Threat Actors Abuse AI Website Creation App to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have discovered a new avenue for malicious activities by exploiting Lovable, an AI-powered website creation platform, to develop sophisticated phishing campaigns and malware delivery systems. The platform, designed to …

Warlock Ransomware Exploiting SharePoint Vulnerabilities to Gain Access and Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, the cybersecurity community has witnessed the rapid emergence of Warlock, a novel ransomware strain that weaponizes unpatched Microsoft SharePoint servers to infiltrate enterprise networks. Initial analysis reveals …

Internet Archive Abused for Hosting Stealthy JScript Loader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a novel malware delivery chain in recent weeks that leverages the Internet Archive’s legitimate infrastructure to host obfuscated payloads. The attack begins with a seemingly innocuous …

Weekly Cybersecurity News Recap : Microsoft, Cisco, Fortinet Security Updates and Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the week of August 11-17, 2025, the cybersecurity landscape was marked by critical updates from major vendors and a surge in sophisticated threats, underscoring the ongoing battle against digital …

New Elastic EDR 0-Day Vulnerability Allows Attackers to Bypass Detection, Execute Malware, and Cause BSOD

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered zero-day vulnerability in Elastic’s Endpoint Detection and Response (EDR) solution allows attackers to bypass security measures, execute malicious code, and trigger a BSOD system crash, according to …

CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA in collaboration with international partners, has released comprehensive guidance, titled “Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators,” to strengthen cybersecurity defenses across critical infrastructure sectors. …

Google Awards $250,000 Bounty for Chrome RCE Vulnerability Discovery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has awarded a record-breaking $250,000 bounty to security researcher “Micky” for discovering a critical remote code execution vulnerability in Chrome’s browser architecture.  The vulnerability allowed malicious websites to escape …

Microsoft IIS Web Deploy Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Microsoft Web Deploy tool could allow authenticated attackers to execute remote code on affected systems.  The vulnerability, tracked as CVE-2025-53772, was disclosed on August 12, …