HubSpot’s Jinjava Engine Vulnerability Exposes Thousands of Websites to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed flaw in HubSpot’s open-source Jinjava template engine could allow attackers to bypass sandbox restrictions and achieve remote code execution (RCE) on thousands of websites relying on versions prior to 2.8.1.  Tracked as CVE-2025-59340 and rated Critical with …

Luxury Jewelry Creator Tiffany Confirms Data breach – Hackers Stolen Users Personal Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Luxury jewelry brand Tiffany and Company has confirmed a data breach that resulted in the theft of customers’ personal information. The company is in the process of sending out notification letters to affected individuals, detailing the scope of the incident …

New Malware Loader ‘CountLoader’ Weaponized PDF File to Deliver Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security teams have observed the emergence of a sophisticated malware loader, dubbed CountLoader, which leverages weaponized PDF files to deliver ransomware payloads. First detected in late August 2025, CountLoader is linked to multiple Russian-speaking cybercriminal groups, including …

Qilin Led Ransomware Attack Claimed to Compromised 104 Organizations in August

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware threat landscape witnessed a dramatic shift in August 2025 as the Qilin group claimed responsibility for 104 separate attacks worldwide. Emerging earlier this year, Qilin quickly cemented its position through aggressive double-extortion tactics and a broad affiliate recruitment …

Global Spyware Markets to Identify New Entities Entering The Market

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The global spyware market continues its alarming expansion, with new research revealing the emergence of 130 additional entities spanning 46 countries between 1992 and 2024. This shadowy ecosystem of surveillance technologies has grown from 435 documented entities in the initial …

New Phishing Attack Targets Facebook Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has recently emerged, targeting Facebook users with carefully crafted emails designed to harvest login credentials. Attackers leverage the platform’s own external URL warning system to cloak malicious links, presenting URLs that appear legitimate while redirecting victims …

Russian Airline Suffered Cyberattack Website and Other Systems Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Krasnoyarsk Regional Airlines (KrasAvia) confirmed a sophisticated cyberattack that has rendered its primary online services inoperable.  The breach targeted the airline’s web portal and associated back-end systems, including the Passenger Service System (PSS) and flight planning applications.  As a result, …

UK Arrested 2 Scattered Spider Hackers Linked to London Transport System Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

UK law enforcement has arrested two individuals linked to the notorious Scattered Spider cybercriminal group, including 19-year-old Thalha Jubair from London, who faces charges in connection with over 120 network intrusions that resulted in more than $115 million in ransom …

Splunk Releases Guide to Detect Remote Employment Fraud Within Your Organization

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Detecting remote employment fraud has become a critical priority for organizations striving to secure their digital onboarding processes and safeguard sensitive systems. In recent months, threat actors posing as legitimate hires have leveraged sophisticated tactics to bypass pre-hire screenings and …

New iOS Video Injection Tool Bypasses Biometric Verification with Jailbroken iPhones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new attack tool targeting jailbroken iOS devices has emerged, representing a significant escalation in digital identity fraud capabilities.  The discovery by iProov’s threat intelligence team reveals a highly specialized tool designed to perform advanced video injection attacks on …