NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An urgent security update for its DGX Spark AI workstation after discovering 14 vulnerabilities in the system’s firmware that could allow attackers to execute malicious code and launch denial-of-service attacks. The most severe flaw has a CVSS score of 9.3 …

KawaiiGPT – Free WormGPT Variant Leveraging DeepSeek, Gemini, and Kimi-K2 AI Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

KawaiiGPT emerges as an accessible, open-source tool that mimics the controversial WormGPT, providing unrestricted AI assistance via jailbroken large language models. Hosted on GitHub with over 188 stars and 52 forks, it requires no API keys and installs quickly on …

North Korean Hackers Exploiting npm, GitHub, and Vercel to Deliver OtterCookie Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major security threat has emerged targeting software developers worldwide. North Korean state-sponsored threat actors, operating under the “Contagious Interview” campaign, are systematically spreading malicious packages across npm, GitHub, and Vercel infrastructure to deliver OtterCookie malware. This sophisticated multi-stage operation …

Gitlab Patches Multiple Vulnerabilities that Enable Authentication Bypass and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released critical security updates for its Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities. The patches, rolled out in versions 18.6.1, 18.5.3, and 18.4.5, fix security flaws that could allow attackers to bypass authentication, steal user credentials, …

Hackers Actively Exploiting IoT Vulnerabilities to Deploy New ShadowV2 Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

During late October 2025, a new malware campaign dubbed ShadowV2 emerged, coinciding with a global AWS disruption. This sophisticated threat actively exploits vulnerabilities in IoT devices to assemble a botnet for distributed denial-of-service (DDoS) attacks. The malware’s rapid deployment indicates …

Malicious Chrome Extension Silently Steal and Injects Hidden SOL Fees Into Solana Swaps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat has emerged in the Solana trading community. Security researchers have discovered a malicious Chrome extension named Crypto Copilot that appears to offer convenient trading features but secretly siphons cryptocurrency from users during transactions. Published on the Chrome …

Angular HTTP Client Vulnerability Exposes XSRF Token to an Attacker-Controlled Domain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the Angular framework that could allow attackers to steal sensitive user security tokens. The vulnerability, tracked as CVE-2025-66035, affects the Angular HttpClient and involves the accidental leakage of Cross-Site Request Forgery (XSRF) tokens. Angular applications …

ByteToBreach Cybercriminal Selling Sensitive Global Data from Airlines, Banks, and Governments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A cybercriminal operating under the alias ByteToBreach has emerged as a notable threat actor in the underground market, actively selling and leaking sensitive data from airlines, banks, universities, and government entities worldwide. Active since at least June 2025, this threat …

Threat Actors Leverage Fake Update Lures to Deliver SocGholish Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors continue to exploit a dangerous vulnerability in user behavior by deploying fake software updates to deliver the SocGholish malware. This malware delivery framework has evolved significantly since its discovery in 2017, transforming from a simple web-based nuisance into …

OpenAI Discloses Mixpanel Data Breach – Name, Email Address and Operating System Details Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The company has publicly revealed a security incident involving Mixpanel, a third-party analytics provider previously used to monitor activity on platform.openai.com, the frontend for its API product. The company emphasized transparency in its announcement, assuring users that the breach did not …