LummaStealer Technical Details Uncovered Using ML-Based Detection Approach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LummaStealer has emerged as one of the most prolific information-stealing malware families in recent years, targeting victims across multiple industry verticals including telecommunications, healthcare, banking, and marketing. The sophisticated malware gained widespread notoriety in early 2025 when cybercriminals extensively deployed …

17-year-old Hacker Responsible for Vegas Casinos Hack has Been Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A 17-year-old suspect who surrendered over his alleged role in the 2023 cyberattacks against two major Las Vegas casino operators was released to his parents under strict supervision.  During his initial hearing before Family Court Judge Dee Smart Butler in …

LLM-Based LAMEHUG Malware Dynamically Generate Commands for Reconnaissance and Data Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new threat has emerged in the cybersecurity landscape that represents a significant evolution in malware development. The LAMEHUG malware family, first identified by CERT-UA in July 2025, marks a concerning advancement in cyber attack methodology by integrating artificial …

GitLab High-Severity Vulnerabilities Let Attackers Crash Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has disclosed multiple high-severity Denial-of-Service (DoS) vulnerabilities that could allow unauthenticated attackers to crash self-managed GitLab instances.  These flaws impact Community Edition (CE) and Enterprise Edition (EE) versions prior to 18.4.1, 18.3.3, and 18.2.7, and exploit both HTTP endpoints …

Fortra GoAnywhere Vulnerability Exploited as 0-Day Before Patch

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical, perfect 10.0 CVSS score vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) solution was actively exploited as a zero-day at least a week before the company released a patch. The vulnerability, tracked as CVE-2025-10035, is a command injection …

New Variant of The XCSSET Malware Attacking macOS App Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The macOS threat landscape has witnessed a significant escalation with the discovery of a new variant of the XCSSET malware targeting app developers. First observed in late September 2025, this variant builds upon earlier versions by introducing enhanced stealth techniques, …

First-Ever Malicious MCP Server Found in the Wild Steals Emails via AI Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The first-ever malicious Model-Context-Prompt (MCP) server discovered in the wild, a trojanized npm package named postmark-mcp that has been secretly exfiltrating sensitive data from users’ emails. The package, downloaded approximately 1,500 times per week, contained a backdoor that copied every …

CISA Warns of Cisco Firewall 0-Day Vulnerabilities Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an Emergency Directive mandating immediate action to mitigate two critical zero-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362, actively exploited against Cisco Adaptive Security Appliances (ASA) and select Firepower platforms.  The vulnerabilities allow unauthenticated remote code execution and privilege escalation, enabling advanced threat actors …

Chinese State-Sponsored Hackers Attacking Telecommunications Infrastructure to Harvest Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In late 2024, a new wave of cyber espionage emerged targeting global telecommunications infrastructure. Operating under the moniker Salt Typhoon, this Chinese state-sponsored group has focused its efforts on routers, firewalls, VPN gateways, and lawful intercept systems within major telecom …

Hackers Compromise Active Directory to Steal NTDS.dit that Leads to Full Domain Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Active Directory (AD) remains the foundation of authentication and authorization in Windows environments. Threat actors targeting the NTDS.dit database can harvest every domain credential, unlock lateral movement, and achieve full domain compromise.  Attackers leveraged native Windows utilities to dump and exfiltrate …