Navia Confirms Data Breach – 2.7 Million Users Sensitive Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Navia Data Breach A prominent U.S. consumer-focused benefits administrator has disclosed a significant data breach exposing the sensitive personal and health information of approximately 2.7 million individuals.​ On January 23, …

Bamboo Data Center and Server Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Bamboo Data Center and Server Vulnerability A high-severity security flaw has been addressed in Bamboo Data Center, an enterprise platform widely used for software build and release management. Tracked as …

New ‘Speagle’ Malware Hijacks Cobra DocGuard to Steal Sensitive Data via Compromised Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered infostealer malware named Speagle has emerged as a serious threat targeting organizations that run Cobra DocGuard, a document security and encryption platform developed by Chinese company EsafeNet. …

Apex – AI-Powered Pentester Attacks Apps in Black-Box Mode to Find Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apex AI Penetration Testing Agent Apex is an autonomous, AI-powered penetration testing agent designed to operate in black-box mode against live applications. It does not require access to source code, …

SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. It uses VBScript, in-memory PowerShell execution, and PEB masquerading to …

Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Russian state-linked threat actor has launched a targeted cyberattack against a Ukrainian government agency, exploiting a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite to steal credentials and sensitive …

Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Authorities Disrupts IoT Botnet Authorities have successfully dismantled the command-and-control (C2) infrastructure powering four massive Internet of Things (IoT) botnets. The U.S. Justice Department, collaborating closely with Canadian and German …

CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns Zimbra Collaboration Suite Vulnerability Exploit CISA has added a high-severity vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2025-66376, this …

CISA Urges Organizations to Secure Microsoft Intune Environments Following Stryker Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert urging organizations to harden their endpoint management system configurations following a cyberattack on Stryker Corporation, a U.S.-based …