Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged targeting job seekers through fake Google career recruitment opportunities, leveraging social engineering tactics to harvest Gmail credentials and personal information. The malicious operation exploits the trust associated with Google’s brand reputation, crafting convincing recruitment …

Microsoft Investigating Widespread Outlook.com Outage Preventing Mailbox Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is actively investigating and addressing widespread errors preventing users from accessing their mailboxes on Outlook.com. The company has been providing regular updates throughout the day, indicating that targeted infrastructure restarts are gradually restoring service. The issue, which began early …

Hackers Exploit Cellular Router’s API to Send Malicious SMS Messages With Weaponized Links

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have recently leveraged a vulnerability in the web-based management interfaces of certain cellular routers to co-opt their built-in SMS functionality for nefarious purposes. By targeting exposed APIs, attackers are able to dispatch large volumes of malicious SMS messages containing …

48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability affecting thousands of Cisco firewalls is being actively exploited by threat actors in the wild.  The vulnerability, tracked as CVE-2025-20333, poses an immediate risk to organizations worldwide with a CVSS score of 9.9, representing one of …

Windows 11 25H2 Released for General Availability – Know Issues and Mitigations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially released Windows 11, version 25H2, also known as the Windows 11 2025 Update, marking the next feature update for the operating system. The update became available for general availability on September 30, 2025, initiating a phased rollout …

New Android Banking Trojan Uses Hidden VNC to Gain Complete Remote Control Over Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Android banking trojan has emerged that combines traditional overlay attacks with a stealthy hidden Virtual Network Computing (VNC) server to achieve full remote control of compromised devices. First detected in late September 2025, the malware is distributed through …

OpenSSL Vulnerabilities Let Attackers Execute Malicious Code and Recover Private Key Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OpenSSL Project has released a critical security advisory, addressing three significant vulnerabilities that could allow attackers to execute remote code and potentially recover private cryptographic keys.  These flaws affect multiple OpenSSL versions across different platforms and could lead to …

Beware! Threat Actors Distributing Malicious AI Tools as Chrome Extensions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A concerning cybersecurity trend has emerged as threat actors exploit the growing popularity of artificial intelligence tools by distributing malicious Chrome extensions masquerading as legitimate platforms. These deceptive extensions target users seeking convenient access to popular services like ChatGPT, Claude, …

CISA Warns of Libraesva ESG Command Injection Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In late September 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued a public alert regarding the active exploitation of a critical command injection vulnerability tracked as CVE-2025-59689 in Libraesva Email Security Gateway (ESG) devices. This flaw has rapidly emerged …

Threat Actors Hijacking MS-SQL Server to Deploy XiebroC2 Framework

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack campaign targeting improperly managed Microsoft SQL servers has emerged, deploying the XiebroC2 command and control framework to establish persistent access to compromised systems. The attack leverages vulnerable credentials on publicly accessible database servers, allowing threat actors to …