Mazda Data Breach Exposing Employee and Partner Records Via System Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mazda Motor Corporation has officially disclosed a security incident involving unauthorized external access to an internal warehouse management system, potentially exposing 692 personal data records of employees, group company staff, and business partners. The Japanese automaker published its formal breach …

Tax-Themed Google Ads Lead to BYOVD EDR Killer in Huntress-Traced Malvertising Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every April, millions of Americans rush to file taxes before the deadline — and attackers count on it. A large-scale malvertising campaign, active since at least January 2026, has been exploiting that urgency by placing fake tax form pages through …

SEO Poisoning Campaign Impersonates 25+ Popular Apps to Deliver AsyncRAT Since October 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated SEO poisoning campaign has been quietly targeting Windows users since at least October 2025, luring them into downloading trojanized installers for more than 25 popular software applications. The operation went undetected for roughly five months before investigators uncovered …

Critical QNAP QVR Pro Vulnerability Let Remote Attackers Gain Access to the System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP QVR Pro Vulnerability QNAP has released a critical security advisory addressing a severe vulnerability in its QVR Pro surveillance software. Tracked as CVE-2026-22898, this flaw allows remote, unauthenticated attackers to gain unauthorized access to affected systems. Users relying on …

Libyan Oil Refinery Hit in Long-Running Espionage Campaign Using AsyncRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Libyan oil refinery, a telecoms organization, and a state institution fell victim to a coordinated espionage campaign between November 2025 and February 2026. The attacks delivered AsyncRAT, a publicly available remote access Trojan with a documented history of use …

MacOS Stealer MioLab Adds ClickFix Delivery, Wallet Theft and Team API Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated macOS infostealer known as MioLab — also tracked as Nova — has emerged as one of the most advanced Malware-as-a-Service (MaaS) platforms targeting Apple users. Advertised on Russian-speaking underground forums, MioLab marks a shift in the threat landscape, …

Oblivion RAT Turns Fake Play Store Updates Into a Full-Service Android Spyware Operation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered Android remote access trojan known as Oblivion RAT has emerged on cybercrime networks as a complete malware-as-a-service (MaaS) platform, turning fake Google Play Store update pages into a full-scale spyware operation. First reported by Certo Software, the …

Trivy Supply Chain Attack Expands as Compromised Docker Images Hit Docker Hub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A supply chain attack targeting Trivy, the widely used open-source vulnerability scanner, has grown well beyond its initial scope. What started as a GitHub Actions compromise has now extended to Docker Hub, where three malicious Docker image versions were silently …

Windows 11 Emergency Update to Fix ‘No Internet’ Sign-In Errors for OneDrive, Teams, and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released an out-of-band (OOB) update, KB5085516, for Windows 11 versions 25H2 and 24H2 to address a critical sign-in issue introduced by the March 2026 Patch Tuesday update. The emergency patch, released on March 21, 2026, targets a bug …

CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Craft CMS (CVE-2025-32432) has been added to the Known Exploited Vulnerabilities catalog following confirmed active exploitation in the wild. Security teams and system administrators are advised to address this issue immediately to prevent severe network compromises. …