Linux Kernel’s KSMBD Subsystem Vulnerability Let Remote Attackers Exhaust Server Resources

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A denial-of-service flaw in the Linux kernel’s KSMBD (SMB Direct) subsystem has raised alarms across the open-source community.  Tracked as CVE-2025-38501, the issue allows a remote, unauthenticated adversary to exhaust …

Massive “Shai-Halud” Supply Chain Attack Compromised 477 NPM Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale supply chain attack dubbed “Shai-Halud” that infiltrated the JavaScript ecosystem via the npm registry.  In total, 477 packages, including packages from CrowdStrike, were found to contain stealthy backdoors …

FinWise Insider Breach Exposes 700K Customer Records to Former Employee

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

American First Finance, LLC, a Dallas-based financial services firm, suffered a significant insider breach when a recently terminated employee exploited unauthorized access to its production database.  The incident, dubbed the …

Hackers Can Exploit Bitpixie Vulnerability to Bypass BitLocker Encryption and Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Windows Boot Manager, known as bitpixie, enables attackers to bypass BitLocker drive encryption and escalate local privileges on Windows systems.  The vulnerability affects boot managers from 2005 to …

3 Weeks Left Until the Start of the OpenSSL Conference 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Newark, New Jersey, United States, September 16th, 2025, CyberNewsWire The OpenSSL Conference 2025 will take place on October 7 – 9 in Prague. The program will bring together lawyers, regulators, developers, and …

Hackers Stolen Millions of Users Personal Data from Gucci, Balenciaga and Alexander McQueen Stores

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Luxury fashion company Kering has confirmed a data exfiltration incident in which threat actor Shiny Hunters accessed private customer records for Gucci, Balenciaga, and Alexander McQueen. The breach, detected in …

Seraphic Browser-Native Protection Now Available for Purchase on the CrowdStrike Marketplace

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Las Vegas, United States, September 16th, 2025, CyberNewsWire Seraphic today announced at Fal.Con 2025 that its Secure Enterprise Browser (SEB) solution is now available for purchase in the CrowdStrike Marketplace, …

Why Real-Time Threat Intelligence Is Critical for Modern SOCs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security Operations Centers (SOCs) exist under ever-increasing pressure to detect and respond to threats before they escalate. Today’s fast-moving adversaries exploit gaps in threat visibility with automation, targeted ransomware, and …

KillSec Ransomware Attacking Healthcare Industry IT Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The KillSec ransomware strain has rapidly emerged as a formidable threat targeting healthcare IT infrastructures across Latin America and beyond. First observed in early September 2025, KillSec operators have leveraged …