Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated campaign targeting macOS users has emerged through spoofed Homebrew installer websites that deliver malicious payloads alongside legitimate package manager installations. The attack exploits the widespread trust users place …

Pro-Russian Hacktivist Attacking OT/ICS Devices to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified pro-Russian hacktivist group has successfully infiltrated operational technology and industrial control systems belonging to critical infrastructure organizations, employing sophisticated techniques to steal login credentials and disrupt vital …

Hackers Can Bypass OpenAI Guardrails Using a Simple Prompt Injection Technique

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI’s newly launched Guardrails framework, designed to enhance AI safety by detecting harmful behaviors, has been swiftly compromised by researchers using basic prompt injection methods. Released on October 6, 2025, …

Axis Communications Vulnerability Exposes Azure Storage Account Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Axis Communications’ Autodesk Revit plugin has exposed Azure Storage Account credentials, creating significant security risks for customers and potentially enabling supply chain attacks targeting the architecture …

Hackers Leveraging Microsoft Edge Internet Explorer Mode to Gain Access to Users’ Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape witnessed a concerning development as threat actors discovered a novel attack vector targeting Microsoft Edge’s Internet Explorer mode functionality. This sophisticated campaign emerged in August 2025, exploiting …

North Korean Hackers Attacking Developers with 338 Malicious npm Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean state-sponsored threat actors have intensified their supply chain attacks against software developers through a sophisticated campaign dubbed “Contagious Interview,” deploying 338 malicious npm packages that have accumulated over …

New WhatsApp Worm Attacks Users with Banking Malware to Users Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified a sophisticated malware campaign that exploits WhatsApp’s messaging platform to deploy banking trojans targeting Brazilian financial institutions and cryptocurrency exchanges. The self-propagating worm, which emerged on …

PoC Exploit Unveiled for Lenovo Code Execution Vulnerability Enabling Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Lenovo’s Dispatcher drivers has come under the spotlight after researchers released a proof-of-concept exploit that demonstrates privilege escalation on affected Windows systems. Identified as CVE-2025-8061, this …

Linux Kernel 6.18-rc1 Released With Extensive Updates Following a Steady Merge Window

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Linus Torvalds has announced the release of Linux 6.18-rc1, marking the start of the release candidate phase for the upcoming kernel version. In his typical straightforward style, Torvalds noted that …

Scattered Lapsus$ Hunters Claim to Have Stolen More Than 1 Billion Salesforce Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Scattered Lapsus$ Hunters, a threat group previously associated with high-profile data thefts, recently claimed responsibility for exfiltrating over one billion records from Salesforce environments worldwide. Emerging in mid-2025, the group …