Threat Actors Attacking Outlook and Google Bypassing Traditional Email Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Email-based threats have reached a critical inflection point in the third quarter of 2025. Threat actors are systematically exploiting weaknesses in traditional email security defenses by targeting the world’s two …

Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zoom has issued multiple security bulletins detailing patches for several vulnerabilities affecting its Workplace applications. The disclosures, published today, highlight two high-severity issues alongside medium-rated flaws, underscoring the ongoing challenges …

SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SAP released its monthly Security Patch Day updates, addressing 18 new security notes and providing two updates to existing ones, focusing on vulnerabilities that could enable remote code execution and …

Hackers Exploiting Triofox 0-Day Vulnerability to Execute Malicious Payload Abusing Anti-Virus Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Mandiant has disclosed active exploitation of CVE-2025-12480, a critical unauthenticated access vulnerability in Gladinet’s Triofox file-sharing platform. The threat cluster tracked as UNC6485 has been weaponizing this flaw since August 2025 to …

CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a critical zero-day vulnerability affecting Samsung mobile devices to its Known Exploited Vulnerabilities catalog. Warning that threat actors are actively exploiting the flaw in real-world attacks. The …

Threat Actors Leverage RMM Tools to Deploy Medusa & DragonForce Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated wave of ransomware attacks targeting UK organizations has emerged in 2025, exploiting vulnerabilities in the widely-used SimpleHelp Remote Monitoring and Management platform. Two prominent ransomware groups, Medusa and …

Threat Actors Actively Hacking Websites to Inject Malicious Links and Boost their SEO

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly targeting websites to inject malicious links and boost their search engine optimization rankings through sophisticated blackhat SEO tactics. This campaign primarily focuses on online casino spam, which …

Italian Adviser Becomes Latest Target in Expanding Paragon Graphite Spyware Surveillance Case

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Francesco Nicodemo, a prominent political communications strategist and former Democratic Party communications director, has been identified as a new target in the expanding Paragon spyware surveillance campaign. The revelation marks …

APT Groups Attacking Construction Industry Networks to Steal RDP, SSH and Citrix Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The construction industry has emerged as a lucrative target for advanced persistent threat groups and organized cybercriminal networks seeking unauthorized access to corporate systems. State-sponsored APT groups from China, Russia, …

Chinese Cybersecurity Firm Data Breach Exposes State-Sponsored Hackers Cyber Weapons and Target List

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In early November 2025, Knownsec, one of China’s largest cybersecurity firms with direct government ties, experienced a catastrophic data breach that exposed over 12,000 classified documents. The incident revealed the …