CISA Warns Of Rapid7 Velociraptor Vulnerability Exploited in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert on October 14, 2025, highlighting a critical vulnerability in Rapid7’s Velociraptor endpoint detection and response (EDR) tool. This flaw, stemming from incorrect default permissions, has already been weaponized by …

BlackSuit Ransomware Actors Breached Corporate Environment, Including 60+ VMware ESXi Hosts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The BlackSuit ransomware group, tracked as Ignoble Scorpius by cybersecurity experts, devastated a prominent manufacturer’s operations. The attack, detailed in a recent Unit 42 report from Palo Alto Networks, began with something as simple as compromised VPN credentials, escalating into …

TigerJack Hacks Infiltrated Developer Marketplaces with 11 Malicious VS Code Extensions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated threat actor known as TigerJack has systematically infiltrated developer marketplaces with at least 11 malicious Visual Studio Code extensions, targeting thousands of unsuspecting developers worldwide. Operating under multiple publisher identities including ab-498, 498, and 498-00, this cybercriminal has …

Chinese Hackers Leverage Geo-Mapping Tool to Maintain Year-Long Persistence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The emergence of a sophisticated malware campaign leveraging geo-mapping technology has put critical infrastructure and enterprise networks on high alert. First observed targeting sectors across Asia and North America, the malware was traced to a group of Chinese threat actors …

Pro-Russian Hacktivist Group Attacking Government Portals, Financial Services and Online Commerce

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated campaign orchestrated by multiple hacktivist groups has emerged, targeting government portals, financial services, and online commerce platforms across Israel and allied nations. The coordinated cyber offensive, timed around the October 7 anniversary, demonstrated unprecedented levels of organization and …

Windows 11 And Server 2025 Will Start Caching Plaintext Credentials By Enabling WDigest Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity threats are rapidly evolving; even advanced operating systems like Windows 11 and Windows Server 2025 can have vulnerabilities due to legacy configurations. Horizon Secure highlighted a concerning feature: WDigest authentication, which can be enabled to cache plaintext passwords in …

Windows Agere Modem Driver 0-Day Vulnerabilities Actively Exploited To Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has disclosed two critical zero-day vulnerabilities in the Agere Modem driver bundled with Windows operating systems, confirming active exploitation to escalate privileges. The flaws, tracked as CVE-2025-24990 and CVE-2025-24052, affect the ltmdm64.sys driver and could allow low-privileged attackers to …

NCSC Warns of UK Experiencing Four Cyber Attacks Every Week

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The United Kingdom faces an unprecedented cyber security crisis as the National Cyber Security Centre (NCSC) reports handling an average of four ‘nationally significant’ cyber attacks weekly. This alarming escalation represents a dangerous shift in the threat landscape, with the …

Microsoft IIS Vulnerability Allows Unauthorized Attacker To execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has disclosed a critical remote code execution flaw in its Internet Information Services (IIS) platform, posing risks to organizations relying on Windows servers for web hosting. Tracked as CVE-2025-59282, the vulnerability affects the Inbox COM Objects handling global memory, …

Critical Veeam Backup RCE Vulnerabilities Let Attackers Execute Malicious Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Veeam Software has disclosed three serious security flaws in its Backup & Replication suite and Agent for Microsoft Windows, which enable remote code execution and privilege escalation, potentially compromising enterprise backup infrastructures. These vulnerabilities, patched in recent updates, primarily affect …