New GlassWorm Using Invisible Code Hits Attacking VS Code Extensions on OpenVSX Marketplace

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past week, cybersecurity professionals have been gripped by the emergence of GlassWorm, a highly sophisticated, self-propagating malware campaign targeting VS Code extensions on the OpenVSX Marketplace. The scale …

Hackers Exploited 34 Zero-Day Vulnerabilities And Earned $522,500 In Pwn2Own Ireland 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The first day of Pwn2Own Ireland 2025 wrapped up with a bang, as security researchers uncovered 34 unique zero-day vulnerabilities across various smart devices. Not a single attempt failed, leading …

Threat Actors Compromise Xubuntu Website To Deliver Malicious Windows Executable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors infiltrated the official Xubuntu website, redirecting torrent downloads to a malicious ZIP file containing Windows-targeted malware. The incident, uncovered on October 18, 2025, highlights vulnerabilities in community-maintained Linux …

Chrome V8 JavaScript Engine Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has swiftly addressed a high-severity flaw in its Chrome browser’s V8 JavaScript engine, releasing an emergency update to thwart potential remote code execution attacks. The vulnerability, tracked as CVE-2025-12036, …

Cavalry Werewolf APT Hackers Attacking Multiple Industries with FoalShell and StallionRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated threat campaign has emerged targeting Russia’s public sector and critical industries between May and August 2025. The Cavalry Werewolf APT group, also known as YoroTrooper and Silent Lynx, …

Threat Actors Leverage npm Ecosystem to Deliver AdaptixC2 Post-Exploitation Framework

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The emergence of the AdaptixC2 post-exploitation framework in 2025 marked a significant milestone in the evolution of attacker toolsets targeting open-source supply chains. Positioning itself as a formidable alternative to …

Pakistani Threat Actors Targeting Indian Govt. With Email Mimic as ‘NIC eEmail Services’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign orchestrated by Pakistan-linked threat actors has been discovered targeting Indian government entities by impersonating the National Informatics Centre’s email services. The operation, attributed to APT36, also …

How Threat Intelligence Can Save Money and Resources for Businesses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity is not just about defense; it is about protecting profits. Organizations without modern threat intelligence (TI) face escalating breach costs, wasted resources, and operational inefficiencies that hit the bottom …

Microsoft Confirms Recent Updates Cause Login Issues on Windows 11 24H2, 25H2, and Windows Server 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has acknowledged a significant authentication problem affecting users of recent Windows versions, stemming from security enhancements in updates released since late August 2025. The company detailed how these updates …

Meta Launches New Tools to Protect Messenger and WhatsApp Users from Scammers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta announced innovative tools on Tuesday to shield users of Messenger and WhatsApp from scammers. The updates, revealed during Cybersecurity Awareness Month, aim to detect suspicious activity in real-time and …