Dark Web Omertà Market Shut Downed Following the Leak of Real Server IPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The dark web landscape constantly shifts between emerging platforms and sudden closures, often driven by the very anonymity they promise. On November 21, 2025, a new contender named Omertà Market …

FreePBX Vulnerabilities Enables Authentication Bypass that Leads Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FreePBX has addressed critical vulnerabilities enabling authentication bypass and remote code execution in its Endpoint Manager module. Discovered by Horizon3.ai researchers, these flaws affect telephony endpoint configurations in the open-source …

Malicious NuGet Package Uses .NET Logging Tool to Steal Cryptocurrency Wallet Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has once again been rattled by a subtle yet dangerous supply chain attack. A malicious NuGet package named Tracer.Fody.NLog was discovered masquerading as a legitimate .NET tracing …

Popular Chrome Extension with Over 6 Million Installs Captures User Inputs to AI Chatbots

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widely trusted Chrome extension with more than 6 million users has been discovered secretly collecting and selling conversations from major AI platforms. Urban VPN Proxy, which carries Google’s “Featured” …

SoundCloud Confirms Data Breach – Hackers Exfiltrated User Account Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SoundCloud has confirmed a security incident involving unauthorized access to user data, revealing that hackers exfiltrated email addresses and public profile information from approximately 20% of its user base. The …

New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered account takeover campaign targeting WhatsApp users demonstrates how attackers can compromise messaging accounts without stealing passwords or exploiting technical vulnerabilities. The threat, identified as the GhostPairing Attack, …

Critical FortiGate Devices SSO Vulnerabilities Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active intrusion is targeting critical authentication bypass vulnerabilities in Fortinet’s FortiGate appliances and related products. Threat actors are exploiting CVE-2025-59718 and CVE-2025-59719 to perform unauthenticated single sign-on (SSO) logins …

PornHub Breached by ShinyHunters Group and Premium Members’ Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious hacking collective ShinyHunters has claimed responsibility for a major data breach at Mixpanel, a popular analytics provider, exposing limited user data tied to Pornhub Premium accounts. The incident, …

ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since December 2025, a concerning trend has emerged across Japanese organizations as attackers exploit a critical vulnerability in React/Next.js applications. The vulnerability, tracked as CVE-2025-55182 and known as React2Shell, represents …

New PCPcat Exploiting React2Shell Vulnerability to compromise 59,000+ Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign called PCPcat has successfully compromised more than 59,000 servers in under 48 hours through targeted exploitation of critical vulnerabilities in Next.js and React frameworks. The malware …