Hackers Leverage GitHub Notifications to Mimic as Y Combinator to Steal Funds from Wallets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have orchestrated a sophisticated phishing campaign exploiting GitHub’s notification system to impersonate the prestigious startup accelerator Y Combinator, targeting developers’ cryptocurrency wallets through fake funding opportunity notifications. The attack leverages GitHub’s issue tracking system to mass-distribute phishing notifications, bypassing …

New LNK Malware Uses Windows Binaries to Bypass Security Tools and Execute Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent wave of attacks leveraging malicious Windows shortcut files (.LNK) has put security teams on high alert. Emerging in late August 2025, this new LNK malware distribution exploits trusted Microsoft binaries to bypass endpoint protections and execute payloads without …

New LockBit 5.0 Ransomware Variant Attacking Windows, Linux, and ESXi Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Following a major law enforcement disruption in February 2024, the notorious LockBit ransomware group has resurfaced, marking its sixth anniversary with the release of a new version: LockBit 5.0. Trend Micro has identified and analyzed binaries for Windows, Linux, and …

ZendTo Vulnerability Let Attackers Bypass Security Controls and Access Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical path traversal flaw in ZendTo has been assigned CVE-2025-34508 researchers discovered that versions 6.15–7 and prior enable authenticated users to manipulate file paths and retrieve sensitive data from the host system.  This issue underscores the persistent risk in …

SetupHijack Tool Exploits Race Conditions and Insecure File Handling in Windows Installer Processes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SetupHijack, an open-source research utility, has emerged as a powerful method for red teaming and security research by targeting race conditions and insecure file handling within Windows installer and update mechanisms.  By polling world-writable directories such as %TEMP%, %APPDATA%, and …

COLDRIVER APT Group Uses ClickFix To Deliver a New PowerShell-Based Backdoor BAITSWITCH

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, security researchers have observed a surge in targeted attacks attributed to the COLDRIVER advanced persistent threat (APT) group. This adversary has introduced a new PowerShell-based backdoor, dubbed BAITSWITCH, which exhibits sophisticated command-and-control techniques while blending into legitimate …

Cisco IOS and XE Vulnerability Let Remote Attacker Bypass Authentication and Access Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the implementation of the TACACS+ protocol for Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication controls or access sensitive data. The flaw originates from the software’s failure to properly …

Volvo Group Discloses Data Breach After Ransomware Attack on HR Supplier

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Volvo Group North America has begun notifying employees and associates about a data breach that exposed their personal information, including names and Social Security numbers. The security incident did not originate within Volvo’s own networks but was the result of …

NVIDIA Merlin Vulnerability Allow Attacker to Achieve Remote Code Execution With Root Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in NVIDIA’s Merlin Transformers4Rec library (CVE-2025-23298) enables unauthenticated attackers to achieve remote code execution (RCE) with root privileges via unsafe deserialization in the model checkpoint loader.  The discovery underscores the persistent security risks inherent in ML/AI frameworks’ …

Numerous Applications Using Google’s Firebase Platform Leaking Highly Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Numerous mobile applications have been found to expose critical user information through misconfigured Firebase services, allowing unauthenticated attackers to access databases, storage buckets, Firestore collections, and Remote Config secrets. This widespread issue first came to light when security researcher Mike …