SoundCloud Confirms Data Breach – Hackers Exfiltrated User Account Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SoundCloud has confirmed a security incident involving unauthorized access to user data, revealing that hackers exfiltrated email addresses and public profile information from approximately 20% of its user base. The …

New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered account takeover campaign targeting WhatsApp users demonstrates how attackers can compromise messaging accounts without stealing passwords or exploiting technical vulnerabilities. The threat, identified as the GhostPairing Attack, …

Critical FortiGate Devices SSO Vulnerabilities Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active intrusion is targeting critical authentication bypass vulnerabilities in Fortinet’s FortiGate appliances and related products. Threat actors are exploiting CVE-2025-59718 and CVE-2025-59719 to perform unauthenticated single sign-on (SSO) logins …

PornHub Breached by ShinyHunters Group and Premium Members’ Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious hacking collective ShinyHunters has claimed responsibility for a major data breach at Mixpanel, a popular analytics provider, exposing limited user data tied to Pornhub Premium accounts. The incident, …

ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since December 2025, a concerning trend has emerged across Japanese organizations as attackers exploit a critical vulnerability in React/Next.js applications. The vulnerability, tracked as CVE-2025-55182 and known as React2Shell, represents …

New PCPcat Exploiting React2Shell Vulnerability to compromise 59,000+ Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign called PCPcat has successfully compromised more than 59,000 servers in under 48 hours through targeted exploitation of critical vulnerabilities in Next.js and React frameworks. The malware …

xHunt APT Hackers Attacking Microsoft Exchange and IIS Web Servers to Deploy Custom Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The xHunt advanced persistent threat group has firmly established itself as a sophisticated cyber-espionage actor, orchestrating targeted campaigns against organizations in Kuwait. Since its emergence in 2018, the group has …

Jaguar Land Rover Confirms Employee Data Stolen in August Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jaguar Land Rover (JLR), the iconic British luxury automaker, has finally disclosed that a cyberattack in August compromised sensitive data on current and former employees. This marks the company’s first …

JumpCloud Remote Assist for Windows Agent Flaw Let Attackers Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The JumpCloud Remote Assist vulnerability (CVE-2025-34352) exposes Windows systems to local privilege escalation and denial-of-service attacks. Discovered by XM Cyber researcher Hillel Pinto, the flaw stems from insecure file operations …

Threat Actors Advertising ‘MioLab MacOS’ Infostealer on an Underground Forum

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware threat targeting macOS users has emerged on underground cybercrime forums, with threat actors marketing a sophisticated information-stealing tool called “MioLab MacOS.” This resident infostealer comes equipped with …