New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security teams have observed a significant increase in sophisticated phishing campaigns leveraging a newly discovered Phishing-as-a-Service (PhaaS) platform dubbed VoidProxy. The operation, first detected in August 2025, combines multiple anti-analysis techniques and adversary-in-the-middle (AitM) capabilities to target …

Microsoft Warns Of Windows 11 23H2 Support Ending In 60 Days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an official reminder that support for Windows 11 version 23H2 Home and Pro editions is set to expire in approximately 60 days. The end-of-servicing date is scheduled for November 11, 2025, after which these devices will no …

ACR Stealer – Uncovering Attack Chains, Functionalities And IOCs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ACR Stealer represents one of the most sophisticated information-stealing malware families actively circulating in 2025, distinguished by its advanced evasion techniques and comprehensive data harvesting capabilities. Originally emerging in March 2024 as a Malware-as-a-Service (MaaS) offering on Russian-speaking cybercrime forums, …

FlowiseAI Password Reset Token Vulnerability Allows Account Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting FlowiseAI’s Flowise platform has been disclosed, revealing a severe authentication bypass flaw that allows attackers to perform complete account takeovers with minimal effort.  The vulnerability tracked as CVE-2025-58434 impacts both cloud deployments at cloud.flowiseai.com and self-hosted …

Linux CUPS Vulnerability Let Attackers Remote DoS and Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical vulnerabilities have been discovered in the Linux Common Unix Printing System (CUPS), exposing millions of systems to remote denial-of-service attacks and authentication bypass exploits.  The vulnerabilities, tracked as CVE-2025-58364 and CVE-2025-58060, affect the core printing infrastructure used across …

BitlockMove Tool Enables Lateral Movement via Bitlocker DCOM & COM Hijacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new proof-of-concept (PoC) tool named BitlockMove demonstrates a novel lateral movement technique that leverages BitLocker’s Distributed Component Object Model (DCOM) interfaces and COM hijacking. Released by security researcher Fabian Mosch of r-tec Cyber Security, the tool enables attackers to …

Weekly Cybersecurity News Recap : Tenable, Qualys, Workday Data Breaches and Security Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

This week in cybersecurity serves as a critical reminder of the pervasive risks within the digital supply chain, as several industry-leading companies disclosed significant data breaches. The incidents, affecting vulnerability management giants Tenable and Qualys, as well as enterprise software …

FBI Unveils IOCs for Hacker Groups Targeting Salesforce Instances for Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Bureau of Investigation (FBI) has released a flash alert detailing the activities of two cybercriminal groups, UNC6040 and UNC6395, that are actively compromising Salesforce environments to steal data for extortion purposes. The advisory, published by the FBI on …

Nmap vs. Wireshark: Choosing the Right Tool for Network Penetration Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Nmap vs Wireshark are the most popular Network penetration testing tools. Security professionals face an increasingly complex threat landscape, and picking the right penetration testing tools can make the difference between a secure infrastructure and a compromised network. While both …

EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged that leverages artificial intelligence to create deceptively legitimate applications, marking a significant evolution in cyberthreat tactics. The EvilAI malware family represents a new breed of threats that combines AI-generated code with traditional trojan techniques …