SolarWinds Releases Advisory on Salesloft Drift Security Incident

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SolarWinds has released an advisory regarding a security incident involving the Salesloft Drift integration for Salesforce, which led to unauthorized data access. The company confirmed that its own systems were not impacted by the breach, but is treating the matter …

GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cyberthreat landscape has witnessed the emergence of another sophisticated ransomware operation as GOLD SALEM, a new threat actor group also known as Warlock Group, has been actively compromising enterprise networks since March 2025. This emerging ransomware collective has successfully …

Russian Fake-News Network CopyCop Added 200+ New Websites to Targets US, Canada and France

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Russian covert influence network CopyCop has significantly expanded its disinformation campaign, establishing over 200 new fictional media websites since March 2025. This expansion represents a marked escalation in Russian information warfare efforts, targeting democratic nations with sophisticated artificial intelligence-driven …

How to Radically Cut Response Time for Each Security Incident 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

When an incident happens, there’s no time to waste.  SOC teams must react fast to protect their organization, and this requires more than expertise. Strong solutions tailored to the needs of businesses can make all the difference.  The secret to …

Cloudflare API Outage Linked to React useEffect Bug Causes Service Overload and Recovery Failure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare has published a detailed post-mortem explaining the significant outage on September 12, 2025, that made its dashboard and APIs unavailable for over an hour. The company traced the incident to a software bug in its dashboard that, combined with …

0-Click ChatGPT Agent Vulnerability Allows Sensitive Data Exfiltration from Gmail

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A zero-click vulnerability discovered in ChatGPT’s Deep Research agent allowed attackers to exfiltrate sensitive data from a user’s Gmail account without any user interaction. The flaw, which OpenAI has since patched, leveraged a sophisticated form of indirect prompt injection hidden …

Top 10 Best Model Context Protocol (MCP) Servers in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In 2025, the Model Context Protocol (MCP) revolutionizes AI agent integration, making it seamless for tools, databases, and workflows to work harmoniously in enterprises and developer workspaces. Top MCP servers power next-generation automation and data-driven applications, connecting everything from cloud …

Windows 11 Notepad to Get AI Support for Free to Generate and Summarize Text

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is integrating free, on-device artificial intelligence capabilities into the classic Notepad application for Windows 11 users with Copilot+ PCs. The update introduces powerful text generation and editing tools, including “Summarize,” “Write,” and “Rewrite,” without requiring a subscription. Windows 11 …

Hackers Injecting Malicious Code into GitHub Actions Workflows to Steal PyPI Publishing Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers injected malicious code into GitHub Actions workflows in a widespread campaign to steal Python Package Index (PyPI) publishing tokens. While some tokens stored as GitHub secrets were successfully exfiltrated, PyPI administrators have confirmed that the platform itself was not …

Critical Microsoft’s Entra ID Vulnerability Allows Attackers to Gain Complete Administrative Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Microsoft’s Entra ID could have allowed an attacker to gain complete administrative control over any tenant in Microsoft’s global cloud infrastructure. The flaw, now patched, was discovered in July 2025 and has been assigned CVE-2025-55241. The …