Hackers Use AI Platforms to Steal Microsoft 365 Credentials in Phishing Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly exploiting the trust organizations place in artificial intelligence platforms to conduct sophisticated phishing attacks, according to a new report from cybersecurity firm Cato Networks. The company’s Managed …

Hackers May Leverage Raw Disk Reads to Bypass EDR Solutions and Access Highly Sensitive Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new technique that allows attackers to read highly sensitive files on Windows systems, bypassing many of the modern security tools designed to prevent such breaches. A report from Workday’s …

Colombian Malware Weaponizing SWF and SVG to Bypass Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A previously unseen malware campaign began circulating in early August 2025, through email attachments and web downloads, targeting users in Colombia and beyond. By leveraging two distinct vector-based file formats—Adobe …

CISA Warns of Linux Kernel Race Condition Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new high-severity vulnerability in the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, signaling that it is being …

Windows Heap-based Buffer Overflow Vulnerability Let Attackers Elevate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently patched vulnerability in a core Windows driver could allow a local attacker to execute code with the highest system privileges, effectively taking full control of a target machine. …

Hackers Scanning Cisco ASA Devices to Exploit Vulnerabilities from 25,000 IPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An unprecedented surge in malicious scanning activity targeting Cisco Adaptive Security Appliances (ASAs) occurred in late August 2025, with over 25,000 unique IP addresses participating in coordinated reconnaissance efforts. GreyNoise, …

Chess.com Data Breach – Hackers Breached External System and Gained Internal Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Online chess giant Chess.com has disclosed a data breach that compromised the personal information of 4,541 individuals, according to a filing with the Maine Attorney General’s Office. The cyber incident took place on June …

Tycoon Phishing Kit Employs New Technique to Hide Malicious Links

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are deploying increasingly sophisticated methods to bypass security systems, with the latest threat emerging from the advanced Tycoon phishing-as-a-service kit. This malicious platform has introduced novel techniques designed to …

Bridgestone Confirms Cyberattack Impacts Manufacturing Facilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tire manufacturing giant Bridgestone Americas has confirmed it is responding to a cyberattack that disrupted operations at some of its manufacturing facilities this week. In a statement, the company asserted …

NoisyBear Weaponizing ZIP Files to PowerShell Loaders and Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated threat actor known as NoisyBear has emerged as a significant concern for Kazakhstan’s energy sector, employing advanced tactics to infiltrate critical infrastructure through weaponized ZIP files and PowerShell-based …