10 Best Data Loss Prevention Software in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Data Loss Prevention (DLP) software is a critical cybersecurity solution designed to protect sensitive data from leaving an organization’s network. In an era where data is a company’s most valuable asset, and regulatory penalties for data breaches are severe, DLP …

HeartCrypt-Packed EDR Killer Tools ‘AVKiller’ Actively Used in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity teams have confronted a rising threat from a novel “EDR killer” payload in recent months, commonly referred to as AVKiller, which has been observed disabling endpoint defenses to facilitate the deployment of ransomware. First detected in mid-2024, this tool …

Nvidia Says No Backdoors, No Kill Switches, and No Spyware in its Chips

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Nvidia Corporation has issued a strong statement asserting that its graphics processing units (GPUs) contain no backdoors, kill switches, or spyware, directly addressing growing concerns from policymakers about potential hardware-based control mechanisms.  The semiconductor giant’s declaration comes as some industry …

SocGholish Leverages Parrot and Keitaro TDS Systems to Push Fake Updates and Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware operation known as SocGholish has emerged as one of the internet’s most persistent and deceptive threats, masquerading as legitimate software updates to compromise unsuspecting users’ systems. The malware, operated by the cybercriminal group TA569, has evolved from …

HashiCorp Vault 0-Day Vulnerabilities Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers uncovered a series of critical zero-day vulnerabilities in HashiCorp Vault in early August 2025, the widely adopted secrets management solution. These flaws, spanning authentication bypasses, policy enforcement inconsistencies, and audit-log abuse, create end-to-end attack paths that culminate in …

1.2 Million Healthcare Devices and Systems Data Leaked Online – Patient Records at Risk of Exposure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 1.2 million internet-connected healthcare devices and systems with exposure that endanger patient data shown in new research by European cybersecurity company Modat. Global findings showing Top 10 Regions (most results are across Europe, the USA, and South Africa):  United States (174K+)   …

HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the HTTP/1.1 protocol threatens tens of millions of websites with potential hostile takeovers through sophisticated desynchronization attacks.  This fundamental flaw in the decades-old protocol creates extreme ambiguity about where one request ends and the next begins, …

Gemini Exploited via Prompt Injection in Google Calendar Invite to Steal Emails, and Control Smart Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack method exploits Google’s Gemini AI assistant through seemingly innocent calendar invitations and emails.  The attack, dubbed “Targeted Promptware Attacks,” demonstrates how indirect prompt injection can compromise users’ digital privacy and even control physical devices in their homes.  …

Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors successfully compromised corporate systems within just five minutes using a combination of social engineering tactics and rapid PowerShell execution.  The incident, investigated by NCC Group’s Digital Forensics and Incident Response (DFIR) team, demonstrates how cybercriminals are weaponizing trusted …

New Microsoft Exchange Server Vulnerability Enables Attackers to Gain Admin Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Microsoft Exchange Server hybrid deployments has been disclosed, allowing attackers with on-premises administrative access to escalate privileges to cloud environments without easily detectable traces. The vulnerability, tracked as CVE-2025-53786, was officially documented by Microsoft on …