IT Security News

Cybersecurity news and articles about information security, vulnerabilities, exploits, hacks, laws, spam, viruses, malware, breaches.

Main menu

Skip to content
  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Apps
    • Telegram Channel
EN, Help Net Security

Attackers exploited critical Fortra GoAnywhere flaw in zero-day attacks (CVE-2025-10035)

2025-09-26 17:09

CVE-2025-10035, a perfect CVSS 10.0 vulnerability in the Fortra GoAnywhere managed file transfer solution, has apparently been exploited in zero-day attacks before the patch was released on September 15, 2025. Evidence of in-the-wild exploitation revealed On September 18, Fortra urged…

Read more →

EN, The Register - Security

LockBit’s new variant is ‘most dangerous yet,’ hitting Windows, Linux and VMware ESXi

2025-09-26 16:09

Operation Cronos didn’t kill LockBit – it just came back meaner Trend Micro has sounded the alarm over the new LockBit 5.0 ransomware strain, which it warns is “significantly more dangerous” than past versions due to its newfound ability to…

Read more →

EN, eSecurity Planet

Vietnamese Hackers Exploit Fake Copyright Notices to Spread ‘Lone None’ Stealer

2025-09-26 16:09

Vietnamese hackers use fake copyright notices and Telegram-based malware to steal data and crypto in a growing phishing campaign. The post Vietnamese Hackers Exploit Fake Copyright Notices to Spread ‘Lone None’ Stealer appeared first on eSecurity Planet. This article has…

Read more →

EN, securityweek

Interpol Says 260 Suspects in Online Romance Scams Have Been Arrested in Africa

2025-09-26 16:09

The operation took place in July and August and focused on scams in which perpetrators build online romantic relationships to extract money from targets or blackmail them with explicit images, Interpol said. The post Interpol Says 260 Suspects in Online…

Read more →

EN, eSecurity Planet

Vietnamese Hackers Exploit Fake Copyright Notices to Spread “Lone None” Stealer

2025-09-26 16:09

Vietnamese hackers use fake copyright notices and Telegram-based malware to steal data and crypto in a growing phishing campaign. The post Vietnamese Hackers Exploit Fake Copyright Notices to Spread “Lone None” Stealer appeared first on eSecurity Planet. This article has…

Read more →

EN, Malwarebytes

Google and Flo to pay $56 million after misusing users’ health data

2025-09-26 16:09

Flo Health and Google agreed to pay $56 million to settle lawsuits alleging the period-tracking app shared sensitive health data for ads. This article has been indexed from Malwarebytes Read the original article: Google and Flo to pay $56 million…

Read more →

CySecurity News - Latest Information Security and Hacking Incidents, EN

OpenAI Patches ChatGPT Gmail Flaw Exploited by Hackers in Deep Research Attacks

2025-09-26 16:09

  OpenAI has fixed a security vulnerability that could have allowed hackers to manipulate ChatGPT into leaking sensitive data from a victim’s Gmail inbox. The flaw, uncovered by cybersecurity company Radware and reported by Bloomberg, involved ChatGPT’s “deep research” feature.…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Malicious MCP Server Discovered Stealing Sensitive Emails Using AI Agents

2025-09-26 15:09

Enterprises everywhere are embracing MCP servers—tools that grant AI assistants “god-mode” permissions to send emails, run database queries, and automate tedious tasks. But no one ever stopped to ask: Who built these tools? Today, the first real-world malicious MCP server—postmark-mcp—has…

Read more →

Check Point Blog, EN

How to Defend Against Credential Attacks with a Hybrid Mesh Architecture

2025-09-26 15:09

Introduction Credential-based attacks have reached epidemic levels. The 2025 Verizon Data Breach Investigations Report (DBIR) underscores the trend: 22% of breaches now start with compromised credentials, while Check Point External Risk Management found that leaked credential volumes surged 160% year-over-year.…

Read more →

EN, Fortinet Threat Research Blog

SVG Phishing hits Ukraine with Amatera Stealer, PureMiner

2025-09-26 15:09

A phishing campaign in Ukraine uses malicious SVG files to drop Amatera Stealer and PureMiner, enabling data theft and cryptomining. Learn more.        This article has been indexed from Fortinet Threat Research Blog Read the original article: SVG Phishing hits…

Read more →

Cyber Security News, EN

First-Ever Malicious MCP Server Found in the Wild Steals Emails via AI Agents

2025-09-26 15:09

The first-ever malicious Model-Context-Prompt (MCP) server discovered in the wild, a trojanized npm package named postmark-mcp that has been secretly exfiltrating sensitive data from users’ emails. The package, downloaded approximately 1,500 times per week, contained a backdoor that copied every…

Read more →

Cyber Security News, EN

New Variant of The XCSSET Malware Attacking macOS App Developers

2025-09-26 15:09

The macOS threat landscape has witnessed a significant escalation with the discovery of a new variant of the XCSSET malware targeting app developers. First observed in late September 2025, this variant builds upon earlier versions by introducing enhanced stealth techniques,…

Read more →

Cyber Security News, EN

Fortra GoAnywhere Vulnerability Exploited as 0-Day Before Patch

2025-09-26 15:09

A critical, perfect 10.0 CVSS score vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) solution was actively exploited as a zero-day at least a week before the company released a patch. The vulnerability, tracked as CVE-2025-10035, is a command injection…

Read more →

EN, The Hacker News

New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks

2025-09-26 15:09

The Russian advanced persistent threat (APT) group known as COLDRIVER has been attributed to a fresh round of ClickFix-style attacks designed to deliver two new “lightweight” malware families tracked as BAITSWITCH and SIMPLEFIX. Zscaler ThreatLabz, which detected the new multi-stage…

Read more →

EN, www.infosecurity-magazine.com

Singapore Threatens Meta With Fines Over Facebook Impersonation Scams

2025-09-26 15:09

The Singapore police said Facebook is the top platform for online scams in the country This article has been indexed from www.infosecurity-magazine.com Read the original article: Singapore Threatens Meta With Fines Over Facebook Impersonation Scams

Read more →

Cyber Defense Magazine, EN

Customer Authentication Challenges That Impact Your Organization’s Security Posture

2025-09-26 15:09

Introduction In today’s cybersecurity landscape, CISOs face the challenge of securing data while managing costs effectively. As cyber threats become more sophisticated, traditional user authentication methods often prove inadequate or… The post Customer Authentication Challenges That Impact Your Organization’s Security…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Apache Airflow Vulnerability Lets Read-Only Users Access Sensitive Data

2025-09-26 15:09

Apache Airflow maintainers have disclosed a serious security issue, tracked as CVE-2025-54831, that allows users holding only read permissions to view sensitive connection details via both the Airflow API and web interface. The vulnerability, present in Airflow version 3.0.3, undermines…

Read more →

EN, Malwarebytes

Neon App pays users to record their phone calls, sells data for AI training

2025-09-26 15:09

An app called Neon Mobile which pays a small price for privacy is storming the popularity chart in the US Apple app store. This article has been indexed from Malwarebytes Read the original article: Neon App pays users to record…

Read more →

EN, The Register - Security

Prompt injection – and a $5 domain – trick Salesforce Agentforce into leaking sales

2025-09-26 15:09

More fun with AI agents and their security holes A now-fixed flaw in Salesforce’s Agentforce could have allowed external attackers to steal sensitive customer data via prompt injection, according to security researchers who published a proof-of-concept attack on Thursday. They…

Read more →

CySecurity News - Latest Information Security and Hacking Incidents, EN

Teens Arrested Over Scattered Spider’s $115M Hacking Spree

2025-09-26 15:09

  Law enforcement authorities in the United States and United Kingdom have arrested two teenagers connected to the notorious Scattered Spider hacking collective, charging them with executing an extensive cybercrime operation that netted over $115 million in ransom payments. The…

Read more →

EN, The Register - Security

Volvo North America confirms staff data stolen following ransomware attack on IT supplier

2025-09-26 14:09

The downstream consequences of Miljödata’s ransomware attack continue to affect major organizations Volvo North America is the latest large organization to announce attackers accessed employee data after a ransomware attack struck its HR system provider.… This article has been indexed…

Read more →

EN, securityweek

North Korea’s Fake Recruiters Feed Stolen Data to IT Workers

2025-09-26 14:09

North Korean threat actors pose as recruiters to steal developers’ identities and supply them to fraudulent IT workers. The post North Korea’s Fake Recruiters Feed Stolen Data to IT Workers appeared first on SecurityWeek. This article has been indexed from…

Read more →

EN, securityweek

Microsoft Reduces Israel’s Access to Cloud and AI Products Over Reports of Mass Surveillance in Gaza

2025-09-26 14:09

Microsoft said Thursday it had disabled services to a unit within the Israeli military after a company review had determined its artificial intelligence and cloud computing products were being used to help carry out mass surveillance of Palestinians. The action…

Read more →

EN, Security Boulevard

Salesforce Faces Lawsuits Over Compromises of Third-Party Apps: Report

2025-09-26 14:09

Salesforce is facing a possible class action lawsuit from almost two dozen plaintiffs who say the SaaS giant should have had better security around its platform, even though a spate of high-profile data-stealing attacks on third-party partners did not start…

Read more →

Page 221 of 4465
« 1 … 219 220 221 222 223 … 4,465 »

Pages

  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Apps
    • Telegram Channel

Recent Posts

  • New VanHelsing Ransomware-as-a-Service Hits Windows, Linux, BSD, ARM and ESXi November 11, 2025
  • Devolutions Server Flaw Allows Attackers to Impersonate Users via Pre-MFA Cookie November 11, 2025
  • Attackers Use Quantum Route Redirect to Launch Instant Phishing on M365 November 11, 2025
  • Quantum Route Redirect Phishing Kit Democratizes Cyber-Attacks November 11, 2025
  • EU Said To Consider Forced Huawei Ban November 11, 2025
  • Apple Said To Delay iPhone Air Upgrade Amid Weak Demand November 11, 2025
  • WatchGuard Firebox Flaw Allows Attackers to Gain Unauthorized SSH Access November 11, 2025
  • U.S. CISA adds Samsung mobile devices flaw to its Known Exploited Vulnerabilities catalog November 11, 2025
  • Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data November 11, 2025
  • AI Agents Rewriting Fraud Rules November 11, 2025
  • Hackers Exploiting Triofox 0-Day Vulnerability to Execute Malicious Payload Abusing Anti-Virus Feature November 11, 2025
  • SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks November 11, 2025
  • China Resumes Export Of Nexperia Chips November 11, 2025
  • EU Proposes Stripping Back Privacy Rules To Boost AI November 11, 2025
  • Critical Triofox bug exploited to run malicious payloads via AV configuration November 11, 2025
  • Firewalla unveils MSP 2.9 to simplify multi-device network management November 11, 2025
  • Reauthorizing CISA, Electric bus kill switches, GDPR for AI November 11, 2025
  • Researchers Expose Deep Connections Between Maverick and Coyote Banking Malware November 11, 2025
  • IT Security News Hourly Summary 2025-11-11 09h : 2 posts November 11, 2025
  • Beware of Security Alert-Themed Malicious Emails that Steal Your Email Logins November 11, 2025

Copyright © 2025 IT Security News. All Rights Reserved. The Magazine Basic Theme by bavotasan.com.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}