Hackers Leverage Multiple Ad Networks to Attack Adroid Users With Triada Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mobile security continues to face significant challenges as sophisticated malware campaigns evolve to bypass traditional defenses. The Triada Trojan, a persistent threat to Android users for nearly a decade, has resurfaced with a highly coordinated operation targeting advertising networks. This …

CISA Adds Critical React2Shell Vulnerability to KEV Catalog Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting Meta React Server Components has been added to the Known Exploited Vulnerabilities catalog, signalling widespread active exploitation by CISA. Tracked as CVE-2025-55182, this remote code execution vulnerability poses an immediate threat to organizations that rely on …

Critical Cal.com Vulnerability Let Attackers Bypass Authentication Via Fake TOTP Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe authentication bypass vulnerability has been discovered in cal.com, the popular open-source scheduling platform. Allowing attackers to gain unauthorized access to user accounts by submitting fake TOTP codes. According to GitHub, flaw tracked as CVE-2025-66489, this critical flaw affects versions …

US Accounts for 44% of Cyber Attacks; Financial Gain Targets Public Administration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The United States continues to face an unprecedented surge in cyber threats, accounting for nearly half of all documented cyber attacks globally between 2024 and 2025. Recent data from the Cyber Events Database reveals that the US experienced 646 reported …

The ‘Kitten’ Project – Hacktivist Groups Carrying Out Attacks Targeting Israel

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Kitten Project has emerged as a coordinated hacktivist platform operating at the intersection of activism and technical operations. This initiative represents a shift in how cyber-focused groups organize their campaigns, moving beyond isolated attacks toward centralized infrastructure that facilitates …

LOLPROX Exposes Hidden Exploitation Paths that Can Enable Stealthy Hypervisor Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Proxmox Virtual Environment has become a popular choice for organizations building private cloud infrastructure and virtual machine management systems. However, a new analysis reveals significant security gaps in how the hypervisor can be exploited once an attacker gains initial access …

Hackers Compromising Developers with Malicious VS Code, Cursor AI Extensions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The developer tools used by millions of programmers worldwide have become a prime target for attackers seeking to compromise entire organizations. Visual Studio Code and AI-powered IDEs like Cursor AI, when combined with their extension marketplaces, present a critical vulnerability …

Critical WatchGuard Firebox Vulnerabilities Let Attackers Bypass Integrity Checks and Inject Malicious Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security alerts have been issued for Firebox firewall devices due to serious ten vulnerabilities. The vulnerabilities in WatchGuard, disclosed on December 4, 2025, span multiple severity levels and attack vectors. With several requiring urgent patching to prevent unauthorized code …

OceanLotus Hacker Group Targeting Xinchuang IT Ecosystems to Launch Supply Chain Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OceanLotus hacker group, widely tracked as APT32, has initiated a highly targeted surveillance campaign aimed at China’s “Xinchuang” IT ecosystem. This strategic pivot focuses on compromising indigenized domestic hardware and software frameworks that were specifically designed to establish secure, …

Indonesia’s Gambling Ecosystem Exposed With Indicators of National-Level Cyber Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercrime infrastructure operating for over fourteen years has been dismantled through extensive research into Indonesia’s illegal gambling networks. Security researchers have uncovered a sprawling ecosystem spanning hundreds of thousands of domains, thousands of malicious mobile applications, and widespread …