SolarWinds Web Help Desk Vulnerability Enables Unauthenticated RCE

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SolarWinds has released an urgent security advisory for a critical vulnerability in its Web Help Desk software that could allow an unauthenticated attacker to achieve remote code execution (RCE). The …

Hackers Exploits IMDS Service to Gain Initial Access to a Cloud Environment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors were manipulating the Instance Metadata Service (IMDS), a core component designed to securely furnish compute instances with temporary credentials to infiltrate and navigate cloud infrastructures.  By compelling unsuspecting …

GitHub Enhances NPM’s Security with Strict Authentication, Granular Tokens, and  Trusted Publishing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recent High-profile supply‐chain attacks have exposed critical weaknesses in package registry security, prompting GitHub to roll out a suite of defenses designed to harden the npm ecosystem.  “GitHub Enhances npm’s …

EV Charging Provider Confirm Data Breach – Customers Personal Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Digital Charging Solutions GmbH (DCS), a leading provider of white-label charging services for automotive OEMs and fleet operators, has confirmed a data breach affecting a limited number of its customers.  …

Hackers Hijacking IIS Servers Using Malicious BadIIS Module to Serve Malicious Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber campaign, dubbed “Operation Rewrite,” is actively hijacking Microsoft Internet Information Services (IIS) web servers to serve malicious content through a technique known as search engine optimization (SEO) …

Hackers Abusing GitHub Notifications to Deliver Phishing Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, security researchers have uncovered an elaborate phishing campaign that leverages legitimate GitHub notification mechanisms to deliver malicious content. Victims receive seemingly authentic repository alerts, complete with real-looking …

Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in Libraesva ESG email security gateways has been identified and patched, allowing threat actors to execute arbitrary commands through specially crafted email attachments.  The vulnerability, tracked …

European Airport Disruptions Caused by Sophisticated Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the weekend, a sophisticated ransomware attack compromised Collins Aerospace’s Muse check-in and boarding systems, forcing key hubs including Heathrow, Brussels, and Berlin to return to manual processes. Airlines reported …

22.2 Tbps DDoS Attack Breaks Internet With New World Record

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare announced it had autonomously mitigated the largest distributed denial-of-service (DDoS) attack ever recorded. The hyper-volumetric attack peaked at an unprecedented 22.2 terabits per second (Tbps) and 10.6 billion packets …

Top 10 Best Supply Chain Risk Management Solutions in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In today’s rapidly evolving global market, supply chain risk management has become more crucial than ever before. Organizations face risks like geopolitical issues, market unpredictability, compliance challenges, supplier failures, and …