Apache Log4j Vulnerability Allow Attackers to Intercept Sensitive Log Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apache Logging Services has disclosed a critical security vulnerability in Log4j Core that exposes applications to potential interception of log data. The flaw resides in the Socket Appender component. It …

New Research Uncovers the Alliance Between Qilin, DragonForce and LockBit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three major ransomware groups have joined forces to create what cybersecurity experts are calling one of the most concerning developments in the criminal underground. On September 15, 2025, the ransomware …

Cloud Atlas Hacker Group Exploiting Office Vulnerabilities to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cloud Atlas advanced persistent threat group has continued its sophisticated campaign targeting organizations across Eastern Europe and Central Asia during the first half of 2025, leveraging outdated Microsoft Office …

Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iranian state-sponsored threat actors, commonly tracked as “Prince of Persia,” have resurfaced with a sophisticated cyberespionage campaign targeting global critical infrastructure and private networks. Active since the early 2000s, this …

Scripted Sparrow Uses Automation to Generate and Send their Attack Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Scripted Sparrow is a newly identified Business Email Compromise (BEC) group operating across three continents. Their operations are vast, leveraging significant automation to generate and distribute attack messages on a …

Hackers Targeting HubSpot Users in Targeted Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active phishing campaign is currently targeting HubSpot users through a sophisticated combination of social engineering and infrastructure compromise. The attack leverages business email compromise tactics, paired with website hijacking, …

Ransomware Attack 2025 Recap – From Critical Data Extortion to Operational Disruption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware landscape in 2025 has reached new heights, evolving from a cybersecurity issue into a strategic threat to national security and global economic stability. This year saw a 34%-50% …

Hackers Using PuTTY for Both Lateral Movement and Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are increasingly abusing the popular PuTTY SSH client for stealthy lateral movement and data exfiltration in compromised networks, leaving subtle forensic traces that investigators can exploit. In a recent …

New Tool Released to Detect Cisco Secure Email Gateway 0-Day Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A lightweight Python script to help organizations quickly identify exposure to CVE-2025-20393, a critical zero-day vulnerability in Cisco Secure Email Gateway (SEG) and Secure Malware Analytics (SMA), also known as …