London Councils’ IT Systems Impacted by CyberAttack, Including Phone Lines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three West London councils are struggling with significant disruption to IT systems and phone lines after a cyberattack on a shared services provider, which officials are publicly describing only as an “IT incident”. The Royal Borough of Kensington and Chelsea …

Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Shai Hulud 2.0 worm, first detected on November 24, 2025, has compromised nearly 1,200 organizations, including major banks, government bodies, and Fortune 500 technology firms. While initial reports described it as a simple npm supply chain attack that flooded …

Scattered Lapsus$ Hunters Registered 40+ Domains Mimicking Zendesk Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated, complex new cyber offensive has emerged from the “Scattered Lapsus$ Hunters,” a threat collective that has aggressively shifted toward exploiting supply-chain vulnerabilities. This latest campaign targets Zendesk, a critical customer support platform, effectively turning a trusted business tool …

Vulnerable Codes in Legacy Python Packages Enables Attacks on Python Package Index Via Domain Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hidden vulnerabilities in legacy code often create unseen risks for modern development environments. One such issue recently surfaced within the Python ecosystem, where outdated bootstrap scripts associated with the zc.buildout tool expose users to domain takeover attacks. These scripts, designed …

Over 390 Abandoned iCalendar Sync Domains Could Expose ~4 Million Devices to Security Risks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Digital calendars have become indispensable tools for managing personal and professional schedules. Users frequently subscribe to external calendars for public holidays, sports schedules, or community events to keep their agendas up to date. While these subscriptions offer convenience, they create …

One Identity Safeguard Named a Visionary in the 2025 Gartner Magic Quadrant for PAM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Alisa Viejo, CA, USA, November 27th, 2025, CyberNewsWire Gartner has recognized One Identity as a Visionary in the 2025 Gartner Magic Quadrant for Privileged Access Management (PAM).  In a rapidly transforming market, innovation and demonstrated performance continue to shape expectations. The …

Quttera Launches “Evidence-as-Code” API to Automate Security Compliance for SOC 2 and PCI DSS v4.0V

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New API capabilities and AI-powered Threat Encyclopedia eliminate manual audit preparation, providing real-time compliance evidence and instant threat intelligence Quttera today announced major enhancements to its Web Malware Scanner API that transform static security scanning into automated compliance evidence. The …

Shai Hulud v2 Exploits GitHub Actions Workflows as Attack Vector to Steal Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The software supply chain is under siege from “Shai Hulud v2,” a sophisticated malware campaign that has compromised 834 packages across the npm and Maven ecosystems. This new wave specifically targets GitHub Actions workflows, exploiting pull_request_target triggers to inject malicious …

Qilin RaaS Exposed 1 Million Files and 2 TB of Data Linked to Korean MSP Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The “Korean Leaks” campaign has emerged as one of the most sophisticated supply chain attacks targeting South Korea’s financial sector in recent memory. This operation combined the capabilities of the Qilin Ransomware-as-a-Service (RaaS) group with potential involvement from North Korean …

Dead Man’s Switch – Widespread npm Supply Chain Attack Driving Malware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab’s Vulnerability Research team has uncovered a large-scale supply chain attack spreading a destructive malware variant through the npm ecosystem. The malware, an evolved version of “Shai-Hulud,” contains a dangerous feature that threatens to destroy user data if attackers lose …