Hackers Use ClickFix Lure to Drop Node.js-Based Windows RAT With Tor-Powered C2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fresh wave of cyberattacks is targeting Windows users through a deceptive social engineering technique called ClickFix. Attackers use a fake browser verification page to trick users into running a hidden command that quietly drops a Node.js-based Remote Access Trojan …

Russian Hackers Exploiting Home and Small-office Routers in Massive DNS hijacking Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale campaign by Forest Blizzard, a Russian military-linked threat actor, targeting home and small-office routers to hijack DNS traffic and intercept encrypted communications with over 200 organizations and 5,000 consumer devices already compromised. Forest Blizzard (also tracked as APT28 …

Fake Software Installers Used to Drop RATs and Monero Miners in Long-Running Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financially motivated threat actor has been running a quiet malware campaign since at least late 2023, tricking users into downloading fake software installers that secretly deliver remote access trojans (RATs) and Monero cryptocurrency miners. The operation, designated REF1695, has …

New GPUBreach Attack Enables System-Wide Compromise Up to a Root Shell

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability, dubbed GPUBreach, that allows attackers to achieve a full system compromise, including a root shell. Scheduled for presentation at the IEEE Symposium on Security and Privacy, researchers from the University of Toronto show that this exploit elevates …

From Alert Overload to Rapid Response: Why Threat Intelligence Is a Top Solution for Fast MTTR 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat Intelligence for Faster MTTR and Response Reducing Mean Time to Respond (MTTR) is one of the most persistent challenges for modern SOC teams.  Despite investments in SIEM, EDR, and automation, many organizations still struggle to investigate alerts quickly and …

Critical Android “Zero-Interaction” Vulnerability Enables DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released its highly anticipated Android Security Bulletin for April 2026, bringing essential security patches to millions of Android devices worldwide.  The most pressing issue in this month’s rollout is CVE-2026-0049, a critical zero-interaction vulnerability residing in the core …

Iran-Linked Hackers Launch Password Spray Campaign Against Microsoft 365 Tenants in Middle East

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft 365 tenants in the Middle East are facing a new password spray campaign tied to an Iran-linked threat actor. Rather than starting with malware files or software exploits, the attackers are trying to break in through weak passwords and …

Microsoft Releases New Defender Update for Windows 11, 10, and Server Installation Images

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially rolled out its latest security intelligence update for Microsoft Defender Antivirus, delivering crucial protections for Windows 11, Windows 10, and Windows Server installation images. This vital release ensures that Microsoft’s built-in antimalware solutions are fully equipped to identify …

Microsoft Warns Storm-1175 Exploits Web-Facing Assets 0-Day Flaws in Medusa Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ransomware campaign is putting organizations on high alert. A financially motivated threat group known as Storm-1175 has been running fast-paced attacks targeting vulnerable, internet-facing systems — and deploying the Medusa ransomware as the final blow. What makes this …

50,000 WordPress Sites Exposed to Critical Ninja Forms File Upload RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in the popular WordPress plugin “Ninja Forms – File Upload” has left approximately 50,000 websites vulnerable to complete takeover. Tracked as CVE-2026-0740, this flaw boasts a maximum CVSS severity score of 9.8, making it a severe …