Threat Actors Leveraging Foxit PDF Reader to Gain System Control and Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have discovered a clever way to slip malware onto job seekers’ computers by disguising malicious files as legitimate recruitment documents. A new campaign called ValleyRAT targets people actively searching for employment through email messages containing fake job offers and …

New Phishing Attack Mimic as Income Tax Department of India Delivers AsyncRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A comprehensive phishing operation began targeting Indian companies in November 2025 by impersonating the Income Tax Department of India. The campaign employed remarkably authentic government communication templates, bilingual messaging in Hindi and English, and legal references to sections of the …

PickleScan 0-Day Vulnerabilities Enable Arbitrary Code Execution via Malicious PyTorch Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical zero‑day vulnerabilities in PickleScan, a popular open‑source tool used to scan machine learning models for malicious code. PickleScan is widely used in the AI world, including by Hugging Face, to check PyTorch models saved with Python’s pickle format. Pickle is flexible …

Hackers Using Evilginx to Steal Session Cookies and Bypass Multi-Factor Authentication Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing toolkit known as Evilginx is empowering attackers to execute advanced attacker-in-the-middle (AiTM) campaigns with alarming success. These attacks are engineered to steal temporary session cookies, allowing threat actors to sidestep the critical security layer provided by multi-factor …

New ‘Sryxen’ Stealer Bypasses Chrome Encryption via Headless Browser Technique

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new information stealer called Sryxen has emerged in the underground malware market, targeting Windows systems with advanced techniques to harvest browser credentials and sensitive data. Sold as Malware-as-a-Service, this C++ based threat demonstrates how modern stealers are adapting to …

Hackers Leverage Velociraptor DFIR Tool for Stealthy C2 & Ransomware Delivery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Legitimate administrative tools are increasingly becoming the weapon of choice for sophisticated threat actors aiming to blend in with normal network activity. A recent campaign has highlighted this dangerous trend, where attackers are weaponizing Velociraptor, a widely respected Digital Forensics …

Hackers Actively Exploiting Worpress Plugin Vulnerability to Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability in the Sneeit Framework WordPress plugin has come under active exploitation by threat actors, posing an immediate risk to thousands of websites worldwide. The vulnerability, tracked as CVE-2025-6389 with a CVSS score of 9.8, …

Vim for Windows Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Vim for Windows that could allow attackers to execute malicious code on users’ computers. The vulnerability, identified as CVE-2025-66476, affects Vim versions before 9.1.1947 and has been rated high severity, with a …

Akamai Patches HTTP Request Smuggling Vulnerability in Edge Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical HTTP request smuggling vulnerability in Akamai’s edge server infrastructure has been successfully fixed. The vulnerability, identified as CVE-2025-66373, stemmed from improper processing of HTTP requests containing invalid chunk-encoded bodies, potentially exposing thousands of customers to sophisticated attacks. Understanding …

CISA Releases Five ICS Advisories Covering Vulnerabilities, and Exploits Surrounding ICS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency released five critical Industrial Control Systems advisories on December 2, 2025, addressing significant security threats across industrial environments. These advisories cover vulnerabilities and active exploits affecting systems used in manufacturing, power generation, and medical …