One Identity Safeguard Named a Visionary in the 2025 Gartner Magic Quadrant for PAM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Alisa Viejo, CA, USA, November 27th, 2025, CyberNewsWire Gartner has recognized One Identity as a Visionary in the 2025 Gartner Magic Quadrant for Privileged Access Management (PAM).  In a rapidly transforming market, innovation and demonstrated performance continue to shape expectations. The …

Quttera Launches “Evidence-as-Code” API to Automate Security Compliance for SOC 2 and PCI DSS v4.0V

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New API capabilities and AI-powered Threat Encyclopedia eliminate manual audit preparation, providing real-time compliance evidence and instant threat intelligence Quttera today announced major enhancements to its Web Malware Scanner API that transform static security scanning into automated compliance evidence. The …

Shai Hulud v2 Exploits GitHub Actions Workflows as Attack Vector to Steal Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The software supply chain is under siege from “Shai Hulud v2,” a sophisticated malware campaign that has compromised 834 packages across the npm and Maven ecosystems. This new wave specifically targets GitHub Actions workflows, exploiting pull_request_target triggers to inject malicious …

Qilin RaaS Exposed 1 Million Files and 2 TB of Data Linked to Korean MSP Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The “Korean Leaks” campaign has emerged as one of the most sophisticated supply chain attacks targeting South Korea’s financial sector in recent memory. This operation combined the capabilities of the Qilin Ransomware-as-a-Service (RaaS) group with potential involvement from North Korean …

Dead Man’s Switch – Widespread npm Supply Chain Attack Driving Malware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab’s Vulnerability Research team has uncovered a large-scale supply chain attack spreading a destructive malware variant through the npm ecosystem. The malware, an evolved version of “Shai-Hulud,” contains a dangerous feature that threatens to destroy user data if attackers lose …

NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An urgent security update for its DGX Spark AI workstation after discovering 14 vulnerabilities in the system’s firmware that could allow attackers to execute malicious code and launch denial-of-service attacks. The most severe flaw has a CVSS score of 9.3 …

KawaiiGPT – Free WormGPT Variant Leveraging DeepSeek, Gemini, and Kimi-K2 AI Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

KawaiiGPT emerges as an accessible, open-source tool that mimics the controversial WormGPT, providing unrestricted AI assistance via jailbroken large language models. Hosted on GitHub with over 188 stars and 52 forks, it requires no API keys and installs quickly on …

North Korean Hackers Exploiting npm, GitHub, and Vercel to Deliver OtterCookie Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major security threat has emerged targeting software developers worldwide. North Korean state-sponsored threat actors, operating under the “Contagious Interview” campaign, are systematically spreading malicious packages across npm, GitHub, and Vercel infrastructure to deliver OtterCookie malware. This sophisticated multi-stage operation …

Gitlab Patches Multiple Vulnerabilities that Enable Authentication Bypass and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released critical security updates for its Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities. The patches, rolled out in versions 18.6.1, 18.5.3, and 18.4.5, fix security flaws that could allow attackers to bypass authentication, steal user credentials, …

Hackers Actively Exploiting IoT Vulnerabilities to Deploy New ShadowV2 Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

During late October 2025, a new malware campaign dubbed ShadowV2 emerged, coinciding with a global AWS disruption. This sophisticated threat actively exploits vulnerabilities in IoT devices to assemble a botnet for distributed denial-of-service (DDoS) attacks. The malware’s rapid deployment indicates …