Latest Cybersecurity News and Articles
08 May 2025
Threat actors with ties to the Qilin ransomware family have leveraged malware known as SmokeLoader along with a previously undocumented .NET compiled loader codenamed NETXLOADER as part of a campaign observed in November 2024.
"NETXLOADER is a new .NET-based loader that plays a critical role in cyber attacks," Trend Micro researchers Jacob Santos, Raymart Yambot, John Rainier Navato, Sarah Pearl
08 May 2025
SonicWall patches three SMA 100 vulnerabilities, including a potential zero-day, that could be chained to execute arbitrary code remotely.
The post Possible Zero-Day Patched in SonicWall SMA Appliances appeared first on SecurityWeek.
08 May 2025
CISA, along with other government entities, has issued a warning about cyberattacks targeting the nation’s critical oil and natural gas infrastructure.
08 May 2025
Russia-linked APT Star Blizzard is using the ClickFix technique in recent attacks distributing the LostKeys malware.
The post Google Finds Data Theft Malware Used by Russian APT in Select Cases appeared first on SecurityWeek.
08 May 2025
61% of security leaders reported suffering a breach due to failed or misconfigured controls over the past 12 months. This is despite having an average of 43 cybersecurity tools in place.
This massive rate of security failure is clearly not a security investment problem. It is a configuration problem. Organizations are beginning to understand that a security control installed or deployed is not
08 May 2025
The patches for an exploited Samsung MagicINFO vulnerability are ineffective and a Mirai botnet has started targeting it.
The post Improperly Patched Samsung MagicINFO Vulnerability Exploited by Botnet appeared first on SecurityWeek.
08 May 2025
The nation-state threat actor known as MirrorFace has been observed deploying malware dubbed ROAMINGMOUSE as part of a cyber espionage campaign directed against government agencies and public institutions in Japan and Taiwan.
The activity, detected by Trend Micro in March 2025, involved the use of spear-phishing lures to deliver an updated version of a backdoor called ANEL.
"The ANEL file from
08 May 2025
Cisco releases patches for 26 vulnerabilities in IOS and IOS XE software, including 17 critical- and high-severity bugs.
The post Cisco Patches 35 Vulnerabilities Across Several Products appeared first on SecurityWeek.
08 May 2025
SysAid patches IT service management software vulnerabilities that can be chained for unauthenticated remote command execution.
The post Dozens of SysAid Instances Vulnerable to Remote Hacking appeared first on SecurityWeek.
08 May 2025
Health technology and consumer electronics firm Masimo detected unauthorized activity on its network in late April.
The post Masimo Manufacturing Facilities Hit by Cyberattack appeared first on SecurityWeek.
08 May 2025
The Russia-linked threat actor known as COLDRIVER has been observed distributing a new malware called LOSTKEYS as part of an espionage-focused campaign using ClickFix-like social engineering lures.
"LOSTKEYS is capable of stealing files from a hard-coded list of extensions and directories, along with sending system information and running processes to the attacker," the Google Threat
08 May 2025
A recent campaign driven by Venom Spider, a financially-motivated threat group, is using spear-phishing emails to target hiring managers.
08 May 2025
Cisco has released software fixes to address a maximum-severity security flaw in its IOS XE Wireless Controller that could enable an unauthenticated, remote attacker to upload arbitrary files to a susceptible system.
The vulnerability, tracked as CVE-2025-20188, has been rated 10.0 on the CVSS scoring system.
"This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an
07 May 2025
A Texas firm recently charged with conspiring to distribute synthetic opioids in the United States is at the center of a vast network of companies in the U.S. and Pakistan whose employees are accused of using online ads to scam westerners seeking help with trademarks, book writing, mobile app development and logo designs, a new investigation reveals.
07 May 2025
Cisco unveils its Quantum Network Entanglement Chip and new Quantum Labs, laying the groundwork for a scalable quantum internet that connects distributed quantum computers into a unified, powerful system.
The post Cisco’s Quantum Bet: Linking Small Machines Into One Giant Quantum Computer appeared first on SecurityWeek.
07 May 2025
According to a recent report, 94% of Fortune 50 companies have employee identity data exposed as a consequence of phishing attacks.
07 May 2025
Code quality and security firm CodeAnt has secured $2 million in seed funding and it has been valued at $20 million.
The post CodeAnt AI Raises $2 Million for Code Quality and Application Security Platform appeared first on SecurityWeek.
07 May 2025
CrowdStrike said the planned cuts will affect approximately 500 employees and will span the first half of fiscal 2026.
The post CrowdStrike Plans Layoffs to Pursue $10B ARR Target appeared first on SecurityWeek.
07 May 2025
Ox Security has raised a total $94 million since its launch in 2021 with ambitious plans to cash in on two fast-moving trends.
The post Ox Security Bags $60M Series B to Tackle Appsec Alert Fatigue appeared first on SecurityWeek.
07 May 2025
By baking minimum expectations into procurement conversations, the plan is to steer software vendors to “secure-by-design and default” basics.
The post New UK Framework Pressures Vendors on SBOMs, Patching and Default MFA appeared first on SecurityWeek.