Lightship Security and the OpenSSL Corporation Submit OpenSSL 3.5.4 for FIPS 140-3 Validation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Newark, United States, October 9th, 2025, CyberNewsWire Lightship Security, an Applus+ Laboratories company and accredited cryptographic security test laboratory, and the OpenSSL Corporation, the co-maintainer of the OpenSSL Library, announce the submission of OpenSSL version 3.5.4 to the Cryptographic Module …

Hackers Exploit DFIR Tool ‘Velociraptor’ in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Cisco Talos have confirmed that ransomware operators are actively exploiting Velociraptor, an open-source digital forensics and incident response (DFIR) tool, in their attacks. This marks the first definitive link between a legitimate security tool and a ransomware …

New Phishing Kit Automates Generation of ClickFix Attack Bypassing Security Measures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community has witnessed the rapid emergence of a novel phishing toolkit that automates the creation of “ClickFix” attack pages, enabling threat actors with minimal technical expertise to deploy sophisticated social engineering lures. Dubbed the IUAM ClickFix Generator, this …

SonicWall Confirms That Hackers Stole All Customers Firewall Configuration Backup Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has confirmed that an unauthorized party accessed and stole the entire repository of customer firewall configuration backup files from its cloud service. The confirmation comes after the completion of an investigation with the cybersecurity firm Mandiant, which determined that …

AI Chatbot Leveraged as a Critical Backdoor to Access Sensitive Data and Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, a sophisticated malware campaign has emerged that leverages conversational chatbots as covert entry points into enterprise systems. Initially observed in mid-September 2025, the threat actors targeted organizations running customer-facing chat applications built on large language models. By …

Microsoft Azure Faces Global Outage Affecting Services Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Azure, one of the world’s leading cloud computing platforms, experienced a significant service outage on Thursday, October 9, 2025, leaving customers across Europe and Africa unable to access their services. The disruption began at approximately 07:40 UTC, with the …

New Hacker Alliance Trinity of Chaos Leaked 39 Companies Data Including Google, CISCO and Others

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has been shaken by the emergence of Trinity of Chaos, a sophisticated ransomware collective that has launched a data leak site containing sensitive information from 39 major corporations. This formidable alliance, presumably comprising members from the notorious …

Microsoft 365 Outage Disrupts Access to Admin Center, Services, and Entra ID

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major service outage is affecting Microsoft 365, preventing users from accessing the admin center and other services that rely on Microsoft Entra ID for authentication. The disruption, which began on Thursday, October 9, 2025, is causing widespread access issues …

Microsoft Events Vulnerability Exposes Users Personal Data From Registration And Waitlist Databases

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security flaw has been discovered within the Microsoft Events platform, which could have allowed attackers to access the personal information of users from two separate databases: the event registration list and the waitlist. The vulnerability, uncovered by a …

Shuyal Stealer Attacking 19 Browsers to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Shuyal Stealer has rapidly ascended as one of the most versatile credential theft tools observed in recent months. First detected in early August 2025, its modular architecture allows it to target an expansive range of web browsers, including Chromium-based, Gecko-based, …