Critical Sophos Firewall Vulnerabilities Enables pre-auth Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple security vulnerabilities affecting Sophos firewall products, with two enabling pre-authentication remote code execution that could allow attackers to compromise systems without valid credentials.  The vulnerabilities, tracked as CVE-2025-6704, CVE-2025-7624, …

Cisco Warns of Identity Services Engine RCE Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco Systems has issued a critical security advisory warning of multiple remote code execution vulnerabilities in its Identity Services Engine (ISE) that are being actively exploited by attackers in the …

UK Sanctions Russian APT 28 Hackers for Attacking Microsoft Cloud Service Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The UK Government has imposed sanctions on Russian military intelligence units and 18 individuals following the exposure of a sophisticated cyber espionage campaign targeting Microsoft cloud services.  The National Cyber …

New DCHSpy Android Malware Steals WhatsApp Data, Call Logs, Record Audio and Take Photos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of DCHSpy Android surveillanceware, deployed by the Iranian cyber espionage group MuddyWater just one week after escalating tensions in the Israel-Iran conflict.  This malicious tool represents …

ExpressVPN Windows Client Vulnerability Exposes Users Real IP Addresses With RDP Connection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in ExpressVPN Windows desktop application that could expose users’ real IP addresses when using Remote Desktop Protocol (RDP) connections.  The flaw, discovered through the company’s bug …

Threat Actors Combine Android Malware With Click Fraud Apps to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fresh wave of malicious Android Package Kit (APK) files is weaving together two of cybercrime’s most reliable revenue streams—click-fraud advertising and credential theft—into a single, adaptable threat that has …

GLOBAL GROUP’s Golang Ransomware Attacks Windows, Linux, and macOS Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new ransomware threat has emerged from the cybercriminal underground, targeting organizations across multiple operating systems with advanced cross-platform capabilities. In June 2025, a ransomware actor operating under the …

Wireshark 4.4.8 Released With Bug Fixes and Updated Protocol Support

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Wireshark Foundation has announced the availability of Wireshark 4.4.8, the latest maintenance release of the world’s most widely used network-protocol analyzer. Although the update does not introduce brand-new protocols, it …

Dior, a Louis Vuitton Brand, Alerts Customers Following Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Christian Dior Couture, the luxury fashion house owned by Louis Vuitton, has begun notifying customers of a major cybersecurity incident that exposed sensitive personal information of clients.  The breach, discovered …

Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Thousands of organizations worldwide face active cyberattacks targeting Microsoft SharePoint servers through two critical vulnerabilities, prompting urgent government warnings and emergency patches. Microsoft confirmed over the weekend that threat actors …