Beer Brewing Giant Asahi Halts Production Following Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Japanese beverage conglomerate Asahi Group Holdings has halted production at its domestic factories following a significant cyberattack that crippled its systems on Monday. A company spokesperson confirmed on Tuesday that …

Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious npm package masquerading as the official Postmark MCP Server has been exfiltrating user emails to an external server.  This fake “postmark-mcp” module, available on npm from versions 1.0.0 …

VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A zero-day local privilege escalation vulnerability in VMware Tools and VMware Aria Operations is being actively exploited in the wild. The flaw, tracked as CVE-2025-41244, allows an unprivileged local attacker …

VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware has released an advisory to address three high-severity vulnerabilities in VMware Aria Operations, VMware Tools, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.  Disclosed on …

Critical Western Digital My Cloud NAS Devices Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Western Digital has released security updates for a critical vulnerability affecting multiple My Cloud network-attached storage (NAS) devices. The flaw, tracked as CVE-2025-30247, could allow a remote attacker to execute …

Apple Font Parser Vulnerability Enables Malicious Fonts to Crash or Corrupt Process Memory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has rolled out security updates across its operating systems to address a vulnerability in the Font Parser component that could allow malicious fonts to crash applications or corrupt process …

VMware vCenter and NSX Vulnerabilities Let Attackers Enumerate Valid Usernames

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware has disclosed critical security vulnerabilities in vCenter Server and NSX platforms that could allow attackers to enumerate valid usernames and manipulate system notifications.  The vulnerabilities, tracked as CVE-2025-41250, CVE-2025-41251, …

Hackers Trick Users to Download Weaponized Microsoft Teams to Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber campaign is exploiting the trust users place in popular collaboration software, tricking them into downloading a weaponized version of Microsoft Teams to gain remote access to their …

New Harrods Data Breach Exposes 430,000 Customer Personal Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Luxury department store Harrods has disclosed a significant data breach affecting approximately 430,000 customer records after a third-party provider was compromised. The hackers behind the attack have contacted the retailer, …

New Spear-Phishing Attack Delivers DarkCloud Malware to Steal Keystrokes, FTP Credentials and Others

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly observed spear-phishing campaign is leveraging sophisticated social engineering lures to distribute DarkCloud, a modular malware suite designed to harvest keystrokes, exfiltrate FTP credentials and gather system information. Over …