Prompt Injection Flaw in GitHub Actions Hits Fortune 500 Firms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new class of prompt injection vulnerabilities, dubbed “PromptPwnd,” has been uncovered by cybersecurity firm Aikido Security. The flaws affect GitHub Actions and GitLab CI/CD pipelines that are integrated with …

SpyCloud Data Shows Corporate Users 3x More Likely to Be Targeted by Phishing Than by Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Austin, TX, USA, December 4th, 2025, CyberNewsWire Phishing has surged 400% year-over-year, highlighting need for real-time visibility into identity exposures. SpyCloud, the leader in identity threat protection, today released new …

New SVG Clickjacking Attack Let Attackers Create Interactive Clickjacking Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Clickjacking has long been considered a “dumb” attack in the cybersecurity world. Traditionally, it involves placing an invisible frame over a legitimate website to trick a user into clicking a …

CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerability has been added to CISA’s Known Exploited Vulnerabilities list, warning organizations about a dangerous file-upload flaw in OpenPLC ScadaBR systems. The vulnerability allows remote authenticated users to upload …

Arizona Attorney General Suses Chinese E-commerce Retailer Temu Over Data Theft Claims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Arizona Attorney General Kris Mayes has announced a lawsuit against the popular Chinese e-commerce retailer Temu, accusing the company of stealing vast amounts of customer data. The lawsuit, filed Tuesday, …

Lazarus Group’s IT Workers Scheme Hacker Group Caught Live On Camera

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lazarus Group’s Famous Chollima unit has been caught “live on camera” running its remote IT worker scheme, after researchers funneled its operatives into fake laptops that were actually long‑running sandbox …

Threat Actors Leveraging Foxit PDF Reader to Gain System Control and Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have discovered a clever way to slip malware onto job seekers’ computers by disguising malicious files as legitimate recruitment documents. A new campaign called ValleyRAT targets people actively searching …

New Phishing Attack Mimic as Income Tax Department of India Delivers AsyncRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A comprehensive phishing operation began targeting Indian companies in November 2025 by impersonating the Income Tax Department of India. The campaign employed remarkably authentic government communication templates, bilingual messaging in …

PickleScan 0-Day Vulnerabilities Enable Arbitrary Code Execution via Malicious PyTorch Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical zero‑day vulnerabilities in PickleScan, a popular open‑source tool used to scan machine learning models for malicious code. PickleScan is widely used in the AI world, including by Hugging Face, …

Hackers Using Evilginx to Steal Session Cookies and Bypass Multi-Factor Authentication Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing toolkit known as Evilginx is empowering attackers to execute advanced attacker-in-the-middle (AiTM) campaigns with alarming success. These attacks are engineered to steal temporary session cookies, allowing threat …