Venezuela’s Maduro Says Huawei Mate X6 Gift From China is Unhackable by U.S. Spies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In Caracas this week, President Nicolás Maduro unveiled the Huawei Mate X6 gifted by China’s Xi Jinping, declaring the device impervious to U.S. espionage efforts. The announcement coincides with heightened tensions between Washington and Beijing, as the United States enforces …

LunaLock Ransomware Attacking Artists to Steal and Encrypt Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers first observed LunaLock in early September 2025, a sophisticated ransomware strain targeting independent illustrators and digital artists. Leveraging compromised credentials and social engineering, the group behind LunaLock has zeroed in on a niche marketplace—Artists & Clients—where freelance creators …

Exposed ‘Kim’ Dump Exposes Kimsuky Hackers New Tactics, Techniques, and Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive data breach in early September 2025 attributed to a cyber actor known simply as “Kim” laid bare an unprecedented view into the operational playbook of Kimsuky (APT43). The leak, comprising terminal history files, phishing domains, OCR workflows, compiled …

Hackers Weaponize Amazon Simple Email Service to Send 50,000+ Malicious Emails Per Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercriminal campaign has emerged, exploiting Amazon’s Simple Email Service (SES) to orchestrate large-scale phishing operations capable of delivering over 50,000 malicious emails daily. The attack represents a significant evolution in cloud service abuse, transforming AWS’s legitimate bulk email …

Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Qualys has confirmed it was impacted by a widespread supply chain attack that targeted the Salesloft Drift marketing platform, resulting in unauthorized access to a portion of its Salesforce data. The breach originated from a sophisticated cyberattack campaign targeting Salesloft …

Researchers Bypassed Web Application Firewall With JS Injection with Parameter Pollution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have demonstrated a sophisticated technique for bypassing Web Application Firewalls (WAFs) using JavaScript injection combined with HTTP parameter pollution, exposing critical vulnerabilities in modern web security infrastructure. The research, conducted during an autonomous penetration test, revealed how attackers …

PgAdmin Vulnerability Lets Attackers Gain Unauthorised Account Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security flaw has been discovered in pgAdmin, the widely used open-source administration and development platform for PostgreSQL databases. The vulnerability, tracked as CVE-2025-9636, affects all pgAdmin versions up to and including 9.7, potentially allowing remote attackers to gain …

PoC Exploit Released for ImageMagick RCE Vulnerability – Update Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been released for a critical remote code execution (RCE) vulnerability in ImageMagick 7’s MagickCore subsystem, specifically affecting the blob I/O (BlobStream) implementation. Security researchers and the ImageMagick team urge all users and organizations to update immediately to prevent exploitation. …

Salesloft Drift Cyberattack Linked to GitHub Compromise and OAuth Token Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply-chain attack that impacted over 700 organizations, including major cybersecurity firms, has been traced back to a compromise of Salesloft’s GitHub account that began as early as March 2025. In an update on September 6, 2025, Salesloft confirmed …

Microsoft Azure Cloud Disrupted by Undersea Cable Cuts in Red Sea

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s Azure cloud platform is facing significant disruptions after multiple undersea fiber optic cables were severed in the Red Sea. The US technology giant confirmed that users would experience delays and increased latency for services relying on internet traffic moving …