SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A medium-severity vulnerability in the Iconics Suite SCADA system that could allow attackers to trigger denial-of-service conditions on critical industrial control systems. The flaw, tracked as CVE-2025-0921, affects supervisory control …

Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The …

UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of targeted attacks has emerged against Internet Information Services (IIS) servers across Asia, with threat actors deploying sophisticated malware designed to compromise vulnerable systems. The campaign, active …

TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated PowerShell-based malware named TAMECAT has emerged as a critical threat to enterprise security, targeting login credentials stored in Microsoft Edge and Chrome browsers. This malware operates as part …

GhostChat Spyware Attacking Android Users Via WhatsApp to Exfiltrate Sensitive Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Android spyware campaign has emerged, targeting users in Pakistan through a sophisticated romance scam that uses fake dating profiles to steal personal information. The malicious application, known as …

Critical Ivanti Endpoint Manager 0-day RCE Vulnerabilities Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical code-injection vulnerabilities have been disclosed in the Endpoint Manager Mobile (EPMM) platform, which are currently being actively exploited in real-world attacks. The security flaws, tracked as CVE-2026-1281 and …

Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a sophisticated traffic distribution network leveraging deceptive education-themed domains to deliver malware and phishing attacks. The operation, tracked under infrastructure indicators pointing to TOXICSNAKE, uses legitimate-looking …

Hackers Weaponized Open VSX Extension with Sophisticated Malware After Reaching 5066 Downloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has infiltrated the Open VSX extension marketplace, compromising over 5,000 developer workstations through a fake Angular Language Service extension. The malicious package disguised itself as legitimate …

3,280,081 Fortinet Devices Online With Exposed Web Properties Under Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 3,280,081 Fortinet Devices Were exposed, with web properties running vulnerable Fortinet devices affected by CVE-2026-24858, a severe authentication-bypass flaw actively exploited in the wild. The vulnerability, rated 9.4 on the …