New Botnet Leverages DNS Misconfiguration to Launch Massive Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A previously unseen botnet campaign emerged in late November, using a novel combination of DNS misconfiguration and hijacked networking devices to propel a global malspam operation. Initial reports surfaced when dozens of organizations received what appeared to be legitimate freight …

Hackers Bypassing Windows Mark of the Web Files Using LNK Stomping Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack technique called LNK Stomping has emerged as a critical threat to Windows security, exploiting a fundamental flaw in how the operating system handles shortcut files to bypass security controls.  Designated as CVE-2024-38217 and patched on September 10, …

Massive Cyber-Attack Attacking macOS Users via GitHub Pages to Deliver Stealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber-attack campaign exploiting GitHub Pages to distribute the notorious Atomic stealer malware to macOS users.  The threat actors behind this operation are leveraging Search Engine Optimization (SEO) techniques to position malicious repositories at the top of search results …

BlackLock Ransomware Attacking Windows, Linux, and VMware ESXi Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new ransomware operation dubbed BlackLock has emerged as a significant threat to organizations worldwide, demonstrating advanced cross-platform capabilities and targeting diverse computing environments.  Originally operating under the name “El Dorado” since March 2024, the group rebranded to BlackLock …

Cybersecurity Newsletter Weekly – Shai Halud Attack, Ivanti Exploits, FinWise, BMW Data Leak, and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

This week in cybersecurity, researchers exposed hidden alliances between ransomware groups, the rise of AI-powered phishing platforms, and large-scale vulnerabilities affecting telecom and enterprise systems. Major data breaches at financial services and luxury brands highlighted insider threats and supply chain …

New EDR-Freeze Tool That Puts EDRs and Antivirus Into A Coma State

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new proof-of-concept tool named EDR-Freeze has been developed, capable of placing Endpoint Detection and Response (EDR) and antivirus solutions into a suspended “coma” state. According to Zero Salarium, the technique leverages a built-in Windows function, offering a stealthier alternative …

Heathrow and Other European Airports Hit by Cyberattack, Several Flights Delayed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major cyberattack on a popular aviation software provider has caused significant disruptions at key European airports, including London’s Heathrow, Brussels, and Berlin, resulting in hundreds of flight delays and cancellations on Saturday. The attack disabled electronic check-in and baggage …

First-ever AI-powered ‘MalTerminal’ Malware Uses OpenAI GPT-4 to Generate Ransomware Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI-powered malware, known as ‘MalTerminal’, uses OpenAI’s GPT-4 model to dynamically generate malicious code, including ransomware and reverse shells, marking a significant shift in how threats are developed and deployed. This discovery follows the recent analysis of PromptLock, another AI-driven …

Top Zero-Day Vulnerabilities Exploited in the Wild in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape in 2025 has been marked by an unprecedented surge in zero-day vulnerabilities actively exploited by threat actors. According to recent data, more than 23,600 vulnerabilities were published in the first half of 2025 alone, representing a 16% …

Threat Actors Selling New Undetectable RAT as ’ScreenConnect FUD Alternative’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has been observed advertising a new Remote Access Trojan (RAT) on underground forums, marketing it as a fully undetectable (FUD) alternative to the legitimate remote access tool, ScreenConnect. The malware is being sold with a suite of …