Heathrow and Other European Airports Hit by Cyberattack, Several Flights Delayed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major cyberattack on a popular aviation software provider has caused significant disruptions at key European airports, including London’s Heathrow, Brussels, and Berlin, resulting in hundreds of flight delays and cancellations on Saturday. The attack disabled electronic check-in and baggage …

First-ever AI-powered ‘MalTerminal’ Malware Uses OpenAI GPT-4 to Generate Ransomware Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI-powered malware, known as ‘MalTerminal’, uses OpenAI’s GPT-4 model to dynamically generate malicious code, including ransomware and reverse shells, marking a significant shift in how threats are developed and deployed. This discovery follows the recent analysis of PromptLock, another AI-driven …

Top Zero-Day Vulnerabilities Exploited in the Wild in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape in 2025 has been marked by an unprecedented surge in zero-day vulnerabilities actively exploited by threat actors. According to recent data, more than 23,600 vulnerabilities were published in the first half of 2025 alone, representing a 16% …

Threat Actors Selling New Undetectable RAT as ’ScreenConnect FUD Alternative’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has been observed advertising a new Remote Access Trojan (RAT) on underground forums, marketing it as a fully undetectable (FUD) alternative to the legitimate remote access tool, ScreenConnect. The malware is being sold with a suite of …

BreachLock Named Sample Vendor for PTaaS and AEV in Two New 2025 Gartner® Reports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, New York, September 19th, 2025, CyberNewsWire BreachLock, the global leader in offensive security, has been recognized as a Sample Vendor for Penetration Testing as a Service (PTaaS) in the 2025 Gartner Hype Cycle for Application Security. The company …

Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing campaigns have long relied on social engineering to dupe unsuspecting users, but recent developments have elevated these attacks to a new level of sophistication. Attackers now harness advanced content-generation platforms to craft highly personalized emails and webpages, blending genuine …

Top 10 Best API Security Testing Tools in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In today’s rapidly evolving digital landscape, APIs (Application Programming Interfaces) have become the backbone of online business, connecting services, and enabling new customer experiences. However, as the API footprint grows, so does the attack surface making robust API security testing …

Nokia CBIS/NCS Manager API Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability has emerged in Nokia’s CloudBand Infrastructure Software (CBIS) and Nokia Container Service (NCS) Manager API, designated as CVE-2023-49564. This high-severity flaw, scoring 9.6 on the CVSS v3.1 scale, enables unauthorized attackers to circumvent authentication mechanisms …

Russian Hacking Groups Gamaredon and Turla Attacking Organizations to Deploy Kazuar Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In early 2025, cybersecurity researchers observed an unprecedented collaboration between two Russian APT groups targeting Ukrainian organizations. Historically, Gamaredon has focused on broad spear-phishing campaigns against government and critical infrastructure, while Turla has specialized in high-value cyberespionage using sophisticated implants. …

CISA Warns of Hackers Exploiting Ivanti Endpoint Manager Mobile Vulnerabilities to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding sophisticated malware campaigns targeting Ivanti Endpoint Manager Mobile (EPMM) systems. Cybercriminals are actively exploiting two critical vulnerabilities, CVE-2025-4427 and CVE-2025-4428, to deploy advanced persistent threats that enable …