Hackers Allegedly Claim Leak of LG Source Code, SMTP, and Hardcoded Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as “888” has purportedly dumped sensitive data stolen from electronics giant LG Electronics, raising alarms in the cybersecurity community. The breach, first spotlighted on November 16, 2025, allegedly includes source code repositories, configuration files, SQL databases, …

Alice Blue Partners With AccuKnox For Regulatory Compliance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AccuKnox, a global leader in Zero Trust Cloud-Native Application Protection Platforms(CNAPP), today announced its partnership with Alice Blue India, a prominent brokerage andfinancial services firm, to strengthen its security and compliance frameworks across on-premand cloud workloads. The partnership was executed …

Hackers Use Rogue MCP Server to Inject Malicious Code and Control the Cursor’s Built-in Browser

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability allowing attackers to inject malicious code into Cursor’s embedded browser through compromised MCP (Model Context Protocol) servers. Unlike VS Code, Cursor lacks integrity verification on its proprietary features, making it a prime target for tampering. The attack …

SilentButDeadly – Network Communication Blocker Tool That Neutralizes EDR/AV

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new open-source tool called SilentButDeadly has emerged, designed to disrupt Endpoint Detection and Response (EDR) and antivirus (AV) software by severing their network communications. Developed by security researcher Ryan Framiñán, the tool leverages the Windows Filtering Platform (WFP) to …

Cisco Catalyst Center Vulnerability Let Attackers Escalate Priveleges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious security flaw in Cisco Catalyst Center Virtual Appliance has been discovered that allows attackers with low-level access to gain full administrator control over affected systems. The vulnerability, tracked as CVE-2025-20341, impacts virtual appliances running on VMware ESXi and …

PoC Exploit Tool Released for FortiWeb WAF Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit tool for CVE-2025-64446 has been publicly released on GitHub. This vulnerability, affecting FortiWeb devices from Fortinet, involves a critical path traversal flaw that has already been observed in real-world attacks, allowing unauthorized access to sensitive CGI …

Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe remote code execution (RCE) flaw has been uncovered in pgAdmin4, the popular open-source interface for PostgreSQL databases. Dubbed CVE-2025-12762, the vulnerability affects versions up to 9.9 and could allow attackers to run arbitrary commands on the hosting server, …

RONINGLOADER Weaponizes Signed Drivers to Disable Defender and Evade EDR Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat targeting Chinese users has appeared with a dangerous ability to shut down security tools. RONINGLOADER, a multi-stage loader spreading a modified version of the gh0st RAT, uses clever tricks to bypass antivirus protection. The malware arrives through …

Hackers are Weaponizing Invoices to Deliver XWorm That Steals Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers are using fake invoice emails to spread XWorm, a remote-access trojan that quietly steals login credentials, passwords, and sensitive files from infected computers. When a user opens the attached Visual Basic Script file, the malware begins working silently in …

First Large-scale Cyberattack Using AI Tools With Minimal Human Input

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese government-backed hackers used Anthropic’s Claude Code tool to carry out advanced spying on about thirty targets worldwide, successfully breaking into several major organizations. The first documented large-scale cyberattack executed primarily by leveraging artificial intelligence with minimal human intervention. The …