Apache Syncope Vulnerability Let Attackers Hijack User Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical XML External Entity (XXE) vulnerability has been disclosed in the Syncope identity management console. The flaw could allow administrators to expose sensitive user data and compromise session security …

APT28 Hackers Exploiting Microsoft Office 0-Day in the Wild to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT28, the Russia-linked advanced persistent threat group, has launched a sophisticated campaign targeting Central and Eastern Europe using a zero-day vulnerability in Microsoft Office. The threat actors leveraged specially crafted …

Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous banking malware called Anatsa has been discovered spreading through the Google Play Store, reaching more than fifty thousand downloads before detection. The malicious application was cleverly hidden as …

Hikvision Wireless Access Points Vulnerability Enables Malicious Command Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authenticated command execution vulnerability has been disclosed affecting multiple Hikvision Wireless Access Point (WAP) models. The flaw, tracked as CVE-2026-0709, stems from insufficient input validation in device firmware, …

OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hundreds of malicious skills designed to deliver trojans, infostealers, and backdoors disguised as legitimate automation tools. VirusTotal has uncovered a significant malware distribution campaign targeting OpenClaw, a rapidly growing personal …

Notepad++ Hack Detailed Along With the IoCs and Custom Malware Used

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated espionage campaign attributed to the Chinese Advanced Persistent Threat (APT) group Lotus Blossom (also known as Billbug). The threat actors compromised the infrastructure hosting the popular text editor …

DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new data-wiping malware known as DynoWiper has emerged, targeting energy companies in Poland with destructive attacks designed to permanently erase critical data. The malware surfaced in December 2025 …

Russian Hacker Alliance Targeting Denmark in Large-Scale Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly formed Russian hacker alliance known as Russian Legion has launched a coordinated cyberattack campaign against Denmark, threatening critical infrastructure and government services. The alliance, which includes Cardinal, The …