Lumma Stealer Uses Browser Fingerprinting to Collect Data and for Stealthy C&C Server Communications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lumma Stealer has emerged as a serious threat in the cybercrime world, targeting users through fake software updates and cracked applications. This information-stealing malware targets the collection on login details, …

Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has issued an urgent advisory warning of a critical vulnerability in its FortiWeb web application firewall (WAF) product, which attackers are actively exploiting in the wild. Identified as CVE-2025-64446, …

Beware of Phishing Emails as Spam Filter Alerts Steal Your Email Logins in a Blink

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have launched a new phishing campaign that tricks users by impersonating legitimate spam-filter notifications from their own company. These fake emails claim that your organization recently upgraded its Secure …

Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On November 7th, security researchers discovered a dangerous malicious npm package called “@acitons/artifact” that had already been downloaded more than 206,000 times. The package was designed to look like the …

NVIDIA NeMo Framework Vulnerabilities Allows Code Injection and Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NVIDIA has issued a critical security update addressing two high-severity vulnerabilities in its NeMo Framework that could allow attackers to execute malicious code and escalate privileges on affected systems. The …

SmartApeSG Campaign Leverages ClickFix Technique to Deploy NetSupport RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The SmartApeSG campaign, also known as ZPHP or HANEY MANEY, continues to evolve its attack methods to compromise Windows systems with malicious remote access tools. First reported in June 2024, …

Threat Actors Leverage JSON Storage Services to Host and Deliver Malware Via Trojanized Code Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated campaign where threat actors abuse legitimate JSON storage services to deliver malware to software developers. The campaign, known as Contagious Interview, represents a significant …

Multiple vulnerabilities in Cisco Unified CCX Allow Attackers to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has released security updates to address two critical vulnerabilities in Unified Contact Center Express (Unified CCX) that could allow unauthenticated attackers to execute arbitrary commands with root privileges and …

Hackers Flooded npm Registry Over 43,000 Spam Packages Survived for Almost Two Years

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researcher Paul McCarty uncovered a significant coordinated spam campaign targeting the npm ecosystem. The IndonesianFoods worm, as it has been named, consists of more than 43,000 spam packages published …

Washington Post Oracle E-Suite 0-Day Hack Impacts 9K+ Employees and Contractors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Washington Post has publicly disclosed a significant data breach involving external hacking of its Oracle E-Suite system, impacting over 9,700 employees and contractors worldwide. The breach notification, filed with …