Cyber Attacks Against AI Infrastructure Are in The Rise With Key Vulnerabilities Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cyber-criminals have gradually shifted their focus toward the high-value infrastructure that trains, tunes and serves modern artificial-intelligence models. Over the past six months, incident-response teams have documented a new malware family, tentatively dubbed “ShadowInit,” that targets GPU clusters, model-serving gateways …

The Network-Security Compliance Checklist: 25 Controls, Mapped And Audit-Ready

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

You’re on a four-day clock. Following new SEC rules announced on July 26, 2023, U.S. public companies must disclose any cybersecurity incident they determine to be ‘material’ within four business days of that determination. For most companies, this requirement became …

New MCPoison Attack Leverages Cursor IDE MCP Validation to Execute Arbitrary System Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Cursor IDE, the rapidly growing AI-powered development environment, enables persistent remote code execution through manipulation of the Model Context Protocol (MCP) system. The vulnerability, tracked as CVE-2025-54136 and dubbed “MCPoison,” exploits a trust validation flaw that …

How Certificate Mismanagement Opens The Door For Phishing And MITM Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SSL certificates are used everywhere from websites and APIs to mobile apps, internal tools and CI/CD pipelines. While most teams know they’re important, they often don’t manage them well. Certificates are usually forgotten until something breaks. If they expire, get …

New Streamlit Vulnerability Allows Hackers to Launch Cloud Account Takeover Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Streamlit, the popular open-source framework for building data applications, enables attackers to conduct cloud account takeover attacks.  The flaw, discovered in February 2025, exploits weaknesses in Streamlit’s st.file_uploader component to bypass file type restrictions and gain …

Cloudflare Accuses Perplexity AI For Evading Firewalls and Crawling Websites by Changing User Agent

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Perplexity AI, an emerging question-answering engine powered by advanced large language models, has recently come under scrutiny for deploying stealth crawling techniques that bypass standard web defenses. Initially launched with transparent intentions, Perplexity’s crawlers would identify themselves via declared user …

APT36 Hackers Attacking Indian Government Entities to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign attributed to the Pakistan-linked APT36 group has emerged as a serious threat to Indian government infrastructure. First detected in early August 2025, this operation leverages typo-squatted domains designed to mimic official government login portals. When unsuspecting …

North Korean Hackers Weaponizing NPM Packages to Steal Cryptocurrency and Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated North Korean cryptocurrency theft campaign has resurfaced with renewed vigor, weaponizing twelve malicious NPM packages to target developers and steal digital assets. The campaign, which represents a significant escalation in supply chain attacks, exploits the trust developers place …

Cisco Hacked – Attackers Stole Profile Details of Users Registered on Cisco.com

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has confirmed it was the target of a cyberattack where a malicious actor successfully stole the basic profile information of an undisclosed number of users registered on Cisco.com. The technology giant revealed that the breach occurred after an employee …

Kimsuky APT Hackers Weaponizing LNK Files to Deploy Reflective Malware Bypassing Windows Defender

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean state-sponsored cyber-espionage group Kimsuky has unveiled a sophisticated new campaign targeting South Korean entities through malicious Windows shortcut (LNK) files, demonstrating the group’s continued evolution in stealth and precision. The campaign combines tailored social engineering with advanced malware …