BlindEagle Hackers Attacking Government Agencies with Powershell Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BlindEagle, a South American threat group, has launched a sophisticated campaign against Colombian government agencies, demonstrating an alarming evolution in attack techniques. In early September 2025, the group targeted a …

Sleeping Bouncer Vulnerability Impacts Motherboards from Gigabyte, MSI, ASRock and ASUS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has emerged affecting motherboards from Gigabyte, MSI, ASRock, and ASUS. Riot Games analysts and researchers identified a critical flaw during their ongoing investigation into gaming system …

Docker Open Sources Production-Ready Hardened Images for Free

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Docker has announced a significant shift in its container security strategy, making its Docker Hardened Images (DHI) freely available to all developers. Previously a commercial-only offering, DHI provides a set of secure, …

Arcane Werewolf Hacker Group Added Loki 2.1 Malware Toolkit to their Arsenal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The threat actor group known as Arcane Werewolf, also tracked as Mythic Likho, has refreshed its attack capabilities by deploying a new version of its custom malware called Loki 2.1. …

Lies-in-the-Loop Attack Turns AI Safety Dialogs into Remote Code Execution Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered attack technique has exposed a critical weakness in artificial intelligence code assistants by weaponizing their built-in safety features. The attack, known as Lies-in-the-Loop, manipulates the trust users …

Multiple Exim Server Vulnerabilities Let Attackers Seize Control of the Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at the National Institute of Standards and Technology (NIST) have uncovered critical security flaws in the Exim mail server. That could allow remote attackers to take complete control …

Hackers Using Phishing Tools to Access M365 Accounts via OAuth Device Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are now targeting Microsoft 365 accounts using a growing attack method known as OAuth device code phishing. This technique takes advantage of the OAuth 2.0 device authorization flow, …

DIG AI – Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and ominous player has emerged in the rapidly expanding landscape of “Shadow AI.” Researchers at Resecurity have identified DIG AI, an uncensored artificial intelligence tool hosted on the …

Cybersecurity Weekly Recap – PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a week that revealed the flaws in digital trust, cybersecurity headlines were filled with high-profile breaches, zero-day exploits, and bold nation-state espionage. Attackers claimed to have swiped usernames, emails, …

100+ Cisco Secure Email Devices Exposed to Zero‑Day Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified at least 120 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices vulnerable to a critical zero-day flaw that attackers are actively exploiting …