APT Hackers Attacking Maritime and Shipping Industry to Launch Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The maritime industry, which facilitates approximately 90% of global trade, has emerged as a critical battleground for advanced persistent threat (APT) groups deploying sophisticated ransomware campaigns. This surge in cyber warfare represents a paradigm shift where state-sponsored hackers and financially …

Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant zero-day vulnerability in CrushFTP has been disclosed, allowing unauthenticated attackers to achieve complete remote code execution on vulnerable servers.  The flaw, tracked as CVE-2025-54309 and scoring a critical 9.8 on the CVSS scale, stems from a fundamental breakdown …

OAuth2-Proxy Vulnerability Enables Authentication Bypass by Manipulating Query Parameters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in OAuth2-Proxy, a widely-used reverse proxy that provides authentication services for Google, Azure, OpenID Connect, and numerous other identity providers.  The vulnerability, designated as CVE-2025-54576, enables attackers to bypass authentication mechanisms by manipulating …

Gunra Ransomware New Linux Variant Runs Up To 100 Encryption Threads With New Partial Encryption Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Linux variant of Gunra ransomware has emerged, marking a significant escalation in the threat group’s cross-platform capabilities since its initial discovery in April 2025. The ransomware, which drew inspiration from the notorious Conti ransomware techniques, has rapidly …

Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have once again demonstrated their evolving sophistication by weaponizing an obscure Toshiba laptop driver to bypass endpoint detection and response systems. The Qilin ransomware operation, active since July 2022, has incorporated a previously unknown vulnerable driver called TPwSav.sys into …

ChatGPT, Gemini, GenAI Tools Vulnerable to Man-in-the-Prompt Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting popular AI tools, including ChatGPT, Google Gemini, and other generative AI platforms, exposes them to a novel attack vector dubbed “Man-in-the-Prompt.”  The research reveals that malicious browser extensions can exploit the Document Object Model (DOM) to …

New JSCEAL Attack Targeting Crypto App Users To Steal Credentials and Wallets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign targeting cryptocurrency application users has emerged, leveraging compiled JavaScript files and Node.js to steal digital wallets and credentials with unprecedented stealth. The campaign, dubbed JSCEAL, represents a significant evolution in cybercriminal tactics, utilizing advanced evasion …

Free Decryptor Released for AI-Assisted FunkSec Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have successfully developed and released a free decryption tool for the FunkSec ransomware, a malicious strain that leveraged artificial intelligence capabilities to enhance its operations. The ransomware campaign, which targeted 113 victims between December 2024 and March 2025, …

CISA and FBI Shared Tactics, Techniques, and Procedures of Scattered Spider Hacker Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have released an updated joint cybersecurity advisory detailing the sophisticated tactics employed by the Scattered Spider cybercriminal group, also known as UNC3944, Oktapus, and Storm-0875. This threat …

AI Vibe Coding Platform Hacked – Logic Flaw Exposes Private App Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe authentication bypass vulnerability in Base44, a popular AI-powered vibe coding platform recently acquired by Wix, could have allowed attackers unauthorized access to private enterprise applications and sensitive corporate data. The vulnerability, which was patched within 24 hours of …