15+ Weaponized npm Packages Attacking Windows Systems to Deliver Vidar Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply-chain attack has emerged targeting Windows systems through compromised npm packages, marking a critical vulnerability in open-source software distribution. Between October 21 and 26, 2025, threat actors published …

New Phising Attack Targeting Travellers from Hotel’s Compromised Booking.com Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign is actively targeting hotel establishments and their guests through compromised Booking.com accounts, according to research uncovered by security experts. The campaign, dubbed “I Paid Twice” due …

Chinese Hackers Organization Influence U.S. Government Policy on International Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China-linked threat actors have intensified their focus on influencing American governmental decision-making processes by targeting organizations involved in shaping international policy. In April 2025, a sophisticated intrusion into a U.S. …

Researchers Evaded Elastic EDR’s Call Stack Signatures by Exploiting Call Gadgets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have successfully evaded Elastic EDR’s call stack signature detection by exploiting a technique involving “call gadgets” to bypass the security tool’s behavioral analysis. The Almond research builds on …

LeakyInjector and LeakyStealer Malwares Attacks Users to Steal Crypto’s and Browser History

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous two-stage malware threat, LeakyInjector and LeakyStealer, that targets cryptocurrency wallets and personal browser information explicitly. The malware duo works in tandem to steal sensitive data from infected Windows …

Cavalry Werewolf Attacking Government Organizations to Deploy Backdoor for Network Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In July 2025, a sophisticated hacker group known as Cavalry Werewolf executed a targeted campaign against Russian government institutions, compromising critical infrastructure through coordinated phishing operations. The discovery of this …

Amazon WorkSpaces For Linux Vulnerability Let Attackers Extract Valid Authentication Token

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon has disclosed a significant security vulnerability in its WorkSpaces client for Linux that could allow unauthorized users to extract valid authentication tokens and gain unauthorized access to other users’ …

FreeBSD-based OPNsense Firewall Released for Security Issues and Improvements

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OPNsense has released an update focused on eliminating security vulnerabilities and improving firewall performance. The latest version includes third-party security updates, firewall improvements, and fixes that make the system more …

NVIDIA NVApp for Windows Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NVIDIA has patched a critical vulnerability in its App for Windows that could allow local attackers to execute arbitrary code and escalate privileges on affected systems. Tracked as CVE-2025-23358, the …

Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE Unexpectedly

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Cisco Identity Services Engine (ISE) could allow remote attackers to crash the system through a crafted sequence of RADIUS requests. The flaw CVE-2024-20399, lies in how …