BMW Allegedly Breached by Everest Ransomware Group, Internal Documents Reportedly Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The infamous Everest ransomware group has reportedly included Bayerische Motoren Werke AG (BMW) as a high-profile target, claiming the theft of a significant amount of critical internal documents from the …

Researchers Uncover Hidden Connections Between Ransomware Groups and Relationships Between Them

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, cybersecurity researchers have exposed a tangled web of hidden alliances among leading ransomware operations, reshaping how defenders perceive these threats. Historically treated as distinct entities—Conti, LockBit, Evil …

Lessons Learned from Massive npm Supply Chain Attack Using “Shai-Hulud” Self-Replicating Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The JavaScript ecosystem experienced one of its most sophisticated and damaging supply chain attacks in September 2025, when a novel self-replicating worm dubbed “Shai-Hulud” compromised over 477 npm packages, marking the …

Beware of Typosquatted Malicious PyPI Packages That Delivers SilentSync RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Python developers face a growing threat from typosquatted packages in the Python Package Index (PyPI), with malicious actors increasingly targeting this trusted repository to distribute sophisticated malware. Recent discoveries have …

Raven Stealer Attacking Google Chrome Users to Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Raven Stealer has emerged as a potent information‐stealing threat targeting users of Chromium‐based browsers, most notably Google Chrome. First observed in mid-2025, this lightweight malware distinguishes itself through a modular …

Jenkins Patches Multiple Vulnerabilities that Allow Attackers to Cause a Denial of Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jenkins has released critical updates addressing four security flaws that unauthenticated and low-privileged attackers could exploit to disrupt service or glean sensitive configuration details.  Administrators running Jenkins weekly releases up …

Pixie Dust Wi-Fi Attack Exploits Routers WPS to Obtain PIN and Connect With Wireless Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The newly publicized Pixie Dust attack has once again exposed the critical vulnerabilities inherent in the Wi-Fi Protected Setup (WPS) protocol, enabling attackers to extract the router’s WPS PIN offline …

TP-Link Router 0-Day RCE Vulnerability Exploited Bypassing ASLR Protections – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day remote code execution (RCE) vulnerability, identified as CVE-2025-9961, has been discovered in TP-Link routers. Security research firm ByteRay has released a proof-of-concept (PoC) exploit, demonstrating how attackers …

Top 10 Best Next‑Generation Firewall (NGFW) Providers in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Protecting digital infrastructure is critical in 2025, as cyber threats escalate in complexity and diversity. Next‑Generation Firewalls (NGFWs) have become the cornerstone for enterprise security, offering not just robust traffic …

Top 10 Best Dynamic Application Security Testing (DAST) Platforms in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dynamic Application Security Testing (DAST) platforms have become fundamental for safeguarding web applications as digital assets and attack surfaces scale in both size and complexity. The modern DAST landscape is …