Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community was alarmed in late December 2025 when MongoDB announced a serious vulnerability called “Mongobleed” (CVE-2025-14847). This high-severity flaw allows unauthenticated attackers to steal sensitive data directly from …

Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

After a decade of disappearing from the cybersecurity landscape, the Careto threat group, also known as “The Mask,” has resurfaced with sophisticated new attack methods targeting high-profile organizations. Security researchers …

Apache NuttX Vulnerability Let Attackers to Crash Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed use-after-free vulnerability in Apache NuttX RTOS could allow attackers to cause system crashes and unintended filesystem operations, prompting urgent security warnings for users running network-exposed services. The …

WhatsApp Crypt Tool to Encrypt and Decrypt WhatsApp Backups

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An open-source solution for handling encrypted WhatsApp backups. The wa-crypt-tools suite, hosted on GitHub, decrypts and encrypts .crypt12, .crypt14, and .crypt15 files from WhatsApp and WhatsApp Business, provided users supply …

Two U.S. CyberSecurity Pros Plead Guilty for Working as ALPHV/BlackCat Affiliates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A federal court in the Southern District of Florida has accepted guilty pleas from two cybersecurity professionals who used their expertise to conduct ransomware attacks rather than stop them. Ryan …

Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of GlassWorm malware has emerged, marking a significant shift in targeting strategy from Windows to macOS systems. This self-propagating worm, distributed through malicious VS Code extensions on …

New Cybercrime Tool ErrTraffic Let Attackers Automate ClickFix Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous cybercrime tool known as ErrTraffic has appeared in underground forums, making it easier for attackers to trick users into running harmful software on their devices. The tool automates …

DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered DarkSpectre, a well-funded Chinese threat actor responsible for infecting over 8.8 million users across Chrome, Edge, and Firefox browsers through a series of highly coordinated malware campaigns …

Critical IBM API Connect Vulnerability Let Attackers Bypass Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security alert regarding a severe vulnerability in the IBM API Connect platform that could allow remote attackers to bypass authentication mechanisms. Discovered during internal testing, the flaw poses …