New MCPoison Attack Leverages Cursor IDE MCP Validation to Execute Arbitrary System Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Cursor IDE, the rapidly growing AI-powered development environment, enables persistent remote code execution through manipulation of the Model Context Protocol (MCP) system. The vulnerability, tracked as …

How Certificate Mismanagement Opens The Door For Phishing And MITM Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SSL certificates are used everywhere from websites and APIs to mobile apps, internal tools and CI/CD pipelines. While most teams know they’re important, they often don’t manage them well. Certificates …

New Streamlit Vulnerability Allows Hackers to Launch Cloud Account Takeover Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Streamlit, the popular open-source framework for building data applications, enables attackers to conduct cloud account takeover attacks.  The flaw, discovered in February 2025, exploits weaknesses in …

Cloudflare Accuses Perplexity AI For Evading Firewalls and Crawling Websites by Changing User Agent

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Perplexity AI, an emerging question-answering engine powered by advanced large language models, has recently come under scrutiny for deploying stealth crawling techniques that bypass standard web defenses. Initially launched with …

APT36 Hackers Attacking Indian Government Entities to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign attributed to the Pakistan-linked APT36 group has emerged as a serious threat to Indian government infrastructure. First detected in early August 2025, this operation leverages typo-squatted …

North Korean Hackers Weaponizing NPM Packages to Steal Cryptocurrency and Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated North Korean cryptocurrency theft campaign has resurfaced with renewed vigor, weaponizing twelve malicious NPM packages to target developers and steal digital assets. The campaign, which represents a significant …

Cisco Hacked – Attackers Stole Profile Details of Users Registered on Cisco.com

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has confirmed it was the target of a cyberattack where a malicious actor successfully stole the basic profile information of an undisclosed number of users registered on Cisco.com. The …

Kimsuky APT Hackers Weaponizing LNK Files to Deploy Reflective Malware Bypassing Windows Defender

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean state-sponsored cyber-espionage group Kimsuky has unveiled a sophisticated new campaign targeting South Korean entities through malicious Windows shortcut (LNK) files, demonstrating the group’s continued evolution in stealth and …

SonicWall Warns of Escalating Cyberattacks Targeting Gen 7 Firewalls in Last 72 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has issued an urgent security advisory following a significant increase in cyber incidents targeting its Gen 7 SonicWall firewalls over the past 72 hours. The company is actively investigating …

Hackers Can Steal IIS Machine Keys by Exploiting SharePoint Deserialization Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack method where hackers are exploiting a deserialization vulnerability in SharePoint to steal Internet Information Services (IIS) Machine Keys. This enables attackers to bypass security measures, forge trusted …