CISA Warns of Dassault Systèmes Vulnerabilities Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added two critical vulnerabilities affecting Dassault Systèmes DELMIA Apriso to its Known Exploited Vulnerabilities catalog, warning that threat actors are actively exploiting these security flaws in real-world attacks. …

Hackers Allegedly Claim Breach Of HSBC USA Customers’ Records Including Financial Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has claimed responsibility for breaching HSBC USA, alleging possession of a vast database containing sensitive customer personal identifiable information (PII) and financial details. The hacker posted screenshots …

Google Wear OS Message App Vulnerability Let Any Installed App To Send SMS Behalf Of User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A vulnerability in Google Messages on Wear OS devices allows any installed app to silently send SMS, MMS, or RCS messages on behalf of the user. Dubbed CVE-2025-12080, the issue …

New Beast Ransomware Actively Scans for Active SMB Port from Breached System to Spread Across Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Beast ransomware group has emerged as a significant threat in the cybersecurity landscape, evolving from the Monster ransomware strain to establish itself as a formidable Ransomware-as-a-Service operation. Officially launched …

Microsoft Sued for Allegedly Misleading Millions to Subscribe for Microsoft 365 Subscriptions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Australia’s competition regulator has filed legal proceedings against Microsoft for allegedly misleading approximately 2.7 million Australian consumers regarding subscription options and pricing for Microsoft 365 plans. The Australian Competition and …

Magento Input Validation Vulnerability Exploited In Wild To Hijack Session And Execute Malicious Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Magento, the popular e-commerce platform, is now rebranded as Adobe Commerce. Dubbed SessionReaper and tracked as CVE-2025-54236, this improper input validation flaw allows attackers to hijack …

Microsoft Details ASP.NET Vulnerability That Enables Attackers To Smuggle HTTP Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued a critical security update for ASP.NET Core to address CVE-2025-55315, a high-severity flaw that enables HTTP request smuggling and could allow attackers to bypass key security controls. …

Docker Compose Vulnerability Allow Attacks To Overwrite Arbitrary Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Docker Compose, a cornerstone tool for developers managing containerized application harbors a high-severity vulnerability that lets attackers overwrite files anywhere on a host system. Discovered in early October 2025 by …

New Android Malware Herodotus Mimic Human Behaviour to Bypass Biometrics Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android banking trojan named Herodotus has emerged on the mobile threat landscape, introducing groundbreaking techniques to evade detection systems. During routine monitoring of malicious distribution channels, the Mobile …

New Phishing Attack Using Invisible Characters Hidden in Subject Line Using MIME Encoding

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have developed a sophisticated phishing technique that exploits invisible characters embedded within email subject lines to evade automated security filters. This attack method leverages MIME encoding combined with Unicode …