Magento and Adobe SessionReaper Vulnerability Exposes Thousands Of Online Stores to Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adobe has issued an emergency security patch for a critical vulnerability in its Magento and Adobe Commerce platforms, dubbed “SessionReaper”. The vulnerability is considered one of the most severe in …

New APT37 Attacking Windows Machines With New Rust and Python Based Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT37, the North Korean-aligned threat actor also known as ScarCruft, Ruby Sleet, and Velvet Chollima, has expanded its arsenal with sophisticated new malware targeting Windows systems. Active since 2012, the …

Chinese Salt Typhoon and UNC4841 Hackers Teamed Up to Attack Government and Corporate Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers began tracking a sophisticated campaign in the closing months of 2024, targeting both government and corporate networks across multiple continents. The threat actors behind this operation, known colloquially …

Elastic Salesloft Drift Security Incident – Hackers Accessed Email Account Contains Valid Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elastic has disclosed a security incident stemming from a third-party breach at Salesloft Drift, which resulted in unauthorized access to an internal email account containing valid credentials. While the company’s …

SpamGPT – AI-powered Attack Tool Used By Hackers For Massive Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cybercrime toolkit named SpamGPT is enabling hackers to launch massive and highly effective phishing campaigns by combining artificial intelligence with the capabilities of professional email marketing platforms. …

New Technique Uncovered To Exploit Linux Kernel Use-After-Free Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new technique to exploit a complex use-after-free (UAF) vulnerability in the Linux kernel successfully bypasses modern security mitigations to gain root privileges. The method targets CVE-2024-50264, a difficult-to-exploit race condition bug …

Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dynatrace has confirmed it was impacted by a third-party data breach originating from the Salesloft Drift application, resulting in unauthorized access to customer business contact information stored in its Salesforce …

Hackers Hijacked 18 Very Popular npm Packages With 2 Billion Weekly Downloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the largest supply chain attack, hackers compromised 18 popular npm packages, which together account for over two billion downloads per week. The attack, which began on September 8th, involved …

Progress OpenEdge AdminServer Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Progress OpenEdge, a platform for developing and deploying business applications. The flaw, identified as CVE-2025-7388, allows for remote code execution (RCE) and …