Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has issued a broad security alert to its 2.5 billion Gmail users, advising them to enhance their account security in the wake of a data breach involving one of the company’s third-party Salesforce systems. The incident, which occurred in …

U.S. Government Seizes Online Marketplaces Used to Sell Fraudulent Identity Documents to Cybercriminals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Attorney’s Office for the District of New Mexico announced Thursday that federal authorities have executed a court-authorized seizure of two domain names and one affiliated blog associated with VerifTools, an online marketplace peddling counterfeit driver’s licenses, passports, and …

WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack campaign has leveraged a previously unknown zero-day vulnerability in WhatsApp on Apple devices to target specific users, the company has confirmed. The vulnerability, now identified as CVE-2025-55177, was combined with a separate vulnerability in Apple’s operating systems …

Citrix Netscaler 0-day RCE Vulnerability Patched – Vulnerable Instances Reduced from 28.2K to 12.4K

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant global effort to patch a critical zero-day remote code execution (RCE) vulnerability in Citrix NetScaler devices has seen the number of exposed systems drop from approximately 28,200 to 12,400 in just one week. Data from The Shadowserver Foundation, …

NodeBB Vulnerability Let Attackers Inject Boolean-Based Blind and PostgreSQL Error-Based Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NodeBB, a popular open-source forum platform, has been found vulnerable to a critical SQL injection flaw in version 4.3.0.  The flaw, tracked as CVE-2025-50979, resides in the search-categories API endpoint, allowing unauthenticated, remote attackers to inject both boolean-based blind and …

NightSpire Ransomware Group Claims to Exploit The Vulnerabilities of Orgs to Infiltrate Their Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since its emergence in February 2025, the NightSpire ransomware group has rapidly distinguished itself through a sophisticated double-extortion strategy that combines targeted encryption with public data leaks. Initially surfacing in South Korea, the group leveraged vulnerabilities in corporate networks to …

AppSuite PDF Editor Hacked to Execute Arbitrary Commands on The Infected System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged targeting users seeking free PDF editing software, with cybercriminals distributing a malicious application masquerading as the legitimate “AppSuite PDF Editor.” The malware, packaged as a Microsoft Installer (MSI) file, has been distributed through high-ranking …

New TAOTH Campaign Exploits End-of-Support Software to Distribute Malware and Collect Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In June 2025, a previously undocumented campaign leveraging end-of-support software began surfacing in telemetry data gathered across Eastern Asia. Dubbed TAOTH, the operation exploits an abandoned Chinese input method editor (IME), Sogou Zhuyin, to deliver multiple malware families. Initial intelligence …

Hackers Weaponize PDF Along With a Malicious LNK File to Compromise Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers have begun leveraging a seemingly innocuous PDF newsletter alongside a malicious Windows shortcut (LNK) file to infiltrate enterprise environments. The attack surfaced in late August 2025, targeting South Korean academic and government institutions under the guise of a legitimate …

Cyber Attacks Targeting Education Sector Surges Following Back-to-School Season

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As students and staff returned to campuses this August, a stark rise in cyber attacks against educational institutions has been observed worldwide. From January to July 2025, organizations in the education sector endured an average of 4,356 weekly attacks, marking …