CISA Warns of Control Web Panel OS Command Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding a dangerous OS command injection vulnerability affecting Control Web Panel (CWP), formerly known as CentOS Web Panel. …

DragonForce Cartel Emerges From the Leaked Source Code of Conti v3 Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DragonForce, a ransomware-as-a-service operation active since 2023, has dramatically evolved into what researchers now describe as a structured cybercriminal cartel, leveraging the publicly leaked Conti v3 source code to establish …

239 Malicious Android Apps on Google Play With Downloaded Over 40 Million Times

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security threat has emerged from the Google Play Store, where threat actors have successfully deployed 239 malicious applications that have been collectively downloaded more than 42 million times. …

Microsoft Warns Windows Systems May Enter BitLocker Recovery After October 2025 Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an urgent advisory for Windows users, highlighting a potential glitch that could force certain devices into the BitLocker recovery screen after installing security updates released on or …

Jupyter Misconfiguration Flaw Allow Attackers to Escalate Privileges as Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security flaw in Jupyter notebook deployments could allow attackers to gain complete system control by exploiting default configurations and unauthenticated API access. Security researchers discovered that improperly configured …

Cybersecurity Professionals Charged for Deploying ALPHV BlackCat Ransomware Against US Companies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two cybersecurity professionals have been federally charged for orchestrating a sophisticated ransomware campaign targeting multiple American businesses. Ryan Clifford Goldberg, 28, of Watkinsville, Georgia, and Kevin Tyler Martin, 31, of …

Hackers Exploit OneDrive.exe Through DLL Sideloading to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack technique that exploits Microsoft’s OneDrive application through DLL sideloading, allowing threat actors to execute malicious code while evading detection mechanisms. The attack leverages a weaponized version.dll file …

Silent Lynx APT New Attack Targeting Governmental Employees Posing as Officials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Silent Lynx, a sophisticated threat group that has been tracked since 2024, continues its relentless espionage campaign against government entities across Central Asia. Seqrite analysts identified the group as the …

HydraPWK Penetration Testing OS With Necessary Hacking Tools and Simplified Interface

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The HydraPWK project’s latest Apes-T1 snapshot refines its penetration-testing Linux distribution by replacing Elasticsearch with the open-source OpenSearch, resolving licensing issues and enhancing tools for industrial security assessments. This update, …

WordPress Post SMTP Plugin Vulnerability Exposes 400,000 Websites to Account Takeover Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in the WordPress Post SMTP plugin has left more than 400,000 websites vulnerable to account takeover attacks. The vulnerability, identified as CVE-2025-11833, enables unauthenticated attackers to …