7-Zip Vulnerabilities Allows Remote Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two high-severity vulnerabilities have been discovered in the popular open-source file archiver, 7-Zip, which could allow remote attackers to execute arbitrary code. Identified as CVE-2025-11001 and CVE-2025-11002, the flaws affect all versions of the software prior to the latest release …

New Quishing Attack With Weaponized QR Code Targeting Microsoft Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft users are facing a novel quishing campaign that leverages weaponized QR codes embedded in malicious emails. Emerging in early October 2025, this attack exploits trust in QR-based authentication and device pairing workflows, tricking targets into scanning codes that deliver …

Hackers Actively Exploiting WordPress Plugin Vulnerability to Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past two months, threat actors have weaponized a critical authentication bypass flaw in the Service Finder Bookings WordPress plugin, enabling them to hijack any account on compromised sites. First disclosed on July 31, 2025, the vulnerability emerged after …

Threat Actors Mimic as HR Departments to Steal Your Gmail Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged targeting job seekers through legitimate Zoom document-sharing features, demonstrating how cybercriminals exploit trusted platforms to harvest Gmail credentials. The attack leverages social engineering tactics by impersonating HR departments and using authentic Zoom notifications to …

Hackers Upgraded ClickFix Attack With Cache Smuggling to Secretly Download Malicious Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated evolution of the ClickFix attack methodology, where threat actors are leveraging cache smuggling techniques to avoid traditional file download detection mechanisms. This innovative campaign targets enterprise networks by masquerading as a Fortinet VPN compliance …

New Polymorphic Python Malware Repeatedly Mutate its Appearance at Every Execution Time

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently discovered Python-based remote access trojan (RAT) exhibits unprecedented polymorphic behavior, altering its code signature each time it runs. First observed on VirusTotal, the sample, dubbed nirorat.py, initially scored only 26/100 on detection engines, despite containing a full suite …

Data-Leak Sites Hit an All-Time High With New Scattered Spider RaaS and LockBit 5.0

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware landscape witnessed unprecedented upheaval in Q3 2025 as cyberthreat actors ushered in a new era of aggression and sophistication. The quarter marked a pivotal moment with the emergence of Scattered Spider’s inaugural ransomware-as-a-service offering, ShinySp1d3r RaaS, representing the …

Chaos Emerges as Faster, Smarter, and More Dangerous Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, security teams worldwide have grappled with a new ransomware strain that has shattered expectations for speed and sophistication. First detected in late September 2025, this variant encrypts critical data within seconds of execution, leaving little time for …

SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto, California, October 9th, 2025, CyberNewsWire As AI Browsers rapidly gain adoption across enterprises, SquareX has released critical security research exposing major vulnerabilities that could allow attackers to exploit AI Browsers to exfiltrate sensitive data, distribute malware and gain …

KFC Venezuela Alleged Data Breach – 1 Million Customer Records Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has allegedly breached KFC Venezuela, offering a database containing the personal and order information of over one million customers for sale on a dark web forum. The data, advertised on October 8, 2025, includes a vast amount …