SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A medium-severity vulnerability in the Iconics Suite SCADA system that could allow attackers to trigger denial-of-service conditions on critical industrial control systems. The flaw, tracked as CVE-2025-0921, affects supervisory control and data acquisition infrastructure widely deployed across automotive, energy, and …

Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The highlight of this release is a sophisticated trio of modules …

UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of targeted attacks has emerged against Internet Information Services (IIS) servers across Asia, with threat actors deploying sophisticated malware designed to compromise vulnerable systems. The campaign, active from late 2025 through early 2026, focuses primarily on victims …

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security discovery reveals that approximately 175,000 Ollama servers remain publicly accessible across the internet, creating a serious risk for widespread code execution and unauthorized access to external systems. Ollama, an open-source framework designed to run artificial intelligence models …

TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated PowerShell-based malware named TAMECAT has emerged as a critical threat to enterprise security, targeting login credentials stored in Microsoft Edge and Chrome browsers. This malware operates as part of espionage campaigns conducted by APT42, an Iranian state-sponsored cyber-espionage …

GhostChat Spyware Attacking Android Users Via WhatsApp to Exfiltrate Sensitive Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Android spyware campaign has emerged, targeting users in Pakistan through a sophisticated romance scam that uses fake dating profiles to steal personal information. The malicious application, known as GhostChat, disguises itself as a legitimate chat platform while secretly …

Critical Ivanti Endpoint Manager 0-day RCE Vulnerabilities Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical code-injection vulnerabilities have been disclosed in the Endpoint Manager Mobile (EPMM) platform, which are currently being actively exploited in real-world attacks. The security flaws, tracked as CVE-2026-1281 and CVE-2026-1340, allow unauthenticated attackers to execute arbitrary code remotely on …

Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a sophisticated traffic distribution network leveraging deceptive education-themed domains to deliver malware and phishing attacks. The operation, tracked under infrastructure indicators pointing to TOXICSNAKE, uses legitimate-looking university and educational institution branding to deceive users into visiting …

Hackers Weaponized Open VSX Extension with Sophisticated Malware After Reaching 5066 Downloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has infiltrated the Open VSX extension marketplace, compromising over 5,000 developer workstations through a fake Angular Language Service extension. The malicious package disguised itself as legitimate development tooling, bundling authentic Angular and TypeScript components alongside encrypted …

3,280,081 Fortinet Devices Online With Exposed Web Properties Under Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 3,280,081 Fortinet Devices Were exposed, with web properties running vulnerable Fortinet devices affected by CVE-2026-24858, a severe authentication-bypass flaw actively exploited in the wild. The vulnerability, rated 9.4 on the CVSS scale, affects multiple Fortinet product lines, including FortiOS, FortiManager, …