Threat Actors Exploiting Ivanti Connect Secure Vulnerabilities to Deploy Cobalt Strike Beacon

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign targeting Ivanti Connect Secure VPN devices has been actively exploiting critical vulnerabilities CVE-2025-0282 and CVE-2025-22457 since December 2024. The ongoing attacks demonstrate advanced persistent threat techniques, …

Sophos Intercept X for Windows Vulnerabilities Enable Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three critical vulnerabilities in the Sophos Intercept X for Windows product family could allow local attackers to achieve arbitrary code execution with system-level privileges. Identified as CVE-2024-13972, CVE-2025-7433, and CVE-2025-7472, …

Ubiquiti UniFi Devices Vulnerability Allows Attackers to Inject Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability affecting multiple Ubiquiti UniFi Access devices could allow attackers to execute malicious commands remotely.  The vulnerability, tracked as CVE-2025-27212, stems from improper input validation and has …

Threat Actors Weaponizing GitHub Accounts To Host Payloads, Tools and Amadey Malware Plug-Ins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Malware-as-a-Service operation has emerged that exploits the trusted GitHub platform to distribute malicious payloads, representing a significant evolution in cybercriminal tactics. The operation leverages fake GitHub accounts to …

New “Daemon Ex Plist” Vulnerability Gives Attackers Root Access on macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in macOS allows attackers to escalate privileges to root access through misconfigured daemon services.  The vulnerability, dubbed “Daemon Ex Plist,” exploits weaknesses in how macOS handles service …

Hackers Launch 11.5 Million Attacks on CitrixBleed 2-Compromising Over 100 Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive wave of exploitation targeting the critical CitrixBleed 2 vulnerability (CVE-2025-5777), with over 11.5 million attack attempts recorded since its disclosure in June. The campaign has successfully compromised more …

Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In mid-2025, a new surge of targeted intrusions, attributed to the threat group known variously as Scattered Spider, Octo Tempest, UNC3944, Muddled Libra, and 0ktapus, began impacting multiple industries. Initially …

CISA Releases 3 ICS Advisories Covering Vulnerabilities and Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA issued three significant Industrial Control Systems (ICS) advisories on July 17, 2025, addressing critical vulnerabilities affecting energy monitoring, healthcare imaging, and access control systems.  These advisories highlight severe security …

Signal App Clone TeleMessage Vulnerability May Leak Passwords; Hackers Exploiting It

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in TeleMessageTM SGNL, an enterprise messaging system modeled after Signal, has been actively exploited by cybercriminals seeking to extract sensitive user credentials and personal data.  The …

New WAFFLED Attack Exploits AWS, Azure, Cloud Armor, Cloudflare, and ModSecurity WAFs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WAFFLED is a recently disclosed technique that evades leading Web Application Firewalls (WAFs) by targeting subtle parsing inconsistencies rather than tampering with the malicious payload itself.  By mutating innocuous elements …