CISA Adds ASUS Embedded Malicious Code Vulnerability to KEV List Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a new ASUS vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, signaling urgent risk for affected users and organizations. The flaw, tracked as CVE-2025-59374, affects ASUS Live Update, a …

HPE OneView Software Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security alert warns customers about a severe vulnerability in HPE OneView Software that could allow remote attackers to execute arbitrary code without authentication. The flaw, tracked as CVE-2025-37164, …

RansomHouse RaaS Service Upgraded with Double Extortion Strategy that Steals and Encrypt Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

RansomHouse has emerged as a significant threat in the ransomware landscape, operated by a group tracked as Jolly Scorpius. This ransomware-as-a-service platform combines data theft with encryption, creating a dual …

Researchers Uncovered New Lazarus and Kimsuky Infrastructure with Active Tools and Tunnelling Nodes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A joint investigation by Hunt.io and the Acronis Threat Research Unit has exposed an extensive network of North Korean state-sponsored infrastructure, revealing fresh connections between Lazarus and Kimsuky operations across …

Hackers Hijacking VNC Connections to Gain Access to OT Control Devices in Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coalition of U.S. and international cybersecurity agencies issued a stark warning this week about pro-Russia hacktivists exploiting exposed Virtual Network Computing (VNC) connections to infiltrate operational technology (OT) systems …

Chinese-based Ink Dragon Compromises Asia and South America into European Government Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ink Dragon, a Chinese espionage group, has significantly expanded its operations from Southeast Asia and South America into European government networks. This advancement marks a notable shift in the threat …

Phantom Stealer Attacking Users to Steal Sensitive Data like Passwords, Browser Cookies, Credit Card Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phantom Stealer version 3.5 has emerged as a serious threat to users worldwide, capable of extracting sensitive information including passwords, browser cookies, credit card details, and cryptocurrency wallet data. This …

Critical Apache Commons Text Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed security flaw in Apache Commons Text, tracked as CVE-2025-46295, has been identified as a remote code execution (RCE) vulnerability. That could allow attackers to compromise systems using vulnerable versions of …

Hackers Exploiting SonicWall SMA1000 0-day Vulnerability to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have discovered a critical privilege escalation vulnerability in SonicWall’s SMA1000 appliance that attackers are actively exploiting to gain unauthorized administrative access. The vulnerability, tracked as CVE-2025-40602, affects the …

Let’s Encrypt Unveils New “Generation Y” Root and 45-Day Certificates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Let’s Encrypt, the nonprofit certificate authority powering free TLS/SSL certificates for millions of websites, announced sweeping updates to its issuance policies. The changes introduce a new “Generation Y” root hierarchy, …