Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In mid-2025, a new surge of targeted intrusions, attributed to the threat group known variously as Scattered Spider, Octo Tempest, UNC3944, Muddled Libra, and 0ktapus, began impacting multiple industries. Initially …

CISA Releases 3 ICS Advisories Covering Vulnerabilities and Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA issued three significant Industrial Control Systems (ICS) advisories on July 17, 2025, addressing critical vulnerabilities affecting energy monitoring, healthcare imaging, and access control systems.  These advisories highlight severe security …

Signal App Clone TeleMessage Vulnerability May Leak Passwords; Hackers Exploiting It

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in TeleMessageTM SGNL, an enterprise messaging system modeled after Signal, has been actively exploited by cybercriminals seeking to extract sensitive user credentials and personal data.  The …

New WAFFLED Attack Exploits AWS, Azure, Cloud Armor, Cloudflare, and ModSecurity WAFs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WAFFLED is a recently disclosed technique that evades leading Web Application Firewalls (WAFs) by targeting subtle parsing inconsistencies rather than tampering with the malicious payload itself.  By mutating innocuous elements …

Hackers are Using ClickFix Techniques to Deliver NetSupport RAT, Latrodectus and Lumma Stealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Emerging in late 2024 and surging throughout the first half of 2025, ClickFix has become a pervasive social-engineering vector in which threat actors trick users into executing malicious commands under …

BIND 9 Vulnerabilities Expose Organizations to Cache Poisoning and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical vulnerabilities in the BIND 9 DNS resolver software are affecting organizations worldwide, with potential cache poisoning and denial-of-service attacks.  The vulnerabilities, identified as CVE-2025-40776 and CVE-2025-40777, pose significant …

Microsoft Entra ID Vulnerability Let Attackers Escalate Privileges to Global Admin Role

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Microsoft Entra ID allows attackers to escalate privileges to the Global Administrator role through the exploitation of first-party applications.  The vulnerability, reported to Microsoft Security Response …

Ukraine Hackers Claimed Cyberattack on Major Russian Drone Supplier

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Last week, Ukraine’s Main Intelligence Directorate (GUR) orchestrated a sophisticated cyberattack against Gaskar Integration, a leading Russian drone manufacturer. The operation began with reconnaissance of the company’s public-facing infrastructure, where …

Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Chinese state-sponsored cyber espionage campaign has emerged targeting Taiwan’s critical semiconductor industry, employing weaponized Cobalt Strike beacons and advanced social engineering tactics. Between March and June 2025, multiple …