Famous Chollima APT Hackers Attacking Job Seekers and Organization to Deploy JavaScript Based Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean-linked Famous Chollima APT group has emerged as a sophisticated threat actor, orchestrating targeted campaigns against job seekers and organizations through deceptive recruitment processes. Active since December 2022, this …

Fashion Giant Chanel Hacked in Wave of Salesforce Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

French luxury fashion house Chanel has become the latest victim in a sophisticated cybercrime campaign targeting major corporations through their Salesforce customer relationship management systems. The company confirmed on July …

Critical Android System Component Vulnerability Allows Remote Code Execution Without User Interaction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google released its August 2025 Android Security Bulletin on August 4, revealing a critical vulnerability that poses significant risks to Android device users worldwide.  The most severe flaw, designated CVE-2025-48530, …

New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Android malware campaign has emerged targeting Indian banking customers through convincing impersonations of popular financial applications. The malicious software masquerades as legitimate apps from major Indian financial …

NVIDIA Triton Vulnerability Chain Let Attackers Take Over AI Server Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability chain in NVIDIA’s Triton Inference Server that allows unauthenticated attackers to achieve complete remote code execution (RCE) and gain full control over AI servers.  The vulnerability chain, …

WAFs protection Bypassed to Execute XSS Payloads Using JS Injection with Parameter Pollution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated method to bypass Web Application Firewall (WAF) protections using HTTP Parameter Pollution techniques combined with JavaScript injection.  The research, conducted by Bruno Mendes across 17 different WAF configurations …

Raspberry Robin Malware Downloader Attacking Windows Systems With New Exploit for Common Log File System Driver Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape faces a persistent threat as Raspberry Robin, a sophisticated malware downloader also known as Roshtyak, continues its campaign against Windows systems with enhanced capabilities and evasion techniques. …

Threat Actors are Actively Exploiting Vulnerabilities in Open-Source Ecosystem to Propagate Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The open-source software ecosystem, once considered a bastion of collaborative development, has become an increasingly attractive target for cybercriminals seeking to infiltrate supply chains and compromise downstream systems. Recent analysis …

Ransomware Attack on Phone Repair and Insurance Company Cause Millions in Damage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The sudden emergence of the Royal ransomware in early 2023 marked a significant escalation in cyber threats targeting service providers across Europe. Exploiting unpatched VPN and remote-desktop gateways, attackers initiated …

Claude Vulnerabilities Let Attackers Execute Unauthorized Commands With its Own Help

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two high-severity vulnerabilities in Anthropic’s Claude Code could allow attackers to escape restrictions and execute unauthorized commands. Most remarkably, Claude itself unwittingly assisted in developing the exploits used against its …