Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iranian state-sponsored threat actors, commonly tracked as “Prince of Persia,” have resurfaced with a sophisticated cyberespionage campaign targeting global critical infrastructure and private networks. Active since the early 2000s, this …

Scripted Sparrow Uses Automation to Generate and Send their Attack Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Scripted Sparrow is a newly identified Business Email Compromise (BEC) group operating across three continents. Their operations are vast, leveraging significant automation to generate and distribute attack messages on a …

Hackers Targeting HubSpot Users in Targeted Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active phishing campaign is currently targeting HubSpot users through a sophisticated combination of social engineering and infrastructure compromise. The attack leverages business email compromise tactics, paired with website hijacking, …

Ransomware Attack 2025 Recap – From Critical Data Extortion to Operational Disruption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware landscape in 2025 has reached new heights, evolving from a cybersecurity issue into a strategic threat to national security and global economic stability. This year saw a 34%-50% …

Hackers Using PuTTY for Both Lateral Movement and Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are increasingly abusing the popular PuTTY SSH client for stealthy lateral movement and data exfiltration in compromised networks, leaving subtle forensic traces that investigators can exploit. In a recent …

New Tool Released to Detect Cisco Secure Email Gateway 0-Day Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A lightweight Python script to help organizations quickly identify exposure to CVE-2025-20393, a critical zero-day vulnerability in Cisco Secure Email Gateway (SEG) and Secure Malware Analytics (SMA), also known as …

Microsoft Released Out-of-band Update to Fix MSMQ Bug that Impacts IIS Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has deployed an emergency out-of-band update to address a significant issue with Message Queuing (MSMQ) functionality that emerged following the December 9 security patches. The update, released on December …

Roundcube Vulnerabilities Allow Attackers to Execute Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Roundcube Webmail has released critical security updates addressing two significant vulnerabilities affecting versions 1.6 and 1.5 LTS. The flaws could enable attackers to execute malicious scripts and gain unauthorized access …

North Korean Hackers Make History with $2 Billion Crypto Heist in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean hackers reached a dangerous milestone in 2025, stealing a record-breaking $2.02 billion in cryptocurrency throughout the year. This represents a 51% increase from 2024, pushing their total theft …

WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An urgent security update has been released to fix a critical zero-day vulnerability in WatchGuard Firebox firewalls. With warnings that hackers are already actively exploiting the flaw in the wild …