kkRAT Employs Network Communication Protocol to Steal Clipboard Contents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In early May 2025, cybersecurity researchers began tracking a novel Remote Access Trojan (RAT) targeting Chinese-speaking users via phishing sites hosted on GitHub Pages. Masked as legitimate installers for popular applications, the initial ZIP archives contained malicious executables engineered to …

Cornwell Quality Tools Data Breach – 100,000 Users Data Was Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cornwell Quality Tools has disclosed a significant data breach that compromised the sensitive information of nearly 104,000 individuals. The incident involved unauthorized access to the company’s network, resulting in the exposure of both personally identifiable information (PII) and protected health …

PoisonSeed Threat Actor Registering New Domains in Attempt to Compromise Enterprise Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, cybersecurity researchers have observed a surge in malicious domain registrations linked to an emerging e-crime group known as PoisonSeed. First identified in April 2025, this actor has focused its efforts on impersonating legitimate cloud-based email platforms, most …

CoreDNS Vulnerability Let Attackers Pin DNS Cache And Deny Service Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability has been discovered in CoreDNS that could allow attackers to disrupt services by pinning DNS cache entries, effectively creating a denial of service for updates. The flaw, residing in the CoreDNS etcd plugin stems from a critical …

LNER Train Passengers Data Accessed In Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

London North Eastern Railway (LNER) has confirmed that passenger data was accessed following a cyber attack on one of its third-party suppliers. The breach involved unauthorized access to files containing customer contact details and information related to previous journeys. LNER …

ChillyHell macOS Malware Profiles Compromised Machines and Maintain Persistence with 3 Methods

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ChillyHell first surfaced on public malware repositories in early May 2025, although its developer-signed notarization dates back to 2021. This modular backdoor has eluded detection by major antivirus vendors despite leveraging Apple’s own notarization process to appear legitimate. By masquerading …

Palo Alto Networks User-ID Credential Agent Vulnerability Exposes password In Cleartext

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in Palo Alto Networks’ User-ID Credential Agent for Windows, identified as CVE-2025-4235, could expose a service account’s password in cleartext under certain non-standard configurations. This flaw creates a significant security risk, as it could allow an …

New Attack Technique That Enables Attackers To Exfiltrate Git Credentials In Argocd

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed attack technique enables authenticated users within the popular GitOps tool ArgoCD to exfiltrate powerful Git credentials. The method, discovered by the cybersecurity research group Future Sight, exploits Kubernetes’ internal DNS resolution to intercept credentials in transit, posing …

Malicious Chrome Extension Attacking Users to Steal Meta Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel malicious Chrome extension has been uncovered targeting digital marketers by masquerading as a productivity tool for Meta ad campaigns. Dubbed “Madgicx Plus,” this extension is distributed through a network of deceptive websites posing as legitimate AI-driven advertising platforms. …

Hackers Booked Very Little Profit with Widespread npm Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated npm supply chain attack that surfaced in late August targeted thousands of downstream projects by injecting malicious payloads into popular JavaScript libraries. Initial reports pointed to a new variant of the notorious Typosquatting technique, but further analysis revealed …