U.S. Treasury Warns of Crypto ATMs Fueling Criminal Activity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) has issued a critical warning about the exploitation of convertible virtual currency (CVC) kiosks by criminal organizations. Released on …

Microsoft Zero Day Quest Hacking Contest – Rewards Up to $5 Million

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced the return of its groundbreaking Zero Day Quest, the largest public hacking event in history, offering unprecedented bounty rewards of up to $5 million for high-impact security …

Cyber Attacks Against AI Infrastructure Are in The Rise With Key Vulnerabilities Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cyber-criminals have gradually shifted their focus toward the high-value infrastructure that trains, tunes and serves modern artificial-intelligence models. Over the past six months, incident-response teams have documented a new malware …

The Network-Security Compliance Checklist: 25 Controls, Mapped And Audit-Ready

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

You’re on a four-day clock. Following new SEC rules announced on July 26, 2023, U.S. public companies must disclose any cybersecurity incident they determine to be ‘material’ within four business …

New MCPoison Attack Leverages Cursor IDE MCP Validation to Execute Arbitrary System Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Cursor IDE, the rapidly growing AI-powered development environment, enables persistent remote code execution through manipulation of the Model Context Protocol (MCP) system. The vulnerability, tracked as …

How Certificate Mismanagement Opens The Door For Phishing And MITM Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SSL certificates are used everywhere from websites and APIs to mobile apps, internal tools and CI/CD pipelines. While most teams know they’re important, they often don’t manage them well. Certificates …

New Streamlit Vulnerability Allows Hackers to Launch Cloud Account Takeover Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Streamlit, the popular open-source framework for building data applications, enables attackers to conduct cloud account takeover attacks.  The flaw, discovered in February 2025, exploits weaknesses in …

Cloudflare Accuses Perplexity AI For Evading Firewalls and Crawling Websites by Changing User Agent

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Perplexity AI, an emerging question-answering engine powered by advanced large language models, has recently come under scrutiny for deploying stealth crawling techniques that bypass standard web defenses. Initially launched with …

APT36 Hackers Attacking Indian Government Entities to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign attributed to the Pakistan-linked APT36 group has emerged as a serious threat to Indian government infrastructure. First detected in early August 2025, this operation leverages typo-squatted …

North Korean Hackers Weaponizing NPM Packages to Steal Cryptocurrency and Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated North Korean cryptocurrency theft campaign has resurfaced with renewed vigor, weaponizing twelve malicious NPM packages to target developers and steal digital assets. The campaign, which represents a significant …