New Polymorphic Python Malware Repeatedly Mutate its Appearance at Every Execution Time

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently discovered Python-based remote access trojan (RAT) exhibits unprecedented polymorphic behavior, altering its code signature each time it runs. First observed on VirusTotal, the sample, dubbed nirorat.py, initially scored only 26/100 on detection engines, despite containing a full suite …

Data-Leak Sites Hit an All-Time High With New Scattered Spider RaaS and LockBit 5.0

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware landscape witnessed unprecedented upheaval in Q3 2025 as cyberthreat actors ushered in a new era of aggression and sophistication. The quarter marked a pivotal moment with the emergence of Scattered Spider’s inaugural ransomware-as-a-service offering, ShinySp1d3r RaaS, representing the …

Chaos Emerges as Faster, Smarter, and More Dangerous Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, security teams worldwide have grappled with a new ransomware strain that has shattered expectations for speed and sophistication. First detected in late September 2025, this variant encrypts critical data within seconds of execution, leaving little time for …

SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto, California, October 9th, 2025, CyberNewsWire As AI Browsers rapidly gain adoption across enterprises, SquareX has released critical security research exposing major vulnerabilities that could allow attackers to exploit AI Browsers to exfiltrate sensitive data, distribute malware and gain …

KFC Venezuela Alleged Data Breach – 1 Million Customer Records Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has allegedly breached KFC Venezuela, offering a database containing the personal and order information of over one million customers for sale on a dark web forum. The data, advertised on October 8, 2025, includes a vast amount …

Lightship Security and the OpenSSL Corporation Submit OpenSSL 3.5.4 for FIPS 140-3 Validation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Newark, United States, October 9th, 2025, CyberNewsWire Lightship Security, an Applus+ Laboratories company and accredited cryptographic security test laboratory, and the OpenSSL Corporation, the co-maintainer of the OpenSSL Library, announce the submission of OpenSSL version 3.5.4 to the Cryptographic Module …

Hackers Exploit DFIR Tool ‘Velociraptor’ in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Cisco Talos have confirmed that ransomware operators are actively exploiting Velociraptor, an open-source digital forensics and incident response (DFIR) tool, in their attacks. This marks the first definitive link between a legitimate security tool and a ransomware …

New Phishing Kit Automates Generation of ClickFix Attack Bypassing Security Measures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community has witnessed the rapid emergence of a novel phishing toolkit that automates the creation of “ClickFix” attack pages, enabling threat actors with minimal technical expertise to deploy sophisticated social engineering lures. Dubbed the IUAM ClickFix Generator, this …

SonicWall Confirms That Hackers Stole All Customers Firewall Configuration Backup Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has confirmed that an unauthorized party accessed and stole the entire repository of customer firewall configuration backup files from its cloud service. The confirmation comes after the completion of an investigation with the cybersecurity firm Mandiant, which determined that …

AI Chatbot Leveraged as a Critical Backdoor to Access Sensitive Data and Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, a sophisticated malware campaign has emerged that leverages conversational chatbots as covert entry points into enterprise systems. Initially observed in mid-September 2025, the threat actors targeted organizations running customer-facing chat applications built on large language models. By …