Crimson Collective Leverages AWS Services to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat group calling itself Crimson Collective has emerged as a significant cybersecurity concern, targeting Amazon Web Services (AWS) cloud environments with sophisticated data exfiltration and extortion campaigns. The group has recently claimed responsibility for attacking Red Hat, asserting …

Hackers Actively Compromising Databases Using Legitimate Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new breed of ransomware attacks is leveraging legitimate database commands to compromise organizations worldwide, bypassing traditional security measures through “malware-less” operations. Unlike conventional ransomware that encrypts files using malicious binaries, threat actors are exploiting exposed database services by …

Scattered Lapsus$ Hunters Launched a New Leak Site to Release Data Stolen from Salesforce Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious cybercriminal collective known as Scattered Lapsus$ Hunters has escalated their extortion campaign by launching a dedicated leak site to threaten organizations with the exposure of stolen Salesforce data. This supergroup, comprised of established threat actors including ShinyHunters, Scattered …

Mustang Panda Using New DLL Side-Loading Technique to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, cybersecurity analysts have observed a resurgence of the Mustang Panda threat actor deploying a novel DLL side-loading approach to deliver malicious payloads. Emerging in June 2025, this campaign leverages politically themed lures targeting Tibetan advocacy groups. Victims …

3 Steps to Beat Burnout in Your SOC and Solve Cyber Incidents Faster 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security teams are constantly on the move. Alerts never stop coming in, workloads keep piling up, and the pressure to react fast can wear anyone down. Add long investigations and a maze of tools on top of that, and burnout …

Chinese Hackers Weaponized Nezha Tool to Execute Commands on Web Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberattack campaign, active since August 2025, where a China-nexus threat actor has been weaponizing a legitimate server operations tool called Nezha to execute commands and deploy malware on compromised web servers. This campaign, uncovered by Huntress, represents the …

Rethinking AI Data Security: A Buyer’s Guide for CISOs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Generative AI has gone from a novelty to a foundation of organization efficiency in just a few short years. From copilots embedded in office suites to dedicated large language model (LLM) platforms, personnel now rely on these platforms to code, …

Miggo Security Named a Gartner® Cool Vendor in AI Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tel Aviv, Israel, October 8th, 2025, CyberNewsWire Miggo Security, pioneer and innovator in Application Detection & Response (ADR) and AI Runtime Defense, today announced it has been recognized as a Gartner Cool Vendor in AI Security. To us, this recognition …

APT Hackers Exploit ChatGPT to Create Sophisticated Malware and Phishing Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A China-aligned advanced persistent threat (APT) group is actively leveraging OpenAI’s ChatGPT platform to develop malware and craft sophisticated spear-phishing emails for its global campaigns. Security firm Volexity tracks the actor as UTA0388 and has analyzed its operations since June …

New Fully Undetectable FUD Android RAT Hosted on GitHub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android remote access trojan (RAT) has emerged on GitHub, presenting significant security concerns for mobile device users worldwide. The malware, publicly available under the repository “Android-RAT” by user Huckel789, claims to offer fully undetectable (FUD) capabilities that can …