Hackers Use Pastebin-Hosted PowerShell Script to Steal Telegram Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a purpose-built PowerShell script hosted on Pastebin that is designed to silently steal Telegram session data from both desktop and web-based clients. The script is disguised as a routine Windows system update, making it easy for …

Void Dokkaebi Hackers Use Fake Job Interviews to Spread Malware via Code Repositories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korea-linked hacking group known as Void Dokkaebi, also tracked as Famous Chollima, is running a campaign that tricks software developers into installing malware through fake job interviews. The group lures developers into cloning infected code repositories as part …

Xiongmai IP Camera Vulnerability Let Attackers Bypass Authentication and have Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security cameras are designed to keep commercial facilities safe. However, a newly disclosed critical vulnerability in Hangzhou Xiongmai Technology’s XM530 IP Cameras is putting networks at risk. Tracked under the alert code ICSA-26-113-05 and officially designated as CVE-2025-65856, this flaw …

Python Vulnerability Allows Out-of-Bounds Write on Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability has been discovered in Python’s Windows asyncio implementation, allowing attackers to trigger out-of-bounds memory writes through a missing boundary check in network socket operations. The vulnerability, tracked as CVE-2026-3298, carries a high severity rating. It exclusively affects Windows platforms and was publicly …

Udemy Data Breach – ShinyHunters Allegedly Claims Compromise of 1.4M User Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious cybercriminal group ShinyHunters has claimed responsibility for a major data breach targeting Udemy, Inc. (udemy.com), one of the world’s largest online learning platforms, and has alleged the compromise of over 1.4 million records containing personally identifiable information (PII) …

Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly exposed server has revealed how a threat actor used automated tools, AI assistance, and Telegram bots to silently hack into more than 900 companies around the world. The operation, built around a tool called “Bissa scanner,” targeted internet-facing …

Ransomware Hackers Develop Custom Exfiltration Tool to Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware attackers are no longer relying only on widely known tools to steal data. Affiliates linked to the Trigona ransomware group have taken a more calculated approach by building their own custom data exfiltration tool, one that gives them greater …

Hackers Abuse SS7 and Diameter Protocols to Track Mobile Users Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major investigation has revealed that sophisticated threat actors are exploiting fundamental vulnerabilities in global mobile networks to track users worldwide. By abusing legacy 3G SS7 and 4G Diameter signaling protocols, hackers are successfully bypassing telecom firewalls to conduct silent, …

Microsoft Teams Issue Blocking Users From Joining Meetings Following Edge browser update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is actively investigating a known issue preventing some users from joining Microsoft Teams meetings on Windows devices, following a recent update to the Microsoft Edge browser. The disruption is affecting organizations, including those using NHSmail infrastructure, with reports indicating …

Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified threat group, UNC6692, has been caught running a sophisticated multistage intrusion campaign that uses Microsoft Teams impersonation, a custom modular malware suite, and cloud infrastructure abuse to deeply penetrate enterprise networks, all without exploiting a single software …