Hackers Hijacking IIS Servers Using Malicious BadIIS Module to Serve Malicious Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber campaign, dubbed “Operation Rewrite,” is actively hijacking Microsoft Internet Information Services (IIS) web servers to serve malicious content through a technique known as search engine optimization (SEO) poisoning. Palo Alto Networks uncovered the operation in March 2025, …

Hackers Abusing GitHub Notifications to Deliver Phishing Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, security researchers have uncovered an elaborate phishing campaign that leverages legitimate GitHub notification mechanisms to deliver malicious content. Victims receive seemingly authentic repository alerts, complete with real-looking commit messages and collaborator updates. Upon closer inspection, the notification …

Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in Libraesva ESG email security gateways has been identified and patched, allowing threat actors to execute arbitrary commands through specially crafted email attachments.  The vulnerability, tracked as CVE-2025-59689, affects multiple versions of the popular email security …

European Airport Disruptions Caused by Sophisticated Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the weekend, a sophisticated ransomware attack compromised Collins Aerospace’s Muse check-in and boarding systems, forcing key hubs including Heathrow, Brussels, and Berlin to return to manual processes. Airlines reported hundreds of delayed and cancelled flights as security teams raced …

22.2 Tbps DDoS Attack Breaks Internet With New World Record

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare announced it had autonomously mitigated the largest distributed denial-of-service (DDoS) attack ever recorded. The hyper-volumetric attack peaked at an unprecedented 22.2 terabits per second (Tbps) and 10.6 billion packets per second (Bpps), setting a new and alarming benchmark for …

Top 10 Best Supply Chain Risk Management Solutions in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In today’s rapidly evolving global market, supply chain risk management has become more crucial than ever before. Organizations face risks like geopolitical issues, market unpredictability, compliance challenges, supplier failures, and even cyber threats. To maintain resilience, companies must adopt robust …

BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A seemingly innocent patch update for the popular 2D platformer game BlockBlasters has transformed into a sophisticated malware campaign, exposing hundreds of Steam users to data theft and system compromise. The malicious patch, deployed on August 30, 2025, demonstrates how …

Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, security researchers have observed a surge in attacks exploiting Oracle Database Scheduler’s External Jobs feature to gain a foothold in corporate environments. This technique abuses the scheduler’s ability to execute arbitrary commands on Windows-based database servers, allowing …

Subtle Snail Mimic as HR Representatives to Engage Employees and Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Iran-nexus espionage group known as Subtle Snail has emerged as a significant threat to European telecommunications, aerospace, and defense organizations through an elaborate recruitment-themed social engineering campaign. The group, also identified as UNC1549 and linked to the broader …

Kawa4096 Ransomware Attacking Multinational Organizations to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new ransomware group has emerged from the shadows, targeting multinational organizations across diverse sectors with precision and systematic approach. Kawa4096, first detected in June 2025, has rapidly established itself as a formidable threat to enterprises spanning finance, education, …