China-Aligned TA415 Hackers Uses Google Sheets and Google Calendar for C2 Communications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Chinese state-sponsored threat actor TA415 has evolved its tactics, techniques, and procedures by leveraging legitimate cloud services like Google Sheets and Google Calendar for command and control communications in recent campaigns targeting U.S. government, think tank, and academic organizations. …

New Magecart Skimmer Attack With Malicious JavaScript Injection to Skim Payment Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The threat landscape for e-commerce websites has once again shifted with the emergence of a sophisticated Magecart-style attack campaign, characterized by the deployment of obfuscated JavaScript to harvest sensitive payment information. The campaign first came to light in mid-September 2025 …

224 Malicious Android Apps on Google Play With 38 Million Downloads Delivering Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated mobile ad fraud operation dubbed “SlopAds” has infiltrated Google Play Store with 224 malicious applications that collectively amassed over 38 million downloads across 228 countries and territories. The campaign represents one of the most extensive mobile fraud schemes …

New in Syteca Release 7.21: Agentless Access, Sensitive Data Masking, and Smooth Session Playback

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Syteca, a global cybersecurity provider, introduced the latest release of its platform, continuing the mission to help organizations reduce insider risks and ensure sensitive data protection. Syteca 7.21 is a major update designed to enhance user privacy, simplify access management, …

Hackers Exploit RTL/LTR Scripts and Browser Gaps to Hide Malicious URLs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A decade-old Unicode vulnerability known as BiDi Swap allows attackers to spoof URLs for sophisticated phishing attacks. By exploiting how browsers render mixed Right-to-Left (RTL) and Left-to-Right (LTR) language scripts, threat actors can craft URLs that appear legitimate but secretly …

Microsoft Dismantles 300+ Websites Used to Distribute RaccoonO365 Phishing Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since mid-2024, cybercriminals have leveraged a subscription-based phishing platform known as RaccoonO365 to harvest Microsoft 365 credentials at scale. Emerging as an off-the-shelf service, RaccoonO365 requires minimal technical skill, allowing threat actors to deploy convincing phishing campaigns by impersonating official …

Threat Actors Abuse Adtech Companies to Target Users With Malicious Ads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The digital advertising ecosystem has become a prime hunting ground for cybercriminals, who are increasingly exploiting advertising technology companies to distribute malware and conduct malicious campaigns. Rather than simply abusing legitimate platforms, threat actors are now operating as the platforms …

PureHVNC RAT Developers Leverage GitHub Host Source Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The PureHVNC remote administration tool (RAT) has emerged as a sophisticated component of the Pure malware family, gaining prominence in mid-2025 amid an uptick in targeted intrusion campaigns. Originating from underground forums and Telegram channels, PureHVNC is marketed by its …

Windows Screenshot Utility Greenshot Vulnerability Enable Malicious code execution – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has been discovered in Greenshot, a popular open-source screenshot utility for Windows. The vulnerability allows a local attacker to execute arbitrary code within the Greenshot process, potentially enabling them to bypass security measures and carry out …

Top 10 Best Security Orchestration, Automation, And Response (SOAR) Tools in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the face of an ever-increasing volume of security alerts, a critical shortage of skilled cybersecurity professionals, and the growing sophistication of cyber threats, Security Operations Centers (SOCs) are often overwhelmed. This is where Security Orchestration, Automation, and Response (SOAR) …