PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept exploit has been publicly released for CVE-2025-9501, a critical, unauthenticated command-injection vulnerability affecting W3 Total Cache, one of WordPress’s most widely deployed caching plugins. With over 1 million …

Sha1-Hulud Supply Chain Attack: 800+ npm Packages and Thousands of GitHub Repos Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive resurgence of the Sha1-Hulud supply chain malware has struck the open-source ecosystem, compromising over 800 npm packages and tens of thousands of GitHub repositories in a campaign the …

Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

India-aligned threat group Dropping Elephant has launched a sophisticated multi-stage cyberattack targeting Pakistan’s defense sector using a Python-based remote access trojan disguised within an MSBuild dropper. Idan Tarab has identified …

APT35 Hacker Groups Internal Documents Leak Exposes their Targets and Attack Methods

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In October 2025, a significant breach exposed the internal workings of APT35, also known as Charming Kitten, a cyber unit operating within Iran’s Islamic Revolutionary Guard Corps Intelligence Organization. Thousands …

Tenda N300 Vulnerabilities Let Attacker to Execute Arbitrary Commands as Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tenda N300 wireless routers and 4G03 Pro portable LTE devices face severe security threats from multiple command injection vulnerabilities that allow attackers to execute arbitrary commands with root privileges. The …

LLMs Tools Like GPT-3.5-Turbo and GPT-4 Fuels the Development of Fully Autonomous Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Large language models like GPT-3.5-Turbo and GPT-4 are transforming how we work, but they are also opening doors for cybercriminals to create a new generation of malware. Researchers have demonstrated …

Hackers Leverage Malicious PyPI Package to Attack Users and Steal Cryptocurrency Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has surfaced targeting cryptocurrency users through a deceptive Python package hosted on the PyPI repository. The threat actors disguised their malicious code within a fake spell-checking …

New EtherHiding Attack Uses Web-Based Attacks to Deliver Malware and Rotate Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat known as EtherHiding is reshaping how malware spreads through the internet. Unlike older methods that rely on traditional servers to deliver harmful code, this attack uses blockchain …

ToddyCat APT Accessing Organizations Internal Communications of Employees at Target Companies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ToddyCat APT group has developed new ways to access corporate email communications at target organizations. Email remains the main way companies handle business communications, whether through their own servers …

Zapier’s NPM Account Hacked and Multiple Packages Infected with Self-propogating Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive supply chain attack targeting the NPM accounts of automation giant Zapier and the Ethereum Name Service (ENS). Identified by Aikido Security, the campaign is being orchestrated by the …