Chinese Hackers Use Rootkit to Hide ToneShell Malware Activity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Chinese-linked threat group tied to the HoneyMyte, also known as Mustang Panda or Bronze President, is using a new kernel rootkit to hide its ToneShell backdoor. The campaign has hit government networks across Southeast and East Asia, with the …

Critical Vulnerability in SmarterMail Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SmarterTools has issued an urgent security advisory addressing a critical vulnerability in SmarterMail that could allow attackers to execute remote code on mail servers. The flaw, tracked as CVE-2025-52691, poses a severe threat to organizations using the affected versions. The …

CISA Warns of MongoDB Server Vulnerability(CVE-2025-14847) Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a critical MongoDB Server vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively exploited in cyberattacks. CVE-2025-14847 affects MongoDB Server and allows unauthenticated attackers to read uninitialized heap memory due to …

70,000+ MongoDB Servers Vulnerable to MongoBleed Exploit – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in MongoDB Server is putting tens of thousands of databases worldwide at risk. Dubbed MongoBleed and tracked as CVE-2025-14847, this high-severity flaw allows unauthenticated attackers to remotely extract sensitive data from server memory without credentials. The Shadow Server Foundation disclosed …

Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability has been discovered in XSpeeder’s SXZOS firmware, affecting tens of thousands of SD-WAN appliances, edge routers, and smart TV controllers deployed globally. The vulnerability, designated PWN-25-01, enables unauthenticated remote code execution (RCE) with root-level privileges through …

Hackers Exploit Copilot Studio’s New Connected Agents Feature to Gain Backdoor Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s newly unveiled “Connected Agents” feature in Copilot Studio, announced at Build 2025, is creating a significant security vulnerability. Attackers are already exploiting to gain unauthorized backdoor access to critical business systems. Connected Agents enables AI-to-AI integration, allowing agents to …

EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major supply chain attack targeting EmEditor, a widely used text editor software, has exposed millions of users to sophisticated infostealer malware. Between December 19 and December 22, 2025, the official EmEditor website fell victim to unauthorized modification, serving compromised …

Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese threat actors operating under the name Silver Fox are targeting Indian organizations through sophisticated phishing campaigns that impersonate legitimate income tax documents. The attack campaign uses authentic-looking Income Tax Department emails to trick users into downloading a malicious executable …

New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Spanish-speaking phishing operation targeting Microsoft Outlook users has been active since March 2025, using a sophisticated kit that shows clear indicators of AI-assisted development. The campaign, tracked through a unique signature of four mushroom emojis embedded in the string …

Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Public reports about cyberattacks often present a polished picture—threat actors working methodically through a well-planned playbook with every action perfectly executed. This perception leads many to believe that modern attackers operate with machine-like precision, seamlessly moving from one objective to …