New macOS Installer Promising Lightning-fast Data Exfiltration Advertised on Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered macOS stealer, dubbed Mac.c, has surfaced on darknet forums, offering lightning-fast data exfiltration for just $1,500 per month. Developed by the threat actor “mentalpositive,” Mac.c is advertised as a streamlined alternative to the established AMOS stealer, targeting …

PoC Exploit & Vulnerability Analysis Released for Apple 0-Day RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A detailed proof-of-concept exploit and comprehensive vulnerability analysis have been released for CVE-2025-43300, a critical zero-click remote code execution flaw affecting Apple’s image processing infrastructure.  The vulnerability, discovered in Apple’s implementation of JPEG Lossless Decompression within the RawCamera.bundle, allows attackers …

Hackers Leverage SendGrid in Recent Attack to Harvest Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated credential harvesting campaign has emerged, exploiting the trusted reputation of SendGrid to deliver phishing emails that successfully bypass traditional email security gateways. The attack leverages SendGrid’s legitimate cloud-based email service platform to create authentic-looking communications that target unsuspecting …

KorPlug Malware Unmasked – TTPs, Control Flow, IOCs Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware strain known as KorPlug has emerged as a significant threat in the cybersecurity landscape, employing advanced obfuscation techniques to evade detection and complicate analysis efforts. This malware represents a particularly concerning development due to its implementation of …

New Microsoft 365 Admin Feature Let Admins Control Link Creation Policies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is rolling out a significant new administrative control feature in mid-September 2025 that will enable IT administrators to manage organization-wide sharing permissions for user-built Copilot agents.  The feature addresses growing enterprise concerns about governance and security in AI agent …

Top 15 Best Security Incident Response Tools In 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Incident response Tools or incident management software are essential security solutions to protect businesses and enterprises from cyber attacks. Our reliance on the internet is growing, and so make a threat to businesses, despite increased investments and expertise in cyber …

Weekly Cybersecurity News Recap : Apple 0-day, Chrome, Copilot Vulnerabilities and Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

This past week was packed with high-severity disclosures and active exploitation reports across the global threat landscape. At the forefront, Apple rushed out emergency patches for yet another zero-day vulnerability affecting iOS, iPadOS, and macOS devices. The flaw, reportedly being …

New Gmail Phishing Attack Uses AI Prompt Injection to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing has always been about deceiving people. But in this campaign, the attackers weren’t only targeting users; they also attempted to manipulate AI-based defenses. This is an evolution of the Gmail phishing chain I documented last week. That campaign relied …

Hundreds of Thousands of Users Grok Chats Exposed in Google Search Results

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant data exposure has revealed hundreds of thousands of private user conversations with Elon Musk’s AI chatbot, Grok, in public search engine results. The incident, stemming from the platform’s “share” feature, has made sensitive user data freely accessible online, …

Microsoft 365 Exchange Online Outage Blocks Email on Outlook Mobile App

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is investigating a significant service incident within Exchange Online, identified as EX1137017, which is preventing some users from sending or receiving emails through the Outlook mobile application. The issue, which remains ongoing, specifically impacts customers utilizing Hybrid Modern Authentication …