Hackers Allegedly Claim Breach of Mercedes-Benz USA Legal and Customer Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as “zestix” has claimed responsibility for a significant data breach affecting Mercedes-Benz USA (MBUSA), allegedly exfiltrating 18.3 GB of sensitive legal and customer information. The threat actor posted the dataset for sale on a dark web …

CISA Warns of OpenPLC ScadaBR cross-site scripting vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has officially updated its Known Exploited Vulnerabilities (KEV) catalog to include a critical flaw in OpenPLC ScadaBR, confirming that threat actors are actively weaponizing it in the wild. The security defect, identified as …

New Albiriox Malware Attacking Android Users to Take Complete Control of their Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Android malware family dubbed “Albiriox” has emerged on the cybercrime landscape, offering advanced remote access capabilities as a Malware-as-a-Service (MaaS). Identified by researchers at Cleafy, the malware is designed to execute On-Device Fraud (ODF) by granting attackers …

Beware of Weaponized Google Meet Page uses ClickFix Technique to Deliver Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new, highly sophisticated malware campaign has been identified targeting remote workers and organizations through a fake Google Meet landing page. Hosted on the deceptive domain gogl-meet[.]com, this attack leverages the “ClickFix” social engineering technique to bypass traditional browser security …

French Football Federation Reports Data Breach – Hackers Access Club Software Admin Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The French Football Federation (FFF) has confirmed a significant cybersecurity incident resulting in the theft of personal data belonging to members and licensees. The federation revealed that cybercriminals had infiltrated the centralized administrative software used by football clubs across the …

Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The 2025 holiday season has unleashed an unprecedented wave of cyber threats, with attackers deploying industrialized infrastructure to exploit the global surge in online commerce. This year’s threat landscape is characterized by a calculated expansion of deceptive digital assets, where …

Handala Hacker Group Attacking Israeli High-Tech and Aerospace Professionals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Handala hacker group has launched a targeted campaign against Israeli high-tech and aerospace professionals, marking a concerning shift in geopolitically motivated cyber operations. The group recently published a list of individuals working in these critical sectors, accompanied by hostile …

Comcast to Pay a $1.5 Million Fine to Settle an FCC Investigation Linked to Vendor Data Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The company has agreed to pay a $1.5 million fine to settle a Federal Communications Commission investigation into a data breach that exposed personal information from over 237,000 customers. Reuters reports that the FCC announced the settlement on Monday, ending …

Poland Arrested Suspected Russian Citizen Hacking for Local Organizations Computer Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Polish authorities have arrested a Russian citizen suspected of conducting unauthorized cyberattacks against the computer networks of local organizations. The arrest marks a significant development in the country’s efforts to combat cybercrime targeting Polish and European businesses. On November 16, …

Microsoft to Block External Scripts  in Entra ID Logins to Enhance Protections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced a significant security upgrade to its Microsoft Entra ID authentication process, as part of the company’s broader Secure Future Initiative. Microsoft is updating its Content Security Policy (CSP) to block the execution of external scripts during user …