A recently revealed technique known as Zombie ZIP demonstrates how attackers can embed malware inside fragmented and corrupted archives that can’t be fully scanned by most security solutions. By exploiting the way ZIP headers are processed, it enables malicious payloads to…
Tag: CySecurity News – Latest Information Security and Hacking Incidents
HPE Patches Critical Aruba AOS-CX Vulnerabilities Including Authentication Bypass Flaw
Hewlett Packard Enterprise (HPE) has released security updates to address multiple vulnerabilities in its Aruba AOS-CX network operating system, including a critical flaw that could allow attackers to bypass authentication and gain administrative control. AOS-CX comes from Aruba Networks,…
APT28 Deploys Enhanced Version of Covenant in Ongoing Threat Activity
In recent months, the contours of cyber warfare have once again become clearer as APT28 – an agent of Russian intelligence that has operated in Ukraine for a number of years – elicits renewed precision and technological sophistication in…
Termite Ransomware Linked to Velvet Tempest’s ClickFix, CastleRAT Attacks
Cyber threat actors known as Velvet Tempest have been observed deploying sophisticated attacks involving Termite ransomware, utilizing the ClickFix social engineering technique and the CastleRAT backdoor.These intrusions, tracked by MalBeacon researchers, unfolded over 12 days in a simulated U.S.…
Meta’s Smart Glasses Face Privacy Backlash as Experts Flag Legal and Ethical Risks
A whirlwind of concerns around Meta’s AI-enabled smart glasses are intensifying after reports suggested that human reviewers may have accessed sensitive user recordings, raising broader questions about privacy, consent, and data protection. Online discussions have surged, with users expressing…
Russian Cyber Campaign Targets Signal and WhatsApp Users Through Social Engineering Tactics
Hackers believed to be linked to Russia are attempting to gain access to Signal and WhatsApp accounts of government officials, journalists, and military personnel worldwide—not by breaking encryption, but by manipulating users into giving up their access credentials. This…
Spyware Disguised as Safety App Targets Israelis Amid Rising Cyber Espionage Activity
A fresh wave of digital spying has emerged, aiming at people within Israel through fake apps made to look like official warning tools. Instead of relying on obvious tricks, it uses the credibility of public alerts to encourage downloads…
Chinese Cyber Espionage Group Targets Telecom Infrastructure With New Toolkit
In the midst of intensifying geopolitical competition in cyberspace, a previously undetected cyberattack linked to China is quietly unfolding across South America’s telecommunications industry since 2024. Cisco Talos researchers have reported that the operation represents a methodical and deeply…
CBP Admits Buying Ad Data to Secretly Track Phone Locations
U.S. Customs and Border Protections (CBP) has confessed to buying phone location data from the online advertising world, with the purchase making it now the first government agency to confirm such practices. The disclosure was made in a Privacy Threshold Analysis…
Europe Targets Chinese and Iranian Entities in Response to Cyber Threats
Council of the European Union, in response to the escalation of state-linked cyber intrusions, has tightened its defensive posture by imposing targeted sanctions on a cluster of entities and individuals allegedly engaged in sophisticated digital attacks against European interests…
How a Brute-Force Attack Exposed a Wider Ransomware Ecosystem
What initially appeared to be a routine brute-force alert ultimately revealed a far more complex ransomware-linked infrastructure, demonstrating how even low-level signals can expose deeper cybercriminal operations. According to analysis by Huntress, an investigation that began with a single…
AI Boom Turns Browsers into Enterprise Security’s Biggest Blind Spot
Telemetry data from the 2026 State of Browser Security Report reveals that, while the browser has become the de facto operating system for work in the enterprise, it remains one of the least secured segments in the overall security…
Cisco Warns of Actively Exploited SD-WAN Vulnerabilities Affecting Catalyst Network Systems
Cisco warns of several security holes in its Catalyst SD-WAN Manager, noting hackers have begun using at least one in live operations. Updates exist – applying them quickly reduces risk exposure. Exploitation is underway; delayed patching increases danger. Systems…
AkzoNobel Confirms Cyberattack at U.S. Site Following Anubis Ransomware Data Leak
kDutch multinational paints and coatings company AkzoNobel has confirmed that a cyberattack impacted one of its facilities in the United States, according to a statement shared with BleepingComputer. The incident came to light after the Anubis ransomware gang published…
Global Crackdown Dismantles LeakBase Data Breach Forum, Dozens Targeted in Europol Operation
A large-scale international law enforcement effort has reportedly led to multiple arrests as authorities moved to shut down a well-known underground data leak marketplace. Europol revealed details of a coordinated operation that successfully dismantled LeakBase, a platform it described…
Microsoft Releases Hotpatch to Fix Windows 11 RRAS Remote Code Flaw
Microsoft has issued an out-of-band (OOB) security update to remediate critical vulnerabilities affecting a specific subset of Windows 11 Enterprise systems that rely on hotpatch updates instead of the conventional monthly Patch Tuesday cumulative updates. The update, identified as KB5084597,…
Google Faces Wrongful Death Lawsuit Over Gemini AI in Alleged User Suicide Case
A lawsuit alleging wrongful death has been filed in the U.S. against Google, following the passing of a 36-year-old man from Florida. It suggests his interaction with the firm’s AI-powered tool, Gemini, influenced his decision to take his own…
TikTok Rejects Controversial Privacy Tech for DMs, Citing User Safety Risks
TikTok has firmly rejected implementing end-to-end encryption (E2EE) for direct messages (DMs), arguing that the technology could endanger users by limiting content moderation. In a recent statement to lawmakers and regulators, the platform emphasized that forgoing full encryption allows…
Royal Bahrain Hospital Faces Alleged Breach by Payload Ransomware
Several ransomware outfits have recently surfaced, claiming responsibility for significant breaches at Royal Bahrain Hospital, raising fresh concerns about healthcare cybersecurity. The group claims that it has penetrated the hospital’s digital infrastructure and exfiltrated a considerable amount of sensitive…
Deepfake Fraud Expands as Synthetic Media Targets Online Identity Verification Systems
Beyond spreading false stories or fueling viral jokes, deepfakes are shifting into sharper, more dangerous forms. Security analysts point out how fake videos and audio clips now play a growing role in trickier scams – ones aimed at breaking…