Cisco IOS and IOS XE Software Vulnerabilities Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed a severe vulnerability in its widely used IOS and IOS XE Software, potentially allowing attackers to crash devices or seize full control through remote code execution. The flaw, rooted in the Simple Network Management Protocol (SNMP) subsystem, …

North Korean Hackers Using Malicious Scripts Combining BeaverTail and OtterCookie for Keylogging

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new information-stealer has emerged targeting job seekers with a trojanized Node.js application named Chessfi. Delivered via a modified npm package hosted on the official repository, the malware blends two previously separate tools—BeaverTail and OtterCookie—into a unified JavaScript payload. Victims …

Beware of Fake ‘LastPass Hack’ Emails Trying to Trick Users Into Installing Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity professionals are raising alarms over a new wave of phishing emails masquerading as breach notifications from LastPass. These messages warn recipients of an urgent account compromise and urge them to download a “security patch” to restore access. In reality, …

Operation Silk Lure Weaponizing Windows Scheduled Tasks to Drop ValleyRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past month, a targeted campaign dubbed Operation Silk Lure has surfaced, exploiting the Windows Task Scheduler to deploy a novel variant of ValleyRAT. Emerging in mid-2025, the operation hinges on spear-phishing emails that carry malicious LNK attachments masquerading …

Qilin Ransomware Using Ghost Bulletproof Hosting to Attack Organizations Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Qilin ransomware group has emerged as one of the most prolific and dangerous threat actors in the cybersecurity landscape, exploiting sophisticated bulletproof hosting infrastructure to conduct devastating attacks on organizations across multiple sectors. Operating under a Ransomware-as-a-Service (RaaS) model, …

Mysterious Elephant APT Hackers Infiltrate Organization to Steal Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, a new advanced persistent threat (APT) group known as Mysterious Elephant has emerged as a formidable adversary targeting government and diplomatic institutions across the Asia-Pacific region. First identified by Kaspersky’s Global Research and Analysis Team (GReAT) in …

Senate Investigates Cisco Over Zero-Day Firewall Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

U.S. Senator Bill Cassidy, Chairman of the Senate Health, Education, Labor, and Pensions (HELP) Committee, has demanded answers from Cisco Systems regarding recent zero-day vulnerabilities in its widely used networking equipment. The October 10, 2025, letter to CEO Chuck Robbins …

PhantomVAI Loader Attacking Organizations Worldwide to Deliver AsyncRAT, XWorm, FormBook and DCRat

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated multi-stage malware campaign is targeting organizations globally, utilizing the PhantomVAI Loader to distribute dangerous information-stealing malware. The attack chain, which begins with carefully crafted phishing emails, has emerged as a significant threat to businesses across manufacturing, education, healthcare, …

CISA Warns Of Windows Improper Access Control Vulnerability Exploited In Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a critical Microsoft Windows vulnerability to its Known Exploited Vulnerabilities catalog, warning organizations that threat actors are actively exploiting it in real-world attacks. Identified as CVE-2025-59230, the flaw stems from improper access control in the Windows Remote …

Beware of Malicious Ivanti VPN Client Sites in Google Search That Delivers Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An aggressive SEO poisoning campaign has surfaced in early October 2025, preying on users searching for the legitimate Ivanti Pulse Secure VPN client. Attackers have registered lookalike domains such as ivanti-pulsesecure.com and ivanti-secure-access.org to host trojanized installers that appear official. …