APT35 Hackers Attacking Government, Military Organizations to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, a surge in targeted intrusions attributed to the Iranian-aligned threat group APT35 has set off alarm bells across government and military networks worldwide. First detected in early 2025, the campaign leverages custom-built malware to infiltrate secure perimeters …

How SOC Teams Detect Can Detect Cyber Threats Quickly Using Threat Intelligence Feeds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security Operations Centers (SOCs) protect organizations’ digital assets from ongoing cyber threats. To assess their effectiveness, SOCs use key performance indicators (KPIs) such as Mean Time to Detect (MTTD) and False Positive Rate (FPR). Although these metrics are often seen …

CISA Warns of Linux Sudo Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent advisory regarding a critical vulnerability in the Linux and Unix sudo utility CVE-2025-32463 that is currently being exploited in the wild.  This flaw allows local adversaries to bypass access controls and execute arbitrary commands as …

Google Gemini Vulnerabilities Let Attackers Exfiltrate User’s Saved Data and Location

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three new vulnerabilities in Google’s Gemini AI assistant suite could have allowed attackers to exfiltrate users’ saved information and location data. The vulnerabilities uncovered by Tenable, dubbed the “Gemini Trifecta,” highlight how AI systems can be turned into attack vehicles, …

Threat Actors Allegedly Listed Veeam RCE Exploit for Sale on Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Veeam Backup & Replication, a cornerstone of many enterprises’ data protection strategy, has reportedly become the focus of a new exploit being offered on a clandestine marketplace. According to a recent listing, a seller operating under the handle “SebastianPereiro” claims …

Hackers Actively Scanning to Exploit Palo Alto Networks PAN-OS Global Protect Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers are observing a significant increase in internet-wide scans targeting the critical PAN-OS GlobalProtect vulnerability (CVE-2024-3400).  Exploit attempts have surged as attackers seek to leverage an arbitrary file creation flaw to achieve OS command injection and ultimately full root …

Linux 6.17 Released With Fix for use-after-free Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Linus Torvalds has announced the release of Linux Kernel 6.17, a new version focused on stability and incremental improvements rather than groundbreaking features. The update brings a host of bug fixes, security enhancements, and driver updates across various subsystems. In …

Tesla’s Telematics Control Unit Vulnerability Let Attackers Gain Code Execution as Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability in Tesla’s Telematics Control Unit (TCU) allowed attackers with physical access to bypass security measures and gain full root-level code execution. The flaw stemmed from an incomplete lockdown of the Android Debug Bridge (ADB) on an external …

Lunar Spider Infected Windows Machine in Single Click and Harvested Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lunar Spider, a newly observed malware strain, has emerged as a potent threat to Windows environments by compromising systems in a single click. First detected in mid-September 2025, its operators have quickly refined delivery and payload strategies to evade traditional …

Beer Brewing Giant Asahi Halts Production Following Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Japanese beverage conglomerate Asahi Group Holdings has halted production at its domestic factories following a significant cyberattack that crippled its systems on Monday. A company spokesperson confirmed on Tuesday that production has not resumed and that there is no foreseeable …