Google Patches Android 0-Day Vulnerabilities Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released critical security updates to address multiple zero-day vulnerabilities affecting Android devices worldwide. The December 2025 security bulletin reveals that threat actors are actively exploiting at least two of these vulnerabilities in real-world attacks, prompting urgent action from …

OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenVPN has released critical security updates for its 2.6 stable and 2.7 development branches, addressing three vulnerabilities that could lead to local denial-of-service (DoS), security bypasses, and buffer over-reads. The patches, included in the newly released version 2.6.17 and 2.7_rc3, …

India Mandates ‘Undeletable’ Government Cybersecurity App for All Smartphones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

India’s Department of Telecommunications (DoT) has ordered smartphone manufacturers to preload a government-backed cybersecurity app, “Sanchar Saathi,” on all new devices sold in the country. The order, issued privately on November 28, 2025, gives major players like Apple, Samsung, Xiaomi, …

Malicious VS Code Extension as Icon Theme Attacking Windows and macOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious Visual Studio Code extension posing as the popular “Material Icon Theme” has been used to attack Windows and macOS users, turning the add-on into a hidden backdoor. The fake extension shipped through the marketplace with backdoored files, giving …

Chinese Front Companies Providing Advanced Steganography Solutions for APT Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Advanced steganography techniques are becoming increasingly central to state-sponsored cyber operations. Recent analysis has exposed two Chinese technology companies, BIETA and CIII, that allegedly provide sophisticated steganography solutions to support advanced persistent threat campaigns. These organizations operate as front companies …

KimJongRAT Attacking Windows Users via Weaponized .hta Files to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new remote access trojan dubbed KimJongRAT has surfaced, posing a severe threat to Windows users. This sophisticated malware is believed to be orchestrated by the Kimsuky group, a threat actor with alleged state backing. The campaign typically begins with …

Hackers Registered 2,000+ Fake Holiday-Themed Online Stores to Steal User Payments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With the holiday shopping season kicking into high gear, a massive cybersecurity threat has emerged, putting online shoppers at significant risk. A coordinated campaign has been discovered, involving the registration of over 2,000 fake holiday-themed online stores. These malicious sites …

BreachLock Named a Leader in 2025 GigaOm Radar Report for Penetration Testing as a Service (PTaaS) for Third Consecutive Year

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, New York, December 1st, 2025, CyberNewswire BreachLock, the global leader in Penetration Testing as a Service (PTaaS), has been named a Leader and Fast Mover in the 2025 GigaOm Radar Report for PTaaS for the third year in a row. …

TangleCrypt Windows Packer with Ransomware Payloads Evades EDR Using ABYSSWORKER Driver

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered Windows malware packer named TangleCrypt has emerged as a serious threat in ransomware attacks, specifically designed to evade endpoint detection and response (EDR) solutions. The packer was first observed during a September 2025 ransomware incident involving Qilin …

Microsoft Confirms New Outlook Bug Blocking Excel Attachments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has acknowledged a frustrating new issue affecting users of the “new Outlook” for Windows, where Excel attachments fail to open if their filenames contain non-ASCII characters. The technical glitch, tracked under the reference ID EX1189359, triggers a vague error …