TOTOLINK X6000R Router Vulnerabilities Let Remote Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security flaws have been discovered in the TOTOLINK X6000R wireless router, exposing users to severe risks of remote code execution and unauthorized system access. These vulnerabilities affect the router’s …

DrayOS Routers Vulnerability Let Attackers Execute Malicious Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in DrayTek’s DrayOS routers, which could allow unauthenticated remote attackers to execute malicious code. The flaw, tracked as CVE-2025-10547, affects a wide range of …

SideWinder Hacker Group Hosting Fake Outlook/Zimbra Portals to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT SideWinder, a state-sponsored threat actor long associated with espionage across South Asia, has recently launched a campaign deploying phishing portals that mimic legitimate Outlook and Zimbra webmail services. Emerging …

Threat Actors Leveraging WhatsApp Messages to Attack Windows Systems With SORVEPOTEL Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Enterprise networks worldwide are facing an aggressive, self-propagating malware campaign that exploits WhatsApp as its primary delivery mechanism. First observed in early September 2025 targeting Brazilian organizations, SORVEPOTEL spreads through …

New ‘Point-and-Click’ Phishing Kit Bypasses User Awareness and Security Filters to Deliver Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel phishing kit has surfaced that enables threat actors to craft sophisticated lures with minimal technical expertise. This “point-and-click” toolkit combines an intuitive web interface with powerful payload delivery …

Rhadamanthys Stealer Available on Dark Web Prices Ranging from $299 to $499

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Rhadamanthys, a sophisticated multi-modular information stealer, first emerged in September 2022 and has since evolved into one of the most commercially advanced malware offerings on underground forums. Originally advertised by …

Hundreds of Free VPN Apps for Both Android and iOS Leaks Users Personal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mobile VPN apps promise to protect privacy and secure communications on smartphones, but a comprehensive analysis of nearly 800 free Android and iOS VPN applications reveals a troubling reality: many …

Confucius Hacker Group Attacking Weaponizing Documents to Compromised Windows Systems With AnonDoor Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Confucius hacker group, active since 2013, has recently escalated its operations by weaponizing malicious Office documents to compromise Windows endpoints with a new Python-based backdoor, dubbed AnonDoor. Historically known …

Signal Enhances Security With New Hybrid PQ Ratchet to Compact Quantum Computing Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Signal has announced a groundbreaking advancement in secure messaging with the introduction of the Sparse Post Quantum Ratchet (SPQR), a revolutionary cryptographic enhancement designed to protect against future quantum computing …