Kali Linux 2025.3 Released With New Features and 10 New Hacking Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kali team has released Kali Linux 2025.3, the third major update of the year for the popular penetration testing and ethical hacking distribution. This release introduces 10 new tools, brings significant updates to its mobile platform, Kali NetHunter, and enhances …

CISA Details That Hackers Gained Access to a U.S. Federal Agency Network Via GeoServer RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has released a comprehensive cybersecurity advisory detailing how threat actors successfully compromised a U.S. federal civilian executive branch agency’s network by exploiting CVE-2024-36401, a critical remote code execution vulnerability in GeoServer. The incident, which remained undetected for three weeks, …

Chrome High-severity Vulnerabilities Let Attackers Access Sensitive Data and Crash System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has issued an urgent security update for its Chrome web browser to address three high-severity vulnerabilities that could allow attackers to access sensitive information or cause the system to crash. The company is advising users to update their browsers …

Threat Actors Breaking to Enterprise Infrastructure Within 18 Minutes From Initial Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity professionals are facing an unprecedented acceleration in threat actor capabilities as the average breakout time—the period from initial access to lateral movement—has plummeted to a mere 18 minutes during the June-August 2025 reporting period. This alarming statistic represents a …

New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged in the npm ecosystem, utilizing an innovative steganographic technique to conceal malicious code within QR codes. The malicious package, identified as “fezbox,” presents itself as a legitimate JavaScript/TypeScript utility library while secretly executing password-stealing …

Zloader Malware Repurposed to Act as Entry Point Into Corporate Environments to Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zloader, a sophisticated Zeus-based modular trojan that first emerged in 2015, has undergone a significant transformation from its original banking-focused operations to become a dangerous entry point for ransomware attacks in corporate environments. Originally designed to facilitate financial fraud, this …

Beware of Fake Online Speedtest Application With Obfuscated JS Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged that leverages fake online speed test applications to deploy obfuscated JavaScript payloads on Windows systems. These malicious utilities masquerade as legitimate network speed testing tools, manual readers, PDF utilities, and various search frontends to …

Defy Security Appoints Esteemed Cybersecurity Leader Gary Warzala to Its Board of Directors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Defy Security, a leading provider of cybersecurity solutions and services, today announced the appointment of Gary Warzala to its Board of Directors. Warzala is a highly regarded cybersecurity executive with more than 20 years of leadership experience, having served as …

Want to Validate Alerts Faster? Use Free Threat Intel from 15K SOCs 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Alex sighed at his third energy drink of the night shift, watching another batch of security alerts flood his SIEM dashboard. As a Level 2 threat analyst at a mid-sized financial firm, he was drowning in false positives and spending …

Nimbus Manticore Attacking Defense and Telecom Sectors With New Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Iranian threat actor known as Nimbus Manticore has intensified its campaign targeting defense manufacturing, telecommunications, and aviation sectors across Western Europe with sophisticated new malware variants. This mature advanced persistent threat group, also tracked as UNC1549 and Smoke Sandstorm, …