Threat Actors Hijacking MS-SQL Server to Deploy XiebroC2 Framework

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack campaign targeting improperly managed Microsoft SQL servers has emerged, deploying the XiebroC2 command and control framework to establish persistent access to compromised systems. The attack leverages vulnerable …

APT35 Hackers Attacking Government, Military Organizations to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, a surge in targeted intrusions attributed to the Iranian-aligned threat group APT35 has set off alarm bells across government and military networks worldwide. First detected in early …

How SOC Teams Detect Can Detect Cyber Threats Quickly Using Threat Intelligence Feeds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security Operations Centers (SOCs) protect organizations’ digital assets from ongoing cyber threats. To assess their effectiveness, SOCs use key performance indicators (KPIs) such as Mean Time to Detect (MTTD) and …

CISA Warns of Linux Sudo Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent advisory regarding a critical vulnerability in the Linux and Unix sudo utility CVE-2025-32463 that is currently being exploited in the wild.  This flaw allows local …

Google Gemini Vulnerabilities Let Attackers Exfiltrate User’s Saved Data and Location

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three new vulnerabilities in Google’s Gemini AI assistant suite could have allowed attackers to exfiltrate users’ saved information and location data. The vulnerabilities uncovered by Tenable, dubbed the “Gemini Trifecta,” …

Threat Actors Allegedly Listed Veeam RCE Exploit for Sale on Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Veeam Backup & Replication, a cornerstone of many enterprises’ data protection strategy, has reportedly become the focus of a new exploit being offered on a clandestine marketplace. According to a …

Hackers Actively Scanning to Exploit Palo Alto Networks PAN-OS Global Protect Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers are observing a significant increase in internet-wide scans targeting the critical PAN-OS GlobalProtect vulnerability (CVE-2024-3400).  Exploit attempts have surged as attackers seek to leverage an arbitrary file creation …

Linux 6.17 Released With Fix for use-after-free Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Linus Torvalds has announced the release of Linux Kernel 6.17, a new version focused on stability and incremental improvements rather than groundbreaking features. The update brings a host of bug …

Tesla’s Telematics Control Unit Vulnerability Let Attackers Gain Code Execution as Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability in Tesla’s Telematics Control Unit (TCU) allowed attackers with physical access to bypass security measures and gain full root-level code execution. The flaw stemmed from an incomplete …

Lunar Spider Infected Windows Machine in Single Click and Harvested Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lunar Spider, a newly observed malware strain, has emerged as a potent threat to Windows environments by compromising systems in a single click. First detected in mid-September 2025, its operators …