BIND 9 Vulnerabilities Expose Organizations to Cache Poisoning and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical vulnerabilities in the BIND 9 DNS resolver software are affecting organizations worldwide, with potential cache poisoning and denial-of-service attacks.  The vulnerabilities, identified as CVE-2025-40776 and CVE-2025-40777, pose significant security risks to DNS infrastructure, particularly for resolvers configured with …

Microsoft Entra ID Vulnerability Let Attackers Escalate Privileges to Global Admin Role

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Microsoft Entra ID allows attackers to escalate privileges to the Global Administrator role through the exploitation of first-party applications.  The vulnerability, reported to Microsoft Security Response Center (MSRC) in January 2025, affects organizations using hybrid Active …

Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

July 17, 2025 0 Comments Security researchers recently revealed that the personal information of millions of people who applied for jobs at McDonald’s was exposed after they guessed the password (“123456”) for the fast food chain’s account at Paradox.ai, a …

Ukraine Hackers Claimed Cyberattack on Major Russian Drone Supplier

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Last week, Ukraine’s Main Intelligence Directorate (GUR) orchestrated a sophisticated cyberattack against Gaskar Integration, a leading Russian drone manufacturer. The operation began with reconnaissance of the company’s public-facing infrastructure, where threat actors identified vulnerable remote desktop services and outdated VPN …

Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Chinese state-sponsored cyber espionage campaign has emerged targeting Taiwan’s critical semiconductor industry, employing weaponized Cobalt Strike beacons and advanced social engineering tactics. Between March and June 2025, multiple threat actors launched coordinated attacks against semiconductor manufacturing, design, and …

Researchers Uncover on How Hacktivist Groups Gaining Attention and Selecting Targets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The global hacktivist landscape has undergone a dramatic transformation since 2022, evolving from primarily ideologically motivated actors into a complex ecosystem where attention-seeking behavior and monetization strategies drive operational decisions. This shift has fundamentally altered how these groups select targets …

H2Miner Attacking Linux, Windows, and Containers to Mine Monero

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The H2Miner botnet, first observed in late 2019, has resurfaced with an expanded arsenal that blurs the line between cryptojacking and ransomware. The latest campaign leverages inexpensive virtual private servers (VPS) and a grab-bag of commodity malware to compromise Linux …

Hackers Exploiting DNS Blind Spots to Hide and Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new attack vector where malicious actors are hiding malware inside DNS records, exploiting a critical blind spot in most organizations’ security infrastructure. This technique transforms the Internet’s Domain Name System into an unconventional file storage system, allowing attackers …

4M+ Internet-Exposed Systems at Risk From Tunneling Protocol Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered critical security vulnerabilities affecting millions of computer servers and routers worldwide, stemming from the insecure implementation of fundamental internet tunneling protocols. The flaws could allow attackers to bypass security controls, spoof their identity, access private networks, and …

Massistant Chinese Mobile Forensic Tooling Gain Access to SMS Messages, Images, Audio and GPS Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Emerging in mid-2023 as an apparent successor to Meiya Pico’s notorious MFSocket, the newly identified Android application Massistant has begun surfacing on confiscated handsets at Chinese border checkpoints and police stations. Unlike conventional spyware that relies on covert remote delivery, …