Russian and North Korean Hackers Form Alliances to Attack Organizations Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

State-sponsored hacking groups have historically operated in isolation, each pursuing its own national agenda. However, new evidence reveals that two of the world’s most dangerous advanced persistent threat (APT) actors may now be working together. Russia-aligned Gamaredon and North Korea’s …

Critical FluentBit Vulnerabilities Let Attackers to Cloud Environments Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new chain of five critical vulnerabilities discovered in Fluent Bit has exposed billions of containerized environments to remote compromise. Fluent Bit, an open-source logging and telemetry agent deployed over 15 billion times globally, sits at the core of modern …

CISA Warns of Threat Actors Leveraging Commercial Spyware to Target Users of Signal and WhatsApp

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity authorities have raised fresh alarms over the spread of advanced commercial spyware targeting secure messaging apps like Signal and WhatsApp. According to a recent CISA advisory, multiple cyber threat actors actively deploy this sophisticated malware to compromise users’ smartphones, …

Threat Actors Leverage Blender Foundation Files to Deliver Notorious StealC V2 Infostealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have discovered a new attack vector targeting the creative design community by exploiting Blender, a widely used open-source 3D modeling application. Threat actors are uploading malicious files to popular asset platforms like CGTrader, containing embedded Python scripts that execute …

Threat Actors Exploiting Black Friday Shopping Hype – 2+ Million Attacks Recorded

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The 2025 Black Friday shopping season has become a prime hunting ground for cybercriminals, with threat actors recording over 2 million phishing attacks targeting online gamers and shoppers worldwide. As global e-commerce continues to grow at 7-9% annually, attackers have …

Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Canon has officially confirmed that it was targeted during the widespread hacking campaign exploiting a critical zero-day vulnerability in Oracle E-Business Suite (EBS). The attack, orchestrated by the notorious Clop ransomware gang, has impacted dozens of major organizations worldwide. The …

HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has been discovered in HashiCorp’s Vault Terraform Provider that could allow attackers to bypass authentication and access Vault without valid credentials. The vulnerability, tracked as CVE-2025-13357, affects organizations using LDAP authentication with Vault. The security issue …

Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution (RCE) vulnerability in Microsoft’s Update Health Tools (KB4023057). A widely deployed Windows component designed to expedite security updates through Intune. The flaw stems from the tool connecting to dropped Azure Blob storage accounts that attackers could register …

Top 10 Best Exposure Management Tools In 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Exposure Management is a proactive cybersecurity discipline that systematically identifies, assesses, prioritizes, and remediates security vulnerabilities and misconfigurations across an organization’s entire attack surface both internal and external. Unlike traditional, periodic vulnerability scanning, EM leverages continuous monitoring, threat intelligence, and …

ClickFix Attack Uses Steganography to Hide Malicious Code in Fake Windows Security Update Screen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of ClickFix attacks is abusing highly realistic fake Windows Update screens and PNG image steganography to secretly deploy infostealing malware such as LummaC2 and Rhadamanthys on victim systems. The campaigns rely on tricking users into manually running …