Mysterious Elephant APT Hackers Infiltrate Organization to Steal Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, a new advanced persistent threat (APT) group known as Mysterious Elephant has emerged as a formidable adversary targeting government and diplomatic institutions across the Asia-Pacific region. First …

Senate Investigates Cisco Over Zero-Day Firewall Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

U.S. Senator Bill Cassidy, Chairman of the Senate Health, Education, Labor, and Pensions (HELP) Committee, has demanded answers from Cisco Systems regarding recent zero-day vulnerabilities in its widely used networking …

PhantomVAI Loader Attacking Organizations Worldwide to Deliver AsyncRAT, XWorm, FormBook and DCRat

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated multi-stage malware campaign is targeting organizations globally, utilizing the PhantomVAI Loader to distribute dangerous information-stealing malware. The attack chain, which begins with carefully crafted phishing emails, has emerged …

CISA Warns Of Windows Improper Access Control Vulnerability Exploited In Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a critical Microsoft Windows vulnerability to its Known Exploited Vulnerabilities catalog, warning organizations that threat actors are actively exploiting it in real-world attacks. Identified as CVE-2025-59230, the …

Beware of Malicious Ivanti VPN Client Sites in Google Search That Delivers Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An aggressive SEO poisoning campaign has surfaced in early October 2025, preying on users searching for the legitimate Ivanti Pulse Secure VPN client. Attackers have registered lookalike domains such as …

Capita To pay £14 Million For Data Breach Exposes 6.6 Million Users Personal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The UK’s Information Commissioner’s Office (ICO) has imposed a £14 million fine on outsourcing giant Capita following a major cyber attack in 2023 that exposed the personal data of 6.6 …

New nightMARE Python Library to Analyze Malware and Extract Intelligence Indicators

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since its public debut in October 2025, nightmare has quickly become a vital tool for malware analysts seeking to streamline static and dynamic analysis workflows. Developed by Elastic Security Labs, …

Critical Apache ActiveMQ Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache Software Foundation has disclosed a critical vulnerability in its ActiveMQ NMS AMQP Client that could allow attackers to execute arbitrary code on vulnerable systems. Tracked as CVE-2025-54539, this …

Critical Samba RCE Vulnerability Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Samba has disclosed a severe remote code execution (RCE) flaw that could allow attackers to hijack Active Directory domain controllers. Tracked as CVE-2025-10230, the vulnerability stems from improper validation in …

CISA Warns Of Adobe Experience Manager Forms 0-Day Vulnerability Exploited In Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a severe code execution vulnerability in Adobe Experience Manager Forms, urging organizations to patch immediately. Tracked as …