New ‘Sindoor Dropper’ Malware Targets Linux Systems with Weaponized .desktop Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign, dubbed “Sindoor Dropper,” is targeting Linux systems using sophisticated spear-phishing techniques and a multi-stage infection chain. The campaign leverages lures themed around the recent India-Pakistan conflict, …

Top 10 Best API Penetration Testing Companies In 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

API penetration testing has evolved dramatically in 2025. While traditional, human-led penetration testing remains critical, the scale and complexity of modern APIs have necessitated a new approach. The companies on …

U.S. Government Seizes Online Marketplaces Used to Sell Fraudulent Identity Documents to Cybercriminals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Attorney’s Office for the District of New Mexico announced Thursday that federal authorities have executed a court-authorized seizure of two domain names and one affiliated blog associated with …

WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack campaign has leveraged a previously unknown zero-day vulnerability in WhatsApp on Apple devices to target specific users, the company has confirmed. The vulnerability, now identified as CVE-2025-55177, …

Citrix Netscaler 0-day RCE Vulnerability Patched – Vulnerable Instances Reduced from 28.2K to 12.4K

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant global effort to patch a critical zero-day remote code execution (RCE) vulnerability in Citrix NetScaler devices has seen the number of exposed systems drop from approximately 28,200 to …

NodeBB Vulnerability Let Attackers Inject Boolean-Based Blind and PostgreSQL Error-Based Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NodeBB, a popular open-source forum platform, has been found vulnerable to a critical SQL injection flaw in version 4.3.0.  The flaw, tracked as CVE-2025-50979, resides in the search-categories API endpoint, …

NightSpire Ransomware Group Claims to Exploit The Vulnerabilities of Orgs to Infiltrate Their Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since its emergence in February 2025, the NightSpire ransomware group has rapidly distinguished itself through a sophisticated double-extortion strategy that combines targeted encryption with public data leaks. Initially surfacing in …

AppSuite PDF Editor Hacked to Execute Arbitrary Commands on The Infected System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged targeting users seeking free PDF editing software, with cybercriminals distributing a malicious application masquerading as the legitimate “AppSuite PDF Editor.” The malware, packaged as …

New TAOTH Campaign Exploits End-of-Support Software to Distribute Malware and Collect Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In June 2025, a previously undocumented campaign leveraging end-of-support software began surfacing in telemetry data gathered across Eastern Asia. Dubbed TAOTH, the operation exploits an abandoned Chinese input method editor …