Palo Alto Networks User-ID Credential Agent Vulnerability Exposes password In Cleartext

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in Palo Alto Networks’ User-ID Credential Agent for Windows, identified as CVE-2025-4235, could expose a service account’s password in cleartext under certain non-standard configurations. This flaw creates a significant security risk, as it could allow an …

New Attack Technique That Enables Attackers To Exfiltrate Git Credentials In Argocd

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed attack technique enables authenticated users within the popular GitOps tool ArgoCD to exfiltrate powerful Git credentials. The method, discovered by the cybersecurity research group Future Sight, exploits Kubernetes’ internal DNS resolution to intercept credentials in transit, posing …

Malicious Chrome Extension Attacking Users to Steal Meta Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel malicious Chrome extension has been uncovered targeting digital marketers by masquerading as a productivity tool for Meta ad campaigns. Dubbed “Madgicx Plus,” this extension is distributed through a network of deceptive websites posing as legitimate AI-driven advertising platforms. …

Hackers Booked Very Little Profit with Widespread npm Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated npm supply chain attack that surfaced in late August targeted thousands of downstream projects by injecting malicious payloads into popular JavaScript libraries. Initial reports pointed to a new variant of the notorious Typosquatting technique, but further analysis revealed …

NVIDIA NVDebug Tool Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NVIDIA has released a security update for its NVDebug tool to address three high-severity vulnerabilities that could allow an attacker to escalate privileges, execute code, and tamper with data. The company is urging users to immediately install the latest version …

Senator Calls for FTC Investigation into Microsoft’s Use of Outdated RC4 Encryption and Kerberoasting Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

U.S. Senator Ron Wyden has called on the Federal Trade Commission (FTC) to investigate Microsoft for what he terms “gross cybersecurity negligence,” accusing the tech giant of knowingly shipping its Windows operating system with a dangerously outdated form of encryption …

1.5 Billion Packets Per Second DDoS Attack Detected with FastNetMon

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FastNetMon today announced that it detected a record-scale distributed denial-of-service (DDoS) attack targeting the website of a leading DDoS scrubbing vendor in Western Europe. The attack reached 1.5 billion packets per second (1.5 Gpps) — one of the largest packet-rate floods publicly disclosed. The …

DDoS Mitigation Provider targeted In 1.5 Gpps 1.5 Billion Packets per Second DDoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FastNetMon, a prominent provider of DDoS detection solutions, announced this week that it had identified and helped mitigate a record-breaking distributed denial-of-service (DDoS) attack. The assault targeted a major DDoS scrubbing vendor located in Western Europe, pushing packet-forwarding rates to …

ACSC Warns Of Sonicwall Access Control Vulnerability Actively Exploited In Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Australian Cyber Security Centre (ACSC) has issued a critical alert regarding a severe access control vulnerability in SonicWall products that is being actively exploited in attacks. The flaw, tracked as CVE-2024-40766, affects multiple generations of SonicWall firewalls and carries …

Authorities Arrested Admins Of “LockerGoga,” “MegaCortex,” And “Nefilim” Ransomware Gangs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. District Court for the Eastern District of New York has unsealed a superseding indictment against a Ukrainian national, charging him with his alleged role as an administrator in the LockerGoga, MegaCortex, and Nefilim ransomware operations. The schemes reportedly …