Hackers Attempted to Misuse Claude AI to Launch Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has thwarted multiple sophisticated attempts by cybercriminals to misuse its Claude AI platform, according to a newly released Threat Intelligence report. Despite layered safeguards designed to prevent harmful outputs, malicious actors have adapted to exploit Claude’s advanced capabilities, weaponizing …

UTG-Q-1000 Group Weaponizing Subsidy Schemes to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The emergence of sophisticated cybercriminal organizations continues to pose significant threats to individuals and institutions worldwide, with the UTG-Q-1000 group representing one of the most concerning developments in recent cybersecurity history. This highly organized criminal network has demonstrated exceptional technical …

ShadowSilk Leveraging Penetration-Testing Tools, Public Exploits to Attack Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ShadowSilk first surfaced in late 2023 as a sophisticated threat cluster targeting government entities across Central Asia and the broader APAC region. Exploiting known public vulnerabilities and widely available penetration-testing frameworks, the group orchestrates data exfiltration campaigns with a high …

FreePBX Servers Hacked in 0-Day Attack – Admins are Urged to Disable Internet Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day exploit targeting exposed FreePBX 16 and 17 systems. Threat actors are abusing an unauthenticated privilege escalation vulnerability in the commercial Endpoint Manager module, allowing remote code execution (RCE) when the Administrator Control Panel is reachable from the …

New TamperedChef Attack With Weaponized PDF Editor Steals Sensitive Data and Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign that weaponizes a seemingly legitimate PDF editor to steal sensitive data and login credentials from unsuspecting users across Europe. The attack uncovered by Truesec, dubbed “TamperedChef,” represents a new evolution in social engineering tactics that leverage …

CrowdStrike Set to Acquire Onum in $290 Million Deal to Enhance Falcon Next-Gen SIEM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Global cybersecurity leader CrowdStrike announced its intention to acquire Onum, a pioneer in real-time telemetry pipeline management, in a deal reportedly valued at $290 million. The acquisition, unveiled Wednesday, aims to significantly enhance CrowdStrike’s Falcon Next-Gen SIEM platform, transforming it …

NX Build Tool Hacked with Malware That Checks for Claude or Gemini to Find Wallets and Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 1,400 developers discovered today that a malicious post-install script in the popular NX build kit silently created a repository named s1ngularity-repository in their GitHub accounts.  This repository contains a base64-encoded dump of sensitive data wallet files, API keys, .npmrc …

CISA Publish Hunting and Mitigation Guide to Defend Networks from Chinese State-Sponsored Actors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside the NSA, FBI, and a broad coalition of international partners, has released a comprehensive cybersecurity advisory detailing a widespread espionage campaign by People’s Republic of China (PRC) state-sponsored actors targeting critical …

TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past year, a shadowy threat actor known as TAG-144—also tracked under aliases Blind Eagle and APT-C-36—has intensified operations against South American government institutions. First observed in 2018, this group has adopted an array of commodity remote access trojans …

Kea DHCP Server Vulnerability Let Remote Attacker With a Single Crafted Packet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in the widely used ISC Kea DHCP server poses a significant security risk to network infrastructure worldwide.  The flaw, designated CVE-2025-40779, allows remote attackers to crash DHCP services with just a single maliciously crafted packet, potentially …