Lumma Infostealer Steal All Data Stored in Browsers and Selling Them in Underground Markets as Logs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape continues to face significant threats from sophisticated information stealers, with Lumma emerging as one of the most prevalent and dangerous malware families targeting both consumer and enterprise environments. This malicious software systematically harvests enormous volumes of sensitive …

CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiWeb vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of the SQL injection flaw in cyberattacks worldwide. The vulnerability, tracked as CVE-2025-25257, affects Fortinet’s …

Google Sued BadBox 2.0 Malware Botnet Operators That Infects 10 Million+ Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has filed a lawsuit in New York federal court against the operators of the BadBox 2.0 botnet, marking a significant escalation in the tech giant’s fight against cybercriminal networks. The malware campaign represents the largest known botnet of internet-connected …

New Wave of Crypto-Hijacking Infects 3,500+ Websites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A stealth Monero-mining campaign has quietly compromised more than 3,500 websites by embedding an innocuous-looking JavaScript file called karma.js. The operation leverages WebAssembly, Web Workers, and WebSockets to siphon CPU cycles while keeping resource usage low enough to avoid user …

Fancy Bear Hackers Attacking Governments, Military Entities With New Sophisticated Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Russian cyberespionage group Fancy Bear, also known as APT28, has intensified its operations against governments and military entities worldwide using an arsenal of sophisticated new tools and techniques. Active since 2007, this state-sponsored threat actor has established itself …

Threat Actors Exploiting Ivanti Connect Secure Vulnerabilities to Deploy Cobalt Strike Beacon

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign targeting Ivanti Connect Secure VPN devices has been actively exploiting critical vulnerabilities CVE-2025-0282 and CVE-2025-22457 since December 2024. The ongoing attacks demonstrate advanced persistent threat techniques, deploying multiple malware families including MDifyLoader, Cobalt Strike Beacon, vshell, …

Sophos Intercept X for Windows Vulnerabilities Enable Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three critical vulnerabilities in the Sophos Intercept X for Windows product family could allow local attackers to achieve arbitrary code execution with system-level privileges. Identified as CVE-2024-13972, CVE-2025-7433, and CVE-2025-7472, the flaws span registry permission misconfigurations, a weakness in the …

Ubiquiti UniFi Devices Vulnerability Allows Attackers to Inject Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability affecting multiple Ubiquiti UniFi Access devices could allow attackers to execute malicious commands remotely.  The vulnerability, tracked as CVE-2025-27212, stems from improper input validation and has been assigned a maximum CVSS v3.0 base score of 9.8, …

Threat Actors Weaponizing GitHub Accounts To Host Payloads, Tools and Amadey Malware Plug-Ins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Malware-as-a-Service operation has emerged that exploits the trusted GitHub platform to distribute malicious payloads, representing a significant evolution in cybercriminal tactics. The operation leverages fake GitHub accounts to host an arsenal of malware tools, plugins, and payloads, capitalizing …

New “Daemon Ex Plist” Vulnerability Gives Attackers Root Access on macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in macOS allows attackers to escalate privileges to root access through misconfigured daemon services.  The vulnerability, dubbed “Daemon Ex Plist,” exploits weaknesses in how macOS handles service property list (plist) files and has been found to affect …