Top 10 Best Dynamic Application Security Testing (DAST) Platforms in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dynamic Application Security Testing (DAST) platforms have become fundamental for safeguarding web applications as digital assets and attack surfaces scale in both size and complexity. The modern DAST landscape is …

Google Chrome 0-Day Vulnerability Actively Exploited in the Wild – Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an emergency security update for its Chrome web browser to address a high-severity zero-day vulnerability that is being actively exploited in the wild. Users are strongly urged …

MuddyWater Hackers Using Custom Malware With Multi-Stage Payloads and Uses Cloudflare to Mask Fingerprints

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since early 2025, cybersecurity teams have observed a marked resurgence in operations attributed to MuddyWater, an Iranian state–sponsored advanced persistent threat (APT) actor. Emerging initially through broad remote monitoring and …

BeaverTail Variant via Malicious Repositories Targeting Retail Sector Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated North Korean nation-state threat actor campaign has emerged, distributing an evolved variant of the BeaverTail malware through deceptive fake hiring platforms and ClickFix social engineering tactics. This latest …

China-Aligned TA415 Hackers Uses Google Sheets and Google Calendar for C2 Communications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Chinese state-sponsored threat actor TA415 has evolved its tactics, techniques, and procedures by leveraging legitimate cloud services like Google Sheets and Google Calendar for command and control communications in …

New Magecart Skimmer Attack With Malicious JavaScript Injection to Skim Payment Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The threat landscape for e-commerce websites has once again shifted with the emergence of a sophisticated Magecart-style attack campaign, characterized by the deployment of obfuscated JavaScript to harvest sensitive payment …

224 Malicious Android Apps on Google Play With 38 Million Downloads Delivering Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated mobile ad fraud operation dubbed “SlopAds” has infiltrated Google Play Store with 224 malicious applications that collectively amassed over 38 million downloads across 228 countries and territories. The …

New in Syteca Release 7.21: Agentless Access, Sensitive Data Masking, and Smooth Session Playback

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Syteca, a global cybersecurity provider, introduced the latest release of its platform, continuing the mission to help organizations reduce insider risks and ensure sensitive data protection. Syteca 7.21 is a …

Hackers Exploit RTL/LTR Scripts and Browser Gaps to Hide Malicious URLs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A decade-old Unicode vulnerability known as BiDi Swap allows attackers to spoof URLs for sophisticated phishing attacks. By exploiting how browsers render mixed Right-to-Left (RTL) and Left-to-Right (LTR) language scripts, …

Microsoft Dismantles 300+ Websites Used to Distribute RaccoonO365 Phishing Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since mid-2024, cybercriminals have leveraged a subscription-based phishing platform known as RaccoonO365 to harvest Microsoft 365 credentials at scale. Emerging as an off-the-shelf service, RaccoonO365 requires minimal technical skill, allowing …