New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ChaosBot surfaced in late September 2025 as a sophisticated Rust-based backdoor targeting enterprise networks. Initial investigations revealed that threat actors gained entry by exploiting compromised CiscoVPN credentials coupled with over-privileged …

Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances to deploy Akira ransomware on enterprise networks. Beginning in July, multiple incidents of initial access …

Nanoprecise partners with AccuKnox to strengthen its Zero Trust Cloud Security and Compliance Posture

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Menlo Park, USA, October 10th, 2025, CyberNewsWire AccuKnox, a leader in Zero Trust Cloud Native Application Protection Platforms (CNAPP), is proud to announce that Nanoprecise has selected AccuKnox to enhance …

175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Socket’s Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages that collectively accumulated over 26,000 downloads. The campaign, dubbed “Beamglea” based on consistent artifacts across …

RondoDox Botnet Exploits 50+ Vulnerabilities to Attack Routers, CCTV Systems and Web Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since its emergence in early 2025, RondoDox has rapidly become one of the most pervasive IoT-focused botnets in operation, targeting a wide range of network-connected devices—from consumer routers to enterprise …

Microsoft Defender Incorrectly Flags SQL Server Software as End-of-life

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Defender for Endpoint is incorrectly flagging specific versions of SQL Server as having reached their end-of-life, causing potential confusion for system administrators. The issue, tracked under advisory DZ1168079, stems …

Critical GitHub Copilot Vulnerability Let Attackers Exfiltrate Source Code From Private Repos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in GitHub Copilot Chat, rated 9.6 on the CVSS scale, could have allowed attackers to exfiltrate source code and secrets from private repositories silently. The exploit combined …

New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android spyware campaign dubbed ClayRat has emerged as one of the most concerning mobile threats of 2025, masquerading as popular applications including WhatsApp, Google Photos, TikTok, and YouTube …

LLM-enabled MalTerminal Malware Leverages GPT-4 to Generate Ransomware Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified what is believed to be the earliest known instance of malware that leverages a Large Language Model (LLM) to generate malicious code at runtime. Dubbed ‘MalTerminal’ …