ShadowV2 Botnet Exploits Docker Containers on AWS to Turn Thems as Infected System for DDoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercrime campaign has emerged that transforms legitimate AWS infrastructure into weaponized attack platforms through an innovative combination of containerization and distributed denial-of-service capabilities. The ShadowV2 botnet represents a …

New YiBackdoor Allows Attackers to Execute Arbitrary Commands and Exfiltrate Sensitive Data from Hacked Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware family dubbed YiBackdoor has emerged in the cybersecurity landscape, posing a significant threat to organizations worldwide. First observed in June 2025, this malicious software represents a …

CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a high-severity zero-day vulnerability in Google Chrome that is being actively exploited in attacks. The vulnerability, tracked …

Hackers Exploit WerFaultSecure.exe Tool to Steal Cached Passwords From Windows 11 24H2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are leveraging the legacy Windows error‐reporting utility WerFaultSecure.exe to extract the memory region of the Local Security Authority Subsystem Service (LSASS.EXE) and harvest cached credentials from fully patched …

CISA Warns of Shai-Hulud Self-Replicating Worm Compromised 500+ Packages in npm Registry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent security Alert in response to a large-scale software supply chain attack on npmjs.com, the world’s largest JavaScript package registry.  A self-replicating worm, dubbed Shai-Hulud, has …

Kali Linux 2025.3 Released With New Features and 10 New Hacking Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kali team has released Kali Linux 2025.3, the third major update of the year for the popular penetration testing and ethical hacking distribution. This release introduces 10 new tools, brings …

CISA Details That Hackers Gained Access to a U.S. Federal Agency Network Via GeoServer RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has released a comprehensive cybersecurity advisory detailing how threat actors successfully compromised a U.S. federal civilian executive branch agency’s network by exploiting CVE-2024-36401, a critical remote code execution vulnerability …

Chrome High-severity Vulnerabilities Let Attackers Access Sensitive Data and Crash System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has issued an urgent security update for its Chrome web browser to address three high-severity vulnerabilities that could allow attackers to access sensitive information or cause the system to …

Threat Actors Breaking to Enterprise Infrastructure Within 18 Minutes From Initial Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity professionals are facing an unprecedented acceleration in threat actor capabilities as the average breakout time—the period from initial access to lateral movement—has plummeted to a mere 18 minutes during …

New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged in the npm ecosystem, utilizing an innovative steganographic technique to conceal malicious code within QR codes. The malicious package, identified as “fezbox,” presents itself …