Threema, a privacy-focused secure messaging service, was hit by a series of large-scale distributed denial-of-service (DDoS attacks) that temporarily…
Category: Cyber Security News
Microsoft SCCM Vulnerability Chained to Execute Malicious Code Remotely
Security researchers have disclosed a serious attack chain affecting Microsoft System Center Configuration Manager, commonly known as SCCM or…
Roundcube 1.6.18 and 1.7.3 Released With Fix for RCE and SSRF Vulnerabilities
Roundcube has released versions 1.6.18 and 1.7.3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code…
HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Processes, Files and C2 Traffic
HoneyMyte has upgraded its CoolClient backdoor with a kernel-level rootkit for Windows. The change makes routine investigation much harder for defenders.…
GeoServer’s Unauthenticated SQL injection Vulnerability Enables RCE Attacks
GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the…
Z.ai Unveils GLM-5.3 with Major Enhancements for Coding and Cybersecurity
Z.ai has released GLM-5.3, a new AI model built to handle complex coding, long-running agent tasks, and cybersecurity analysis. The company says the model…
New MessiahGPT AI Model Fueling Automated Ransomware and Phishing Attacks
A criminal AI service called MessiahGPT is being marketed on BreachForums as an uncensored platform for creating ransomware, phishing kits, stealers,…
Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices
A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying. Evooo1Bot is the threat that…
ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing
ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300…
Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT
Fake job interviews are again being used to breach cryptocurrency teams. In a documented case, a convincing Web3 recruitment process led a Windows user to…
12 KB Windows Backdoor Hides C2 Domain in desktop.ini Whitespace to Evade Detection
A newly documented Windows backdoor shows how little code an attacker needs to stay hidden. The 12 KB implant was found on one corporate workstation,…
Safepal Confirm Hackers Gained Access to Customer Order Information
SafePal has confirmed a security incident in which unauthorized parties accessed customer order information through a flaw in an order-tracking plug-in.…
Apple Screen Sharing Vulnerability Exploited to Execute Command as Root
A newly disclosed logic flaw in macOS Screen Sharing shows how a feature meant only to grant screen-viewing access can be twisted into a path for full…
Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 Stories
This week’s roundup covers a record-setting Microsoft Patch Tuesday, an actively exploited Cisco firewall zero-day, a Lazarus-linked Windows kernel bug,…
Microsoft Begins to Merge Consumer and Enterprise Copilot Apps to Make New Super App
Microsoft is moving closer to a unified Copilot experience by merging key elements of its consumer AI assistant with the Microsoft 365 productivity…
McDonald’s, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records
A sprawling Azure data exfiltration campaign is unfolding across the dark web, with a threat actor systematically selling off internal employee…
AWS Certificate Manager to Discontinue Email Validation for Public Certificates
AWS Certificate Manager (ACM) has announced plans to permanently discontinue email-based domain control validation (DCV) for public certificate renewals…
Post-Hugging Face Reflections: The Agentic Attacker Is Already Here
Bill Robbins, CEO of Menlo Security An AI agent broke out of the sandbox built to contain it and put itself on the open internet. Then it attacked another…
Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC
Threat actors have begun actively probing and attempting to exploit a maximum-severity flaw in SAP Commerce Cloud, just three days after official security…
Shell Investigating Data Breach Following Cl0p Ransomware Group Claim
Multinational energy giant Shell has launched an active investigation after the notorious Cl0p ransomware syndicate claimed responsibility for…