Canada’s House of Commons Hit by Cyberattack Exploiting Recent Microsoft vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant cyberattack hit the Canadian House of Commons on August 9, 2025, when threat actors exploited a recently disclosed Microsoft vulnerability to gain unauthorized access to sensitive employee information. The breach underscores the growing cybersecurity challenges facing Canada’s government …

Apache Tomcat Vulnerabilities Let Attackers Trigger Dos Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Apache Tomcat’s HTTP/2 implementation has been discovered, enabling attackers to launch devastating denial-of-service (DoS) attacks against web servers.  The vulnerability, designated as CVE-2025-48989 and dubbed the “Made You Reset” attack, affects multiple versions of the …

Adobe’s August 2025 Patch Tuesday – 60 Vulnerabilities Patches Across Multiple Products

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adobe has released a comprehensive security update addressing 60 critical vulnerabilities across 13 of its flagship products as part of its August 2025 Patch Tuesday initiative. The massive security bulletin, published on August 12, 2025, represents one of the most …

How ShinyHunters Breached Google, Adidas, Louis Vuitton and More in Ongoing Salesforce Attack Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape witnessed a sophisticated and ongoing attack campaign throughout 2025 that has successfully compromised major corporations, including Google, Adidas, Louis Vuitton, and numerous other high-profile organizations. This comprehensive technical analysis reveals how the notorious cybercriminal group ShinyHunters, in …

SmartLoader Malware via Github Repository as Legitimate Projects Infection Users Computer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated malware distribution campaign utilizing GitHub repositories disguised as legitimate software projects. The SmartLoader malware has been strategically deployed across multiple repositories, capitalizing on users’ trust in the popular code-sharing platform to infiltrate systems worldwide. …

Hackers Using Dedicated Phishlet to Launch FIDO Authentication Downgrade Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new threat vector has emerged that could undermine one of the most trusted authentication methods in cybersecurity. FIDO-based passkeys, long considered the gold standard for phishing-resistant authentication, are now facing a potentially devastating attack technique that forces users …

Critical WordPress Plugin Vulnerability Exposes 70,000+ Sites to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the popular “Database for Contact Form 7, WPforms, Elementor forms” WordPress plugin, potentially exposing over 70,000 websites to remote code execution attacks.  The vulnerability, tracked as CVE-2025-7384 with a maximum CVSS score …

CISA Warns of N-able N-Central Deserialization and Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued urgent warnings regarding two critical security vulnerabilities in N-able N-Central remote monitoring and management (RMM) software that threat actors are actively exploiting.  The vulnerabilities, identified as CVE-2025-8875 and CVE-2025-8876, pose significant risks to organizations using this widely-deployed …

ShinyHunters Possibly Collaborates With Scattered Spider in Salesforce Attack Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious ShinyHunters cybercriminal group has emerged from a year-long hiatus with a sophisticated new wave of attacks targeting Salesforce platforms across major organizations, including high-profile victims like Google. This resurgence marks a significant tactical evolution for the financially motivated …

“AI-Induced Destruction” – New Attack Vector Where Helpful Tools Become Accidental Weapons

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence coding assistants, designed to boost developer productivity, are inadvertently causing massive system destruction.  Researchers report a significant spike in what they term “AI-induced destruction” incidents, where helpful AI tools become accidental weapons against the very systems they’re meant …