Windows Defender Vulnerability Allows Service Hijacking and Disablement via Symbolic Link Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in Windows Defender’s update process allows attackers with administrator privileges to disable the security service and manipulate its core files. The technique, which leverages a flaw in …

Venezuela’s Maduro Says Huawei Mate X6 Gift From China is Unhackable by U.S. Spies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In Caracas this week, President Nicolás Maduro unveiled the Huawei Mate X6 gifted by China’s Xi Jinping, declaring the device impervious to U.S. espionage efforts. The announcement coincides with heightened …

LunaLock Ransomware Attacking Artists to Steal and Encrypt Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers first observed LunaLock in early September 2025, a sophisticated ransomware strain targeting independent illustrators and digital artists. Leveraging compromised credentials and social engineering, the group behind LunaLock has …

Exposed ‘Kim’ Dump Exposes Kimsuky Hackers New Tactics, Techniques, and Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive data breach in early September 2025 attributed to a cyber actor known simply as “Kim” laid bare an unprecedented view into the operational playbook of Kimsuky (APT43). The …

Hackers Weaponize Amazon Simple Email Service to Send 50,000+ Malicious Emails Per Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercriminal campaign has emerged, exploiting Amazon’s Simple Email Service (SES) to orchestrate large-scale phishing operations capable of delivering over 50,000 malicious emails daily. The attack represents a significant …

Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Qualys has confirmed it was impacted by a widespread supply chain attack that targeted the Salesloft Drift marketing platform, resulting in unauthorized access to a portion of its Salesforce data. …

Researchers Bypassed Web Application Firewall With JS Injection with Parameter Pollution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have demonstrated a sophisticated technique for bypassing Web Application Firewalls (WAFs) using JavaScript injection combined with HTTP parameter pollution, exposing critical vulnerabilities in modern web security infrastructure. The …

PgAdmin Vulnerability Lets Attackers Gain Unauthorised Account Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security flaw has been discovered in pgAdmin, the widely used open-source administration and development platform for PostgreSQL databases. The vulnerability, tracked as CVE-2025-9636, affects all pgAdmin versions up …

PoC Exploit Released for ImageMagick RCE Vulnerability – Update Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been released for a critical remote code execution (RCE) vulnerability in ImageMagick 7’s MagickCore subsystem, specifically affecting the blob I/O (BlobStream) implementation. Security researchers and the ImageMagick …

Salesloft Drift Cyberattack Linked to GitHub Compromise and OAuth Token Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply-chain attack that impacted over 700 organizations, including major cybersecurity firms, has been traced back to a compromise of Salesloft’s GitHub account that began as early as March …