Chinese Hackers Exploiting WSUS Remote Code Execution Vulnerability to Deploy ShadowPad Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese-backed attackers have begun weaponizing a critical vulnerability in Microsoft Windows Server Update Services (WSUS) to distribute ShadowPad, a sophisticated backdoor malware linked to multiple state-sponsored groups. The attack chain exploits CVE-2025-59287, a remote code execution flaw that grants system-level …

Ransomware Actors Primarily Targeting Retailers This Holiday Season to Deploy Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Retailers are facing a sharp rise in targeted ransomware activity as the holiday shopping season begins. Threat groups are timing their attacks to peak sales periods, when downtime is most painful and the pressure to pay is highest. This campaign …

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT24, a sophisticated cyber espionage group linked to China’s People’s Republic, has launched a relentless three-year campaign delivering BadAudio, a highly obfuscated first-stage downloader that enables persistent network access to targeted organizations. The threat actor has demonstrated remarkable adaptability by …

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom’s internal systems as part of an ongoing exploitation campaign targeting Oracle E-Business Suite vulnerabilities. The hack uses a critical zero-day vulnerability (CVE-2025-61882) rated 9.8 on the CVSS scale, allowing attackers …

Windows 11 to Hide BSOD Crash Errors on Public Displays

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors and signage. This new mode ensures that the dreaded Blue Screen of Death (BSOD) and other disruptive error dialogs are hidden from view on non-interactive …

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to crash firewalls through denial-of-service attacks. The vulnerability was internally discovered and reported by SonicWall’s security team. The flaw, tracked as CVE-2025-40601, …

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The new system represents a significant leap in agentic AI capabilities, enabling machines to work on coding projects with minimal human intervention. GPT-5.1-Codex-Max operates differently from …

Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions against Media Land. This Russia-based bulletproof hosting company provides infrastructure to ransomware and other cybercriminals. The U.S. Federal Bureau of Investigation also coordinated the action …

Salesforce Confirms that Customers’ Data Was accessed Following the Gainsight Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Salesforce has issued a critical security alert identifying “unusual activity” involving Gainsight-published applications connected to customer environments. The CRM giant’s investigation indicates that this activity may have enabled unauthorized access to Salesforce data through the applications’ external connections. In an …

Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Clop ransomware gang has listed Oracle on its dark web leak site, alleging a successful breach of the tech giant’s internal systems. This development is part of a massive extortion campaign exploiting a critical zero-day vulnerability in Oracle …