GravityRAT with Remote Access Capabilities Attacking Windows, Android, and macOS Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GravityRAT is a remote access trojan that has been targeting government agencies and military organizations since 2016. This malware originated as a Windows-only threat but has evolved into a cross-platform tool that can attack Windows, Android, and macOS systems. The …

WhatsApp Vulnerabilities Leaks User’s Metadata Including Device’s Operating System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp’s multi-device encryption protocol has long leaked metadata, allowing attackers to fingerprint users’ device operating systems, aiding targeted malware delivery. Recent research highlights partial fixes by Meta, but transparency issues persist. Meta’s WhatsApp, with over 3 billion monthly active users, …

Gmail to Discontinue POP3 Mail Fetching for External Email Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced that Gmail will discontinue support for two key features regarding third-party email accounts. Starting in January 2026, the platform will drop support for “Gmailify” and the widely utilized “Check mail from other accounts” feature via POP3 fetching. …

Cyberattack on Higham Lane School Forced to Close its Doors to all Students and Staff

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Higham Lane School and Sixth Form has been forced to close its doors to all students and staff this week following a significant cyber-attack that has paralyzed the institution’s IT infrastructure. The attack, confirmed by school leadership over the weekend, …

Threat Actor Exploited Multiple FortiWeb Appliances to Deploy Sliver C2 for Persistent Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recent findings indicate that a sophisticated threat actor is actively exploiting multiple outdated FortiWeb appliances to deploy the Sliver Command and Control (C2) framework. This campaign highlights a concerning trend where adversaries leverage open-source offensive tools to maintain persistent access …

Critical GNU Wget2 Vulnerability Let Remote Attackers to Overwrite Sensitive Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in GNU Wget2, a widely used command-line tool for downloading files from the web. `The flaw, tracked as CVE-2025-69194, allows remote attackers to overwrite arbitrary files on a victim’s system, potentially leading to …

Threat Group ‘Crimson Collective’ Allegedly Claim Breach of Largest Fiber Broadband Brightspeed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Brightspeed, one of America’s leading fiber broadband infrastructure providers, has become the latest victim of a significant cyberattack. The threat group known as Crimson Collective has publicly claimed responsibility for breaching the company’s systems and obtaining sensitive data. Brightspeed operates …

Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security advisory addressing multiple vulnerabilities discovered in the Eaton UPS Companion (EUC) software. These security flaws, if exploited, could allow attackers to execute arbitrary code on the host system, potentially giving them complete control over affected devices. The …

Threat Actor Allegedly Claim Leak of NordVPN Salesforce Database with Source Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor operating under the identifier 1011 has publicly claimed to have obtained and leaked sensitive data from NordVPN’s development infrastructure on a dark web forum. The breach reportedly exposes over ten database source codes, along with critical authentication …

GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture to orchestrate security tools via natural-language prompts.​ Developed by GH05TCREW, …