CISA Warns of Apple iOS, iPadOS, and macOS 0-day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent warning regarding a critical zero-day vulnerability affecting Apple’s iOS, iPadOS, and macOS operating systems that threat actors are actively exploiting.  The vulnerability, tracked as CVE-2025-43300, …

Help TDS Weaponize Legitimate Sites’ PHP Code Templates With Fake Microsoft Windows Security Alert Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated traffic direction system known as Help TDS has been weaponizing compromised websites since 2017, transforming legitimate sites into gateways for elaborate tech support scams. The operation specializes in …

New HTTP Smuggling Attack Technique Let Hackers Inject Malicious Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated HTTP request smuggling attack that exploits inconsistent parsing behaviors between front-end proxy servers and back-end application servers.  This newly discovered technique leverages malformed chunked transfer encoding extensions to …

New Cryptojacking Attack Exploits Redis Servers to Install Miners and Disable Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cryptojacking campaign has emerged, exploiting misconfigured Redis servers across multiple continents to deploy cryptocurrency miners while systematically dismantling security defenses. The threat actor behind this operation, designated TA-NATALSTATUS, …

Lumma Affiliates Using Advanced Evasion Tools Designed to Ensure Stealth and Continuity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Lumma information stealer has evolved from its 2022 origins into one of the most sophisticated malware-as-a-service (MaaS) ecosystems in the cybercriminal landscape. Operating through a vast network of affiliates, …

BQTLOCK Ransomware Operates as RaaS With Advanced Evasion Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new ransomware strain named BQTLOCK has emerged in the cyberthreat landscape since mid-July 2025, operating under a comprehensive Ransomware-as-a-Service (RaaS) model that democratizes access to advanced encryption capabilities …

Malicious Go Module Package as Fast SSH Brute Forcer Exfiltrates Passwords via Telegram

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has emerged targeting developers through a malicious Go module package that masquerades as a legitimate SSH brute forcing tool while covertly stealing credentials for cybercriminal …

South Asian APT Hackers Using Novel Tools to Compromise Phones of Military-Adjacent Members

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated South Asian Advanced Persistent Threat (APT) group has been conducting an extensive espionage campaign targeting military personnel and defense organizations across Sri Lanka, Bangladesh, Pakistan, and Turkey. The …

Windows Docker Desktop Vulnerability Leads to Full Host Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in Docker Desktop for Windows has revealed how a simple Server-Side Request Forgery (SSRF) attack could lead to complete host system compromise.  CVE-2025-9074, discovered by Felix …

UAC-0057 Hackers Weaponizing PDF Invitation Files to Execute Shell Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber espionage campaign has emerged targeting Ukrainian and Polish organizations through weaponized PDF invitation files designed to execute malicious shell scripts. The campaign, active since April 2025, demonstrates …