New BruteForceAI Tool Automatically Detects Login Pages and Executes Smart Brute-Force Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BruteForceAI, an innovative penetration testing framework developed by Mor David, integrates large language models (LLMs) with browser automation to autonomously identify login forms and conduct sophisticated brute-force attacks. By combining AI-driven form analysis with evasion techniques and comprehensive logging, BruteForceAI …

New ZipLine Campaign Attacks Critical Manufacturing Companies to Deploy In-memory Malware MixShell

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, a sophisticated phishing operation known as the ZipLine campaign has targeted U.S.-based manufacturing firms, leveraging supply-chain criticality and legitimate-seeming business communications to deploy an advanced in-memory implant dubbed MixShell. This threat actor reverses traditional phishing workflows by …

DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A whistleblower disclosure filed today alleges that the Department of Government Efficiency (DOGE) within the Social Security Administration (SSA) covertly created a live copy of the nation’s entire Social Security dataset in an unsecured cloud environment.  Chief Data Officer Charles …

New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified ransomware strain named Cephalus has emerged as a sophisticated threat, targeting organizations through compromised Remote Desktop Protocol (RDP) connections. The malware, which takes its name from Greek mythology referencing the son of Hermes who tragically killed his …

Critical Chrome Use After Free Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an emergency security update for Chrome to address a critical use-after-free vulnerability (CVE-2025-9478) in the ANGLE graphics library that could allow attackers to execute arbitrary code on compromised systems.  The vulnerability affects Chrome versions prior to 139.0.7258.154/.155 …

Salesloft Drift Hacked to Steal OAuth Tokens and Exfiltrate from Salesforce Corporate Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated data exfiltration campaign targeting corporate Salesforce instances has exposed sensitive information from multiple organizations through compromised OAuth tokens associated with the Salesloft Drift third-party application.  The threat actor, designated as UNC6395, systematically harvested credentials and sensitive data between …

China-based Threat Actor Mustang Panda’s Tactics, Techniques, and Procedures Unveiled

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China-based threat actor Mustang Panda has emerged as one of the most sophisticated cyber espionage groups operating in the current threat landscape, with operations dating back to at least 2014. This advanced persistent threat (APT) group has systematically targeted government …

Securden Unified PAM Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a critical security flaw in Securden Unified PAM that allows attackers to completely bypass authentication mechanisms and gain unauthorized access to sensitive credentials and system functions. The vulnerability, designated as CVE-2025-53118 with a CVSS score of …

New Hook Android Banking Malware With New Advanced Capabilities and Supports 107 Remote Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of the Hook Android banking trojan has emerged with unprecedented capabilities that position it among the most advanced mobile malware families observed to date. This latest version, designated Hook Version 3, represents a significant evolution in …

How SOCs Triage Incidents in Seconds with Threat Intelligence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

When every minute counts, it’s important to have access to fresh threat intelligence at the tip of your finger. That’s what all high-performing SOC teams have in common. Learn where to get relevant threat data for free and how to …