Hackers Weaponizing SVG Files to Stealthily Deliver Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have embraced a new deceptive technique that transforms seemingly harmless vector graphics into dangerous malware delivery systems. A recent campaign targeting Latin America demonstrates how attackers are exploiting oversized SVG files containing embedded malicious payloads to distribute AsyncRAT, a …

Tata-Owned Jaguar Land Rover Delays Factory Reopening Following Major Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jaguar Land Rover (JLR), the United Kingdom’s largest automotive manufacturer, has announced an additional delay in resuming production at its factories following a significant cyber-attack that occurred earlier this month. The company has extended its current production pause until Wednesday, …

SonicWall Releases Urgent Update to Remove Rootkit Malware ‘OVERSTEP’ from SMA Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has issued an urgent firmware update, version 10.2.2.2-92sv, for its Secure Mobile Access (SMA) 100 series appliances to detect and remove known rootkit malware. The advisory, SNWLID-2025-0015, published on September 22, 2025, strongly recommends that all users of SMA …

Threat Actors with Fake Job Lures Attacking Job Seekers to Deploy Advanced Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, a sophisticated campaign has emerged in which state-linked threat actors are leveraging fake job offers to ensnare unsuspecting job seekers and deliver advanced malware. These attackers craft convincing phishing emails that direct victims to look-alike career portals, …

U.S. Secret Service Dismantles 300 SIM Servers and 100,000 SIM Cards Disabling Cell Phone Towers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Secret Service has dismantled a massive, sophisticated network of electronic devices in the New York tristate area, thwarting what it described as an “imminent threat” to senior U.S. government officials and the agency’s protective operations. The operation led …

SpyCloud Report: 2/3 Orgs Extremely Concerned About Identity Attacks Yet Major Blind Spots Persist

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Austin, Texas, USA, September 23rd, 2025, CyberNewsWire New SpyCloud 2025 Identity Threat Report reveals dangerous disconnect between perceived security readiness and operational reality. SpyCloud, the leader in identity threat protection, today released the 2025 SpyCloud Identity Threat Report, revealing that …

SolarWinds Web Help Desk Vulnerability Enables Unauthenticated RCE

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SolarWinds has released an urgent security advisory for a critical vulnerability in its Web Help Desk software that could allow an unauthenticated attacker to achieve remote code execution (RCE). The flaw, tracked as CVE-2025-26399, carries a critical severity rating of …

Hackers Exploits IMDS Service to Gain Initial Access to a Cloud Environment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors were manipulating the Instance Metadata Service (IMDS), a core component designed to securely furnish compute instances with temporary credentials to infiltrate and navigate cloud infrastructures.  By compelling unsuspecting applications to query IMDS endpoints, attackers harvest short-lived tokens, enabling …

GitHub Enhances NPM’s Security with Strict Authentication, Granular Tokens, and  Trusted Publishing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recent High-profile supply‐chain attacks have exposed critical weaknesses in package registry security, prompting GitHub to roll out a suite of defenses designed to harden the npm ecosystem.  “GitHub Enhances npm’s security with strict authentication, granular tokens, and trusted publishing” marks …

EV Charging Provider Confirm Data Breach – Customers Personal Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Digital Charging Solutions GmbH (DCS), a leading provider of white-label charging services for automotive OEMs and fleet operators, has confirmed a data breach affecting a limited number of its customers.  DCS disclosed that unauthorized access to personal data occurred in …