ShadowSilk Leveraging Penetration-Testing Tools, Public Exploits to Attack Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ShadowSilk first surfaced in late 2023 as a sophisticated threat cluster targeting government entities across Central Asia and the broader APAC region. Exploiting known public vulnerabilities and widely available penetration-testing …

FreePBX Servers Hacked in 0-Day Attack – Admins are Urged to Disable Internet Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day exploit targeting exposed FreePBX 16 and 17 systems. Threat actors are abusing an unauthenticated privilege escalation vulnerability in the commercial Endpoint Manager module, allowing remote code execution …

New TamperedChef Attack With Weaponized PDF Editor Steals Sensitive Data and Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign that weaponizes a seemingly legitimate PDF editor to steal sensitive data and login credentials from unsuspecting users across Europe. The attack uncovered by Truesec, dubbed “TamperedChef,” …

CrowdStrike Set to Acquire Onum in $290 Million Deal to Enhance Falcon Next-Gen SIEM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Global cybersecurity leader CrowdStrike announced its intention to acquire Onum, a pioneer in real-time telemetry pipeline management, in a deal reportedly valued at $290 million. The acquisition, unveiled Wednesday, aims …

NX Build Tool Hacked with Malware That Checks for Claude or Gemini to Find Wallets and Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 1,400 developers discovered today that a malicious post-install script in the popular NX build kit silently created a repository named s1ngularity-repository in their GitHub accounts.  This repository contains a …

CISA Publish Hunting and Mitigation Guide to Defend Networks from Chinese State-Sponsored Actors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside the NSA, FBI, and a broad coalition of international partners, has released a comprehensive cybersecurity advisory detailing a widespread espionage campaign …

TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past year, a shadowy threat actor known as TAG-144—also tracked under aliases Blind Eagle and APT-C-36—has intensified operations against South American government institutions. First observed in 2018, this …

Kea DHCP Server Vulnerability Let Remote Attacker With a Single Crafted Packet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in the widely used ISC Kea DHCP server poses a significant security risk to network infrastructure worldwide.  The flaw, designated CVE-2025-40779, allows remote attackers to crash …

Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Attack Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Threat Intelligence has released a detailed report exposing a significant evolution in ransomware attacks, pioneered by the financially motivated threat actor Storm-0501. The group has shifted from traditional on-premises …

CISA Warns of Citrix Netscaler 0-day RCE Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent warning regarding a critical zero-day vulnerability affecting Citrix NetScaler systems, designated as CVE-2025-7775.  This memory overflow vulnerability enables remote code execution (RCE) and has been …