New Innovative FileFix Attack in The Wild Leverages Steganography to Deliver StealC Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberthreat campaign has emerged that represents a significant evolution in social engineering attacks, introducing the first real-world implementation of FileFix attack methodology beyond proof-of-concept demonstrations. This advanced threat leverages steganography techniques to conceal malicious payloads within seemingly innocent …

Apple Fixes 0-Day Vulnerabilities in Older version of iPhones and iPad

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has released iOS 16.7.12 and iPadOS 16.7.12 on September 15, 2025, delivering critical security updates to older-generation devices.  The patches address a zero-day flaw in the ImageIO framework that could allow an attacker to execute arbitrary code by enticing …

40,000+ Cyberattacks Targeting API Environments To Inject Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has witnessed an unprecedented surge in API-focused attacks during the first half of 2025, with threat actors launching over 40,000 documented incidents against application programming interfaces across 4,000 monitored environments. This alarming escalation represents a fundamental shift …

Microsoft OneDrive Auto-Sync Exposes Enterprise Secrets in SharePoint Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A default auto-sync feature in Microsoft OneDrive automatically moves local files to SharePoint, creating a significant security risk by exposing sensitive data and secrets on a large scale. Research from Entro Security highlights the severity of the issue, revealing that …

Google Announces Full Availability of Client-Side Encryption for Google Sheets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced the full general availability of client-side encryption (CSE) for Google Sheets. This significant upgrade gives organizations direct control over encryption keys and enhances data confidentiality within Google Workspace. This move extends robust security features to spreadsheets, ensuring …

Critical Chaos Mesh Vulnerabilities Let Attackers Takeover Kubernetes Cluster

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerabilities were identified in Chaos Mesh, a popular Cloud Native Computing Foundation chaos engineering platform used for fault injection testing in Kubernetes environments.  The security flaws, collectively dubbed “Chaotic Deputy,” comprise four CVEs that enable complete cluster compromise through …

Kubernetes C# Client Vulnerability Exposes API Server Communication To MiTM Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A medium-severity vulnerability has been discovered in the official Kubernetes C# client, which could allow an attacker to intercept and manipulate sensitive communications. The flaw, rated 6.8 on the CVSS scale, stems from improper certificate validation logic. This weakness exposes …

World’s Largest Hacking Forum BreachForums Creator Sentenced to Three Years in Prison

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Conor Brian Fitzpatrick, the 22-year-old founder of BreachForums, has been resentenced to three years in federal prison for operating one of the world’s largest cybercriminal marketplaces.  The New York resident was sentenced on September 16, 2025, for creating and administering …

How a Plaintext File On Users’ Desktops Exposed Secrets Leads to Akira Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor who gained initial access through a SonicWall VPN device was able to escalate their attack by finding Huntress recovery codes saved in a plaintext file on a user’s desktop. This allowed the attacker to log into the …

Linux Kernel’s KSMBD Subsystem Vulnerability Let Remote Attackers Exhaust Server Resources

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A denial-of-service flaw in the Linux kernel’s KSMBD (SMB Direct) subsystem has raised alarms across the open-source community.  Tracked as CVE-2025-38501, the issue allows a remote, unauthenticated adversary to exhaust all available SMB connections by exploiting the kernel’s handling of …