CISA Warns of VMware Aria Operations Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware Aria Operations Vulnerability A critical vulnerability affecting VMware Aria Operations has been added to the Known Exploited Vulnerabilities (KEV) catalog. Broadcom recently issued a security advisory detailing a flaw …

Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT and Enables Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A supply chain attack targeting the PHP developer community has surfaced through Packagist, the official package repository for PHP and Laravel projects. Threat actor nhattuanbl published several packages that disguised a fully …

Windows 11 23H2 to 25H2 Upgrade Allegedly Breaking Internet Connectivity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows 11 23H2 to 25H2 Upgrade A persistent bug in Windows 11 in-place upgrades is reportedly wiping critical 802.1X wired authentication configurations, leaving enterprise workstations completely offline until manual intervention …

Coruna Exploit Kit With 23 Exploits Hacked Thousands of iPhones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Coruna iOS Exploit Kit Google’s Threat Intelligence Group (GTIG) has uncovered Coruna, a sophisticated iOS exploit kit containing 23 exploits across five full exploit chains that compromised thousands of iPhones …

SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A suspected India-aligned threat group known as SloppyLemming has been conducting a sustained espionage campaign against government agencies, defense organizations, nuclear oversight bodies, and critical infrastructure operators in Pakistan and …

Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor tracked as D-Shortiez has been running a persistent malvertising campaign that turns a WebKit browser behavior into a trap, forcing iOS Safari users into scam pages with …

LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor operating under the alias FulcrumSec has publicly claimed responsibility for a fresh breach of LexisNexis Legal & Professional, the legal information division of RELX Group, alleging the …

Microsoft Warns of New Phishing Attack Exploiting OAuth in Entra ID to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing Attack Exploiting OAuth A new active phishing attack that exploits OAuth’s legitimate redirection behavior, allowing it to bypass traditional email and browser defenses without stealing any tokens. According to …

Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Mirai-based botnet campaign known as Zerobot has resurfaced with renewed force, this time targeting critical flaws in Tenda AC1206 routers and the n8n workflow automation platform. The campaign, now …

Archipelo and Checkmarx Announce Partnership Connecting AppSec Detection with DevSPM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

San Francisco, CA, United States, March 3rd, 2026, CyberNewswire Archipelo and Checkmarx today announced a technical partnership focused on correlating application vulnerability findings with development-origin context within modern software delivery …