Raaga Data Breach Exposes 10.2 Million User Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Indian music streaming platform Raaga suffered a significant data breach in December 2025, compromising the personal information of 10.2 million users. The stolen database was subsequently offered for sale on …

VoidLink Rewrites Rootkit Playbook with Server-Side Kernel Compilation and AI-Assisted Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VoidLink emerges as a significant threat to Linux cloud environments, representing a major shift in how rootkits are designed and deployed. This Chinese-developed malware framework was first discovered by Check …

Attackers Abuse Discord to Deliver Clipboard Hijacker That Steals Wallet Addresses on Paste

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new clipboard hijacker is quietly draining cryptocurrency from gamers and streamers by abusing trust inside Discord communities. The campaign centers on a malicious Windows program shared as a supposed …

Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SolyxImmortal represents a notable advancement in information-stealing malware targeting Windows systems. This Python-based threat combines multiple data theft capabilities into a single, persistent implant designed for long-term surveillance rather than …

Critical AVEVA Software Vulnerabilities Enables Remote Code Execution Under System Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Seven vulnerabilities were disclosed in Process Optimization (formerly ROMeo) 2024.1 and earlier on January 13, 2026, including a critical flaw enabling unauthenticated SYSTEM-level remote code execution. The most severe vulnerability …

WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent – Millions Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Google’s Fast Pair protocol that allows attackers to hijack Bluetooth audio accessories and track users without their knowledge or consent.​ Security researchers from KU Leuven have …

Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malvertising campaign identified in September 2025 has brought a significant threat to Windows users worldwide. Attackers created fake PDF editing applications and promoted them through Google Ads to distribute …

Pulsar RAT Using Memory-Only Execution & HVNC to Gain Invisible Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pulsar RAT has emerged as a sophisticated derivative of the open-source Quasar RAT, introducing dangerous enhancements that enable attackers to maintain invisible remote access through advanced evasion techniques. This modular …

ChatGPT Go Launched for $8 USD/month With Support for Ads and Privacy Risks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI’s global rollout of its budget-friendly ChatGPT Go subscription at $8 USD monthly introduces significant data privacy and security considerations for cybersecurity professionals monitoring AI platform access controls. The tiered …

Apache bRPC Vulnerability Enables Remote Command Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote command-injection vulnerability has been discovered in Apache bRPC’s built-in heap profiler service, affecting all versions before 1.15.0 across all platforms. The vulnerability allows unauthenticated attackers to execute …