New Cyberattack Leverages NPM Ecosystem to Infect Developers While Installing Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated phishing campaign that weaponizes the NPM ecosystem through an unprecedented attack vector. Unlike traditional malicious package installations, this operation leverages the trusted unpkg.com CDN …

Hackers Leverage Judicial Notifications to Deploy Info-Stealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have developed a sophisticated phishing campaign targeting Colombian users through fake judicial notifications, deploying a complex multi-stage malware delivery system that culminates in AsyncRAT infection. The campaign demonstrates an …

FortiPAM and FortiSwitch Manager Vulnerability Let Attackers Bypass Authentication Process

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has issued an urgent advisory revealing a critical weakness in its FortiPAM and FortiSwitch Manager products that could allow attackers to sidestep authentication entirely through brute-force methods. Tracked as …

FortiOS CLI Command Bypass Vulnerability Let Attacker Execute System Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet disclosed a high-severity vulnerability in its FortiOS operating system on October 14, 2025, that could enable local authenticated attackers to execute arbitrary system commands. Tracked as CVE-2025-58325, the flaw …

Microsoft October 2025 Patch Tuesday – 4 Zero-days and 172 Vulnerabilities Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft rolled out its October 2025 Patch Tuesday updates, addressing a staggering 172 vulnerabilities across its ecosystem, including four zero-day flaws, of which two are actively exploited in the wild. …

Hackers Mimic as OpenAI and Sora Services to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, a sophisticated phishing campaign has emerged, targeting corporate and consumer accounts by impersonating both OpenAI and Sora-branded login portals. Attackers distribute emails crafted to appear as legitimate …

UEFI Shell Vulnerabilities Could Let Hackers Bypass Secure Boot on 200,000+ Laptops

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers can exploit vulnerabilities in signed UEFI shells to bypass Secure Boot protections on over 200,000 Framework laptops and desktops. According to Eclypsium, these vulnerabilities expose fundamental flaws in how …

Criminal IP to Showcase ASM and CTI Innovations at GovWare 2025 in Singapore

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Torrance, United States, October 14th, 2025, CyberNewsWire Criminal IP at Booth J30 | Sands Expo Singapore | October 21 – 23, 2025 Criminal IP, a global cybersecurity company, announced its …

Sweet Security Named Cloud Security Leader and CADR Leader in Latio Cloud Security Report

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tel Aviv, Israel, October 14th, 2025, CyberNewsWire Sweet Security, a leader in Runtime Cloud and AI security solutions, today announced that it has been recognized as both a Cloud Security …