MatrixPDF Attacks Gmail Users Bypassing Email Filters and Fetch Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, a novel malware campaign dubbed MatrixPDF has surfaced, targeting Gmail users with carefully crafted emails that slip past conventional spam and phishing filters. This campaign has been active since mid-September 2025 and leverages PDF attachments that, when …

WestJet Confirms Data Breach – Customers Personal Information Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WestJet announced a cybersecurity incident in which a sophisticated third-party actor gained unauthorized access to internal systems, exposing personal information of some customers.  The breach, discovered on June 13, 2025, has since been contained and remediated, but not before sensitive …

Patchwork APT Using PowerShell Commands to Create Scheduled Task and Downloads Final Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since mid-2025, cybersecurity researchers have tracked a resurgence of Patchwork Advanced Persistent Threat (APT) campaigns targeting government and telecommunications sectors across Asia and Eastern Europe. Initially leveraging spear-phishing emails containing malicious Office document attachments, this latest wave of activity has …

Red Hat Openshift AI Service Vulnerability Allow Attackers to Take Control of the Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Red Hat published security advisory CVE-2025-10725, detailing an Important severity flaw in the OpenShift AI Service that could enable low-privileged attackers to elevate their permissions to full cluster administrator and compromise the entire platform.  With a CVSS v3 base score …

New Battering RAM Attack Bypasses Latest Defenses on Intel and AMD Cloud Processors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Confidential computing promised to protect sensitive workloads in the public cloud. Yet a new low-cost hardware attack, Battering RAM, demonstrates that even up-to-date memory-encryption schemes on Intel and AMD processors can be defeated with a simple interposer costing under 50 dollars. Modern …

New Chinese Nexus APT Hackers Attacking Organizations to Deliver NET-STAR Malware Suite

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, security teams worldwide have observed a surge in covert operations orchestrated by a clandestine group known colloquially as the “Chinese Nexus” APT. This actor has been tailoring highly targeted campaigns against organizations in the finance, telecommunication, and …

Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged targeting job seekers through fake Google career recruitment opportunities, leveraging social engineering tactics to harvest Gmail credentials and personal information. The malicious operation exploits the trust associated with Google’s brand reputation, crafting convincing recruitment …

Microsoft Investigating Widespread Outlook.com Outage Preventing Mailbox Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is actively investigating and addressing widespread errors preventing users from accessing their mailboxes on Outlook.com. The company has been providing regular updates throughout the day, indicating that targeted infrastructure restarts are gradually restoring service. The issue, which began early …

Hackers Exploit Cellular Router’s API to Send Malicious SMS Messages With Weaponized Links

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have recently leveraged a vulnerability in the web-based management interfaces of certain cellular routers to co-opt their built-in SMS functionality for nefarious purposes. By targeting exposed APIs, attackers are able to dispatch large volumes of malicious SMS messages containing …

48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability affecting thousands of Cisco firewalls is being actively exploited by threat actors in the wild.  The vulnerability, tracked as CVE-2025-20333, poses an immediate risk to organizations worldwide with a CVSS score of 9.9, representing one of …