New Malware Attack Leveraging Exposed Docker APIs to Maintain Persistent SSH Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware strain targeting exposed Docker APIs has emerged with enhanced infection capabilities that go beyond traditional cryptomining operations. The threat, discovered in August 2025, demonstrates evolved tactics designed to establish persistent root access while denying other attackers access …

SAP Security Patch Day September 2025 – 21 Vulnerabilities and 4 Critical One’s Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As part of its scheduled security maintenance, SAP released its September 2025 Patch Day notes, addressing a total of 21 new vulnerabilities and providing updates to four previously released security advisories. Among the newly addressed flaws are four critical vulnerabilities …

MostereRAT Attacking Windows Systems With AnyDesk/TightVNC to Enable Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a sophisticated campaign in recent weeks leveraging a novel Remote Access Trojan (RAT) dubbed MostereRAT that targets Windows systems by deploying legitimate remote access tools such as AnyDesk and TightVNC. The malware’s emergence represents a significant …

Magento and Adobe SessionReaper Vulnerability Exposes Thousands Of Online Stores to Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adobe has issued an emergency security patch for a critical vulnerability in its Magento and Adobe Commerce platforms, dubbed “SessionReaper”. The vulnerability is considered one of the most severe in Magento’s history, prompting an out-of-band update on Tuesday, September 9th, …

New APT37 Attacking Windows Machines With New Rust and Python Based Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT37, the North Korean-aligned threat actor also known as ScarCruft, Ruby Sleet, and Velvet Chollima, has expanded its arsenal with sophisticated new malware targeting Windows systems. Active since 2012, the group primarily focuses on South Korean individuals connected to the …

Chinese Salt Typhoon and UNC4841 Hackers Teamed Up to Attack Government and Corporate Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers began tracking a sophisticated campaign in the closing months of 2024, targeting both government and corporate networks across multiple continents. The threat actors behind this operation, known colloquially as Salt Typhoon and UNC4841, leveraged overlapping infrastructure and shared …

Elastic Salesloft Drift Security Incident – Hackers Accessed Email Account Contains Valid Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elastic has disclosed a security incident stemming from a third-party breach at Salesloft Drift, which resulted in unauthorized access to an internal email account containing valid credentials. While the company’s core Salesforce environment was not impacted, the incident exposed sensitive …

SpamGPT – AI-powered Attack Tool Used By Hackers For Massive Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cybercrime toolkit named SpamGPT is enabling hackers to launch massive and highly effective phishing campaigns by combining artificial intelligence with the capabilities of professional email marketing platforms. Marketed on the dark web as a “spam-as-a-service” platform, SpamGPT …

New Technique Uncovered To Exploit Linux Kernel Use-After-Free Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new technique to exploit a complex use-after-free (UAF) vulnerability in the Linux kernel successfully bypasses modern security mitigations to gain root privileges. The method targets CVE-2024-50264, a difficult-to-exploit race condition bug in the AF_VSOCK subsystem that was recognized with a Pwnie …

Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dynatrace has confirmed it was impacted by a third-party data breach originating from the Salesloft Drift application, resulting in unauthorized access to customer business contact information stored in its Salesforce CRM. The company confirmed that the incident was limited to …