Surveillance Company Using SS7 Bypass Attack to Track the User’s Location Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A surveillance company has been detected exploiting a sophisticated SS7 bypass technique to track mobile phone users’ locations. The attack leverages previously unknown vulnerabilities in the TCAP (Transaction Capabilities Application Part) layer of SS7 networks to circumvent security protections implemented …

APT41 Hackers Leveraging Atexec and WmiExec Windows Modules to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Chinese-speaking cyberespionage group APT41 has expanded its operations into new territories, launching sophisticated attacks against government IT services across Africa using advanced Windows administration modules. This represents a significant geographical expansion for the group, which has previously concentrated …

Dell Data Breach – Test Lab Platform Hacked by World Leaks Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dell Technologies has confirmed a security breach of its Customer Solution Centers platform by the World Leaks extortion group, marking another high-profile attack by the newly rebranded threat actor.  The incident, which occurred earlier this month, targeted Dell’s isolated product …

CISA Warns of Microsoft SharePoint Server 0-Day RCE Vulnerability Exploited in Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent warning about a critical zero-day remote code execution vulnerability affecting Microsoft SharePoint Server on-premises installations that threat actors are actively exploiting in the wild. The vulnerability, tracked as CVE-2025-53770, poses a significant security risk to …

Lighthouse Studio RCE Vulnerability Let Attackers Gain Access to Hosting Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability has been discovered in Lighthouse Studio, one of the most widely deployed yet relatively unknown survey software platforms developed by Sawtooth Software. The flaw, designated CVE-2025-34300, affects the Perl CGI scripts that power web-based …

Livewire Vulnerability Exposes Millions of Laravel Apps to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Laravel’s Livewire framework has been discovered that could expose millions of web applications to remote code execution (RCE) attacks.  The flaw, designated as CVE-2025-54068, affects Livewire v3 versions from 3.0.0-beta.1 through 3.6.3, with a CVSS …

New KAWA4096’s Ransomware Leverages Windows Management Instrumentation to Delete Shadow Copies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new ransomware strain named KAWA4096 has emerged in the cybersecurity landscape, showcasing advanced evasion techniques and borrowing design elements from established threat actors. Named after the Japanese word for “river,” this malicious software first surfaced in June 2025 …

CoinDCX Hacked – $44.2 million Wiped off From the Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

India’s second-largest cryptocurrency exchange, CoinDCX, confirmed a sophisticated security breach on July 19, 2025, resulting in approximately $44.2 million being stolen from the platform. This incident marks another significant cyberattack on India’s crypto infrastructure, coming exactly one year after the …

HPE Warns of Aruba Hardcoded Credentials Allowing Attackers to Bypass Device Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Hewlett Packard Enterprise (HPE) Aruba Networking Instant On Access Points could allow attackers to bypass device authentication mechanisms completely.  The vulnerability, tracked as CVE-2025-37103, stems from hardcoded login credentials embedded within the devices’ software, presenting a …

Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an urgent security advisory addressing critical zero-day vulnerabilities in on-premises SharePoint Server that attackers are actively exploiting.  The vulnerabilities, assigned as CVE-2025-53770 and CVE-2025-53771, pose immediate risks to organizations running SharePoint infrastructure and require immediate remediation. Key …