Hackers Registering Domains to Launch Cyberattack Targeting 2026 FIFA World Cup Tournament

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have observed an unprecedented surge in domain registrations in recent months, closely tied to the upcoming 2026 FIFA World Cup tournament. These domains, often masquerading as legitimate ticketing …

Beware of Fraudulent Scholarship Apps Attacking Students in Defarud Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android malware campaign has emerged in recent months, targeting students in Bangladesh by masquerading as legitimate scholarship applications. Disguised under the guise of the Bangladesh Education Board, these …

IBM Watsonx Vulnerability Let Attackers Inject Malicious SQl Queries

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

IBM published a security bulletin disclosing a serious Blind SQL injection vulnerability in its IBM Watsonx Orchestrate Cartridge for IBM Cloud Pak for Data, assigned CVE-2025-0165.  With a CVSS 3.1 …

Windows 11 25H2 Update Preview Released, What’s New?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has opened the Release Preview Channel to Windows Insiders for the forthcoming Windows 11, version 25H2 (Build 26200.5074) enablement package (eKB), offering an early look at this year’s annual …

Malicious npm Package Mimics as Popular Nodemailer with Weekly 3.9 Million Downloads to Hijack Crypto Transactions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Socket.dev uncovered a sophisticated supply chain attack in late August 2025 leveraging a malicious npm package named nodejs-smtp, which masquerades as the widely used email library nodemailer, …

Sitecore CMS Platform Vulnerabilities Enables Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerabilities in Sitecore Experience Platform allow attackers to achieve complete system compromise through a sophisticated attack chain combining HTML cache poisoning with remote code execution capabilities. These flaws also …

Infostealer Malware is Being Exploited by APT Groups for Targeted Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Infostealer malware, initially designed to indiscriminately harvest credentials from compromised hosts, has evolved into a potent weapon for state-sponsored Advanced Persistent Threat (APT) groups. Emerging in early 2023, families such …

Amazon Dismantles Russian APT 29 Infrastructure Used to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon’s threat intelligence team uncovered a sophisticated watering hole campaign in late August 2025, which is orchestrated by APT29, also known as Midnight Blizzard, a Russian Foreign Intelligence Service–linked actor. …

Hackers Leverage Windows Defender Application Control Policies to Disable EDR Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are exploiting Windows Defender Application Control (WDAC) policies to systematically disable Endpoint Detection and Response (EDR) agents, creating a dangerous blind spot in corporate security infrastructure. Real-world threat actors, …