RondoDox Botnet Exploits 50+ Vulnerabilities to Attack Routers, CCTV Systems and Web Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since its emergence in early 2025, RondoDox has rapidly become one of the most pervasive IoT-focused botnets in operation, targeting a wide range of network-connected devices—from consumer routers to enterprise CCTV systems and web servers. Its modular design allows operators …

Microsoft Defender Incorrectly Flags SQL Server Software as End-of-life

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Defender for Endpoint is incorrectly flagging specific versions of SQL Server as having reached their end-of-life, causing potential confusion for system administrators. The issue, tracked under advisory DZ1168079, stems from a code bug and affects the Threat and Vulnerability …

Critical GitHub Copilot Vulnerability Let Attackers Exfiltrate Source Code From Private Repos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in GitHub Copilot Chat, rated 9.6 on the CVSS scale, could have allowed attackers to exfiltrate source code and secrets from private repositories silently. The exploit combined a novel prompt injection technique with a clever bypass of …

New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android spyware campaign dubbed ClayRat has emerged as one of the most concerning mobile threats of 2025, masquerading as popular applications including WhatsApp, Google Photos, TikTok, and YouTube to infiltrate devices and steal sensitive user data. The malware …

LLM-enabled MalTerminal Malware Leverages GPT-4 to Generate Ransomware Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified what is believed to be the earliest known instance of malware that leverages a Large Language Model (LLM) to generate malicious code at runtime. Dubbed ‘MalTerminal’ by SentinelLABS, the malware uses OpenAI’s GPT-4 to dynamically create …

SnakeKeylogger via Weaponized E-mails Leverage PowerShell to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Emerging from a recent wave of targeted campaigns, SnakeKeylogger has surfaced as a potent infostealer that capitalizes on PowerShell and social engineering. The malware’s operators craft convincing spear-phishing e-mails under aliases such as “CPA-Payment Files,” impersonating reputable financial and research …

Microsoft Warns of Hackers Compromising Employee Accounts to Steal Salary Payments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated financially motivated threat actor known as Storm-2657 has been orchestrating elaborate “payroll pirate” attacks targeting US universities and other organizations, Microsoft Threat Intelligence has revealed. These attacks represent a concerning evolution in cybercriminal tactics, where hackers compromise employee …

Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active in-the-wild exploitation of a zero-day vulnerability in Gladinet CentreStack and Triofox products. Tracked as CVE-2025-11371, the unauthenticated Local File Inclusion (LFI) flaw allows attackers to achieve remote code execution (RCE) on affected systems. The vulnerability is currently unpatched, …

Google Warns of CL0P Ransomware Group Actively Exploiting Oracle E-Business Suite Zero-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape faces a new and significant threat as the notorious CL0P ransomware group has launched a large-scale extortion campaign targeting Oracle E-Business Suite (EBS) environments. Starting September 29, 2025, security researchers began tracking a sophisticated operation where threat …

Authorities Seize BreachForums New Clearnet Cybercrime Marketplace Domain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

International law enforcement agencies have seized the latest clearnet domain of the notorious cybercrime marketplace, BreachForums. The domain, breachforums[.]hn, now displays a seizure notice from the U.S. Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI), alongside French …