Authorities Seized Thousands of Servers from Rogue Hosting Company Used to Fuel Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a major law enforcement operation conducted on November 12, 2025, the East Netherlands cybercrime team successfully dismantled a significant criminal infrastructure. Authorities seized approximately 250 physical servers located in data centers across The Hague and Zoetermeer, which collectively powered …

Remcos RAT C2 Activity Mapped Along with The Ports Used for Communications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Remcos, a commercial remote access tool distributed by Breaking-Security and marketed as administrative software, has become a serious threat in the cybersecurity landscape. Developed in the mid-2010s, this malware enables attackers to execute remote commands, steal files, capture screens, log …

Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Lazarus APT Group has unveiled a new Remote Access Trojan called ScoringMathTea, representing a significant advancement in their cyberattack capabilities. This C++ based malware was identified as part of Operation DreamJob, a campaign aligned with the North Korean government. …

W3 Total Cache Command Injection Vulnerability Exposes 1 Million WordPress Sites to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical command injection vulnerability has been discovered in the W3 Total Cache plugin, one of WordPress’s most popular caching solutions used by approximately 1 million websites. The vulnerability, tracked as CVE-2025-9501 with a CVSS severity score of 9.0 (Critical), allows unauthenticated attackers to execute …

Imunify AI-Bolit Vulnerability Let Execute Arbitrary Code and Escalate Privileges to Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious security flaw was discovered in the AI-Bolit component of Imunify products. This vulnerability allows attackers to run arbitrary code and even become root on a server. Imunify released a fix on October 23, 2025, and most servers have …

Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Everest ransomware group has claimed responsibility for a major cyber breach against Under Armour, the global sportswear giant, alleging the theft of 343 GB of internal data that could impact millions of customers and employees worldwide. The announcement, …

UNC1549 Hackers with Custom Tools Attacking Aerospace and Defense Systems to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since mid-2024, a sophisticated Iranian-backed threat group known as UNC1549 has been conducting targeted campaigns against aerospace, aviation, and defense organizations across the globe. The hackers employ an advanced dual approach, combining carefully crafted phishing campaigns with the exploitation of …

Google Reveals Public Preview of Alert Triage and Investigation Agent for Security Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced the public preview of its Alert Triage and Investigation agent, a significant advancement in artificial intelligence-driven security operations. The intelligent agent is now embedded directly within Google Security Operations, helping security teams process alerts faster and more effectively. …

CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about a severe vulnerability in Lynx+ Gateway devices that could expose sensitive information in clear text during transmission. The flaw allows attackers to catch network traffic and obtain …

Threat Actors Leveraging Compromised RDP Logins to Deploy Lynx Ransomware After Deleting Server Backups

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lynx ransomware has emerged as a significant threat to enterprise environments, with recent intrusions demonstrating sophisticated attack strategies that prioritize data exfiltration and infrastructure destruction. The malware campaign combines compromised credentials with careful planning to ensure maximum impact on target …