New HTTP/2 MadeYouReset Vulnerability Enables Large-Scale DDoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified a new denial-of-service (DoS) vulnerability in HTTP/2 implementations, referred to as MadeYouReset (CVE-2025-8671). This discovery represents a notable escalation in the threats associated with web protocols. Publicly disclosed on August 13, 2025, this flaw allows attackers …

New NFC-Driven PhantomCard Android Malware Attacking Banking Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Android malware dubbed PhantomCard has emerged from the shadows of Brazil’s cybercriminal underground, representing a significant evolution in mobile banking threats. This malicious application leverages Near Field Communication (NFC) technology to create a seamless bridge between victims’ …

Cisco Secure Firewall Vulnerability Allows Hackers to Inject Remote Shell Command Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed a critical security vulnerability in its Secure Firewall Management Center (FMC) Software that could allow unauthenticated attackers to execute arbitrary shell commands with high-level privileges remotely. The vulnerability, tracked as CVE-2025-20265 and assigned the maximum CVSS score …

Threat Actors Personalize Phishing Attacks With Advanced Tactics for Malware Delivery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly leveraging personalization tactics to enhance the effectiveness of their malware-delivery phishing campaigns, with threat actors customizing subject lines, attachment names, and embedded links to create a false sense of authenticity and urgency. This sophisticated approach represents a …

Qilin Ransomware Leads The Attack Landscape With 70+ Claimed Victims in July

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware threat landscape witnessed a concerning surge in July 2025, with the Qilin ransomware group maintaining its dominant position for the third time in four months. The group successfully claimed 73 victims on its data leak site, representing 17.3% …

New FireWood Malware Attacking Linux Systems to Execute Commands and Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of the FireWood backdoor has emerged, targeting Linux systems with enhanced evasion capabilities and streamlined command execution functionality. This latest iteration represents a significant evolution of the malware family first discovered by ESET’s research team, which …

New EncryptHub Campaign Leverages Brave Support Platform to Deliver Malicious Payloads via MMC Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cyberthreat landscape continues to evolve as malicious actors develop increasingly sophisticated attack methods, with the EncryptHub threat group emerging as a particularly concerning adversary. This emerging threat actor, also known as LARVA-208 and Water Gamayun, has been making headlines …

Threat Actors Weaponizing YouTube Video Download Site to Download Proxyware Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have escalated their proxyjacking campaigns by exploiting legitimate user behavior around YouTube video downloads, according to a recent security analysis. The attack leverages fake YouTube download sites to distribute proxyware malware, specifically targeting users seeking free video conversion services. …

New Trends in Phishing Attacks Emerges as AI Reshaping the Tool Used by Cybercriminals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape is witnessing a fundamental transformation as artificial intelligence becomes the newest weapon in cybercriminals’ arsenals, revolutionizing traditional phishing and scam operations. Unlike conventional phishing campaigns that were often riddled with grammatical errors and obvious tells, modern AI-powered …

Google Announces That Android’s pKVM Framework Achieves SESIP Level 5 Certification

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has achieved a significant milestone in mobile security with the announcement that Android’s protected KVM (pKVM) hypervisor has officially received SESIP Level 5 certification, marking it as the first software security system designed for large-scale consumer electronics deployment to …