Tata Motors Data Leak – 70+ TB of Sensitive Info and Test Drive Data Exposed via AWS Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researcher Eaton Zveare has disclosed critical vulnerabilities in Tata Motors’ systems that exposed over 70 terabytes of sensitive data, including customer personal information, financial reports, and fleet management details. …

Pentest Copilot – AI-based Ethical Hacking Tool to Streamline Penetration Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pentest Copilot is an innovative open-source tool that leverages AI to help ethical hackers streamline penetration testing workflows. This browser-based assistant integrates large language models to automate tasks while preserving …

Aisuru Botnet Shifts from DDoS to Residential Proxies

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Aisuru, the botnet responsible for a series of record-smashing distributed denial-of-service (DDoS) attacks this year, recently was overhauled to support a more low-key, lucrative and sustainable business: Renting hundreds of …

Threat Actors Advertising Anivia Stealer Malware on Dark Web bypassing UAC Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated information-stealing malware named Anivia Stealer has emerged on underground forums, marketed by a threat actor known as ZeroTrace. The malware represents a dangerous evolution in credential theft operations, …

Threat Actors Merging FileFix and Cache Smuggling Attacks to Evade Security Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated phishing campaign that combines two emerging attack techniques to bypass conventional security defenses. The hybrid approach merges FileFix social engineering tactics with cache smuggling …

New GhostGrab Android Malware Silently Steals Banking Login Details and Intercept SMS for OTPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android banking trojan dubbed GhostGrab has emerged in the threat landscape, targeting financial institutions across multiple regions with advanced credential theft capabilities. The malware operates silently on infected …

BlueNoroff Hackers Adopts New Infiltration Strategies To Attack C-Level Executives, and Managers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The BlueNoroff threat group, also tracked as Sapphire Sleet, APT38, and TA444, has significantly evolved its targeting capabilities with sophisticated new infiltration strategies designed specifically to compromise C-level executives and …

Mozilla Wants All New Firefox Extensions to Disclose Data Collection Policies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mozilla is implementing a significant transparency requirement for Firefox extensions, mandating that all new browser add-ons disclose their data collection practices to users before installation. Starting November 3rd, 2025, developers …

XWiki RCE Vulnerability Actively Exploted In Wild To Deliver Coinminer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution (RCE) flaw in XWiki, a popular open-source wiki platform, was exploited in the wild to deploy cryptocurrency mining malware on compromised servers. The vulnerability, tracked …

How Threat Intelligence Feeds Help Organizations Quickly Mitigate Malware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Organizations today face constant threats from malware, including ransomware, phishing attacks, and zero-day exploits. These threats are evolving faster than ever. Threat intelligence feeds emerge as a game-changer, delivering real-time, …