CISA Warns of Delta Electronics Vulnerabilities Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA issued a warning of two critical path traversal flaws in Delta Electronics’ DIALink industrial control system software.  With a maximum CVSS v4 base score of 10.0, these vulnerabilities could be exploited remotely with low attack complexity to bypass authentication …

RDP vs SSH Comparison – Features, Protocols, Security, And Use Cases

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Remote Desktop Protocol (RDP) and Secure Shell (SSH) have changed how organizations manage their IT systems. These tools allow employees to access and control their computers from anywhere, which helps teams work together better. By enabling secure connections to work …

Critical GoAnywhere MFT Platform Vulnerability Exposes Enterprises to Remote Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A deserialization flaw in the License Servlet component of Fortra GoAnywhere Managed File Transfer (MFT) platform. Identified as CVE-2025-10035, this vulnerability permits an unauthenticated attacker who can deliver a forged license response signature to trigger Java deserialization of attacker-supplied objects, …

HubSpot’s Jinjava Engine Vulnerability Exposes Thousands of Websites to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed flaw in HubSpot’s open-source Jinjava template engine could allow attackers to bypass sandbox restrictions and achieve remote code execution (RCE) on thousands of websites relying on versions prior to 2.8.1.  Tracked as CVE-2025-59340 and rated Critical with …

Luxury Jewelry Creator Tiffany Confirms Data breach – Hackers Stolen Users Personal Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Luxury jewelry brand Tiffany and Company has confirmed a data breach that resulted in the theft of customers’ personal information. The company is in the process of sending out notification letters to affected individuals, detailing the scope of the incident …

New Malware Loader ‘CountLoader’ Weaponized PDF File to Deliver Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security teams have observed the emergence of a sophisticated malware loader, dubbed CountLoader, which leverages weaponized PDF files to deliver ransomware payloads. First detected in late August 2025, CountLoader is linked to multiple Russian-speaking cybercriminal groups, including …

Qilin Led Ransomware Attack Claimed to Compromised 104 Organizations in August

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware threat landscape witnessed a dramatic shift in August 2025 as the Qilin group claimed responsibility for 104 separate attacks worldwide. Emerging earlier this year, Qilin quickly cemented its position through aggressive double-extortion tactics and a broad affiliate recruitment …

Global Spyware Markets to Identify New Entities Entering The Market

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The global spyware market continues its alarming expansion, with new research revealing the emergence of 130 additional entities spanning 46 countries between 1992 and 2024. This shadowy ecosystem of surveillance technologies has grown from 435 documented entities in the initial …

New Phishing Attack Targets Facebook Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has recently emerged, targeting Facebook users with carefully crafted emails designed to harvest login credentials. Attackers leverage the platform’s own external URL warning system to cloak malicious links, presenting URLs that appear legitimate while redirecting victims …

Russian Airline Suffered Cyberattack Website and Other Systems Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Krasnoyarsk Regional Airlines (KrasAvia) confirmed a sophisticated cyberattack that has rendered its primary online services inoperable.  The breach targeted the airline’s web portal and associated back-end systems, including the Passenger Service System (PSS) and flight planning applications.  As a result, …