LLMs Accelerating Offensive R&D, Helps to Identify and Exploit Trapped COM Objects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has witnessed a significant evolution in offensive research methodologies with the integration of Large Language Models (LLMs) into malware development workflows. Security researchers at Outflank have pioneered the use of artificial intelligence to accelerate the discovery and …

APT36 Hackers Weaponizing PDF Files to Attack Indian Railways, Oil & Government Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Pakistan-linked Advanced Persistent Threat (APT) group APT36, also known as Transparent Tribe, has significantly expanded its cyber operations beyond traditional military targets to encompass critical Indian infrastructure including railway systems, oil and gas facilities, and key government ministries. This …

11 Best Email Security Software and Solutions in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In 2025, the threat landscape is more sophisticated than ever, with attackers leveraging advanced AI to craft hyper-realistic phishing campaigns, sophisticated business email compromise (BEC) schemes, and evasive malware that bypass traditional defenses. Organizations, irrespective of size, face a relentless …

$1,000,000 for WhatsApp 0-Click RCE Exploit at Pwn2Own Ireland 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Trend Micro’s Zero Day Initiative (ZDI) announces an unprecedented $1,000,000 bounty for a zero-click remote code execution (RCE) exploit targeting WhatsApp at the upcoming Pwn2Own Ireland 2025 competition.  This record-breaking reward, co-sponsored by Meta, represents the largest single payout in …

CISA Issues ICS Advisories for Rockwell Automation Using VMware, and Güralp Seismic Monitoring Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA released two high-severity Industrial Control Systems (ICS) advisories on July 31, 2025, highlighting critical vulnerabilities in widely deployed industrial equipment that could enable remote attackers to manipulate critical infrastructure systems.  The flaws affect seismic monitoring devices and virtualized industrial …

Threat Actors Abuse Proofpoint’s and Intermedia’s Link Wrapping Features to Hide Phishing Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The latest wave of credential-phishing campaigns has revealed an unexpectedly convenient ally for threat actors: the very e-mail security suites meant to protect users. First observed in late July 2025, multiple phishing clusters began embedding malicious URLs inside the legitimate …

Microsoft Upgrades .NET Bounty Program with Rewards to Researchers Up to $40,000

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has significantly enhanced its .NET bounty program, announcing substantial updates that expand the program’s scope, streamline award structures, and provide greater incentives for cybersecurity researchers.  The enhanced program now offers rewards of up to $40,000 USD for identifying critical …

Search Engines are Indexing ChatGPT Conversations! – Here is our OSINT Research

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ChatGPT shared conversations are being indexed by major search engines, effectively turning private exchanges into publicly discoverable content accessible to millions of users worldwide. The issue first came to light through investigative reporting by Fast Company, which revealed that nearly …

Hackers Weaponizing Free Trials of EDR to Disable Existing EDR Protections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack technique was uncovered where cybercriminals exploit free trials of Endpoint Detection and Response (EDR) software to disable existing security protections on compromised systems.  This method, dubbed BYOEDR (Bring Your Own EDR), represents a concerning evolution in defense …

Unit 42 Unveils Attribution Framework to Classify Threat Actors Based on Activity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks’ Unit 42 threat research team has introduced a groundbreaking systematic approach to threat actor attribution, addressing longstanding challenges in cybersecurity intelligence analysis. The Unit 42 Attribution Framework, unveiled on July 31, 2025, transforms what has traditionally been …