A criminal AI service called MessiahGPT is being marketed on BreachForums as an uncensored platform for creating ransomware, phishing kits, stealers,…
Category: Cyber Security News
Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices
A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying. Evooo1Bot is the threat that…
ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing
ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300…
Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT
Fake job interviews are again being used to breach cryptocurrency teams. In a documented case, a convincing Web3 recruitment process led a Windows user to…
12 KB Windows Backdoor Hides C2 Domain in desktop.ini Whitespace to Evade Detection
A newly documented Windows backdoor shows how little code an attacker needs to stay hidden. The 12 KB implant was found on one corporate workstation,…
Safepal Confirm Hackers Gained Access to Customer Order Information
SafePal has confirmed a security incident in which unauthorized parties accessed customer order information through a flaw in an order-tracking plug-in.…
Apple Screen Sharing Vulnerability Exploited to Execute Command as Root
A newly disclosed logic flaw in macOS Screen Sharing shows how a feature meant only to grant screen-viewing access can be twisted into a path for full…
Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 Stories
This week’s roundup covers a record-setting Microsoft Patch Tuesday, an actively exploited Cisco firewall zero-day, a Lazarus-linked Windows kernel bug,…
Microsoft Begins to Merge Consumer and Enterprise Copilot Apps to Make New Super App
Microsoft is moving closer to a unified Copilot experience by merging key elements of its consumer AI assistant with the Microsoft 365 productivity…
McDonald’s, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records
A sprawling Azure data exfiltration campaign is unfolding across the dark web, with a threat actor systematically selling off internal employee…
AWS Certificate Manager to Discontinue Email Validation for Public Certificates
AWS Certificate Manager (ACM) has announced plans to permanently discontinue email-based domain control validation (DCV) for public certificate renewals…
Post-Hugging Face Reflections: The Agentic Attacker Is Already Here
Bill Robbins, CEO of Menlo Security An AI agent broke out of the sandbox built to contain it and put itself on the open internet. Then it attacked another…
Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC
Threat actors have begun actively probing and attempting to exploit a maximum-severity flaw in SAP Commerce Cloud, just three days after official security…
Shell Investigating Data Breach Following Cl0p Ransomware Group Claim
Multinational energy giant Shell has launched an active investigation after the notorious Cl0p ransomware syndicate claimed responsibility for…
Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication
Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in…
Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malware
A “Bring Your Own EDR” attack abuses trusted SentinelOne components to turn endpoint protection into a powerful malware shield. The research was presented…
Multiple TP-Link Vulnerabilities Allow Attackers to Bypass Authentication and Escalate Privileges
TP-Link has disclosed multiple high-severity vulnerabilities affecting ISP-managed Aginet networking products, including mesh systems, routers, PON…
Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root – PoC Released
A working proof-of-concept (PoC) exploit demonstrating how a pre-authentication heap overflow in Citrix NetScaler ADC and NetScaler Gateway can be turned…
AI Agents Don’t Stop When Malware Fails, They Write Another Tool and Keep Attacking
AI agents are changing the shape of cyberattacks. Instead of relying on a fixed piece of malware, an agent can test an approach, see it fail, write a…
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
A new DCRat campaign is using a familiar image format to hide a dangerous malware archive. The operation begins with phishing emails that pose as legal…