706,000+ BIND 9 Resolver Instances Vulnerable to Cache Poisoning Exposed Online – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability in BIND 9 resolvers has been disclosed, potentially allowing attackers to poison caches and redirect internet traffic to malicious sites. Tracked as CVE-2025-40778, the flaw affects over …

LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious LockBit ransomware operation has resurfaced with a vengeance after months of dormancy following Operation Cronos takedown efforts in early 2024. Despite law enforcement disruptions and infrastructure seizures, the …

Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated backdoor named Android.Backdoor.Baohuo.1.origin has been discovered in maliciously modified versions of Telegram X messenger, granting attackers complete control over victims’ accounts while operating undetected. The malware infiltrates devices …

Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Southeast Asia’s online gambling ecosystem has become a breeding ground for sophisticated cyber threats, with criminal networks leveraging seemingly legitimate platforms to distribute malicious software to millions of unsuspecting users. …

Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have adopted a sophisticated social engineering strategy that exploits the trust inherent in job hunting, according to a recent security advisory. A financially motivated threat cluster operating from Vietnam …

Hackers Hijacking IIS Servers in The Wild Using Exposed ASP .NET Machine Keys to Inject Malicious Modules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberattack campaign targeting Microsoft Internet Information Services (IIS) servers has emerged, exploiting decades-old security vulnerabilities to deploy malicious modules that enable remote command execution and search engine optimization …

North Korean Hackers Attacking Unmanned Aerial Vehicle Industry to Steal Confidential Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean state-sponsored hackers from the Lazarus APT group launched a cyberespionage campaign targeting European companies involved in unmanned aerial vehicle development. Starting in late March 2025, attackers compromised three …

New Phishing Attack Bypasses Using UUIDs Unique to Bypass Secure Email Gateways

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign leveraging randomly generated Universal Unique Identifiers (UUIDs) has emerged, successfully bypassing Secure Email Gateways (SEGs) and evading perimeter defenses. The attack employs an advanced JavaScript-based phishing …

OpenAI ChatGPT Atlas Browse Jailbroken to Disguise Malicious Prompt as URLs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI’s newly launched ChatGPT Atlas browser, designed to blend AI assistance with web navigation, faces a serious security flaw that allows attackers to jailbreak the system by disguising malicious prompts …

Ransomware Actors Targeting Global Public Sectors and Critical Services in Targeted Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In 2025, ransomware attacks against the public sector continue to accelerate at an alarming rate, showing no signs of slowing down despite increased cybersecurity awareness and defensive measures. Throughout the …