CISA Warns of Chinese Hackers Exploiting SharePoint 0-Day Flaws in Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent alert regarding active exploitation of critical Microsoft SharePoint vulnerabilities by suspected Chinese threat actors.  The attack campaign, dubbed “ToolShell,” leverages a vulnerability chain involving CVE-2025-49706 …

Hackers Injected Malicious Firefox Browser Packages to Arch Linux User Repository

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers discovered that threat actors had uploaded three corrupted browser packages, firefox-patch-bin, librewolf-fix-bin, and zen-browser-patched-bin, to the Arch User Repository (AUR).  These packages appeared to be benign forks of …

Windows 11 Gets New Black Screen of Death With Auto Recovery Tool

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has unveiled significant improvements to Windows 11’s system recovery capabilities, introducing a redesigned Black Screen of Death restart screen alongside an automated Quick Machine Recovery (QMR) tool.  These enhancements …

CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent warning regarding two critical Microsoft SharePoint vulnerabilities that threat actors are actively exploiting in the wild.  The vulnerabilities, designated as CVE-2025-49704 and CVE-2025-49706, pose significant …

Kali Linux Unveils Two New Tools to Boost Wi-Fi Performance for Raspberry Pi Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kali Linux has announced the release of two groundbreaking packages that significantly enhance wireless penetration testing capabilities for Raspberry Pi users. The new brcmfmac-nexmon-dkms and firmware-nexmon packages, introduced in Kali …

Chinese Hackers Actively Exploiting SharePoint Servers 0-Day Flaw in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed that Chinese state-sponsored threat actors are actively exploiting critical zero-day vulnerabilities in on-premises SharePoint servers, prompting urgent security warnings for organizations worldwide.  The tech giant’s Security Response …

Chrome High-Severity Vulnerabilities Allow Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an urgent security update for its Chrome browser, addressing three critical vulnerabilities that could enable attackers to execute arbitrary code on users’ systems. The Stable channel update …

Researchers Unmasked Russia’s Most Secretive FSB’s Spy Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A groundbreaking investigation has pulled back the curtain on one of Russia’s most clandestine intelligence operations, revealing unprecedented details about the Federal Security Service’s (FSB) 16th Center and its extensive …

Scavenger Malware Hijacks Popular npm Packages to Attack Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack targeting JavaScript developers emerged on Friday, July 18th, 2025, when cybercriminals compromised multiple popular npm packages to distribute the newly identified “Scavenger” malware. The attack …

Threat Actors Attacking Linux SSH Servers to Deploy SVF Botnet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated attack campaign targeting poorly managed Linux servers through SSH brute force attacks to deploy the SVF Botnet, a Python-based distributed denial-of-service malware. The malware …