China Hacked Email Systems Used by US Congressional Staff, New Report

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Chinese hacking group has breached email systems accessed by staffers on critical U.S. House committees, exposing sensitive communications amid escalating cyber tensions between Washington and Beijing. The Financial …

Top 50 Best Penetration Testing Companies in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Penetration testing companies serve as vital cybersecurity allies, simulating real-world cyberattacks to expose vulnerabilities in systems, networks, and applications before malicious actors strike. Employing ethical hackers with advanced techniques, they …

BlueDelta Hackers Attacking Microsoft OWA, Google, and Sophos VPN Users to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BlueDelta, a Russian state-sponsored threat group linked to the country’s military intelligence agency known as the GRU, has expanded its credential-stealing operations significantly throughout 2025. Between February and September, the …

Ni8mare Vulnerability Let Attackers Hijack n8n Servers – Exploit Released and 26,512 Hosts Vulnerable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical unauthenticated remote code execution vulnerability discovered in n8n, the popular workflow automation platform, exposes an estimated 100,000 servers globally to complete takeover. Tracked as CVE-2026-21858 with a maximum …

Three Malicious NPM Packages Attacking Developers to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three malicious npm packages are targeting JavaScript developers to steal browser logins, API keys, and cryptocurrency wallet data. The packages, named bitcoin-main-lib, bitcoin-lib-js, and bip40, were uploaded to the public …

Hackers Exploiting VMware ESXi Instances in the Wild Using zero-day Exploit Toolkit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are exploiting VMware ESXi instances in the wild with a zero-day exploit toolkit that chains multiple vulnerabilities for VM escapes. Cybersecurity firm Huntress disrupted one such attack, attributing initial …

Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns Delivering Multiple Malware Families

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Windows packer known as pkr_mtsi has emerged as a powerful tool for delivering multiple malware families through widespread malvertising campaigns. First detected on April 24, 2025, this malicious …

ownCloud Urges Users to Enable Multi-Factor Authentication Following Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ownCloud has urgently urged users of its Community Edition to enable multi-factor authentication (MFA). A threat intelligence report from Hudson Rock highlighted incidents in which attackers compromised self-hosted file-sharing platforms, …

GoBruteforcer Botnet brute-forces Passwords for FTP, MySQL, and phpMyAdmin on Linux Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Go-based botnet dubbed GoBruteforcer is aggressively targeting Linux servers worldwide, brute-forcing weak passwords on internet-exposed services including FTP, MySQL, PostgreSQL, and phpMyAdmin. Check Point Research recently documented a …