Indonesia’s Gambling Ecosystem Exposed With Indicators of National-Level Cyber Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercrime infrastructure operating for over fourteen years has been dismantled through extensive research into Indonesia’s illegal gambling networks. Security researchers have uncovered a sprawling ecosystem spanning hundreds of thousands of domains, thousands of malicious mobile applications, and widespread …

Crypto User Loses $9,000 in Seconds After Clicking Instagram Ad Promising Easy Profits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jack, a Solana enthusiast using the Phantom wallet, fell victim to a sophisticated crypto drainer scam that wiped out $9,000 from his wallet almost instantly. He informed Cybersecurity News that the incident began with an attractive Instagram advertisement touting quick …

Shanya EDR Killer Leveraged by Ransomware Groups to Clear the Way for Ransomware Infection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybercriminal landscape has recently witnessed the aggressive rise of “Shanya,” a potent packer-as-a-service and EDR killer now fueling major ransomware operations. Emerging on underground forums in late 2024 under the alias “VX Crypt,” this tool was engineered to supersede …

Pharma Firm Inotiv Confirms Data Breach Following Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A leading contract research organization specializing in pharmaceutical drug discovery and development services disclosed a significant data breach stemming from a ransomware attack that occurred in early August 2025. The Inotiv company announced the cybersecurity incident in its fiscal 2025 …

Hundreds of Porsche Cars Immobilized Following Malfunction in Installed Satellite Security System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Owners of hundreds of Porsche vehicles across Russia are facing a sudden crisis: their high-performance cars have been rendered completely undrivable due to a widespread malfunction in the German automaker’s factory-installed alarm systems. Reports from the Rolf dealership network, Russia’s …

Next.js Released a Scanner to Detect and Update Apps Impacted by React2Shell Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dedicated command-line tool, fix-react2shell-next, to help developers immediately detect and patch the critical “React2Shell” vulnerability (CVE-2025-66478). This new scanner offers a one-line solution to identify vulnerable versions of Next.js and React Server Components (RSC). Automatically apply the required security updates …

Critical Vulnerabilities in GitHub Copilot, Gemini CLI, Claude, and Other Tools Impact Millions of Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The software development landscape has been fundamentally altered by AI-driven integrated development environments (IDEs). Tools like GitHub Copilot, Gemini CLI, and Claude Code have evolved from simple autocompletion engines into autonomous agents capable of executing tasks. However, this rapid pursuit …

Predator Spyware Compamy Used 15 Zero-Days Since 2021 to Target iOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A commercial spyware company called Intellexa has exploited 15 zero-day vulnerabilities since 2021 to target iOS and Android users worldwide. The company, known for developing the Predator spyware, continues operations despite being sanctioned by the US government. The threats remain …

Critical React2Shell RCE Vulnerability Exploited in the Wild to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability, tracked as CVE-2025-55182 and dubbed “React2Shell,” is now under active exploitation in the wild. GreyNoise researchers have detected opportunistic, largely automated exploitation attempts targeting the unsafe deserialization flaw in the React Server Components Flight …

Malicious Go Packages Mimic as Google’s UUID Library to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a long-running supply chain attack targeting the Go programming community. The Socket Threat Research Team recently identified two malicious packages. github.com/bpoorman/uuid and github.com/bpoorman/uid. That has been silently stealing data from unsuspecting developers for years. The attack relies on …