China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT24, a sophisticated cyber espionage group linked to China’s People’s Republic, has launched a relentless three-year campaign delivering BadAudio, a highly obfuscated first-stage downloader that enables persistent network access to …

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom’s internal systems as part of an ongoing exploitation campaign targeting Oracle E-Business Suite vulnerabilities. The hack uses a critical zero-day …

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to crash firewalls through denial-of-service attacks. The vulnerability was internally discovered …

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The new system represents a significant leap in agentic AI capabilities, enabling machines to work on …

Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions against Media Land. This Russia-based bulletproof hosting company provides infrastructure to ransomware and other cybercriminals. …

Salesforce Confirms that Customers’ Data Was accessed Following the Gainsight Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Salesforce has issued a critical security alert identifying “unusual activity” involving Gainsight-published applications connected to customer environments. The CRM giant’s investigation indicates that this activity may have enabled unauthorized access …

Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution flaw in Microsoft’s Windows Graphics Component allows attackers to seize control of systems using specially crafted JPEG images. With a CVSS score of 9.8, this …