Disney Agreed to Pay $10 Million for Collection Personal Data From Children

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Disney Worldwide Services, Inc. and Disney Entertainment Operations LLC have agreed to pay $10 million in a landmark settlement to resolve allegations that they systematically collected personal data from children …

Attackers Are Abusing Malicious PDFs: Here’s How to Spot Them Early

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing has moved far beyond suspicious links. Today, attackers hide inside the files employees trust most; PDFs. On the surface, they look like invoices, contracts, or reports. But once opened, …

New Stealthy Python Malware Leverages Discord to Steal Data From Windows Machines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Python-based information stealer has emerged in the cybersecurity landscape, demonstrating advanced capabilities for data exfiltration through Discord channels. The malware, identified as “Inf0s3c Stealer,” represents a significant …

RapperBot Hijacking Devices to Launch DDoS Attack In a Split Second

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers began detecting an alarming surge in early April 2025 in UDP flood traffic emanating from compromised network video recorders (NVRs) and other edge devices. Within milliseconds of infection, …

PagerDuty Confirms Data Breach After Third-Party App Vulnerability Exposes Salesforce Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PagerDuty, a leader in digital operations management, has confirmed a security incident that resulted in unauthorized access to some of its data stored in Salesforce. The company stated that no …

OpenAI Set to Acquire Analytics Platform Statsig in $1.1 Billion Agreement

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI announced today its definitive agreement to acquire Statsig, a product experimentation and analytics platform, for $1.1 billion. The acquisition is a key move by the leader in artificial intelligence. …

Chrome 140 Released With Fix For Six Vulnerabilities that Enable Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially promoted Chrome 140 to the stable channel, initiating a multi-platform rollout for Windows, Mac, Linux, Android, and iOS. The update brings the usual stability and performance improvements, …

Android Security Update – Patch for 0-Day Vulnerabilities Actively Exploited in Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In response to the discovery of actively exploited 0-day vulnerabilities, Google has released its September 2025 Android Security Bulletin, rolling out patch level 2025-09-05 to safeguard millions of devices. The …

CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent advisory concerning a newly disclosed zero-day vulnerability in Meta Platforms’ WhatsApp messaging service (CVE-2025-55177).  This flaw, categorized under CWE-863: Incorrect Authorization, allows an unauthorized actor …

PoC Exploit Released for IIS WebDeploy Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept exploit for CVE-2025-53772, a critical remote code execution vulnerability in Microsoft’s IIS Web Deploy (msdeploy) tool, was published this week, raising urgent alarms across the .NET and DevOps communities.  The flaw …