Top 10 Best Endpoint Protection Solutions For MSPs/MSSPs in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the complex and rapidly evolving world of cybersecurity, Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) stand as the crucial first line of defense for a diverse …

Microsoft Confirms 900+ XSS Vulnerabilities Found in IT Services, Ranging from Low Impact to Zero-Click

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Of all the vulnerabilities that plague modern applications, Cross-Site Scripting (XSS) is one of the oldest and most persistent. Despite being a known threat for over two decades, XSS continues …

Critical LangChainGo Vulnerability Let Attackers Access Sensitive Files by Injecting Malicious Prompts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability was identified in LangChainGo, the Go implementation of the popular LLM orchestration framework LangChain.  Tracked as CVE-2025-9556, this flaw allows unauthenticated attackers to perform arbitrary file reads …

Actors Behind AppSuite-PDF and PDF Editor Used 26 Code-Signing Certificates to Make Software Appear Legitimate

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a sophisticated malware campaign spanning seven years, where threat actors behind AppSuite-PDF and PDF Editor applications systematically abused code-signing certificates to legitimize their malicious software. The …

IBM QRadar SIEM Vulnerability Let Attackers Perform Unauthorized Actions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical permission misconfiguration in the IBM QRadar Security Information and Event Management (SIEM) platform could allow local privileged users to manipulate configuration files without authorization.  Tracked as CVE-2025-0164, the flaw stems …

Great Firewall of China’s Sensitive Data of Over 500GB+ Leaked Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Great Firewall of China (GFW) suffered its largest-ever internal data breach. More than 500 GB of sensitive material—including source code, work logs, configuration files, and internal communications—was exfiltrated and …

DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DarkCloud Stealer has recently emerged as a potent threat targeting financial organizations through convincing phishing campaigns. Adversaries employ weaponized RAR attachments masquerading as legitimate documents to deliver a multi-stage JavaScript-based …

New Yurei Ransomware With PowerShell Commands Encrypts Files With ChaCha20 Algorithm

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Emerging in early September 2025, the Yurei ransomware has swiftly drawn attention for its novel combination of Go-based execution and ChaCha20 encryption. First documented on September 5 when a Sri …

Top 10 Best Ransomware Protection Solutions in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware continues to be one of the most destructive and pervasive cyber threats facing organizations of all sizes. In 2025, the sophistication of ransomware attacks has reached unprecedented levels, with …

New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security teams have observed a significant increase in sophisticated phishing campaigns leveraging a newly discovered Phishing-as-a-Service (PhaaS) platform dubbed VoidProxy. The operation, first detected in August 2025, …