Scattered Lapsus$ Hunters Claim to Have Stolen More Than 1 Billion Salesforce Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Scattered Lapsus$ Hunters, a threat group previously associated with high-profile data thefts, recently claimed responsibility for exfiltrating over one billion records from Salesforce environments worldwide. Emerging in mid-2025, the group has honed its tactics to exploit misconfigurations in cloud identities …

Microsoft Intune MDM and Entra ID Leveraged to Elevate your Trust in Device Identity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New research uncovers valuable insights hidden within Microsoft Intune’s Mobile Device Management (MDM) certificates, offering a more reliable way to verify device and tenant identities compared to traditional methods like registry values. These certificates, issued to enrolled devices, contain Object …

Astaroth Banking Malware Leveraging GitHub to Host Malware Configurations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of the Astaroth banking trojan has emerged, leveraging a novel approach to distribute its malicious configuration files. First detected in late 2025, this latest campaign employs GitHub’s raw content service to host encrypted JSON configurations containing target …

New RMPocalypse Attack Let Hackers Break AMD SEV-SNP To Exfiltrate Confidential Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in AMD’s Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP), a cornerstone of confidential computing deployed by major cloud providers like AWS, Azure, and Google Cloud. Dubbed RMPocalypse, the attack exploits a flaw in the initialization of …

Threat Actors Weaponize Discord Webhooks for Command and Control with npm, PyPI, and Ruby Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have discovered a novel way to co-opt Discord webhooks as surrogate command-and-control (C2) channels across popular language ecosystems. Unlike traditional C2 servers, webhooks offer free, low-profile exfiltration that blends seamlessly into legitimate HTTPS traffic. Over the past month, malicious …

EDR-Freeze Tool Technical Workings Along With Forensic Artifacts Revealed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent analysis from researcher Itamar Hällström has revealed the technical workings and forensic trail of “EDR-Freeze,” a proof-of-concept technique that temporarily disables security software. By abusing legitimate Windows components, this method can place Endpoint Detection and Response (EDR) and …

Happy DOM Vulnerability Exposes 2.7 Million Users To Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security flaw has been discovered in Happy DOM, a popular JavaScript DOM implementation, affecting versions up to v19. This vulnerability places systems at risk of Remote Code Execution (RCE) attacks, potentially impacting the package’s 2.7 million weekly users. …

New Stealit Malware Attacking Windows Systems Abuses Node.js Extensions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign targeting Windows systems has emerged, leveraging Node.js Single Executable Application (SEA) features to distribute malicious payloads while evading traditional detection mechanisms. The Stealit malware represents a significant evolution in malware-as-a-service operations, combining advanced obfuscation techniques …

RealBlindingEDR Tool That Permanently Turns Off AV/EDR Using Kernel Callbacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An open-source tool called RealBlindingEDR enables attackers to blind, permanently disable, or terminate antivirus (AV) and endpoint detection and response (EDR) software by clearing critical kernel callbacks on Windows systems. Released on GitHub in late 2023, the utility leverages signed …

SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A surge in attacks targeting SonicWall SSLVPN devices, affecting numerous customer networks, just weeks after a major breach exposed sensitive firewall data. Starting October 4, 2025, threat actors have rapidly authenticated into over 100 accounts across 16 environments, using what …