Threat Actors Gaining Access to Victims’ Machines and Monetizing Access to Their Bandwidth

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A stealthy campaign emerged in early March 2025 that capitalized on a critical remote code execution flaw in GeoServer (CVE-2024-36401) to compromise publicly exposed geospatial servers. Attackers exploited JXPath query injection within Apache Commons libraries, allowing arbitrary code execution through …

Hackers Weaponize QR Codes Embedded with Malicious Links to Steal Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have observed a surge in phishing campaigns leveraging QR codes to deliver malicious payloads. This emerging threat, often dubbed “quishing,” exploits the opaque nature of QR codes to conceal harmful URLs that redirect victims to credential-harvesting sites or …

Threat Actors Abuse AI Website Creation App to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have discovered a new avenue for malicious activities by exploiting Lovable, an AI-powered website creation platform, to develop sophisticated phishing campaigns and malware delivery systems. The platform, designed to democratize web development through natural language prompts, has inadvertently become …

Warlock Ransomware Exploiting SharePoint Vulnerabilities to Gain Access and Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, the cybersecurity community has witnessed the rapid emergence of Warlock, a novel ransomware strain that weaponizes unpatched Microsoft SharePoint servers to infiltrate enterprise networks. Initial analysis reveals that threat actors exploit publicly exposed SharePoint instances via specially …

Internet Archive Abused for Hosting Stealthy JScript Loader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a novel malware delivery chain in recent weeks that leverages the Internet Archive’s legitimate infrastructure to host obfuscated payloads. The attack begins with a seemingly innocuous JScript file delivered via malspam, which in turn invokes a …

SIM-Swapper, Scattered Spider Hacker Gets 10 Years

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

A 20-year-old Florida man at the center of a prolific cybercrime group known as “Scattered Spider” was sentenced to 10 years in federal prison today, and ordered to pay roughly $13 million in restitution to victims. Noah Michael Urban of …

Oregon Man Charged in ‘Rapper Bot’ DDoS Service

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

A 22-year-old Oregon man has been arrested on suspicion of operating “Rapper Bot,” a massive botnet used to power a service for launching distributed denial-of-service (DDoS) attacks against targets — including a March 2025 DDoS that knocked Twitter/X offline. The …

Weekly Cybersecurity News Recap : Microsoft, Cisco, Fortinet Security Updates and Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the week of August 11-17, 2025, the cybersecurity landscape was marked by critical updates from major vendors and a surge in sophisticated threats, underscoring the ongoing battle against digital vulnerabilities. Microsoft rolled out its Patch Tuesday updates on August …

New Elastic EDR 0-Day Vulnerability Allows Attackers to Bypass Detection, Execute Malware, and Cause BSOD

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered zero-day vulnerability in Elastic’s Endpoint Detection and Response (EDR) solution allows attackers to bypass security measures, execute malicious code, and trigger a BSOD system crash, according to the Ashes Cybersecurity research. The vulnerability resides in a core …

CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA in collaboration with international partners, has released comprehensive guidance, titled “Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators,” to strengthen cybersecurity defenses across critical infrastructure sectors. The document emphasizes the critical importance of maintaining accurate operational …