Hackers Use AI to Create Malicious NPM Package that Drains Your Crypto Wallet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have escalated their attack sophistication by leveraging artificial intelligence to create a malicious NPM package that masquerades as a legitimate development tool while secretly draining cryptocurrency wallets. The package, named @kodane/patch-manager, presents itself as an “NPM Registry Cache Manager” …

Critical Squid Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Squid Web Proxy Cache that enables attackers to execute remote code through a heap buffer overflow in URN (Uniform Resource Name) handling.  The vulnerability, tracked as CVE-2025-54574, affects all Squid versions prior …

LARGEST EVER Bitcoin Hack Valued $3.5 Billion Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The largest cryptocurrency hack ever recorded involved the theft of 127,426 BTC from Chinese mining pool LuBian in December 2020.  The stolen Bitcoin was worth approximately $3.5 billion at the time of the theft and has since appreciated to an …

Hackers Can Manipulate BitLocker Registry Keys Via WMI to Execute Malicious Code as Interactive User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel lateral movement technique that exploits BitLocker’s Component Object Model (COM) functionality to execute malicious code on target systems. The technique, demonstrated through the BitLockMove proof-of-concept tool, represents a sophisticated evolution in lateral movement tactics that bypasses traditional detection …

Critical HashiCorp Vulnerability Let Attackers Execute Arbitrary Code on Underlying Host

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical HashiCorp security vulnerability affecting Vault Community Edition and Enterprise versions could allow privileged operators to execute arbitrary code on underlying host systems.  The vulnerability, tracked as CVE-2025-6000, affects Vault versions from 0.8.0 up to 1.20.0 and has been …

AI-Powered Code Editor Cursor IDE Vulnerability Enables Remote Code Without User Interaction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in the popular AI-powered code editor Cursor IDE, dubbed “CurXecute,” allows attackers to execute arbitrary code on developers’ machines without any user interaction.  The vulnerability, tracked as CVE-2025-54135 with a high severity score of 8.6, affects all …

NestJS Framework Vulnerability Let Attackers Execute Arbitrary Code in Developers Machine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the NestJS framework’s development tools that enables remote code execution (RCE) attacks against JavaScript developers.  The flaw, identified as CVE-2025-54782, affects the @nestjs/devtools-integration package and allows malicious websites to execute arbitrary code …

Microsoft PlayReady DRM Used by Netflix, Amazon, and Disney+ Leaked Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security breach has compromised Microsoft’s PlayReady Digital Rights Management (DRM) system, exposing critical certificates that protect premium streaming content across major platforms including Netflix, Amazon Prime Video, and Disney+. The leak, which surfaced on GitHub through an account …

Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape continues to evolve as threat actors develop increasingly sophisticated methods to compromise Windows systems. A new ransomware variant known as Interlock has emerged as a significant threat, leveraging the deceptive ClickFix social engineering technique to execute malicious …

APT37 Hackers Weaponizes JPEG Files to Attack Windows System Leveraging “mspaint.exe” File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new wave of cyberattacks attributed to North Korea’s notorious APT37 (Reaper) group is leveraging advanced malware hidden within JPEG image files to compromise Microsoft Windows systems, signaling a dangerous evolution in evasion tactics and fileless attack techniques. Security …