Hackers Can Bypass EDR by Downloading a Malicious File as an In-Memory PE Loader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated technique that allows attackers to execute malicious code directly in memory is gaining traction, posing a significant challenge to modern Endpoint Detection and Response (EDR) solutions. This method, …

Weaponized Malwarebytes, LastPass, Citibank, SentinelOne, and Others on GitHub Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, cybersecurity teams have observed a surge in malicious GitHub repositories masquerading as legitimate security and financial software. Threat actors have crafted convincing forks of projects bearing names …

OnePlus OxygenOS Vulnerability Allows Any App to Read SMS Data Without Permission

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe security vulnerability in OnePlus OxygenOS has been discovered that allows any installed application to read SMS and MMS messages without requesting permission or notifying users.  The flaw, designated …

Salesforce CLI Installer Vulnerability Let Attackers Execute Code and Gain SYSTEM-Level Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Salesforce CLI installer (sf-x64.exe) enables attackers to achieve arbitrary code execution, privilege escalation, and SYSTEM-level access on Windows systems.  Tracked as CVE-2025-9844, the flaw stems …

Hackers Exploiting Libraesva Email Security Gateway Vulnerability to Inject Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Libraesva has issued an emergency patch for a significant command injection vulnerability in its Email Security Gateway (ESG) after confirming state-sponsored hackers exploited it. The flaw, identified as CVE-2025-59689, allowed …

ShadowV2 Botnet Exploits Docker Containers on AWS to Turn Thems as Infected System for DDoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercrime campaign has emerged that transforms legitimate AWS infrastructure into weaponized attack platforms through an innovative combination of containerization and distributed denial-of-service capabilities. The ShadowV2 botnet represents a …

New YiBackdoor Allows Attackers to Execute Arbitrary Commands and Exfiltrate Sensitive Data from Hacked Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware family dubbed YiBackdoor has emerged in the cybersecurity landscape, posing a significant threat to organizations worldwide. First observed in June 2025, this malicious software represents a …

CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a high-severity zero-day vulnerability in Google Chrome that is being actively exploited in attacks. The vulnerability, tracked …

Hackers Exploit WerFaultSecure.exe Tool to Steal Cached Passwords From Windows 11 24H2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are leveraging the legacy Windows error‐reporting utility WerFaultSecure.exe to extract the memory region of the Local Security Authority Subsystem Service (LSASS.EXE) and harvest cached credentials from fully patched …

CISA Warns of Shai-Hulud Self-Replicating Worm Compromised 500+ Packages in npm Registry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent security Alert in response to a large-scale software supply chain attack on npmjs.com, the world’s largest JavaScript package registry.  A self-replicating worm, dubbed Shai-Hulud, has …