scam. Victims receive a seemingly legitimate email, complete with Microsoft’s official logo, claiming there is an important financial transaction or security …