29.7 Tbps DDoS Attack Via Aisuru Botnet Breaks Internet With New World Record

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new 29.7 Tbps distributed denial-of-service (DDoS) blast from the Aisuru botnet has set a new world record for attack volume, underscoring how fragile core internet infrastructure remains under extreme load. The previous record of 22Tbps, quietly broken in Q3 …

Hackers Using Calendly-Themed Phishing Attack to Steal Google Workspace Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged targeting business professionals with Calendly-themed emails, combining social engineering with advanced credential theft techniques. The attack specifically focuses on Google Workspace and Facebook Business accounts, using carefully crafted job opportunity lures to trick users …

K7 Antivirus Vulnerability Allows Attackers Gain SYSTEM-level Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious privilege escalation vulnerability in K7 Ultimate Security, an antivirus product from K7 Computing, was found by abusing named pipes with overly permissive access control lists. This flaw enables low-privileged users to manipulate registry settings and achieve SYSTEM-level access …

Shai-Hulud 2.0 Malware Attack Compromised 30,000 Repositories and Stolen 500 GitHub Usernames and Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant supply chain security breach has emerged with the discovery of Shai-Hulud 2.0, a sophisticated malware that has compromised over 30,000 GitHub repositories since its emergence on November 24, 2025. This worm-like malware represents a growing threat to the …

Malicious Rust Evm-Units Mimic as EVM Version Silently Executes OS-specific Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The open-source software supply chain recently encountered a deceptive threat in the form of evm-units, a malicious Rust crate published by the author ablerust. Masquerading as a standard utility for verifying Ethereum Virtual Machine (EVM) versions, the package accumulated thousands …

Storm-0900 Hackers Leveraging Parking Ticket and Medical Test Themes in Massive Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On Thanksgiving eve, a sophisticated threat actor known as Storm-0900 launched a high-volume phishing campaign targeting users across the United States. Microsoft Threat Intelligence security analysts detected and blocked this coordinated attack consisting of tens of thousands of emails designed …

Microsoft Patched Windows LNK Vulnerability Abused by Hackers to Hide Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has silently patched a Windows shortcut vulnerability that threat actors have been exploiting since 2017 to hide malicious commands from users inspecting file properties. The flaw, tracked as CVE-2025-9491, was addressed in Microsoft’s November 2025 Patch Tuesday updates but …

CISA Warns of Android 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added two critical Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling active exploitation in the wild. The vulnerabilities affect the Android OS and pose significant risks to millions of mobile devices worldwide. CISA added the vulnerabilities …

MuddyWater Attacks Critical Infrastructure With Custom Malware and Improved Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MuddyWater, an Iran-aligned cyberespionage group also known as Mango Sandstorm, has launched a new, highly targeted campaign against critical infrastructure in Israel and Egypt. Active from September 2024 through March 2025, the group zeroed in on diverse sectors including engineering, …

Microsoft Confirms Windows 11 25H2 UI Features Broken Along With 24H2 Following Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially confirmed a critical issue affecting enterprise and managed environments running Windows 11 versions 24H2 and 25H2. The bug, first triggered by cumulative updates released in July 2025, causes widespread failures in essential UI components, rendering the desktop …