Hikvision Exploiter – An Automated Exploitation Toolkit Targeting Hikvision IP Cameras

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new open-source tool called HikvisionExploiter has emerged, designed to automate attacks on vulnerable Hikvision IP cameras. Released on GitHub in mid-2024 but gaining renewed attention amid 2025’s surge in …

10 Malicious npm Packages with Auto-Run Feature on Install Deploys Multi-Stage Credential Harvester

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The npm ecosystem faces a sophisticated new threat as ten malicious packages have emerged, each designed to automatically execute during installation and deploy a comprehensive credential harvesting operation. This attack …

PoC Exploit Released for BIND 9 Vulnerability that Let Attackers Forge DNS Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A public exploit code demonstrating how attackers could exploit CVE-2025-40778, a critical vulnerability in BIND 9 that enables DNS cache poisoning. The Internet Systems Consortium (ISC) initially disclosed this flaw …

Thousands of Exchange Servers in Germany Still Running with Out-of-Support Versions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Exchange servers in Germany are still running without security updates, just weeks after the official end of support for key versions. The Federal Office for Information Security (BSI) issued …

Chrome to Alert Users “Always Use Secure Connections” While Opening Public HTTP Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced a significant security initiative that will fundamentally change how Chrome handles unsecured web connections. Beginning with Chrome 154’s release in October 2026, the browser will enable the …

Windows Accessibility Flaw Allows Stealthy Persistence and Lateral Movement via Narrator DLL Hijack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A persistent vulnerability related to DLL hijacking has been identified in the Narrator accessibility tool, which has been a significant concern over time. This flaw allows malicious actors to exploit …

CISA Warns of Dassault Systèmes Vulnerabilities Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added two critical vulnerabilities affecting Dassault Systèmes DELMIA Apriso to its Known Exploited Vulnerabilities catalog, warning that threat actors are actively exploiting these security flaws in real-world attacks. …

Hackers Allegedly Claim Breach Of HSBC USA Customers’ Records Including Financial Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has claimed responsibility for breaching HSBC USA, alleging possession of a vast database containing sensitive customer personal identifiable information (PII) and financial details. The hacker posted screenshots …

Google Wear OS Message App Vulnerability Let Any Installed App To Send SMS Behalf Of User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A vulnerability in Google Messages on Wear OS devices allows any installed app to silently send SMS, MMS, or RCS messages on behalf of the user. Dubbed CVE-2025-12080, the issue …

New Beast Ransomware Actively Scans for Active SMB Port from Breached System to Spread Across Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Beast ransomware group has emerged as a significant threat in the cybersecurity landscape, evolving from the Monster ransomware strain to establish itself as a formidable Ransomware-as-a-Service operation. Officially launched …