IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since emerging in the mid-2010s as a persistent threat actor, the IRGC-linked APT35 collective has continually adapted its tactics to target government entities, energy firms, and diplomatic missions across the …

Hackers Abuse CSS Properties With Messages to Inject Malicious Codes in Hidden Text Salting Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated technique known as hidden text salting has emerged as a significant threat to email security systems, allowing cybercriminals to bypass detection mechanisms through the strategic abuse of cascading …

Microsoft 365 Outage Blocks Access to Teams, Exchange Online, and Admin Center – Updated

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant Microsoft 365 outage blocked user access to several critical services, including Microsoft Teams, Exchange Online, and the Microsoft 365 admin center. The incident began late on Wednesday, October …

Discord Data Breach – 1.5 TB of Data and 2 Million Government ID Photos Extorted

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular communication platform Discord is facing an extortion attempt following a significant data breach at one of its third-party customer service providers, Zendesk. Threat actors claim to have stolen …

CrowdStrike Falcon Windows Sensor Vulnerability Enables Code Execution and File Deletion

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CrowdStrike has disclosed and released patches for two medium-severity vulnerabilities in its Falcon sensor for Windows that could allow an attacker to delete arbitrary files. The security vulnerabilities, designated as …

FreePBX SQL Injection Vulnerability Exploited to Modify The Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical SQL injection vulnerability in FreePBX has emerged as a significant threat to VoIP infrastructure worldwide, enabling attackers to manipulate database contents and achieve arbitrary code execution. FreePBX, a …

Crimson Collective Leverages AWS Services to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat group calling itself Crimson Collective has emerged as a significant cybersecurity concern, targeting Amazon Web Services (AWS) cloud environments with sophisticated data exfiltration and extortion campaigns. The …

Hackers Actively Compromising Databases Using Legitimate Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new breed of ransomware attacks is leveraging legitimate database commands to compromise organizations worldwide, bypassing traditional security measures through “malware-less” operations. Unlike conventional ransomware that encrypts files using …

Scattered Lapsus$ Hunters Launched a New Leak Site to Release Data Stolen from Salesforce Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious cybercriminal collective known as Scattered Lapsus$ Hunters has escalated their extortion campaign by launching a dedicated leak site to threaten organizations with the exposure of stolen Salesforce data. …

Mustang Panda Using New DLL Side-Loading Technique to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, cybersecurity analysts have observed a resurgence of the Mustang Panda threat actor deploying a novel DLL side-loading approach to deliver malicious payloads. Emerging in June 2025, this …