GhostRedirector Hackers Compromise Windows Servers With Malicious IIS Module To Manipulate Search Results

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified hacking group, dubbed “GhostRedirector” by cybersecurity researchers, has compromised at least 65 Windows servers across the globe, deploying custom malware designed to manipulate search engine results for financial gain. According to a new report from ESET, the …

Hackers Leverage X’s Grok AI To Amplify Malicious Links Via Promoted Posts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new cyber-attack, dubbed “Grokking,” is exploiting features on the social media platform X to spread malicious links on a massive scale. Scammers are manipulating the platform’s advertising system and its generative AI, Grok, to bypass security measures and amplify …

Google Services Down For Most Of The Users In US, Turkey And Eastern Europe

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant outage of Google services, including its search engine, Gmail, and YouTube, has affected users across Turkey and several countries in Eastern Europe. The disruption, which began on Thursday morning, also impacted other popular platforms such as Google Maps, …

Microsoft Confirms UAC Bug Breaks App Install On Windows 11 And 10 Versions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially acknowledged a significant bug in recent Windows security updates that is causing application installation and repair failures across multiple versions of Windows 10, Windows 11, and Windows Server. The issue stems from a security enhancement in the …

Threat Actors Using Stealerium Malware to Attack Educational Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Educational institutions have become prime targets in the escalating battle against commodity information stealers. First emerging in 2022 as an open-source project on GitHub, Stealerium was initially released “for educational purposes” but rapidly attracted illicit interest. Adversaries adapted and enhanced …

Django Critical Vulnerability Let attackers Execute Malicious SQL Code on Web Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Django development team has issued critical security updates to address a high-severity vulnerability that could allow attackers to execute malicious SQL code on web servers using the popular framework. The flaw, identified as CVE-2025-57833, affects multiple versions of Django, …

US Offers $10M Bounty For FSB Hackers Who Exploited Cisco Vulnerability To Attack Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The United States government has announced a reward of up to $10 million for information leading to the identification or location of three Russian intelligence officers. The bounty, offered through the Department of State’s Rewards for Justice program, targets members …

Google Warns of Zero-Day Vulnerability in Sitecore Products Allowing Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in several Sitecore products could allow attackers to execute code remotely. The vulnerability, identified as CVE-2025-53690, stems from a ViewState deserialization flaw and is being actively exploited in the wild. The investigation by Mandiant revealed that …

Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past several years, a concerted campaign by Chinese state-sponsored Advanced Persistent Threat (APT) groups has exploited critical vulnerabilities in enterprise-grade routers to establish long-term footholds within global telecommunications and government networks. These actors, often identified under monikers such …

Threat Actors Attack PayPal Users in New Account Profile Set up Scam

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targeting PayPal’s massive user base has emerged, utilizing deceptive “Set up your account profile” emails to compromise user accounts through an ingenious secondary user addition scheme. The attack leverages advanced email spoofing techniques and psychological manipulation …