Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese threat actors operating under the name Silver Fox are targeting Indian organizations through sophisticated phishing campaigns that impersonate legitimate income tax documents. The attack campaign uses authentic-looking Income Tax …

New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Spanish-speaking phishing operation targeting Microsoft Outlook users has been active since March 2025, using a sophisticated kit that shows clear indicators of AI-assisted development. The campaign, tracked through a …

Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Public reports about cyberattacks often present a polished picture—threat actors working methodically through a well-planned playbook with every action perfectly executed. This perception leads many to believe that modern attackers …

2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated exploitation campaign that generated more than 2.5 million malicious requests against Adobe ColdFusion servers and 47+ other technology platforms during the Christmas 2025 holiday period. The operation was …

New Vulnerabilities in Bluetooth Headphones Let Hackers Hijack Connected Smartphone

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have disclosed critical vulnerabilities affecting widely used Bluetooth headphones and earbuds that could allow attackers to eavesdrop on conversations, steal sensitive data, and even hijack connected smartphones. The …

Hacktivist Proxy Operations Emerge as a Repeatable Model of Geopolitical Cyber Pressure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new form of cyber disruption is reshaping the landscape of modern conflict. Hacktivist groups are increasingly operating as strategic instruments of state pressure, launching coordinated attacks that align perfectly …

Windows LPE Vulnerabilities via Kernel Drivers and Named Pipes Allows Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers are increasingly focusing on privilege escalation attacks through two primary Windows attack surfaces: kernel drivers and named pipes. These vectors exploit fundamental trust boundary weaknesses between the user …

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An open-source detection tool to help organizations identify potential exploitation of MongoBleed (CVE-2025-14847), a critical memory disclosure vulnerability affecting MongoDB databases.​ The vulnerability allows attackers to extract sensitive information, including …