Linux Kernel ksmbd Vulnerability Allows Remote Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in the Linux kernel’s ksmbd SMB server implementation has been disclosed, potentially allowing authenticated remote attackers to execute arbitrary code on affected systems.  The vulnerability, tracked as CVE-2025-38561 and assigned a CVSS score of 8.5, represents a …

Banking Trojans Attacking Android Users Mimic as Government and Legitimate Payment Apps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercriminal campaign has emerged targeting Indonesian and Vietnamese Android users with banking trojans disguised as legitimate government identity applications and payment services. The malicious operation, active since approximately August 2024, employs advanced evasion techniques to deliver variants of …

Critical DNN Platform Vulnerability Let Attackers Execute Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical stored cross-site scripting vulnerability has emerged in the popular DotNetNuke (DNN) Platform, threatening websites powered by this widely-used content management system. The vulnerability, tracked as CVE-2025-59545 with a severity score of 9.1 out of 10, affects all DNN …

Malicious SVGs in Phishing Campaigns: How to Detect Hidden Redirects and Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing campaigns are getting harder to spot, sometimes hiding in files you’d never suspect. ANY.RUN’s cybersecurity analysts recently uncovered one such case: a malicious SVG disguised as a PDF, hosted on a legitimate domain and packed with hidden redirects. By …

Cisco IOS 0-Day RCE Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed a zero-day vulnerability, CVE-2025-20352, in its widely used IOS and IOS XE software, confirming it is being actively exploited in the wild. The flaw exists in the Simple Network Management Protocol (SNMP) subsystem and can allow a …

RainyDay, Turian and Naikon Malwares Abuse DLL Search Order to Execute Malicious Loaders

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three sophisticated malware families have emerged as significant threats to telecommunications and manufacturing sectors across Central and South Asia, representing a coordinated campaign that exploits legitimate system processes to deliver powerful backdoor capabilities. RainyDay, Turian, and a new variant of …

New North Korean IT Worker With Innocent Job Application Get Access to Organization’s Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, a sophisticated threat actor leveraging North Korean IT worker employment fraud has surfaced, demonstrating how social engineering can bypass traditional security controls. The adversary’s modus operandi involves posing as remote software engineers, submitting legitimate-looking résumés, completing coding …

Hackers Can Compromise Chromium Browsers in Windows by Loading Arbitrary Extensions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chromium-based browsers, including Chrome, Edge, and Brave, manage installed extensions via JSON preference files stored under %AppData%GoogleUser DataDefaultPreferences (for domain-joined machines) or Secure Preferences (for standalone systems).  Synacktiv research indicates that by directly altering these files, attackers can make the browser …

UK Police Arrested Man Linked to Ransomware Attack That Crippeled European Airports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A man in his forties has been arrested in West Sussex, England, in connection with a cyber-attack that has caused days of widespread disruption at several major European airports, including London’s Heathrow. The UK’s National Crime Agency (NCA) confirmed the …

Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

U.S. prosecutors last week levied criminal hacking charges against 19-year-old U.K. national Thalha Jubair for allegedly being a core member of Scattered Spider, a prolific cybercrime group blamed for extorting at least $115 million in ransom payments from victims. The …