Operation PCPcat Hacked 59,000+ Next.js/React Servers Within 48 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive credential-theft campaign dubbed PCPcat compromised 59,128 Next.js servers in under 48 hours. The operation exploits critical vulnerabilities CVE-2025-29927 and CVE-2025-66478, achieving a 64.6% success rate across 91,505 scanned …

Microsoft Teams to Enforce Messaging Safety Defaults Starting January 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is strengthening the security posture of enterprise collaboration by automatically enabling critical messaging safety features in Microsoft Teams. According to a new administrative update, the company will switch several …

HardBit 4.0 Ransomware Actors Attack Open RDP and SMB Services to Persist Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HardBit ransomware continues to evolve as a serious threat to organizations worldwide. The latest version, HardBit 4.0, emerged as an upgraded variant of a strain that has been active since …

Indian Income Tax-Themed Attacking Businesses with a Multi-Stage Infection Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have increasingly weaponized the Income Tax Return (ITR) filing season to orchestrate sophisticated phishing campaigns targeting Indian businesses. By exploiting public anxiety surrounding tax compliance and refund timelines, attackers …

University of Phoenix Data Breach – 3.5 Million+ Individuals Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

University of Phoenix, one of the largest for-profit educational institutions in the United States, disclosed a significant data breach affecting approximately 3.5 million individuals on December 22, 2025. The breach …

Critical n8n Automation Platform Vulnerability Enables RCE Attacks – 103,000+ Instances Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability has been discovered in n8n, the open-source workflow automation platform, exposing over 103,000 potentially vulnerable instances worldwide. Tracked as CVE-2025-68613 with a maximum CVSS …

New GhostLocker Tool that Uses Windows AppLocker to Neutralize and Control EDR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new tool named GhostLocker has been released, demonstrating a novel technique to neutralize Endpoint Detection and Response (EDR) systems by weaponizing the native Windows AppLocker feature. Developed by security …

Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two fake Chrome extensions named “Phantom Shuttle” are deceiving thousands of users by posing as legitimate VPN services while secretly intercepting their web traffic and stealing sensitive login information. These …

Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Ontinue’s Cyber Defense Center have uncovered a significant threat as attackers exploit Nezha, a legitimate open-source server monitoring tool, for post-exploitation access. The discovery reveals how sophisticated threat …

CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting Digiever DS-2105 Pro network video recorders was added to the Known Exploited Vulnerabilities (KEV) catalog on December 22, 2025, following evidence of active exploitation in the …