Salesloft Drift Hacked to Steal OAuth Tokens and Exfiltrate from Salesforce Corporate Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated data exfiltration campaign targeting corporate Salesforce instances has exposed sensitive information from multiple organizations through compromised OAuth tokens associated with the Salesloft Drift third-party application.  The threat actor, designated as UNC6395, systematically harvested credentials and sensitive data between …

China-based Threat Actor Mustang Panda’s Tactics, Techniques, and Procedures Unveiled

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China-based threat actor Mustang Panda has emerged as one of the most sophisticated cyber espionage groups operating in the current threat landscape, with operations dating back to at least 2014. This advanced persistent threat (APT) group has systematically targeted government …

Securden Unified PAM Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a critical security flaw in Securden Unified PAM that allows attackers to completely bypass authentication mechanisms and gain unauthorized access to sensitive credentials and system functions. The vulnerability, designated as CVE-2025-53118 with a CVSS score of …

New Hook Android Banking Malware With New Advanced Capabilities and Supports 107 Remote Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of the Hook Android banking trojan has emerged with unprecedented capabilities that position it among the most advanced mobile malware families observed to date. This latest version, designated Hook Version 3, represents a significant evolution in …

How SOCs Triage Incidents in Seconds with Threat Intelligence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

When every minute counts, it’s important to have access to fresh threat intelligence at the tip of your finger. That’s what all high-performing SOC teams have in common. Learn where to get relevant threat data for free and how to …

First AI Ransomware ‘PromptLock’ Uses OpenAI gpt-oss-20b Model for Encryption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ransomware has been identified, which is believed to be the first-ever ransomware strain that leverages a local AI model to generate its malicious components. Dubbed “PromptLock” by the ESET Research team that discovered it, the malware uses OpenAI’s …

New Attack Targeting ScreenConnect Cloud Administrators to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated credential harvesting campaign has emerged targeting ScreenConnect cloud administrators with spear phishing attacks designed to steal super administrator credentials. The ongoing operation, designated MCTO3030, has maintained consistent tactics since 2022 while operating largely undetected through low-volume distribution strategies …

Citrix NetScaler ADC and Gateway 0-Day RCE Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloud Software Group has disclosed multiple high-severity vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that can lead to remote code execution (RCE) and denial of service (DoS). Exploitation of CVE-2025-7775 has been observed in …

Online PDF Editors Safe to Use? Detailed Analysis of Security Risks Associated With It

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Online PDF editors have become common tools for quick document manipulation, providing convenient alternatives to desktop software. However, their cloud-based nature brings significant security vulnerabilities that both organizations and individuals must carefully consider. Recent cybersecurity research reveals that these platforms present …

Microsoft Unveils New Tool to Migrate VMware Virtual Machines From vCenter to Hyper-V

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released a new VM Conversion extension for Windows Admin Center, designed to streamline the migration of VMware virtual machines from vCenter to Hyper-V environments.  The preview tool, announced on August 20, 2025, provides enterprises with a cost-free solution …