WinRAR 0-Day Vulnerabilities Exploited in Wild by Hackers – Detailed Case Study

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has been significantly impacted by the discovery and active exploitation of two critical zero-day vulnerabilities in WinRAR, one of the world’s most widely used file compression utilities.  CVE-2025-6218 and CVE-2025-8088 represent sophisticated attack vectors that have enabled threat actors to …

French Retailer Auchan Cyberattack  – Thousands of Customers Personal Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Major French retail chain Auchan announced on August 21, 2025, that it suffered a significant cybersecurity incident resulting in the unauthorized access and theft of personal data from “several hundred thousand” customer loyalty accounts.  The breach represents another critical example …

X/Twitter The Most Aggressive Social Media App Collecting Users Location Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A comprehensive analysis of the top 10 social media platforms reveals that X (formerly Twitter) stands out as the most invasive collector of user location information, gathering both precise and coarse location data across all categories listed in Apple’s App …

Malicious Bing Ads deploy Weaponized PuTTY to Exploit Kerberos and Attack Active Directory services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malvertising campaign using sponsored results on Microsoft’s search platform delivered a weaponized PuTTY that established persistence, enabled hands-on keyboard control, and executed Kerberoasting to target Active Directory service accounts. According to an investigation published by LevelBlue’s MDR SOC and …

Threat Actors Adapting Android Droppers Even to Deploy Simple Malware to Stay Future-Proof

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Android droppers have evolved from niche installers for heavyweight banking Trojans into universal delivery frameworks, capable of deploying even rudimentary spyware or SMS stealers. Initially, droppers served banking malware families that required elevated Accessibility permissions to harvest credentials. These small …

Chinese UNC6384 Hackers Leverages Valid Code Signing Certificates to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A stealthy espionage campaign emerged in early 2025 targeting diplomats and government entities in Southeast Asia and beyond. At the heart of this operation lies STATICPLUGIN, a downloader meticulously disguised as a legitimate Adobe plugin update. Victims encountered a captive …

CISA Warns of Citrix RCE and Privilege Escalation Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued a critical alert regarding three newly identified vulnerabilities being actively exploited by threat actors. On August 25, 2025, CISA added these high-risk Common Vulnerabilities and Exposures (CVEs) to its Known Exploited Vulnerabilities (KEV) Catalog, signaling immediate concern …

Hackers Actively Scanning to Exploit Microsoft Remote Desktop Protocol Services From 30,000+ IPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive coordinated scanning campaign targeting Microsoft Remote Desktop Protocol (RDP) services, with threat actors deploying over 30,000 unique IP addresses to probe for vulnerabilities in Microsoft RD Web Access and RDP Web Client authentication portals.  The campaign represents one …

Hackers Sabotage Iranian Ships Using Maritime Communications Terminals in Its MySQL Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated campaign of cyber sabotage unfolded against Iran’s maritime communications infrastructure in late August 2025, cutting off dozens of vessels from vital satellite links and navigation aids. Rather than targeting each ship individually—a logistical nightmare across international waters—the attackers …

Proxyware Malware Mimic as YouTube Video Download Site Delivers Malicious Javascripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have observed a surge in deceptive sites masquerading as YouTube video download services to deliver Proxyware malware in recent weeks. Victims seeking to grab videos in MP4 format are redirected through ad pages that sporadically present a download …