Palo Alto Networks Confirms Data Breach: Hackers Stole Customer Data from Salesforce Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks has confirmed it is one of hundreds of organizations impacted by a significant supply chain attack that resulted in the theft of customer data from its Salesforce …

Microsoft to Kill Popular Editor Browser Extensions on Edge and Chrome

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On August 29, 2025, Microsoft announced the retirement of its popular Microsoft Editor browser extensions for Microsoft Edge and Google Chrome.  The Editor extensions will be officially deprecated on October …

Record-breaking 11.5 Tbps UDP Flood DDoS Attack Originated from Google Cloud Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare, a company that provides web security and infrastructure, recently reported that it stopped a huge cyber attack. This attack reached a record high of 11.5 terabits per second (Tbps). …

Lazarus Hackers Deploying Three RATs on Compromised Systems Possibly Using 0-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated subgroup of the Lazarus threat actor has surfaced in recent months, deploying three distinct remote access trojans (RATs) across compromised financial and cryptocurrency organizations. Initial access has primarily …

HashiCorp Vault Vulnerability Let Attackers to Crash Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical denial-of-service vulnerability in HashiCorp Vault could allow malicious actors to overwhelm servers with specially crafted JSON payloads, leading to excessive resource consumption and rendering Vault instances unresponsive.  Tracked …

MobSF Security Testing Tool Vulnerability Let Attackers Upload Malicious Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw in the Mobile Security Framework (MobSF) has been discovered, allowing authenticated attackers to upload and execute malicious files by exploiting improper path validation.  The vulnerability, present in …

New TinkyWinkey Stealthily Attacking Windows Systems With Advanced Keylogging Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Windows-based keylogger known as TinkyWinkey began surfacing on underground forums in late June 2025, targeting enterprise and individual endpoints with unprecedented stealth. Unlike traditional keylogging tools that rely …

Critical Qualcomm Vulnerabilities Allow Attackers to Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical vulnerabilities in Qualcomm Technologies’ proprietary Data Network Stack and Multi-Mode Call Processor that permit remote attackers to execute arbitrary code.  These flaws, tracked as CVE-2025-21483 and CVE-2025-27034, each …

Azure Active Directory Vulnerability Exposes Credentials and Enables Attackers to Deploy Malicious Apps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has emerged in Azure Active Directory (Azure AD) configurations that exposes sensitive application credentials, providing attackers with unprecedented access to cloud environments.  This vulnerability centers around …

28 Years of Nmap – From Simple Port Scanner to Comprehensive Network Security Suite

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Nmap has remained at the forefront of network discovery and security assessment for nearly three decades. Originally introduced on September 1, 1997, in Phrack magazine as a modest, 2,000-line Linux-only …