PureVPN Vulnerability Exposes Users IPv6 Address While Toggling Wi-Fi

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PureVPN’s Linux clients leak users’ IPv6 addresses when Wi-Fi reconnections or system resumes occur, and also obliterate host firewall rules without restoring them upon disconnect.  This undermines privacy guarantees and …

SonicWall Urges Customers to Reset Login Credentials After Configuration Backup Files Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has issued an urgent advisory urging all customers to perform an Essential Credential Reset after security researchers discovered that MySonicWall configuration backup files were inadvertently exposed on public storage.  …

BMW Allegedly Breached by Everest Ransomware Group, Internal Documents Reportedly Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The infamous Everest ransomware group has reportedly included Bayerische Motoren Werke AG (BMW) as a high-profile target, claiming the theft of a significant amount of critical internal documents from the …

Researchers Uncover Hidden Connections Between Ransomware Groups and Relationships Between Them

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, cybersecurity researchers have exposed a tangled web of hidden alliances among leading ransomware operations, reshaping how defenders perceive these threats. Historically treated as distinct entities—Conti, LockBit, Evil …

Lessons Learned from Massive npm Supply Chain Attack Using “Shai-Hulud” Self-Replicating Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The JavaScript ecosystem experienced one of its most sophisticated and damaging supply chain attacks in September 2025, when a novel self-replicating worm dubbed “Shai-Hulud” compromised over 477 npm packages, marking the …

Beware of Typosquatted Malicious PyPI Packages That Delivers SilentSync RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Python developers face a growing threat from typosquatted packages in the Python Package Index (PyPI), with malicious actors increasingly targeting this trusted repository to distribute sophisticated malware. Recent discoveries have …

Raven Stealer Attacking Google Chrome Users to Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Raven Stealer has emerged as a potent information‐stealing threat targeting users of Chromium‐based browsers, most notably Google Chrome. First observed in mid-2025, this lightweight malware distinguishes itself through a modular …

Jenkins Patches Multiple Vulnerabilities that Allow Attackers to Cause a Denial of Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jenkins has released critical updates addressing four security flaws that unauthenticated and low-privileged attackers could exploit to disrupt service or glean sensitive configuration details.  Administrators running Jenkins weekly releases up …

Pixie Dust Wi-Fi Attack Exploits Routers WPS to Obtain PIN and Connect With Wireless Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The newly publicized Pixie Dust attack has once again exposed the critical vulnerabilities inherent in the Wi-Fi Protected Setup (WPS) protocol, enabling attackers to extract the router’s WPS PIN offline …

TP-Link Router 0-Day RCE Vulnerability Exploited Bypassing ASLR Protections – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day remote code execution (RCE) vulnerability, identified as CVE-2025-9961, has been discovered in TP-Link routers. Security research firm ByteRay has released a proof-of-concept (PoC) exploit, demonstrating how attackers …