Hackers Impersonate Linux Foundation Leader in Slack to Target Open Source Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Open source developers are facing a growing and sophisticated threat — one that does not rely on complex exploits or hidden vulnerabilities but instead uses something far simpler: trust. A …

CISA Warns of Critical Ivanti EPMM Code Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in Ivanti Endpoint Manager Mobile (EPMM). The agency recently added this flaw, tracked …

GitLab Patches Multiple Vulnerabilities That Enables DoS and Code Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released urgent security updates (versions 18.10.3, 18.9.5, and 18.8.9) for its Community Edition (CE) and Enterprise Edition (EE) to address high-severity flaws that enable Denial-of-Service (DoS) and code-injection …

Hackers Claim to Have Stolen 10 Petabytes of Data from China’s Tianjin Supercomputer Center

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are claiming that one of China’s most strategically important computing facilities suffered a massive cyber intrusion, with more than 10 petabytes of sensitive information allegedly taken from a state-run …

Microsoft Suspends Developer Accounts of High-Profile Open-Source Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has suspended the Windows Hardware Program developer accounts of two critical open-source security projects, VeraCrypt and WireGuard, blocking their ability to sign drivers and push updates to millions of …

New RoningLoader Campaign Uses DLL Side-Loading and Code Injection to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as DragonBreath has launched a stealthy campaign using a multi-stage malware loader called RoningLoader. The malware targets Chinese-speaking users by disguising itself as trusted software such …

Critical Chrome Vulnerabilities Let Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome 147 to the stable channel for Windows, Mac, and Linux, patching a sweeping set of security vulnerabilities — including two critical-severity flaws that could allow remote …

New Silver Fox Campaign Hides ValleyRAT Inside Fake Telegram Chinese Language Pack Installer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign linked to the Silver Fox APT group has been discovered, using a fake Telegram Chinese language pack installer to secretly deliver ValleyRAT — a powerful remote …

Hackers Abuse Legitimate Meta Business Manager Notifications to Deliver Phishing Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign is actively targeting businesses worldwide by exploiting one of the most trusted tools in digital marketing — Meta’s Business Manager platform. Cybercriminals have found a clever …

Microsoft 365 Network-Level Disruption Affecting Exchange Online, Teams, and Core Suite Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A network-level disruption struck multiple Microsoft 365 services on Wednesday evening, knocking out or degrading access to Exchange Online, Microsoft Teams, and the broader Microsoft 365 suite for users across …