TamperedChef Malware as PDF Editor Harvest Browser Credentials and Allows Backdoor Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, security teams have observed a surge in malvertising campaigns distributing what appears to be a fully functional PDF editor. Dubbed TamperedChef, this malware masquerades as a legitimate application—AppSuite PDF Editor—leveraging convincing advertisements to lure European organizations and …

Google’s New AI Agent, CodeMender, Automatically Rewrites Vulnerable Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has introduced CodeMender, a new artificial intelligence-powered agent that automatically enhances software security by identifying and fixing vulnerabilities. This initiative addresses the growing gap between the rapid, AI-assisted discovery of security flaws and the time-consuming manual effort required to …

Yurei Ransomware Leverages SMB Shares and Removable Drives to Encrypt Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Yurei ransomware first emerged in early September 2025, targeting Windows environments with a sophisticated Go-based payload designed for rapid, large-scale encryption. Once executed, the malware enumerates all accessible local and network drives, appends a .Yurei extension to each file, and …

ClamAV 1.5.0 Released with New MS Office and PDF Verification Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has announced the release of ClamAV 1.5.0, a significant update to the open-source antivirus engine that introduces major security enhancements, new document scanning capabilities, and extensive API improvements. This version strengthens the platform’s detection and verification mechanisms, with a …

Critical AWS ClientVPN for macOS Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw in the AWS Client VPN for macOS has been disclosed, presenting a local privilege escalation risk to non-administrator users.  The vulnerability tracked as CVE-2025-11462 allows attackers to gain root privileges by abusing the client’s log rotation mechanism. …

ASCII Smuggling Attack Lets Hackers Manipulate Gemini to Deliver Smuggled Data to Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers set out to test leading large language models (LLMs) for resilience against the long-standing ASCII Smuggling technique.  By embedding invisible control characters within seemingly harmless text, ASCII Smuggling abuses Unicode “tag” blocks to hide malicious instructions from human reviewers …

PoC Exploit Released for Critical Lua Engine Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three newly disclosed vulnerabilities have been identified in the Lua scripting engine of Redis 7.4.5, each presenting severe risks of remote code execution and privilege escalation.  Redrays has released a detailed proof-of-concept (PoC) to exploit these vulnerabilities, which is now …

OpenAI Banned ChatGPT Accounts Used by Chinese Hackers to Develop Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI announced it has banned a series of ChatGPT accounts linked to Chinese state-affiliated hacking groups that used the AI models to refine malware and create phishing content. The October 2025 report details the disruption of several malicious networks as …

Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WordPress websites have become a prime target for threat actors seeking to monetize traffic and compromise visitor security. In recent months, a new malvertising campaign has emerged, leveraging silent PHP code injections within theme files to serve unwanted third-party scripts. …

CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued a critical warning regarding a zero-day cross-site scripting (XSS) vulnerability in Synacor’s Zimbra Collaboration Suite (ZCS), designated as CVE-2025-27915.  This vulnerability has been actively exploited in attacks and poses significant risks to organizations using the popular email …