TA585 Hackers Uses Unique Web Injection Technique to Deliver MonsterV2 Malware Targeting Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape continues to face new threats as sophisticated threat actors develop increasingly complex attack methodologies. A newly identified cybercriminal group, designated TA585, has emerged as a significant concern …

178,000+ Invoices With Customers Personal Records Exposes from Invoice Platform Invoicely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In early October 2025, cybersecurity researcher Jeremiah Fowler discovered a publicly accessible database belonging to Invoicely, a Vienna-based invoicing and billing platform used by over 250,000 businesses worldwide. The repository …

New IAmAntimalware Tool Injects Malicious Code Into Processes Of Popular Antiviruses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new tool called IAmAntimalware, designed to inject malicious code directly into antivirus software processes, potentially turning protective defenses into hidden backdoors for attackers. Released on October 11, 2025, …

SimonMed Data Breach Exposes 1.2 Million Patients Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SimonMed Imaging, a leading U.S. provider of outpatient medical imaging services, has disclosed a major cybersecurity incident that compromised the personal and health data of approximately 1.2 million patients. The …

ScreenConnect Abused by Threat Actors to Gain Unauthorized Remote Access to Your Computer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Remote monitoring and management (RMM) tools have long served as indispensable assets for IT administrators, providing seamless remote control, unattended access, and scripted automation across enterprise endpoints. In recent months, …

Gcore Mitigates Record-Breaking 6 Tbps DDoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Luxembourg, Luxembourg, October 14th, 2025, CyberNewsWire Surge in scale and sophistication highlights rising threats to tech and digital infrastructure Gcore, the global edge AI, cloud, network, and security solutions provider, …

Ivanti Patches 13 Vulnerabilities in Endpoint Manager Allowing Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has disclosed 13 vulnerabilities in its Endpoint Manager (EPM) software, including two high-severity flaws that could enable remote code execution and privilege escalation, urging customers to apply mitigations while …

New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the widely used Sudo utility has come under scrutiny following the public release of a proof-of-concept exploit, raising alarms for Linux system administrators worldwide. CVE-2025-32463 targets …

Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elastic has disclosed a critical vulnerability in its Elastic Cloud Enterprise (ECE) platform that allows administrators with malicious intent to execute arbitrary commands and exfiltrate sensitive data. Tracked as CVE-2025-37729 …

Russian Cybercrime Market Hub Transferring from RDP Access to Malware Stealer Logs to Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new evolution is underway in the Russian cybercrime ecosystem: market operators and threat actors are rapidly shifting from selling compromised Remote Desktop Protocol (RDP) access to trading malware stealer …