Nokia CBIS/NCS Manager API Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability has emerged in Nokia’s CloudBand Infrastructure Software (CBIS) and Nokia Container Service (NCS) Manager API, designated as CVE-2023-49564. This high-severity flaw, scoring 9.6 on the …

Russian Hacking Groups Gamaredon and Turla Attacking Organizations to Deploy Kazuar Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In early 2025, cybersecurity researchers observed an unprecedented collaboration between two Russian APT groups targeting Ukrainian organizations. Historically, Gamaredon has focused on broad spear-phishing campaigns against government and critical infrastructure, …

CISA Warns of Hackers Exploiting Ivanti Endpoint Manager Mobile Vulnerabilities to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding sophisticated malware campaigns targeting Ivanti Endpoint Manager Mobile (EPMM) systems. Cybercriminals are actively exploiting two critical vulnerabilities, …

ChatGPT Tricked Into Bypassing CAPTCHA Security and Enterprise Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ChatGPT agents can be manipulated into bypassing their own safety protocols to solve CAPTCHA, raising significant concerns about the robustness of both AI guardrails and widely used anti-bot systems. The …

Beware of Weaponized ScreenConnect App That Delivers AsyncRAT and PowerShell RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The emergence of a new campaign weaponizing legitimate remote monitoring and management software has alarmed security teams worldwide. Attackers are distributing trojanized installers for ConnectWise ScreenConnect—now known as ConnectWise Control—to …

Researchers Uncover Link Between Belsen and ZeroSeven Cybercriminal Groups

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified a potential connection between two Yemen-based cybercriminal organizations, the Belsen Group and ZeroSevenGroup, following an extensive investigation into their operational patterns and attack methodologies. The discovery …

SystemBC Botnet Hacking 1,500 VPS Servers Daily to Hire for DDoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The emergence of the SystemBC botnet marks a significant evolution in proxy-based criminal infrastructure. Rather than co-opt residential devices for proxying, SystemBC operators have shifted to compromising large commercial Virtual …

CISA Warns of Delta Electronics Vulnerabilities Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA issued a warning of two critical path traversal flaws in Delta Electronics’ DIALink industrial control system software.  With a maximum CVSS v4 base score of 10.0, these vulnerabilities could …

RDP vs SSH Comparison – Features, Protocols, Security, And Use Cases

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Remote Desktop Protocol (RDP) and Secure Shell (SSH) have changed how organizations manage their IT systems. These tools allow employees to access and control their computers from anywhere, which helps …

Critical GoAnywhere MFT Platform Vulnerability Exposes Enterprises to Remote Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A deserialization flaw in the License Servlet component of Fortra GoAnywhere Managed File Transfer (MFT) platform. Identified as CVE-2025-10035, this vulnerability permits an unauthenticated attacker who can deliver a forged …