Zapier’s NPM Account Hacked and Multiple Packages Infected with Self-propogating Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive supply chain attack targeting the NPM accounts of automation giant Zapier and the Ethereum Name Service (ENS). Identified by Aikido Security, the campaign is being orchestrated by the …

Threats Actors Leverage Python-based Malware to Inject Process into a Legitimate Windows Binary

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated Python-based malware that employs process injection techniques to hide inside legitimate Windows binaries. This threat represents a new evolution in fileless attack strategies, combining …

Hackers Replace ‘m’ with ‘rn’ in Microsoft(.)com to Steal Users’ Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign is currently leveraging a subtle typographical trick to bypass user vigilance, deceiving victims into handing over sensitive login credentials. Attackers utilize the domain “rnicrosoft.com” to impersonate …

vLLM Vulnerability Enables Remote Code Execution Via Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical memory corruption vulnerability in vLLM versions 0.10.2 and later allows attackers to achieve remote code execution through the Completions API endpoint by sending maliciously crafted prompt embeddings. The …

Beware of North Korean Fake Job Platform Targeting U.S. Based AI-Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated recruitment scam linked to North Korea has emerged, targeting American artificial intelligence developers, software engineers, and cryptocurrency professionals through an elaborate fake job platform. Validin security researchers have …

DeepSeek-R1 Makes Code for Prompts With Severe Security Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A concerning vulnerability in DeepSeek-R1, a Chinese-developed artificial intelligence coding assistant. When the AI model encounters politically sensitive topics related to the Chinese Communist Party, it produces code with severe …

Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Wireshark Foundation has rolled out a crucial security update for its widely used network protocol analyzer, addressing multiple vulnerabilities that could lead to denial-of-service conditions. The latest release, version …

CISA Warns of Oracle’s Identity Manager RCE Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to immediately address a critical security flaw in Oracle Identity Manager following reports of active exploitation. The vulnerability, tracked as …

Cybersecurity News Weekly Newsletter – Fortinet, Chrome 0-Day Flaws, Cloudflare Outage and Salesforce Gainsight Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Welcome to this week’s edition of the Cybersecurity News Weekly Newsletter, where we analyze the critical incidents defining the current threat landscape. If this week has taught us anything, it …

Critical Vulnerability in Azure Bastion Let Attackers Bypass Authentication and Escalate privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Azure Bastion (CVE-2025-49752) allows remote attackers to bypass authentication mechanisms and escalate privileges to administrative levels. The flaw, categorized as an authentication bypass vulnerability, poses an …