Critical Chaos Mesh Vulnerabilities Let Attackers Takeover Kubernetes Cluster

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerabilities were identified in Chaos Mesh, a popular Cloud Native Computing Foundation chaos engineering platform used for fault injection testing in Kubernetes environments.  The security flaws, collectively dubbed “Chaotic …

Kubernetes C# Client Vulnerability Exposes API Server Communication To MiTM Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A medium-severity vulnerability has been discovered in the official Kubernetes C# client, which could allow an attacker to intercept and manipulate sensitive communications. The flaw, rated 6.8 on the CVSS …

World’s Largest Hacking Forum BreachForums Creator Sentenced to Three Years in Prison

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Conor Brian Fitzpatrick, the 22-year-old founder of BreachForums, has been resentenced to three years in federal prison for operating one of the world’s largest cybercriminal marketplaces.  The New York resident …

How a Plaintext File On Users’ Desktops Exposed Secrets Leads to Akira Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor who gained initial access through a SonicWall VPN device was able to escalate their attack by finding Huntress recovery codes saved in a plaintext file on a …

Linux Kernel’s KSMBD Subsystem Vulnerability Let Remote Attackers Exhaust Server Resources

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A denial-of-service flaw in the Linux kernel’s KSMBD (SMB Direct) subsystem has raised alarms across the open-source community.  Tracked as CVE-2025-38501, the issue allows a remote, unauthenticated adversary to exhaust …

Massive “Shai-Halud” Supply Chain Attack Compromised 477 NPM Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale supply chain attack dubbed “Shai-Halud” that infiltrated the JavaScript ecosystem via the npm registry.  In total, 477 packages, including packages from CrowdStrike, were found to contain stealthy backdoors …

FinWise Insider Breach Exposes 700K Customer Records to Former Employee

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

American First Finance, LLC, a Dallas-based financial services firm, suffered a significant insider breach when a recently terminated employee exploited unauthorized access to its production database.  The incident, dubbed the …

Hackers Can Exploit Bitpixie Vulnerability to Bypass BitLocker Encryption and Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Windows Boot Manager, known as bitpixie, enables attackers to bypass BitLocker drive encryption and escalate local privileges on Windows systems.  The vulnerability affects boot managers from 2005 to …

3 Weeks Left Until the Start of the OpenSSL Conference 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Newark, New Jersey, United States, September 16th, 2025, CyberNewsWire The OpenSSL Conference 2025 will take place on October 7 – 9 in Prague. The program will bring together lawyers, regulators, developers, and …

Hackers Stolen Millions of Users Personal Data from Gucci, Balenciaga and Alexander McQueen Stores

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Luxury fashion company Kering has confirmed a data exfiltration incident in which threat actor Shiny Hunters accessed private customer records for Gucci, Balenciaga, and Alexander McQueen. The breach, detected in …