Capita To pay £14 Million For Data Breach Exposes 6.6 Million Users Personal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The UK’s Information Commissioner’s Office (ICO) has imposed a £14 million fine on outsourcing giant Capita following a major cyber attack in 2023 that exposed the personal data of 6.6 million individuals. This penalty, split as £8 million to Capita …

New nightMARE Python Library to Analyze Malware and Extract Intelligence Indicators

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since its public debut in October 2025, nightmare has quickly become a vital tool for malware analysts seeking to streamline static and dynamic analysis workflows. Developed by Elastic Security Labs, nightmare brings together mature open-source reverse engineering components under a …

Critical Apache ActiveMQ Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache Software Foundation has disclosed a critical vulnerability in its ActiveMQ NMS AMQP Client that could allow attackers to execute arbitrary code on vulnerable systems. Tracked as CVE-2025-54539, this deserialization flaw poses a serious risk to applications relying on …

Critical Samba RCE Vulnerability Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Samba has disclosed a severe remote code execution (RCE) flaw that could allow attackers to hijack Active Directory domain controllers. Tracked as CVE-2025-10230, the vulnerability stems from improper validation in the Windows Internet Name Service (WINS) hook mechanism, earning a …

CISA Warns Of Adobe Experience Manager Forms 0-Day Vulnerability Exploited In Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a severe code execution vulnerability in Adobe Experience Manager Forms, urging organizations to patch immediately. Tracked as CVE-2025-54253, this flaw affects the Java Enterprise Edition (JEE) version …

Windows BitLocker Vulnerabilities Let Attackers Bypass Security Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has disclosed two critical vulnerabilities in its Windows BitLocker encryption feature, allowing attackers with physical access to bypass security protections and access encrypted data. Released on October 14, 2025, as part of the latest Patch Tuesday updates, these flaws, …

New Banking Malware Abusing WhatsApp to Gain Complete Remote Access to Your Computer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated banking Trojan named Maverick has emerged in Brazil, leveraging WhatsApp as its primary distribution channel to compromise thousands of users. The malware campaign was detected in mid-October 2025, with cybersecurity solutions blocking over 62,000 infection attempts in just …

Microsoft Disrupted Vanilla Tempest Attack by Revoking Certificates Used to Sign Fake Teams File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft announced that it had revoked more than 200 digital certificates exploited by the notorious Vanilla Tempest hacking group. This action effectively disrupted an ongoing campaign where attackers impersonated Microsoft Teams installations to infiltrate corporate networks and deploy ransomware. The …

YouTube Down for Users Globally – Google Confirms Outage – Updated

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

YouTube experienced a widespread outage on Wednesday, October 15, 2025, disrupting video streaming for millions of users across the United States, Europe, Asia, and beyond. The platform, which serves over 2.7 billion monthly users, saw reports of playback errors and …

MCPTotal Launches to Power Secure Enterprise MCP Workflows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MCPTotal, a comprehensive secure Model Context Protocol (MCP) platform, today announced its flagship platform to help businesses adopt and secure MCP servers.  MCP has become the standard interface for connecting AI models with enterprise systems, external data sources, and third-party …