New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged that weaponizes seemingly legitimate productivity tools to infiltrate systems and steal sensitive information. The TamperedChef malware represents a concerning evolution in threat actor tactics, utilizing trojanized applications disguised as calendar tools and image viewers …

JLR Confirms Phased Restart of Operations Following Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jaguar Land Rover (JLR) has confirmed it will begin a phased restart of its manufacturing operations in the coming days, nearly a month after a significant cyber attack forced the company to halt production across the United Kingdom. The luxury …

New Malware-as-a-Service Olymp Loader Promises Defender-Bypass With Automatic Certificate Signing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community is currently observing a surge in interest around Olymp Loader, a recently unveiled Malware-as-a-Service (MaaS) platform written entirely in Assembly. First advertised on underground forums and Telegram channels in early June 2025, Olymp Loader has rapidly evolved …

Threat Actors Weaponizing Facebook and Google Ads as Financial Platforms to Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, cybersecurity teams have observed an alarming trend in which malicious actors exploit Facebook and Google advertising channels to masquerade as legitimate financial services. By promoting free or premium access to well-known trading platforms, these threat actors have …

New ModStealer Evade Antivirus Detection to Attack macOS Users and Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cross-platform information stealer known as ModStealer has emerged, targeting macOS users and demonstrating concerning capabilities to evade Apple’s built-in security mechanisms. The malware represents the latest evolution in macOS-focused threats, which have seen a dramatic surge throughout …

WhatsApp 0-Click Vulnerability Exploited Using Malicious DNG File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp 0-click remote code execution (RCE) vulnerability affecting Apple’s iOS, macOS, and iPadOS platforms, detailed with a proof of concept demonstration. The attack chain exploits two distinct vulnerabilities, identified as CVE-2025-55177 and CVE-2025-43300, to compromise a target device without requiring …

SUSE Rancher Vulnerabilities Let Attackers Lockout the Administrators Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw in SUSE Rancher’s user management module allows privileged users to disrupt administrative access by modifying usernames of other accounts.  Tracked as CVE-2024-58260, this vulnerability affects Rancher Manager versions 2.9.0 through 2.12.1, enabling both username takeover and full …

ThreatBook Launches Best-of-Breed Advanced Threat Intelligence Solution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Singapore, Singapore, September 29th, 2025, CyberNewsWire Analyzing over 14 billion cyber-attack records daily, ThreatBook ATI is a global solution enriched with granular, local insights; and can offer organizations a truly APAC perspective. Boasting low false positive rates, the solution is …

Lesson From Cisco ASA 0-Day RCE Vulnerability That Actively Exploited In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape experienced a significant escalation in September 2025, when Cisco disclosed multiple critical zero-day vulnerabilities affecting its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) platforms. At the center of this security crisis lies CVE-2025-20333, a devastating …

Formbricks Signature Verification Vulnerability Let Attackers Reset User Passwords Without Authorization

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw discovered in Formbricks, an open-source experience management platform, demonstrates how missing JWT signature verification can lead to complete account takeovers.  The vulnerability tracked as CVE-2025-59934 affects all versions prior to 4.0.1 and stems from improper token …