WordPress Plugin Vulnerability Let Attackers Bypass Authentication via Social Login

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability in the Case Theme User WordPress plugin has emerged as a significant security threat, allowing unauthenticated attackers to gain administrative access to websites by exploiting …

Ongoing npm Supply Chain Attack Compromises Various CrowdStrike npm Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An ongoing supply chain attack has compromised multiple npm packages published by CrowdStrike, extending a malicious campaign known as the “Shai-Halud attack.” The incident, which involves the same malware previously …

Threat Actors Can Weaponize MCP Servers To Harvests Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, threat actors have begun exploiting the Model Context Protocol (MCP)—a universal “plug-in bus” designed to streamline AI-assistant integrations—as a novel supply chain attack vector. MCP servers allow …

AWSDoor – New Persistence Technique Allows Attackers to Hide Malware Within AWS Cloud Environment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers are increasingly leveraging sophisticated techniques to maintain long-term access in cloud environments, and a newly surfaced tool named AWSDoor is emerging as a major threat.  AWSDoor automates a range …

Nessus vs Metasploit Comparison: How To Exploit Vulnerabilities Using These Powerful Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape demands sophisticated tools to identify and exploit vulnerabilities effectively, with Nessus vs Metasploit representing one of the most powerful combinations in modern penetration testing. As cyber threats …

Spring Framework Security Flaws Enable Authorization Bypass and Annotation Detection Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical vulnerabilities, CVE-2025-41248 and CVE-2025-41249, have emerged in Spring Security and Spring Framework that could allow attackers to bypass authorization controls in enterprise applications.  These flaws arise when using …

SmokeLoader Utilizes Optional Plugins To Perform Tasks Such as Stealing Data and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SmokeLoader, first seen on criminal forums in 2011, has evolved into a highly modular malware loader designed to deliver a variety of second-stage payloads, including trojans, ransomware, and credential stealers. …

AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since early 2025, the cybersecurity community has witnessed an unprecedented surge in distributed denial-of-service (DDoS) bandwidth, culminating in a record-shattering 11.5 Tbps assault attributed to a botnet named AISURU. Emerging …

Open Source CyberSOCEval Sets New Standards for AI in Malware Analysis and Threat Intelligence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A groundbreaking open-source benchmark suite called CyberSOCEval has emerged as the first comprehensive evaluation framework for Large Language Models (LLMs) in Security Operations Center (SOC) environments.  Released as part of …

New Maranhão Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since May 2025, a novel credential stealer dubbed Maranhão Stealer has emerged as a significant threat to users of pirated gaming software. Distributed through deceptive websites hosting cracked launchers and …