BlackSuit Ransomware’s Data Leak and Negotiation Portal Seized

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major win against cybercrime happened this week, as authorities from around the world teamed up to take down key websites run by the BlackSuit ransomware gang. If you visit the group’s data leak site or their negotiation portal now, …

Elephant APT Group Attacking Defense Industry Leveraging VLC Player, and Encrypted Shellcode

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Dropping Elephant advanced persistent threat group has launched a sophisticated cyber-espionage campaign targeting Turkish defense contractors, particularly companies manufacturing precision-guided missile systems. This malicious operation represents a significant evolution in the group’s capabilities, employing a complex five-stage execution chain …

Hackers Injected Destructive System Commands in Amazon’s AI Coding Agent

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious pull request slipped through Amazon’s review process and into version 1.84.0 of the Amazon Q extension for Visual Studio Code, briefly arming the popular AI assistant with instructions to wipe users’ local files and AWS resources. The rogue …

Phishers Target Aviation Execs to Scam Customers

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

KrebsOnSecurity recently heard from a reader whose boss’s email account got phished and was used to trick one of the company’s customers into sending a large payment to scammers. An investigation into the attacker’s infrastructure points to a long-running Nigerian …

TP-Link Network Video Recorder Vulnerability Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two high-severity vulnerabilities in TP-Link VIGI network video recorder (NVR) systems could allow attackers to execute arbitrary commands on affected devices.  The security flaws, identified as CVE-2025-7723 and CVE-2025-7724, impact the VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2 models, posing …

SharePoint 0-day Vulnerability Exploited in Wild by All Sorts of Hacker Groups

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in Microsoft SharePoint servers has become a playground for threat actors across the cybercriminal spectrum, with attacks ranging from opportunistic hackers to sophisticated nation-state groups since mid-July 2025. On July 19, 2025, Microsoft confirmed that vulnerabilities …

First Known LLM-Powered Malware From APT28 Hackers Integrates AI Capabilities into Attack Methodology

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The newly revealed LAMEHUG campaign signals a watershed moment for cyber-def: Russian state-aligned APT28 has fused a large language model (LLM) directly into live malware, allowing each infected host to receive tailor-made shell commands on the fly. By invoking the …

Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated malware campaign where threat actors are exploiting Hangul Word Processor (.hwp) documents to distribute the notorious RokRAT malware. This marks a significant shift from the malware’s traditional distribution method through malicious shortcut (LNK) files, …

NoName057(16)’s Hackers Attacked 3,700 Unique Devices Over Last Thirteen Months

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The pro-Russian hacktivist group NoName057(16) has orchestrated a massive distributed denial-of-service campaign targeting over 3,700 unique hosts across thirteen months, according to new research published on July 22, 2025. The group, which emerged in March 2022 shortly after Russia’s full-scale …

Splunk Details on How to Detect, Mitigate and Respond to CitrixBleed 2 Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CitrixBleed 2 (CVE-2025-5777) erupted in 2025 when researchers uncovered an out-of-bounds read in Citrix NetScaler ADC and Gateway that lets an unauthenticated request siphon memory straight from the appliance. The flaw is triggered by a malformed POST sent to /p/u/doAuthentication.do, …