Web DDoS, App Exploitation Attacks Saw a Huge Surge in First Half of 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape experienced an unprecedented escalation in digital threats during the first half of 2025, with Web Distributed Denial of Service (DDoS) attacks surging by 39% compared to the second half of 2024. The second quarter alone witnessed a …

Microsoft Patch Tuesday, August 2025 Edition

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Microsoft today released updates to fix more than 100 security flaws in its Windows operating systems and other software. At least 13 of the bugs received Microsoft’s most-dire “critical” rating, meaning they could be abused by malware or malcontents to …

28,000+ Microsoft Exchange Servers Vulnerable to CVE-2025-53786 Exposed Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 28,000 unpatched Microsoft Exchange servers are exposed on the public internet and remain vulnerable to a critical security flaw designated CVE-2025-53786, according to new scanning data released on August 7, 2025, by The Shadowserver Foundation. The Cybersecurity and Infrastructure …

CastleBot Malware-as-a-Service Deploys Range of Payloads Linked to Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware framework named CastleBot has emerged as a significant threat to cybersecurity, operating as a Malware-as-a-Service (MaaS) platform that enables cybercriminals to deploy diverse malicious payloads ranging from infostealers to backdoors linked to ransomware attacks. First appearing …

New Windows-Based DarkCloud Stealer Attacking Computers to Steal Login Credentials and Financial Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of the DarkCloud information stealer has emerged in the cyberthreat landscape, targeting Windows users through carefully crafted phishing campaigns designed to harvest sensitive credentials and financial information. This fileless malware variant represents a significant evolution in …

KrebsOnSecurity in New ‘Most Wanted’ HBO Max Series

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

August 8, 2025 1 Comment A new documentary series about cybercrime airing next month on HBO Max features interviews with Yours Truly. The four-part series follows the exploits of Julius Kivimäki, a prolific Finnish hacker recently convicted of leaking tens …

Axis Camera Server Vulnerabilities Exposes Thousands of Organizations to Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security flaws in Axis Communications’ surveillance infrastructure have left over 6,500 organizations worldwide vulnerable to sophisticated cyberattacks, with potential impacts spanning government agencies, educational institutions, and Fortune 500 companies. The Swedish security camera manufacturer’s popular video surveillance products contain …

VexTrio TDS System Developing Several Malicious Apps Mimic as VPNs to Publish in Google Play and App Store

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious VexTrio traffic distribution system (TDS) has expanded its cybercriminal operations beyond traditional web-based scams to include the development and distribution of malicious mobile applications designed to masquerade as legitimate VPN services. . This sophisticated threat actor, which has …

US Confirms Shutdown of BlackSuit Ransomware That Hacked Over 450 Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

U.S. authorities have announced the successful dismantling of the BlackSuit ransomware operation, a notorious group linked to attacks on more than 450 organizations worldwide. The operation, led by Immigration and Customs Enforcement’s (ICE) Homeland Security Investigations (HSI), involved seizing servers, …

PyPI Released Advisory to Prevent ZIP Parser Confusion Attacks on Python Package Installers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security researchers have uncovered a novel attack vector targeting Python package installers through ambiguities in the ZIP archive format. By exploiting discrepancies between local file headers and the central directory, malicious actors can craft seemingly benign wheel …