Mozilla Warns of Phishing Attacks Targeting Add-on Developers Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mozilla has issued an urgent security alert to its developer community following the detection of a sophisticated phishing campaign specifically targeting AMO (addons.mozilla.org) accounts. The company’s security team, led by Scott DeVaney, reported on August 1, 2025, that cybercriminals are …

FUJIFILM Printers Vulnerability Let Attackers Trigger DoS Condition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability affecting multiple FUJIFILM printer models could allow attackers to trigger denial-of-service (DoS) conditions through malicious network packets.  The vulnerability, tracked as CVE-2025-48499, was announced on August 4, 2025, and affects various DocuPrint and Apoes printer series. …

Researchers Exploited Google kernelCTF Instances And Debian 12 With A 0-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers exploited CVE-2025-38001—a previously unknown Use-After-Free (UAF) vulnerability in the Linux HFSC queuing discipline—to compromise all Google kernelCTF instances (LTS, COS, and mitigation) as well as fully patched Debian 12 systems.  Their work netted an estimated $82,000 in cumulative bounties …

New Malware Attack Weaponizing LNK Files to Install The REMCOS Backdoor on Windows Machines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, cybersecurity teams have observed a surge in malicious campaigns exploiting Windows shortcut (LNK) files to deliver sophisticated backdoors. This new wave of attacks disguises LNK shortcuts as innocuous documents or folders, relying on Windows’ default behavior of …

Threat Actors Exploitation Attempts Spikes as an Early Indicator of New Cyber Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a groundbreaking pattern that could revolutionize how organizations prepare for emerging threats. A comprehensive analysis reveals that spikes in malicious attacker activity against enterprise edge technologies serve as reliable early warning signals for new vulnerability disclosures, …

Hackers Use AI to Create Malicious NPM Package that Drains Your Crypto Wallet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have escalated their attack sophistication by leveraging artificial intelligence to create a malicious NPM package that masquerades as a legitimate development tool while secretly draining cryptocurrency wallets. The package, named @kodane/patch-manager, presents itself as an “NPM Registry Cache Manager” …

Critical Squid Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Squid Web Proxy Cache that enables attackers to execute remote code through a heap buffer overflow in URN (Uniform Resource Name) handling.  The vulnerability, tracked as CVE-2025-54574, affects all Squid versions prior …

LARGEST EVER Bitcoin Hack Valued $3.5 Billion Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The largest cryptocurrency hack ever recorded involved the theft of 127,426 BTC from Chinese mining pool LuBian in December 2020.  The stolen Bitcoin was worth approximately $3.5 billion at the time of the theft and has since appreciated to an …

Hackers Can Manipulate BitLocker Registry Keys Via WMI to Execute Malicious Code as Interactive User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel lateral movement technique that exploits BitLocker’s Component Object Model (COM) functionality to execute malicious code on target systems. The technique, demonstrated through the BitLockMove proof-of-concept tool, represents a sophisticated evolution in lateral movement tactics that bypasses traditional detection …

Critical HashiCorp Vulnerability Let Attackers Execute Arbitrary Code on Underlying Host

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical HashiCorp security vulnerability affecting Vault Community Edition and Enterprise versions could allow privileged operators to execute arbitrary code on underlying host systems.  The vulnerability, tracked as CVE-2025-6000, affects Vault versions from 0.8.0 up to 1.20.0 and has been …