New Prompt Injection Attack via Malicious MCP Servers Let Attackers Drain Resources

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered critical vulnerabilities in the Model Context Protocol (MCP) sampling feature. Revealing how malicious servers can exploit LLM-integrated applications to conduct resource theft, conversation hijacking, and unauthorized system modifications. Attack Vector Mechanism Impact Resource theft Hidden instructions …

Proofpoint Acquires Hornetsecurity in $1.8 Billion Deal to Strengthen SMB Cybersecurity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Proofpoint, Inc., a pioneer in human-centric cybersecurity, has finalized its $1.8 billion acquisition of Hornetsecurity Group, a dominant European provider of AI-driven Microsoft 365 security solutions. The deal, announced today, catapults Proofpoint’s reach into the SMB market via MSP channels, …

Malicious VS Code on Microsoft Registry Captures Your Screen and Steals Your WiFi Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly weaponizing developer environments, as seen in a newly discovered malware campaign infiltrating the Visual Studio Code Marketplace. Unlike typical extensions that simply harvest credentials or mine cryptocurrency, this sophisticated attack actively captures screenshots of a victim’s desktop, …

GhostPenguin Backdoor With Zero-Detection Attacking Linux Servers Uncovered Using AI-Automated Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A previously undocumented Linux backdoor named GhostPenguin has been discovered evading detection for over four months. This multi-threaded C++ malware establishes remote shell access and file-system operations via encrypted UDP, making it exceptionally difficult to detect with traditional security tools. …

Hackers Exploiting Vulnerabilities in Ivanti Connect Secure to Deploy MetaRAT Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A China-based attack group has launched a targeted campaign against Japanese shipping and transportation companies by exploiting critical vulnerabilities in Ivanti Connect Secure (ICS). The campaign, uncovered in April 2025, leverages two severe vulnerabilities to gain initial access to target …

New Mirai Botnet Variant ‘Broadside’ Actively Attacking Users in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of the Mirai botnet, named “Broadside,” has emerged as an active threat targeting maritime shipping companies and vessel operators. The malware exploits a critical vulnerability in TBK Digital Video Recorder (DVR) devices used for security monitoring …

Microsoft Copilot Disruption in the UK: Users Face Access Issues and Degraded Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft 365 services encountered a snag today, leaving users in the United Kingdom struggling to access Microsoft Copilot or experiencing reduced functionality in key features. The outage, flagged on the official Microsoft 365 Status X account, has raised concerns among businesses …

AI-Powered Free Security-Audit Checklist for 2026 – ISO 27001, SOC 2, NIST, NIS 2 and GDPR Compliance 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In many companies, audit preparation in 2025 still feels like 2005: Excel lists, scattered evidence, copy & paste from old answers, long coordination loops. At the same time, requirements are increasing – ISO 27001:2022, SOC 2, NIST CSF, NIS 2, …

Authorities Arrested Hackers With Specialized FLIPPER Hacking Equipment Used to Attack IT Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Authorities in Warsaw have arrested three suspected hackers found carrying specialized FLIPPER hacking equipment. Other tools are allegedly intended to attack IT and telecommunications systems. The suspects, all Ukrainian citizens aged 43, 42, and 39, were detained during a routine …

Operation FrostBeacon Attacking Finance and Legal Departments with Cobalt Strike Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged targeting financial and legal sectors in the Russian Federation, delivering the notorious Cobalt Strike remote access tool to organizations handling sensitive business transactions. Security researchers have identified over twenty initial infection files involved in …