Historic Great Firewall Breach – 500GB+ Censorship Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In an unprecedented cybersecurity incident that occurred in September 2025, over 500 gigabytes of internal data from China’s Great Firewall infrastructure were exposed in what security experts are calling one …

WhatsApp Introduces Passkey Encryption for Enhanced Chat Message Backup Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp has unveiled passkey-encrypted backups, simplifying the protection of cherished chat histories without the burden of memorizing complex passwords. This feature allows users to secure their end-to-end encrypted backups using …

Researchers Created a Linux Rootkit that Evades Elastic Security EDR Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Linux kernel rootkit designed to slip past the defenses of Elastic Security, a leading endpoint detection and response (EDR) platform. Released on GitHub by researcher 0xMatheuZ, the rootkit …

CISA Warns of VMware Tools and Aria Operations 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-41244 to its Known Exploited Vulnerabilities catalog. This local privilege escalation flaw affects Broadcom’s VMware Aria Operations and VMware Tools, with …

New Lampion Stealer Uses ClickFix Attack to Silently Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered a sophisticated campaign leveraging the Lampion banking trojan, a malware strain that has operated since 2019 with a renewed focus on Portuguese financial institutions. The threat actor …

New Agent-Aware Cloaking Leverages OpenAI ChatGPT Atlas Browser to Deliver Fake Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new agent-aware cloaking technique uses AI browsers like OpenAI’s ChatGPT Atlas to deliver misleading content. This method allows malicious actors to poison the information AI systems ingest, potentially manipulating …

New Windows-Based Airstalk Malware Employs Multi-Threaded C2 Communication to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered Windows malware family named Airstalk has emerged as a sophisticated threat capable of exfiltrating sensitive browser credentials through an innovative covert command-and-control channel. Available in PowerShell and …

700+ Malicious Android Apps Abusing NFC Relay to Exfiltrate Banking Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign exploiting Near Field Communication technology on Android devices has expanded dramatically since its emergence in April 2024. What began as isolated incidents has escalated into a …

RediShell RCE Vulnerability Exposes 8,500+ Redis Instances to Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape faced a critical threat in early October 2025 with the public disclosure of RediShell, a severe use-after-free vulnerability in Redis’s Lua scripting engine. Identified as CVE-2025-49844 and …

CISA Releases Best Security Practices Guide for Hardening Microsoft Exchange Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a timely response to escalating threats against email infrastructure, the Cybersecurity and Infrastructure Security Agency (CISA), alongside the National Security Agency (NSA), Australian Cyber Security Centre (ACSC), and Canadian …