CrowdStrike Set to Acquire Onum in $290 Million Deal to Enhance Falcon Next-Gen SIEM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Global cybersecurity leader CrowdStrike announced its intention to acquire Onum, a pioneer in real-time telemetry pipeline management, in a deal reportedly valued at $290 million. The acquisition, unveiled Wednesday, aims to significantly enhance CrowdStrike’s Falcon Next-Gen SIEM platform, transforming it …

NX Build Tool Hacked with Malware That Checks for Claude or Gemini to Find Wallets and Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 1,400 developers discovered today that a malicious post-install script in the popular NX build kit silently created a repository named s1ngularity-repository in their GitHub accounts.  This repository contains a base64-encoded dump of sensitive data wallet files, API keys, .npmrc …

CISA Publish Hunting and Mitigation Guide to Defend Networks from Chinese State-Sponsored Actors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside the NSA, FBI, and a broad coalition of international partners, has released a comprehensive cybersecurity advisory detailing a widespread espionage campaign by People’s Republic of China (PRC) state-sponsored actors targeting critical …

TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past year, a shadowy threat actor known as TAG-144—also tracked under aliases Blind Eagle and APT-C-36—has intensified operations against South American government institutions. First observed in 2018, this group has adopted an array of commodity remote access trojans …

Kea DHCP Server Vulnerability Let Remote Attacker With a Single Crafted Packet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in the widely used ISC Kea DHCP server poses a significant security risk to network infrastructure worldwide.  The flaw, designated CVE-2025-40779, allows remote attackers to crash DHCP services with just a single maliciously crafted packet, potentially …

Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Attack Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Threat Intelligence has released a detailed report exposing a significant evolution in ransomware attacks, pioneered by the financially motivated threat actor Storm-0501. The group has shifted from traditional on-premises ransomware to a more destructive, cloud-native strategy that involves data …

CISA Warns of Citrix Netscaler 0-day RCE Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent warning regarding a critical zero-day vulnerability affecting Citrix NetScaler systems, designated as CVE-2025-7775.  This memory overflow vulnerability enables remote code execution (RCE) and has been actively exploited by malicious cyber actors, prompting immediate inclusion in …

New Malware Attack Exploiting TASPEN’s Legacy to Target Indonesian Senior Citizens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged, targeting Indonesia’s most vulnerable digital citizens through a calculated exploitation of trust in the nation’s pension fund system. The malicious operation impersonates PT Dana Tabungan dan Asuransi Pegawai Negeri (TASPEN), the state-owned pension fund …

Underground Ransomware Gang With New Tactics Against Organizations Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past year, the Underground ransomware gang has emerged as a formidable threat to organizations across diverse industries and geographies. First identified in July 2023, the group resurfaced in May 2024 with a Dedicated Leak Site (DLS), signaling a …

Microsoft Teams Issue Blocks Users From Opening Embedded Office Documents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widespread service issue is impacting Microsoft Teams users globally this Thursday, preventing many from opening embedded Microsoft Office documents within the collaboration platform. Reports began surfacing early this morning, with users expressing frustration over their inability to access essential …