Hacker Extradited to US for Stealing Over $2.5 Million in Tax Fraud Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercriminal operation that targeted American tax preparation businesses through spearphishing campaigns has culminated in the extradition of Nigerian national Chukwuemeka Victor Amachukwu from France to face federal charges in New York. The 39-year-old defendant, operating under multiple aliases …

Guided Selling in 3D Product Configurators

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

People don’t want to guess when they buy something – especially something complex or customizable. They want to feel like they’re making the right choice. But with many ecommerce stores, it’s easy to feel lost: too many options, confusing specs, …

WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two malicious npm packages have emerged as sophisticated weapons targeting WhatsApp developers through a remote-controlled destruction mechanism that can completely wipe development systems. The packages, identified as naya-flore and nvlore-hsc, masquerade as legitimate WhatsApp socket libraries while harboring a devastating …

SonicWall Confirms No New SSLVPN 0-Day – Ransomware Attack Linked to Old Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity firm SonicWall has officially addressed recent concerns about a potential new zero-day vulnerability in its Secure Sockets Layer Virtual Private Network (SSLVPN) products. In a statement to Cybersecurity News, the company confirmed that recent ransomware attacks are not the …

ScarCruft Hacker Group Launched a New Malware Attack Using Rust and PubNub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The North Korean state-sponsored Advanced Persistent Threat (APT) group ScarCruft has launched a sophisticated new malware campaign targeting South Korean users through a deceptive postal-code update notice. This latest attack represents a significant evolution in the group’s operational capabilities, marking …

Microsoft 365 Direct Send Weaponized to Bypass Email Security Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated spear phishing campaign that weaponizes Microsoft 365’s Direct Send feature to bypass traditional email security defenses and conduct hyper-personalized credential theft attacks. The campaign demonstrates an alarming evolution in attack sophistication, combining technical exploitation …

New Ghost Calls Attack Abuses Web Conferencing for Covert Command & Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new attack technique called “Ghost Calls” exploits web conferencing platforms to establish covert command and control (C2) channels.  Presented by Adam Crosser from Praetorian at Black Hat USA 2025, this groundbreaking research demonstrates how attackers can leverage the …

CISA Warns of ‘ToolShell’ Exploits Chain Attacks SharePoint Servers – Discloses IOCs and detection signatures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released an urgent analysis in early July 2025, detailing a sophisticated exploit chain targeting on-premises Microsoft SharePoint servers. Dubbed “ToolShell,” the campaign leverages two fresh vulnerabilities—CVE-2025-49706, a network spoofing flaw, and CVE-2025-49704, …

WhatsApp Has Taken Down 6.8 Million Accounts Linked to Malicious Activities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp has successfully dismantled 6.8 million accounts linked to fraudulent activities during the first half of 2024, representing a significant escalation in the platform’s fight against organized cybercrime.  The takedown operation, announced by parent company Meta, specifically targeted scam centers …

New Active Directory Lateral Movement Techniques that Bypasses Authentication and Exfiltrate Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sophisticated attack vectors unveiled that exploit hybrid Active Directory and Microsoft Entra ID environments, demonstrating how attackers can achieve complete tenant compromise through previously unknown lateral movement techniques. These methods, presented at Black Hat USA 2025, expose critical vulnerabilities in …