Threat Actor Exploited Multiple FortiWeb Appliances to Deploy Sliver C2 for Persistent Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recent findings indicate that a sophisticated threat actor is actively exploiting multiple outdated FortiWeb appliances to deploy the Sliver Command and Control (C2) framework. This campaign highlights a concerning trend …

Critical GNU Wget2 Vulnerability Let Remote Attackers to Overwrite Sensitive Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in GNU Wget2, a widely used command-line tool for downloading files from the web. `The flaw, tracked as CVE-2025-69194, allows remote attackers to …

Threat Group ‘Crimson Collective’ Allegedly Claim Breach of Largest Fiber Broadband Brightspeed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Brightspeed, one of America’s leading fiber broadband infrastructure providers, has become the latest victim of a significant cyberattack. The threat group known as Crimson Collective has publicly claimed responsibility for …

Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security advisory addressing multiple vulnerabilities discovered in the Eaton UPS Companion (EUC) software. These security flaws, if exploited, could allow attackers to execute arbitrary code on the host …

Threat Actor Allegedly Claim Leak of NordVPN Salesforce Database with Source Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor operating under the identifier 1011 has publicly claimed to have obtained and leaked sensitive data from NordVPN’s development infrastructure on a dark web forum. The breach reportedly …

GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture …

Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP has patched multiple security vulnerabilities in its License Center application that could allow attackers to access sensitive information or disrupt services on affected NAS devices. The issues, tracked as CVE-2025-52871 and CVE-2025-53597, were disclosed on January 3, 2026. QNAP …

Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Resecurity deploys synthetic data honeypots to outsmart threat actors, turning reconnaissance into actionable intelligence. A recent operation not only trapped an Egyptian-linked hacker but also duped the ShinyHunters group into …

Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous cybercrime feedback loop has emerged where stolen credentials from infostealer malware enable attackers to hijack legitimate business websites and turn them into malware distribution platforms. Recent research by …

Finland Arrests Two Cargo Ship Crew Members Over Undersea Cable Damage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Finnish authorities have detained all 14 crew members of a cargo vessel suspected of deliberately damaging an undersea telecommunications cable connecting Helsinki to Estonia. The ship, named Fitburg, was sailing …