Critical FortiGate Devices SSO Vulnerabilities Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active intrusion is targeting critical authentication bypass vulnerabilities in Fortinet’s FortiGate appliances and related products. Threat actors are exploiting CVE-2025-59718 and CVE-2025-59719 to perform unauthenticated single sign-on (SSO) logins via malicious SAML messages, granting attackers administrative access. Fortinet disclosed …

PornHub Breached by ShinyHunters Group and Premium Members’ Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious hacking collective ShinyHunters has claimed responsibility for a major data breach at Mixpanel, a popular analytics provider, exposing limited user data tied to Pornhub Premium accounts. The incident, which has only affected select Premium subscribers, has raised concerns …

ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since December 2025, a concerning trend has emerged across Japanese organizations as attackers exploit a critical vulnerability in React/Next.js applications. The vulnerability, tracked as CVE-2025-55182 and known as React2Shell, represents a remote code execution flaw attracting widespread exploitation. While initial …

New PCPcat Exploiting React2Shell Vulnerability to compromise 59,000+ Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign called PCPcat has successfully compromised more than 59,000 servers in under 48 hours through targeted exploitation of critical vulnerabilities in Next.js and React frameworks. The malware targets Next.js deployments by exploiting two critical vulnerabilities, CVE-2025-29927 and …

xHunt APT Hackers Attacking Microsoft Exchange and IIS Web Servers to Deploy Custom Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The xHunt advanced persistent threat group has firmly established itself as a sophisticated cyber-espionage actor, orchestrating targeted campaigns against organizations in Kuwait. Since its emergence in 2018, the group has focused intently on the government, shipping, and transportation sectors. Their …

Jaguar Land Rover Confirms Employee Data Stolen in August Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jaguar Land Rover (JLR), the iconic British luxury automaker, has finally disclosed that a cyberattack in August compromised sensitive data on current and former employees. This marks the company’s first public acknowledgment of the breach’s scope, following a production shutdown …

JumpCloud Remote Assist for Windows Agent Flaw Let Attackers Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The JumpCloud Remote Assist vulnerability (CVE-2025-34352) exposes Windows systems to local privilege escalation and denial-of-service attacks. Discovered by XM Cyber researcher Hillel Pinto, the flaw stems from insecure file operations in the agent’s uninstaller.​ The JumpCloud Remote Assist for Windows …

Threat Actors Advertising ‘MioLab MacOS’ Infostealer on an Underground Forum

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware threat targeting macOS users has emerged on underground cybercrime forums, with threat actors marketing a sophisticated information-stealing tool called “MioLab MacOS.” This resident infostealer comes equipped with a web-based control panel and customizable settings, making it an …

New Android Malware Frogblight Mimics as Official Government Websites to Collect SMS and Device Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android banking Trojan named Frogblight has emerged as a significant threat targeting Turkish users, employing deceptive tactics to steal banking credentials and personal data. Discovered in August 2025, this malware initially disguised itself as an application for accessing …

NVIDIA Merlin Vulnerabilities Let Attackers Execute Malicious Code and Trigger DoS Condition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security patches for the Merlin framework addressing two high-severity deserialization vulnerabilities. That could allow attackers to execute arbitrary code and launch denial-of-service attacks on affected Linux systems. NVIDIA researchers have identified two vulnerabilities in Merlin components that leverage insecure deserialization. …