Windows 11 23H2 to 25H2 Upgrade Allegedly Breaking Internet Connectivity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows 11 23H2 to 25H2 Upgrade A persistent bug in Windows 11 in-place upgrades is reportedly wiping critical 802.1X wired authentication configurations, leaving enterprise workstations completely offline until manual intervention …

Coruna Exploit Kit With 23 Exploits Hacked Thousands of iPhones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Coruna iOS Exploit Kit Google’s Threat Intelligence Group (GTIG) has uncovered Coruna, a sophisticated iOS exploit kit containing 23 exploits across five full exploit chains that compromised thousands of iPhones …

SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A suspected India-aligned threat group known as SloppyLemming has been conducting a sustained espionage campaign against government agencies, defense organizations, nuclear oversight bodies, and critical infrastructure operators in Pakistan and …

Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor tracked as D-Shortiez has been running a persistent malvertising campaign that turns a WebKit browser behavior into a trap, forcing iOS Safari users into scam pages with …

LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor operating under the alias FulcrumSec has publicly claimed responsibility for a fresh breach of LexisNexis Legal & Professional, the legal information division of RELX Group, alleging the …

Microsoft Warns of New Phishing Attack Exploiting OAuth in Entra ID to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing Attack Exploiting OAuth A new active phishing attack that exploits OAuth’s legitimate redirection behavior, allowing it to bypass traditional email and browser defenses without stealing any tokens. According to …

Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Mirai-based botnet campaign known as Zerobot has resurfaced with renewed force, this time targeting critical flaws in Tenda AC1206 routers and the n8n workflow automation platform. The campaign, now …

Archipelo and Checkmarx Announce Partnership Connecting AppSec Detection with DevSPM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

San Francisco, CA, United States, March 3rd, 2026, CyberNewswire Archipelo and Checkmarx today announced a technical partnership focused on correlating application vulnerability findings with development-origin context within modern software delivery …

New ‘StegaBin’ Campaign Uses Malicious 26 npm Packages to Deploy Multi-Stage Credential Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new software supply-chain attack is abusing the npm ecosystem today, where a single mistaken dependency can quietly open a door into a developer’s machine. The activity, tracked as “StegaBin,” …

Hackers Leverage Telegram for Initial Access to Corporate VPN, RDP, and Cloud Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Telegram, once widely recognized as a privacy-focused messaging application, has quietly transformed into one of the most powerful operational platforms used by cybercriminals today. What dark web forums once offered …