New Stealthy Linux Malware Combines Mirai-Derived DDoS Botnet and Fileless Cryptominer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a sophisticated Linux malware campaign that merges Mirai-derived DDoS botnet capabilities with a stealthy fileless cryptominer, representing a significant evolution in IoT and cloud-targeted threats. The …

China-Nexus Hackers Actively Exploiting React2Shell Vulnerability in The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China-nexus threat groups are racing to weaponize the new React2Shell bug, tracked as CVE-2025-55182, only hours after its public disclosure. The flaw sits in React Server Components and lets an …

PoC Exploit Released for Critical React, Next.js RCE Vulnerability (CVE-2025-55182)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit for CVE-2025-55182, a maximum-severity remote code execution (RCE) flaw in React Server Components, surfaced publicly this week, heightening alarms for developers worldwide. Dubbed “React2Shell” by some …

CISA and NSA Warns of BRICKSTORM Malware Attacking VMware ESXi and Windows Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Canadian Centre for Cyber Security (Cyber Centre) issued a joint advisory today, warning of a sophisticated …

Prompt Injection Flaw in GitHub Actions Hits Fortune 500 Firms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new class of prompt injection vulnerabilities, dubbed “PromptPwnd,” has been uncovered by cybersecurity firm Aikido Security. The flaws affect GitHub Actions and GitLab CI/CD pipelines that are integrated with …

SpyCloud Data Shows Corporate Users 3x More Likely to Be Targeted by Phishing Than by Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Austin, TX, USA, December 4th, 2025, CyberNewsWire Phishing has surged 400% year-over-year, highlighting need for real-time visibility into identity exposures. SpyCloud, the leader in identity threat protection, today released new …

New SVG Clickjacking Attack Let Attackers Create Interactive Clickjacking Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Clickjacking has long been considered a “dumb” attack in the cybersecurity world. Traditionally, it involves placing an invisible frame over a legitimate website to trick a user into clicking a …

CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerability has been added to CISA’s Known Exploited Vulnerabilities list, warning organizations about a dangerous file-upload flaw in OpenPLC ScadaBR systems. The vulnerability allows remote authenticated users to upload …

Arizona Attorney General Suses Chinese E-commerce Retailer Temu Over Data Theft Claims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Arizona Attorney General Kris Mayes has announced a lawsuit against the popular Chinese e-commerce retailer Temu, accusing the company of stealing vast amounts of customer data. The lawsuit, filed Tuesday, …