Hackers Use AiTM Session Hijacking to Redirect Employee Salaries in New Storm-2755 Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financially motivated threat group called Storm-2755 has launched a campaign that quietly reroutes employee salary payments to attacker-controlled bank accounts. Targeting Canadian workers, the group uses adversary-in-the-middle (AiTM) techniques to hijack authenticated sessions and bypass multi-factor authentication (MFA), in …

Hackers Use Fake BTS World Tour Ticket Sites to Scam Fans Across Multiple Countries

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are capitalizing on the excitement around BTS’s long-awaited return to the world stage by setting up fraudulent ticket websites that steal money from unsuspecting fans. The campaign has already reached fans across nine countries, making it one of the …

Censys Warns 5,219 Rockwell/Allen-Bradley PLCs Are Exposed Amid Iranian APT Activity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command jointly disclosed on April 7, 2026, that Iranian-affiliated advanced persistent threat (APT) actors are actively targeting internet-facing Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs). These industrial devices are widely used in …

Hackers Exploit GitHub Copilot Flaw to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently disclosed high-severity vulnerability in GitHub Copilot Chat allowed attackers to silently siphon sensitive data from private repositories. Tracked as CVE-2025-59145 with a near-perfect CVSS score of 9.6, the flaw enabled the theft of source code, API keys, and …

HPE Aruba Private 5G Platform Vulnerability Enables Credential Theft Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hewlett-Packard Enterprise (HPE) has disclosed a security flaw in its Aruba Networking Private 5G Core On-Prem platform. This vulnerability allows attackers to steal user credentials by exploiting an open redirect issue in the system’s login process. The vulnerability is officially …

Hackers Impersonate Secure Messaging Apps to Deploy ProSpy in Middle East Espionage Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A targeted mobile espionage campaign has been quietly operating across the Middle East since at least 2022, using fake versions of widely trusted secure messaging apps to plant a powerful Android spyware named ProSpy on victims’ devices. Attackers behind this …

MuddyWater Turns to Russian Malware-as-a-Service in New ChainShell Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iranian state-backed hacking group MuddyWater has made a decisive operational shift, adopting a Russian-built Malware-as-a-Service platform to power a new campaign against Israeli targets. The operation, built around a previously unknown tool called ChainShell, marks a clear departure from the …

Multiple TP-Link Vulnerabilities Allow Attackers to Seize Control of the Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified five distinct security flaws in the TP-Link Archer AX53 v1.0 router. Tracked under multiple CVE identifiers, these vulnerabilities impact the router’s core modules, including OpenVPN, dnsmasq, and tmpServer. When exploited, these flaws allow attackers on the …

CPUID Website Compromised to Deliver Weaponized HWMonitor and CPU-Z Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cpuid-dot-com website, home to widely used system utilities CPU-Z and HWMonitor, is at the center of an active supply chain security incident. Users downloading HWMonitor 1.63 or CPU-Z ZIPs since early April have reportedly received trojanized installers capable of …

Trojanized OpenVSX Extension Spreads GlassWorm Across VS Code, Cursor, and Windsurf

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fake developer extension published on the OpenVSX marketplace is silently spreading a known malware strain called GlassWorm to every code editor installed on a developer’s machine. The malicious package disguises itself as a legitimate productivity tool and uses a …