14,000+ F5 BIG-IP APM Devices Exposed Online Amid Active RCE Vulnerability Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in F5’s BIG-IP Access Policy Manager (APM) is currently under active exploitation, leaving thousands of enterprise networks at risk. The vulnerability, officially tracked as CVE-2025-53521, has …

Kimsuky Deploys Malicious LNK Files to Deliver Python-Based Backdoor in Multi-Stage Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korean threat group known as Kimsuky has been caught running a cyberattack campaign that uses malicious Windows shortcut files, known as LNK files, to quietly install a Python-based …

Axios Maintainer Confirms The npm Compromise Was via a Targeted Social Engineering Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two malicious versions of the popular JavaScript HTTP library Axios were briefly published to the npm registry on March 31, 2026. Each version carried a hidden dependency that installed a …

Hackers Abuse Trusted Platforms to Steal Bank Credentials From Philippine Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated phishing campaign has been quietly targeting banking customers across the Philippines since early 2024, and it remains active today. The attackers are not relying on crude tricks — …

Malicious Chrome Extension “ChatGPT Ad Blocker” Steals ChatGPT Conversations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As OpenAI introduces advertisements to its free tier, cybercriminals are seizing the opportunity to trick users with fake utility tools. Security researchers have discovered a malicious Google Chrome extension named …

Hackers Use Venom Stealer to Turn ClickFix Lures Into Full Data Exfiltration Pipelines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware has been quietly spreading across cybercrime networks, and security researchers say it is far more capable than most tools of its kind. Called Venom Stealer, this malware-as-a-service …

Microsoft Forcing Upgrades to Unmanaged Windows 11, Version 24H2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially begun force-upgrading unmanaged Windows 11 version 24H2 devices to version 25H2, marking the final phase of a staged rollout that relies on machine learning to determine device …

Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple high-severity vulnerabilities exist in TP-Link’s Tapo C520WS smart security cameras. If exploited, these vulnerabilities may allow adjacent attackers to trigger Denial-of-Service (DoS) conditions, crash the device, or completely bypass …

Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive automated credential theft campaign is actively targeting web applications worldwide. Cybersecurity researchers at Cisco Talos have uncovered an operation by a hacker group tracked as UAT-10608, which has …