APT36 Hackers Weaponizing PDF Files to Attack Indian Railways, Oil & Government Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Pakistan-linked Advanced Persistent Threat (APT) group APT36, also known as Transparent Tribe, has significantly expanded its cyber operations beyond traditional military targets to encompass critical Indian infrastructure including railway …

11 Best Email Security Software and Solutions in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In 2025, the threat landscape is more sophisticated than ever, with attackers leveraging advanced AI to craft hyper-realistic phishing campaigns, sophisticated business email compromise (BEC) schemes, and evasive malware that …

$1,000,000 for WhatsApp 0-Click RCE Exploit at Pwn2Own Ireland 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Trend Micro’s Zero Day Initiative (ZDI) announces an unprecedented $1,000,000 bounty for a zero-click remote code execution (RCE) exploit targeting WhatsApp at the upcoming Pwn2Own Ireland 2025 competition.  This record-breaking …

CISA Issues ICS Advisories for Rockwell Automation Using VMware, and Güralp Seismic Monitoring Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA released two high-severity Industrial Control Systems (ICS) advisories on July 31, 2025, highlighting critical vulnerabilities in widely deployed industrial equipment that could enable remote attackers to manipulate critical infrastructure …

Threat Actors Abuse Proofpoint’s and Intermedia’s Link Wrapping Features to Hide Phishing Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The latest wave of credential-phishing campaigns has revealed an unexpectedly convenient ally for threat actors: the very e-mail security suites meant to protect users. First observed in late July 2025, …

Microsoft Upgrades .NET Bounty Program with Rewards to Researchers Up to $40,000

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has significantly enhanced its .NET bounty program, announcing substantial updates that expand the program’s scope, streamline award structures, and provide greater incentives for cybersecurity researchers.  The enhanced program now …

Search Engines are Indexing ChatGPT Conversations! – Here is our OSINT Research

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ChatGPT shared conversations are being indexed by major search engines, effectively turning private exchanges into publicly discoverable content accessible to millions of users worldwide. The issue first came to light …

Hackers Weaponizing Free Trials of EDR to Disable Existing EDR Protections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack technique was uncovered where cybercriminals exploit free trials of Endpoint Detection and Response (EDR) software to disable existing security protections on compromised systems.  This method, dubbed BYOEDR …

Unit 42 Unveils Attribution Framework to Classify Threat Actors Based on Activity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks’ Unit 42 threat research team has introduced a groundbreaking systematic approach to threat actor attribution, addressing longstanding challenges in cybersecurity intelligence analysis. The Unit 42 Attribution Framework, …

Threat Actors Embed Malicious RMM Tools to Gain Silent Initial Access to Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber campaign leveraging legitimate Remote Monitoring and Management (RMM) tools has emerged as a significant threat to European organizations, particularly those in France and Luxembourg. Since November 2024, …