Ukraine Police Exposed Russian Hacker Group Specializes in Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ukrainian and German law enforcement have disrupted a Russian‑affiliated hacker group that has been carrying out high‑impact ransomware attacks against organizations worldwide, causing losses estimated in the hundreds of millions …

Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has been discovered in Livewire Filemanager, a widely used file management component embedded in Laravel web applications. Tracked as CVE-2025-14894 and assigned vulnerability note VU#650657, the …

PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PDFSIDER is a newly exposed backdoor that gives attackers long term control of Windows systems while slipping past many antivirus and endpoint detection and response tools. It uses trusted software …

Researchers Gained Access to Hacker Domain Server Using Name Server Delegation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent investigation into a deceptive push-notification network shows how a simple DNS mistake can open a window into criminal infrastructure. The campaign abused browser notifications to flood Android users …

Windows SMB Client Vulnerability Enables Attacker to Own Active Directory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Windows SMB client authentication that enables attackers to compromise Active Directory environments through NTLM reflection exploitation. Classified as an improper access control vulnerability, this vulnerability allows …

CrashFix – Hackers Using Malicious Extensions to Display Fake Browser Warnings

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have discovered a sophisticated malware campaign using an unusual but effective tactic: deliberately crashing users’ browsers. The threat, named CrashFix, operates through a malicious Chrome extension disguised as …

Redmi Buds Vulnerability Allow Attackers Access Call Data and Trigger Firmware Crashes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered significant vulnerabilities in the firmware of Xiaomi’s popular Redmi Buds series, specifically affecting models ranging from the Redmi Buds 3 Pro up to the latest Redmi …

BodySnatcher – New Vulnerability Allows Attacker to Impersonate Any ServiceNow User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in ServiceNow’s Virtual Agent API and the Now Assist AI Agents application has been discovered, allowing unauthenticated attackers to impersonate any user and execute privileged AI agents …

Microsoft January 2026 Security Update Causes Credential Prompt Failures in Remote Desktop Connections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released an out-of-band emergency update to resolve a critical issue affecting Remote Desktop connections on Windows client devices. The problem emerged immediately following the installation of the January …

Mandiant Releases Rainbow Tables Enabling NTLMv1 Admin Password Hacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google-owned Mandiant has publicly released a comprehensive dataset of Net-NTLMv1 rainbow tables, marking a significant escalation in demonstrating the security risks of legacy authentication protocols. The release underscores an urgent …