Kimsuky Deploys Malicious LNK Files to Deliver Python-Based Backdoor in Multi-Stage Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korean threat group known as Kimsuky has been caught running a cyberattack campaign that uses malicious Windows shortcut files, known as LNK files, to quietly install a Python-based backdoor on victim systems. The attack stays hidden across multiple …

Axios Maintainer Confirms The npm Compromise Was via a Targeted Social Engineering Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two malicious versions of the popular JavaScript HTTP library Axios were briefly published to the npm registry on March 31, 2026. Each version carried a hidden dependency that installed a remote access trojan (RAT) across macOS, Windows, and Linux systems. …

Hackers Abuse Trusted Platforms to Steal Bank Credentials From Philippine Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated phishing campaign has been quietly targeting banking customers across the Philippines since early 2024, and it remains active today. The attackers are not relying on crude tricks — they are hiding behind widely trusted internet platforms to steal …

Malicious Chrome Extension “ChatGPT Ad Blocker” Steals ChatGPT Conversations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As OpenAI introduces advertisements to its free tier, cybercriminals are seizing the opportunity to trick users with fake utility tools. Security researchers have discovered a malicious Google Chrome extension named “ChatGPT Ad Blocker.” While it claims to hide unwanted ads, …

Hackers Use Phorpiex Botnet to Spread Ransomware, Sextortion, and Crypto-Clipping Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A botnet that has been running since 2011 is back in the spotlight — not because it is new, but because it keeps reinventing itself. Phorpiex, also known as Trik, has grown from a basic spam tool into a full-scale …

Hackers Use Venom Stealer to Turn ClickFix Lures Into Full Data Exfiltration Pipelines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware has been quietly spreading across cybercrime networks, and security researchers say it is far more capable than most tools of its kind. Called Venom Stealer, this malware-as-a-service platform does not just harvest credentials — it builds an …

Microsoft Forcing Upgrades to Unmanaged Windows 11, Version 24H2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially begun force-upgrading unmanaged Windows 11 version 24H2 devices to version 25H2, marking the final phase of a staged rollout that relies on machine learning to determine device readiness. The move, confirmed in an updated Windows Release Health …

Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple high-severity vulnerabilities exist in TP-Link’s Tapo C520WS smart security cameras. If exploited, these vulnerabilities may allow adjacent attackers to trigger Denial-of-Service (DoS) conditions, crash the device, or completely bypass authentication. TP-Link has released urgent firmware updates to address these …

Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive automated credential theft campaign is actively targeting web applications worldwide. Cybersecurity researchers at Cisco Talos have uncovered an operation by a hacker group tracked as UAT-10608, which has already compromised over 700 servers. The attackers are exploiting a …

CERT-EU Confirms Trivy Supply Chain Attack Led to European Commission AWS Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The European Commission’s primary web platform, “europa.eu,” recently suffered a severe data breach stemming from a supply-chain compromise involving the popular open-source vulnerability scanner, Trivy. On April 3, 2026, CERT-EU published an official advisory detailing how a threat actor known …