xHunt APT Hackers Attacking Microsoft Exchange and IIS Web Servers to Deploy Custom Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The xHunt advanced persistent threat group has firmly established itself as a sophisticated cyber-espionage actor, orchestrating targeted campaigns against organizations in Kuwait. Since its emergence in 2018, the group has …

Jaguar Land Rover Confirms Employee Data Stolen in August Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jaguar Land Rover (JLR), the iconic British luxury automaker, has finally disclosed that a cyberattack in August compromised sensitive data on current and former employees. This marks the company’s first …

JumpCloud Remote Assist for Windows Agent Flaw Let Attackers Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The JumpCloud Remote Assist vulnerability (CVE-2025-34352) exposes Windows systems to local privilege escalation and denial-of-service attacks. Discovered by XM Cyber researcher Hillel Pinto, the flaw stems from insecure file operations …

Threat Actors Advertising ‘MioLab MacOS’ Infostealer on an Underground Forum

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware threat targeting macOS users has emerged on underground cybercrime forums, with threat actors marketing a sophisticated information-stealing tool called “MioLab MacOS.” This resident infostealer comes equipped with …

New Android Malware Frogblight Mimics as Official Government Websites to Collect SMS and Device Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android banking Trojan named Frogblight has emerged as a significant threat targeting Turkish users, employing deceptive tactics to steal banking credentials and personal data. Discovered in August 2025, …

NVIDIA Merlin Vulnerabilities Let Attackers Execute Malicious Code and Trigger DoS Condition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security patches for the Merlin framework addressing two high-severity deserialization vulnerabilities. That could allow attackers to execute arbitrary code and launch denial-of-service attacks on affected Linux systems. NVIDIA researchers have …

Wireshark 4.6.2 Released With Fix for Vulnerabilities, and Updated Protocol Support

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Wireshark 4.6.2, the latest version of the leading open-source network protocol analyzer, addresses critical crash vulnerabilities and plugin compatibility issues. This maintenance release prioritizes stability for users in troubleshooting and …

New ARTEMIS AI Agent Outperformed 9 out of 10 Human Penetration Testers in Detecting Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from Stanford University, Carnegie Mellon University, and Gray Swan AI have unveiled ARTEMIS, a sophisticated AI agent framework that demonstrates remarkable competitive capabilities against seasoned cybersecurity professionals. In the …

New Android Malware Mimic as mParivahan and e-Challan Attacking Android Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android malware campaign named NexusRoute is actively targeting Indian citizens by impersonating government services. The operation uses fake versions of the official mParivahan and e-Challan applications to harvest …

New Clickfix Attack Exploits finger.exe Tool to Trick Users into Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel social engineering campaign, dubbed ClickFix, has been identified, which cleverly employs an old Windows command-line tool, finger.exe, to install malware on victims’ systems. This attack begins with a …