Windows 11 25H2 Update Preview Released, What’s New?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has opened the Release Preview Channel to Windows Insiders for the forthcoming Windows 11, version 25H2 (Build 26200.5074) enablement package (eKB), offering an early look at this year’s annual …

Malicious npm Package Mimics as Popular Nodemailer with Weekly 3.9 Million Downloads to Hijack Crypto Transactions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Socket.dev uncovered a sophisticated supply chain attack in late August 2025 leveraging a malicious npm package named nodejs-smtp, which masquerades as the widely used email library nodemailer, …

Sitecore CMS Platform Vulnerabilities Enables Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerabilities in Sitecore Experience Platform allow attackers to achieve complete system compromise through a sophisticated attack chain combining HTML cache poisoning with remote code execution capabilities. These flaws also …

Infostealer Malware is Being Exploited by APT Groups for Targeted Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Infostealer malware, initially designed to indiscriminately harvest credentials from compromised hosts, has evolved into a potent weapon for state-sponsored Advanced Persistent Threat (APT) groups. Emerging in early 2023, families such …

Amazon Dismantles Russian APT 29 Infrastructure Used to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon’s threat intelligence team uncovered a sophisticated watering hole campaign in late August 2025, which is orchestrated by APT29, also known as Midnight Blizzard, a Russian Foreign Intelligence Service–linked actor. …

Hackers Leverage Windows Defender Application Control Policies to Disable EDR Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are exploiting Windows Defender Application Control (WDAC) policies to systematically disable Endpoint Detection and Response (EDR) agents, creating a dangerous blind spot in corporate security infrastructure. Real-world threat actors, …

AI Waifu RAT Attacking Users With Novel Social Engineering Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign targeting niche Large Language Model (LLM) role-playing communities has emerged, leveraging advanced social engineering tactics to distribute a dangerous Remote Access Trojan (RAT). The malware, dubbed …

QNAP Vulnerability Let Attackers Bypass Authentication and Access Unauthorized Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP Systems has disclosed a critical security vulnerability in its legacy VioStor Network Video Recorder (NVR) firmware that could allow remote attackers to completely bypass authentication mechanisms and gain unauthorized …

Linux UDisks Daemon Vulnerability Let Attackers Gaining Access to Files Owned by Privileged Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the Linux UDisks daemon that could allow unprivileged attackers to gain access to files owned by privileged users.  The flaw, identified as …

CISA Releases Nine ICS Advisories Surrounding Vulnerabilities, and Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has published nine Industrial Control Systems (ICS) advisories on August 28, 2025, detailing high- and medium-severity vulnerabilities across leading vendors’ products.  The advisories …