First-Ever Malicious MCP Server Found in the Wild Steals Emails via AI Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The first-ever malicious Model-Context-Prompt (MCP) server discovered in the wild, a trojanized npm package named postmark-mcp that has been secretly exfiltrating sensitive data from users’ emails. The package, downloaded approximately 1,500 times per week, contained a backdoor that copied every …

CISA Warns of Cisco Firewall 0-Day Vulnerabilities Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an Emergency Directive mandating immediate action to mitigate two critical zero-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362, actively exploited against Cisco Adaptive Security Appliances (ASA) and select Firepower platforms.  The vulnerabilities allow unauthenticated remote code execution and privilege escalation, enabling advanced threat actors …

Chinese State-Sponsored Hackers Attacking Telecommunications Infrastructure to Harvest Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In late 2024, a new wave of cyber espionage emerged targeting global telecommunications infrastructure. Operating under the moniker Salt Typhoon, this Chinese state-sponsored group has focused its efforts on routers, firewalls, VPN gateways, and lawful intercept systems within major telecom …

Hackers Compromise Active Directory to Steal NTDS.dit that Leads to Full Domain Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Active Directory (AD) remains the foundation of authentication and authorization in Windows environments. Threat actors targeting the NTDS.dit database can harvest every domain credential, unlock lateral movement, and achieve full domain compromise.  Attackers leveraged native Windows utilities to dump and exfiltrate …

New Malicious Rust Crates Impersonating fast_log to Steal Solana and Ethereum Wallet Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have launched a sophisticated supply chain attack targeting cryptocurrency developers through malicious Rust crates designed to steal digital wallet keys. Two fraudulent packages, faster_log and async_println, have infiltrated the Rust package registry by impersonating the legitimate fast_log logging library, …

Critical Cisco Vulnerability Let Remote Attackers Execute Arbitrary Code on Firewalls and Routers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco warns of a Critical remote code execution flaw in web services across multiple Cisco platforms.  Tracked as CVE-2025-20363 (CWE-122), this vulnerability carries a CVSS 3.1 Base Score of 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) and impacts ASA, FTD, IOS, IOS XE, and IOS …

Hackers Exploiting Cisco ASA Zero-Day to Deploy RayInitiator and LINE VIPER Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity authorities are urging organizations to take immediate action following the discovery of a sophisticated espionage campaign targeting Cisco Adaptive Security Appliance (ASA) firewalls. In a significant update, Cisco and the UK’s National Cyber Security Centre (NCSC) have revealed that …

RedNovember Hackers Attacking Government and Technology Organizations to Deploy Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In mid-2024, cybersecurity professionals began observing a surge of targeted intrusions against government, defense, and technology organizations worldwide. These incidents were linked to a previously uncharacterized threat group later christened RedNovember, which leverages open-source and commodity tools to deploy a …

Hackers Leverage AI-Generated Code to Obfuscate Its Payload and Evade Traditional Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly turning to artificial intelligence to enhance their attack capabilities, as demonstrated in a sophisticated phishing campaign recently uncovered by security researchers. The campaign represents a significant evolution in malware obfuscation techniques, utilizing AI-generated code to disguise malicious …