Operation DreamJob Attacking Manufacturing Industries Using Job-related WhatsApp Web Message

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In August 2025, a sophisticated cyber attack targeted an Asian subsidiary of a large European manufacturing organization through a deceptive job offer scheme. The intrusion campaign, identified as Operation DreamJob, …

Chinese Hackers Exploiting WSUS Remote Code Execution Vulnerability to Deploy ShadowPad Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese-backed attackers have begun weaponizing a critical vulnerability in Microsoft Windows Server Update Services (WSUS) to distribute ShadowPad, a sophisticated backdoor malware linked to multiple state-sponsored groups. The attack chain …

Ransomware Actors Primarily Targeting Retailers This Holiday Season to Deploy Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Retailers are facing a sharp rise in targeted ransomware activity as the holiday shopping season begins. Threat groups are timing their attacks to peak sales periods, when downtime is most …

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT24, a sophisticated cyber espionage group linked to China’s People’s Republic, has launched a relentless three-year campaign delivering BadAudio, a highly obfuscated first-stage downloader that enables persistent network access to …

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom’s internal systems as part of an ongoing exploitation campaign targeting Oracle E-Business Suite vulnerabilities. The hack uses a critical zero-day …

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to crash firewalls through denial-of-service attacks. The vulnerability was internally discovered …

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The new system represents a significant leap in agentic AI capabilities, enabling machines to work on …

Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions against Media Land. This Russia-based bulletproof hosting company provides infrastructure to ransomware and other cybercriminals. …

Salesforce Confirms that Customers’ Data Was accessed Following the Gainsight Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Salesforce has issued a critical security alert identifying “unusual activity” involving Gainsight-published applications connected to customer environments. The CRM giant’s investigation indicates that this activity may have enabled unauthorized access …