Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code Execution (RCE) with root privileges. The release follows reports of …

Fired Techie Admits Hacking Employer’s Network in Retaliation for Termination

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A former IT contractor from Ohio has admitted to launching a cyberattack against his employer’s network in retaliation for being terminated, federal prosecutors announced this week. Maxwell Schultz, 35, of Columbus, Ohio, pleaded guilty to computer fraud charges after leading …

CrowdStrike Fires Insider for Sharing Internal System Details with Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity giant CrowdStrike has confirmed the termination of an insider who allegedly provided sensitive internal system details to a notorious hacking collective. The incident, which came to light late Thursday and Friday morning, involved the leak of internal screenshots on …

Phishing Breaks More Defenses Than Ever. Here’s the Fix 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

If your tools say a link is clean, do you fully trust it?  Most SOC leaders don’t anymore, and for good reason. Phishing has become polished, quiet, and built to blend into everyday traffic. It slips through filters, lands in inboxes unnoticed, …

AI-Based Obfuscated Malicious Apps Evading AV Detection to Deploy Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of malicious Android applications impersonating a well-known Korean delivery service has emerged, featuring advanced obfuscation techniques powered by artificial intelligence. These apps work to bypass traditional antivirus detection methods while extracting sensitive user information. The threat actors …

Xillen Stealer With New Advanced Features Evade AI Detection and Steal Sensitive Data from Password Managers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Xillen Stealer, a sophisticated Python-based information stealer, has emerged as a significant threat in the cybercriminal landscape. Originally identified by Cyfirma in September 2025, this cross-platform malware has recently evolved into versions 4 and 5, introducing a dangerous arsenal of …

Dark Web Job Market Evolved – Prioritizes Practical Skills Over Formal Education

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The dark web has transformed into a functioning parallel labor market where cyber specialists find employment through unconventional channels. Unlike traditional job boards, this shadow economy operates with distinct recruitment norms and salary expectations that differ significantly from legitimate hiring …

North Korean Kimsuky and Lazarus Join Forces to Exploit Zero-Day Vulnerabilities Targeting Critical Sectors Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two of North Korea’s most dangerous hacking groups have joined forces to launch a coordinated attack campaign that threatens organizations worldwide. The Kimsuky and Lazarus groups are working together to steal sensitive intelligence and cryptocurrencies through a systematic approach that …

Hackers Using New Matrix Push C2 to Deliver Malware and Phishing Attacks via Web Browser

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new command-and-control platform called Matrix Push C2 has emerged as a serious threat to web users across all operating systems. This browser-based attack framework turns legitimate web browser features into a weapon for delivering malware and phishing attacks. Unlike …

Operation DreamJob Attacking Manufacturing Industries Using Job-related WhatsApp Web Message

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In August 2025, a sophisticated cyber attack targeted an Asian subsidiary of a large European manufacturing organization through a deceptive job offer scheme. The intrusion campaign, identified as Operation DreamJob, demonstrates how threat actors continue to refine social engineering techniques …