25,000+ FortiCloud SSO-Enabled Devices Exposed to Remote Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 25,000 Fortinet devices worldwide with FortiCloud Single Sign-On (SSO) enabled, leaving them potentially exposed to remote attacks. The finding stems from enhanced device fingerprinting in a new Device Identification report, which scanned global IP addresses and flagged these systems …

Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Torrance, United States / California, December 19th, 2025, CyberNewsWire Criminal IP (criminalip.io), the AI-powered threat intelligence and attack surface monitoring platform developed by AI SPERA, is now officially integrated into Palo Alto Networks’ Cortex XSOAR. The integration embeds real-time external threat …

Apache Log4j Vulnerability Allow Attackers to Intercept Sensitive Log Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apache Logging Services has disclosed a critical security vulnerability in Log4j Core that exposes applications to potential interception of log data. The flaw resides in the Socket Appender component. It affects versions 2.0-beta9 through 2.25.2, creating a man-in-the-middle attack vector …

New Research Uncovers the Alliance Between Qilin, DragonForce and LockBit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three major ransomware groups have joined forces to create what cybersecurity experts are calling one of the most concerning developments in the criminal underground. On September 15, 2025, the ransomware group DragonForce announced the formation of an alliance between DragonForce, …

Cloud Atlas Hacker Group Exploiting Office Vulnerabilities to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cloud Atlas advanced persistent threat group has continued its sophisticated campaign targeting organizations across Eastern Europe and Central Asia during the first half of 2025, leveraging outdated Microsoft Office vulnerabilities to deliver multiple backdoor implants. This campaign reveals a …

Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iranian state-sponsored threat actors, commonly tracked as “Prince of Persia,” have resurfaced with a sophisticated cyberespionage campaign targeting global critical infrastructure and private networks. Active since the early 2000s, this group recently deployed updated malware variants to infiltrate organizational systems …

Scripted Sparrow Uses Automation to Generate and Send their Attack Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Scripted Sparrow is a newly identified Business Email Compromise (BEC) group operating across three continents. Their operations are vast, leveraging significant automation to generate and distribute attack messages on a global scale. The group primarily targets organizations by masquerading as …

Hackers Targeting HubSpot Users in Targeted Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active phishing campaign is currently targeting HubSpot users through a sophisticated combination of social engineering and infrastructure compromise. The attack leverages business email compromise tactics, paired with website hijacking, to deliver credential-stealing malware to unsuspecting marketing professionals and business …

Ransomware Attack 2025 Recap – From Critical Data Extortion to Operational Disruption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware landscape in 2025 has reached new heights, evolving from a cybersecurity issue into a strategic threat to national security and global economic stability. This year saw a 34%-50% surge in attacks compared with 2024, with 4,701 confirmed incidents …

Hackers Using PuTTY for Both Lateral Movement and Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are increasingly abusing the popular PuTTY SSH client for stealthy lateral movement and data exfiltration in compromised networks, leaving subtle forensic traces that investigators can exploit. In a recent investigation, responders pivoted to persistent Windows registry artifacts after attackers …