New Multi-stage JS#SMUGGLER Malware Attack Delivers ‘NetSupport RAT’ to Gain Full System Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign using multiple attack stages has been discovered that delivers NetSupport RAT through hidden web-based redirects and obfuscated code. The attack unfolds in three stages, starting with a JavaScript loader injected into compromised websites. This first stage …

SAP Security Patch Day: Fix for Critical Vulnerabilities in SAP Solution Manager, NetWeaver, and Other Products

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SAP released 14 new security notes on its monthly Security Patch Day on December 9, 2025, addressing vulnerabilities across key products, including SAP Solution Manager, NetWeaver, Commerce Cloud, and more. Three critical flaws with CVSS scores exceeding 9.0 demand immediate …

500+ Apache Tika Toolkit Instances Vulnerable to Critical XXE Attack Exposed Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 565 internet-exposed Apache Tika Server instances are vulnerable to a critical XML External Entity (XXE) injection flaw. That could enable attackers to steal sensitive data, launch denial-of-service attacks, or conduct server-side request forgery operations. The vulnerability, tracked as CVE-2025-66516, …

Burp Suite’s Scanning Arsenal Powered With Detection for Critical React2Shell Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PortSwigger has enhanced Burp Suite’s scanning arsenal with the latest update to its ActiveScan++ extension, introducing detection for the critical React2Shell vulnerabilities (CVE-2025-55182 and CVE-2025-66478). This server-side request forgery (SSRF) flaw in React applications allows attackers to execute arbitrary shell …

Apple, Google and Samsung May Enable Always-On GPS in India

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Indian government is currently evaluating a controversial proposal from the telecom industry that would mandate smartphone manufacturers to enable “always-on” satellite location tracking. This move has sparked significant opposition from major technology companies, including Apple, Google, and Samsung, who …

Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A deceptive Android application lurking in the Google Play Store, disguised as a document reader and file manager, but delivering the Anatsa banking trojan to users. Cybersecurity firm Zscaler ThreatLabz found an app named “Document Reader – File Manager” by …

Hackers Exploit AWS IAM Eventual Consistency for Persistence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical persistence technique in AWS Identity and Access Management (IAM) stemming from its eventual consistency model, allowing attackers to retain access even after defenders delete compromised access keys. AWS IAM, like many distributed systems, employs eventual consistency to scale …

New GhostFrame Super Stealthy Phishing Kit Attacks Millions of Users Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing kit called GhostFrame has already been used to launch over 1 million attacks. First discovered in September 2025 by Security researchers at Barracuda, this stealthy tool represents a dangerous evolution in phishing-as-a-service technology. What makes GhostFrame …

INE Earns G2 Winter 2026 Badges Across Global Markets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cary, North Carolina, USA, December 4th, 2025, CyberNewsWire Cybersecurity and IT training platform maintains Leader and Momentum Leader positions while expanding regional excellence INE has been recognized with seven G2 Winter 2026 badges, underscoring its continued leadership in online course …

FBI Warns of Hackers Altering Photos Found on Social Media to Use as Fake Proof

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new alert warns people about a growing scam that uses altered photos to trick families into paying fake ransom demands. In a notice titled Alert Number: I-120525-PSA, dated December 5, 2025. The FBI explains that criminals are taking photos …