New Malvertising Campaign Leverages GitHub Repository to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malvertising campaign has emerged, exploiting GitHub repositories through dangling commits to distribute malware via fake GitHub Desktop clients. This novel attack vector represents a significant evolution in cybercriminal tactics, leveraging the trust and legitimacy associated with GitHub’s platform …

Buterat Backdoor Attacking Enterprises to Establish Persistence and Control Endpoints

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated backdoor malware known as Backdoor.WIN32.Buterat has emerged as a significant threat to enterprise networks, demonstrating advanced persistence techniques and stealth capabilities that enable attackers to maintain long-term unauthorized access to compromised systems. The malware has been identified targeting …

New Malware Attack Leverages SVGs, Email Attachments to Deliver XWorm and Remcos RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated malware campaign that exploits SVG (Scalable Vector Graphics) files and email attachments to distribute dangerous Remote Access Trojans, specifically XWorm and Remcos RAT. This emerging threat represents a significant evolution in attack methodologies, as …

What Are The Takeaways From The Scattered LAPSUS $Hunters Statement?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The well-known group of cybercriminals called Scattered Lapsus$ Hunters released a surprising farewell statement on BreachForums. This manifesto, a mix of confession and strategic deception, offers vital insights into the changing landscape of modern cybercrime and the increasing pressure from …

ChatGPT’s New Support for MCP Tools Let Attackers Exfiltrate All Private Details From Email

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly introduced feature in ChatGPT that allows it to connect with personal data applications can be exploited by attackers to exfiltrate private information from a user’s email account. The attack requires only the victim’s email address and leverages a …

Sidewinder Hacker Group Weaponizing LNK File to Execute Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious APT-C-24 threat actor group, commonly known as Sidewinder or Rattlesnake, has evolved its attack methodology by deploying sophisticated LNK file-based phishing campaigns targeting government, energy, military, and mining sectors across South Asia. Active since 2012, this advanced persistent …

AI-powered Pentesting Tool ‘Villager’ Combines Kali Linux Tools with DeepSeek AI for Automated Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New AI-powered penetration testing framework Villager combines Kali Linux toolsets with DeepSeek AI models to fully automate cyber attack workflows. Initially developed by the Chinese-based group Cyberspike, this tool has rapidly gained traction since its July 2025 release on the …

Scattered LAPSUS$ Hunters 4.0 Announced That Their Going Dark Permanently

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sudden and definitive statement emerged from the “Scattered LAPSUS$ Hunters 4.0” Telegram channel on September 8, signaling an abrupt end to their public operations. After months of high-profile campaigns targeting major corporations and critical infrastructure, the collective declared a …

New ToneShell Backdoor With New Features Leverage Task Scheduler COM Service for Persistence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since its first appearance earlier this year, the ToneShell backdoor has demonstrated a remarkable capacity for adaptation, toyed with by the Mustang Panda group to maintain an enduring foothold in targeted environments. This latest variant, discovered in early September, arrives …

Samsung Zero-Day Vulnerability Actively Exploited to Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Samsung has released its September 2025 security update, addressing a critical zero-day vulnerability that is being actively exploited in the wild. The patch resolves a total of 25 Samsung Vulnerabilities and Exposures (SVEs), alongside fixes from Google and Samsung Semiconductor, …