Friday, April 24, 2026
HomeCybersecurity News

Cybersecurity News

Checkout.com Confirms ShinyHunters Breach Of Cloud Storage But Declines Ransom Payment

London-based payment processor Checkout.com has acknowledged a data breach by the notorious hacking group ShinyHunters, confirming unauthorized access to a legacy cloud storage system. In a public statement released on November 12, 2025, the company's Chief Technology Officer, Mariano Albera, detailed the incident, emphasizing...

Operation Endgame Takes Down 1,025 Servers Linked To Rhadamanthys, VenomRAT, and Elysium

In a sweeping crackdown on cybercrime infrastructure, international law enforcement agencies dismantled key components of three prominent malware families during the latest phase of Operation Endgame. Coordinated from Europol's headquarters in The Hague between November 10 and 13, 2025, the operation targeted Rhadamanthys, a...

Multiple Kibana Flaws Enable Server-Side Request Forgery and Cross-Site Scripting Exploits

Elastic has recently released critical security patches for Kibana, addressing vulnerabilities that could expose users to significant risks in their observability and analytics platforms. The update, detailed in Elastic Security Advisory (ESA-2025-24), targets versions 8.19.7, 9.1.7, and 9.2.1. These flaws primarily involve improper origin...

CISA Alerts On Exploited WatchGuard Firebox Out-of-Bounds Write Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in WatchGuard Firebox firewalls to its Known Exploited Vulnerabilities (KEV) catalog, highlighting active exploitation in the wild. Tracked as CVE-2025-9242, this out-of-bounds write flaw in the Fireware OS ike process enables...

Hackers Actively Exploiting Cisco and Citrix 0-Days To Deploy Webshells In The Wild

In a chilling revelation from Amazon's threat intelligence team, sophisticated hackers are weaponizing undisclosed zero-day flaws in critical enterprise tools from Cisco and Citrix. Dubbed as part of an ongoing campaign, these attackers are targeting identity and access management systems the digital gatekeepers that...

Lite XL Vulnerability Allows Attackers To Execute Arbitrary Code

Lite XL, a popular lightweight text editor favored by developers for its speed and Lua-based extensibility, has been found vulnerable to attacks that could let malicious actors run arbitrary code on users' systems. The flaws, detailed in CERT's Vulnerability Note VU#579478 released on November...