Top 50 Best Penetration Testing Companies in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Penetration testing companies serve as vital cybersecurity allies, simulating real-world cyberattacks to expose vulnerabilities in systems, networks, and applications before malicious actors strike. Employing ethical hackers with advanced techniques, they …

BlueDelta Hackers Attacking Microsoft OWA, Google, and Sophos VPN Users to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BlueDelta, a Russian state-sponsored threat group linked to the country’s military intelligence agency known as the GRU, has expanded its credential-stealing operations significantly throughout 2025. Between February and September, the …

Ni8mare Vulnerability Let Attackers Hijack n8n Servers – Exploit Released and 26,512 Hosts Vulnerable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical unauthenticated remote code execution vulnerability discovered in n8n, the popular workflow automation platform, exposes an estimated 100,000 servers globally to complete takeover. Tracked as CVE-2026-21858 with a maximum …

Three Malicious NPM Packages Attacking Developers to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three malicious npm packages are targeting JavaScript developers to steal browser logins, API keys, and cryptocurrency wallet data. The packages, named bitcoin-main-lib, bitcoin-lib-js, and bip40, were uploaded to the public …

Hackers Exploiting VMware ESXi Instances in the Wild Using zero-day Exploit Toolkit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are exploiting VMware ESXi instances in the wild with a zero-day exploit toolkit that chains multiple vulnerabilities for VM escapes. Cybersecurity firm Huntress disrupted one such attack, attributing initial …

Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns Delivering Multiple Malware Families

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Windows packer known as pkr_mtsi has emerged as a powerful tool for delivering multiple malware families through widespread malvertising campaigns. First detected on April 24, 2025, this malicious …

ownCloud Urges Users to Enable Multi-Factor Authentication Following Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ownCloud has urgently urged users of its Community Edition to enable multi-factor authentication (MFA). A threat intelligence report from Hudson Rock highlighted incidents in which attackers compromised self-hosted file-sharing platforms, …

GoBruteforcer Botnet brute-forces Passwords for FTP, MySQL, and phpMyAdmin on Linux Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Go-based botnet dubbed GoBruteforcer is aggressively targeting Linux servers worldwide, brute-forcing weak passwords on internet-exposed services including FTP, MySQL, PostgreSQL, and phpMyAdmin. Check Point Research recently documented a …

From Tycoon2FA to Lazarus Group – Inside ANY.RUN’s Biggest Discoveries of 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ANY.RUN, the interactive malware analysis platform, has wrapped up 2025 with impressive growth figures and significant contributions to the cybersecurity community. The company’s annual report reveals how its global user …