Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Clop ransomware group has launched a new data extortion campaign targeting Internet-facing Gladinet CentreStack file servers, marking another chapter in the threat actor’s pattern of exploiting file transfer solutions. …

China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberespionage campaign targeting governmental entities in Southeast Asia and Japan has unveiled a new China-aligned threat actor dubbed LongNosedGoblin. Active since at least September 2023, this advanced persistent …

Amazon Catches North Korean IT Worker by Tracking Tiny 110ms Keystroke Delays

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A slight delay in keystrokes from a supposed U.S.-based IT worker alerted Amazon to a North Korean infiltrator accessing a corporate laptop. The commands should have zipped from the worker’s …

OpenAI GPT-5.2-Codex Supercharges Agentic Coding and Cyber Vulnerability Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has unveiled GPT-5.2-Codex, a cutting-edge model optimized for agentic coding and enhanced cybersecurity tasks. The release highlights breakthroughs in handling complex software engineering and vulnerability detection. GPT-5.2-Codex tops SWE-Bench …

New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified botnet malware family, dubbed “Udados,” has emerged as a significant threat to the Technology and Telecommunications sectors, orchestrating high-volume HTTP flood Distributed Denial-of-Service (DDoS) attacks. According to …

CISA Adds ASUS Embedded Malicious Code Vulnerability to KEV List Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a new ASUS vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, signaling urgent risk for affected users and organizations. The flaw, tracked as CVE-2025-59374, affects ASUS Live Update, a …

HPE OneView Software Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security alert warns customers about a severe vulnerability in HPE OneView Software that could allow remote attackers to execute arbitrary code without authentication. The flaw, tracked as CVE-2025-37164, …

RansomHouse RaaS Service Upgraded with Double Extortion Strategy that Steals and Encrypt Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

RansomHouse has emerged as a significant threat in the ransomware landscape, operated by a group tracked as Jolly Scorpius. This ransomware-as-a-service platform combines data theft with encryption, creating a dual …

Researchers Uncovered New Lazarus and Kimsuky Infrastructure with Active Tools and Tunnelling Nodes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A joint investigation by Hunt.io and the Acronis Threat Research Unit has exposed an extensive network of North Korean state-sponsored infrastructure, revealing fresh connections between Lazarus and Kimsuky operations across …