Akira and Lynx Ransomware Attacking Managed Service Providers With Stolen Login Credential and Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two sophisticated ransomware operations have emerged as significant threats to managed service providers (MSPs) and small businesses, with the Akira and Lynx groups deploying advanced attack techniques that combine stolen credentials with vulnerability exploitation. These ransomware-as-a-service (RaaS) operations have collectively …

Lazarus Hackers Trick Users To Believe Their Camera or Microphone is Blocked to Deliver PyLangGhost RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have observed a new social engineering campaign attributed to North Korea’s Lazarus Group in recent weeks that leverages fake camera and microphone errors to force targets into running malicious scripts. Victims, primarily in the finance and technology sectors, …

Threat Actors Weaponize Smart Contracts to Drain User Crypto Wallets of More Than $900k

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated campaign uncovered in early 2024, cybercriminals have begun distributing malicious Ethereum smart contracts masquerading as lucrative trading bots. These weaponized contracts leverage Web3 development platforms such as Remix to entice victims into deploying code that appears to …

Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cyber campaign has emerged targeting Windows users through a deceptive malware variant known as ToneShell, which masquerades as the legitimate Google Chrome browser. The advanced persistent threat (APT) group Mustang Panda, known for its strategic targeting of …

UAC-0099 Hackers Weaponizing HTA Files to Deliver MATCHBOIL Loader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Ukrainian threat intelligence group UAC-0099 has significantly evolved its cyber warfare capabilities, deploying a sophisticated new malware toolkit targeting Ukrainian state authorities, Defense Forces, and defense industrial enterprises. The National Cyber Incident Response Team CERT-UA has documented a series …

Google’s Salesforce Instances Hacked in Ongoing Attack: Hackers Exfiltrate User Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has confirmed that one of its corporate Salesforce instances was compromised in June by the threat group tracked as UNC6040. This incident is part of a Salesforce attack campaign involving voice phishing attacks aimed at stealing sensitive data from …

WhatsApp’s New Security Feature Allows Users to Pause, Question, and Verify Malicious Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp has unveiled a comprehensive security enhancement that implements a “pause, question, and verify” protocol to protect users from sophisticated messaging scams.  The platform has simultaneously disrupted over 6.8 million accounts linked to criminal scam centers in the first half …

CAPTCHAgeddon – New ClickFix Attack Leverages Fake Captcha to Deliver Malware Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign has emerged that weaponizes fake CAPTCHA verification pages to trick users into executing malicious PowerShell commands, marking a significant evolution in browser-based attack methodologies. The campaign, dubbed “ClickFix,” represents what cybersecurity experts are calling a …

Who Got Arrested in the Raid on the XSS Crime Forum?

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

On July 22, 2025, the European police agency Europol said a long-running investigation led by the French Police resulted in the arrest of a 38-year-old administrator of XSS, a Russian-language cybercrime forum with more than 50,000 members. The action has triggered …

Akira Ransomware Uses Windows Drivers to Bypass AV/EDR in SonicWall Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated evasion technique employed by Akira ransomware affiliates, exploiting legitimate Windows drivers to bypass antivirus and endpoint detection and response (EDR) systems during recent SonicWall VPN attack campaigns.  The attacks, which have escalated from late July through early August …