New APT37 Attacking Windows Machines With New Rust and Python Based Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT37, the North Korean-aligned threat actor also known as ScarCruft, Ruby Sleet, and Velvet Chollima, has expanded its arsenal with sophisticated new malware targeting Windows systems. Active since 2012, the group primarily focuses on South Korean individuals connected to the …

Chinese Salt Typhoon and UNC4841 Hackers Teamed Up to Attack Government and Corporate Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers began tracking a sophisticated campaign in the closing months of 2024, targeting both government and corporate networks across multiple continents. The threat actors behind this operation, known colloquially as Salt Typhoon and UNC4841, leveraged overlapping infrastructure and shared …

Elastic Salesloft Drift Security Incident – Hackers Accessed Email Account Contains Valid Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elastic has disclosed a security incident stemming from a third-party breach at Salesloft Drift, which resulted in unauthorized access to an internal email account containing valid credentials. While the company’s core Salesforce environment was not impacted, the incident exposed sensitive …

SpamGPT – AI-powered Attack Tool Used By Hackers For Massive Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cybercrime toolkit named SpamGPT is enabling hackers to launch massive and highly effective phishing campaigns by combining artificial intelligence with the capabilities of professional email marketing platforms. Marketed on the dark web as a “spam-as-a-service” platform, SpamGPT …

New Technique Uncovered To Exploit Linux Kernel Use-After-Free Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new technique to exploit a complex use-after-free (UAF) vulnerability in the Linux kernel successfully bypasses modern security mitigations to gain root privileges. The method targets CVE-2024-50264, a difficult-to-exploit race condition bug in the AF_VSOCK subsystem that was recognized with a Pwnie …

Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dynatrace has confirmed it was impacted by a third-party data breach originating from the Salesloft Drift application, resulting in unauthorized access to customer business contact information stored in its Salesforce CRM. The company confirmed that the incident was limited to …

Hackers Hijacked 18 Very Popular npm Packages With 2 Billion Weekly Downloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the largest supply chain attack, hackers compromised 18 popular npm packages, which together account for over two billion downloads per week. The attack, which began on September 8th, involved injecting malicious code designed to steal cryptocurrency from users. The …

18 Popular Code Packages Hacked, Rigged to Steal Crypto

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

September 8, 2025 0 Comments At least 18 popular JavaScript code packages that are collectively downloaded more than two billion times each week were briefly compromised with malicious software today, after a developer involved in maintaining the projects was phished. …

Progress OpenEdge AdminServer Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Progress OpenEdge, a platform for developing and deploying business applications. The flaw, identified as CVE-2025-7388, allows for remote code execution (RCE) and affects multiple versions of the software, potentially enabling attackers to …

Windows Defender Vulnerability Allows Service Hijacking and Disablement via Symbolic Link Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in Windows Defender’s update process allows attackers with administrator privileges to disable the security service and manipulate its core files. The technique, which leverages a flaw in how Defender selects its execution folder, can be carried out …