New Malware Targeting WooCommerce Sites with Malicious Plugins Steals Credit Card Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged targeting WordPress e-commerce sites, particularly those leveraging the WooCommerce plugin to process customer transactions. The threat, discovered in August 2025, demonstrates advanced evasion capabilities …

12 Malicious Extension in VSCode Marketplace Steal Source Code and Exfiltrate Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent discovery has shaken the Visual Studio Code (VSCode) ecosystem, unveiling a sophisticated supply chain attack targeting developers worldwide. At least a dozen malicious extensions were identified in the …

Multiple Jenkins Vulnerability SAML Authentication Bypass And MCP Server Plugin Permissions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Jenkins project released Security Advisory 2025-10-29 on October 28, 2025, disclosing multiple vulnerabilities across 13 plugins that power the popular open-source automation server. These flaws range from high-severity authentication …

Critical Vulnerability in Chromium’s Blink Let Attackers Crash Chromium-based Browsers Within Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researcher Jofpin has disclosed “Brash,” a critical flaw in Google’s Blink rendering engine that enables attackers to crash Chromium-based browsers almost instantly. Affecting billions of users worldwide, this architectural …

Aembit Introduces Identity and Access Management for Agentic AI

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Silver Spring, USA/ Maryland, October 30th, 2025, CyberNewsWire The new capabilities, anchored by Blended Identity and the MCP Identity Gateway, give enterprises a secure and auditable way to manage how …

PhantomRaven Attack Involves 126 Malicious npm Packages with Over 86,000 Downloads Hiding Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign targeting developers has been operating since August 2025, deploying 126 malicious npm packages that have collectively accumulated over 86,000 downloads. The attack, now identified as PhantomRaven, …

PolarEdge Botnet Infected 25,000+ Devices and 140 C2 Servers Exploiting IoT Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated botnet campaign has compromised more than 25,000 IoT devices across 40 countries while establishing 140 command-and-control servers to facilitate cybercrime operations. The PolarEdge botnet, first disclosed in February …

New Attack Combines Ghost SPNs and Kerberos Reflection to Elevate Privileges on SMB Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated privilege escalation vulnerability in Windows SMB servers, leveraging Ghost Service Principal Names (SPNs) and Kerberos authentication reflection to achieve remote SYSTEM-level access. Microsoft designated this as CVE-2025-58726, an …

Canada Warns of Hackers Breached ICS Devices Controlling Water and Energy Facilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Canadian authorities have issued an urgent alert following multiple confirmed incidents where cybercriminals compromised internet-accessible Industrial Control Systems (ICS) devices protecting critical infrastructure across the nation. The Canadian Centre for …

Dentsu has Disclosed that its U.S.-based Subsidiary Merkle Suffers Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Global advertising and marketing giant Dentsu has confirmed that its U.S.-based subsidiary Merkle experienced a cyberattack, prompting immediate incident response measures and system shutdowns to contain the breach. The company …