Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security patch addressing a critical privilege escalation vulnerability that allows unauthorized users to gain administrative access to the data streaming platform. The flaw, tracked as CVE-2025-47411 and rated important, …

Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. Security researchers have identified an over 50-script global campaign that intercepts …

Hackers Advertised VOID ‘AV Killer’ with Kernel-level Termination Claims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybercriminal threat actor known as Crypt4You has recently emerged on underground forums and dark web marketplaces, advertising a sophisticated tool named VOID KILLER. This malicious software operates as a …

ESET Warns AI-driven Malware Attack and Rapidly Growing Ransomware Economy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has reached a critical turning point as artificial intelligence moves from theoretical threat to operational reality. In their H2 2025 Threat Report, ESET researchers have documented a …

New Spear-Phishing Attack Targeting Security Individuals in Israel Region

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Israel’s National Cyber Directorate recently issued an urgent alert about a targeted spear-phishing attack aimed at people working in security and defense-related areas. The campaign uses WhatsApp messages that pretend …

European Space Agency Confirms Breach of Servers Outside the Corporate Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The European Space Agency (ESA) has confirmed a cybersecurity breach affecting a limited number of external servers, marking a rare public admission of vulnerability in the continent’s premier space organization. …

Hackers Infiltrated Maven Central Masquerading as a Legitimate Jackson JSON Library

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign has successfully infiltrated Maven Central, one of the most trusted repositories for Java developers, by masquerading as a legitimate Jackson JSON library extension. The malicious package, …

Critical Vulnerability in SmarterMail Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SmarterTools has issued an urgent security advisory addressing a critical vulnerability in SmarterMail that could allow attackers to execute remote code on mail servers. The flaw, tracked as CVE-2025-52691, poses …

CISA Warns of MongoDB Server Vulnerability(CVE-2025-14847) Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a critical MongoDB Server vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively exploited in cyberattacks. CVE-2025-14847 affects MongoDB Server and …