Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale phishing campaign is targeting software developers on GitHub, using fake Visual Studio Code security alerts posted in GitHub Discussions to trick users into downloading malicious software. The attacks are designed to look like legitimate security advisories, warning developers …

Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated evolution of Kerberoasting dubbed the “Ghost SPN” attack that allows adversaries to extract Active Directory credentials while erasing all traces of their activity, rendering traditional detection models effectively blind to the intrusion. The attack revealed by Trellix security …

China-Linked Hackers Breach Southeast Asian Military Systems in Long-Running Spy Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated and long-running cyber espionage campaign, tracked as CL-STA-1087, has been quietly targeting military organizations across Southeast Asia since at least 2020. The operation, assessed with moderate confidence to be linked to a China-aligned threat actor, focuses on collecting strategic …

Open Directory Malware Campaign Uses Obfuscated VBS, PNG Loaders and RAT Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated multi-stage malware campaign has surfaced, deploying obfuscated Visual Basic Script (VBS) files, PNG-embedded loaders, and remote access trojans (RATs) to target systems without leaving a trace on disk. What began as a routine endpoint detection in early 2026 …

Linux Ransomware Pay2Key Attacking Organizations Ervers, Virtualization Hosts, and Cloud Workloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Linux has long been considered a more secure operating system than Windows, but that reputation is being tested. A ransomware group known as Pay2Key, attributed to Iranian threat actors, has developed a Linux variant that is actively targeting organizational servers, …

macOS Threats Are the Biggest Security Gap in 2026: How SOC Teams Close It 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

macOS Threats: Closing Security Gaps in 2026 macOS has become a standard part of modern business environments, especially across engineering, product, and leadership teams. That makes it a growing security concern: when a Mac used by a high-access employee is …

SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport RAT, StealC and Sectop RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat campaign known as SmartApeSG — also tracked under the names ZPHP and HANEYMANEY — has been observed pushing multiple strains of malware through a social engineering technique called ClickFix. The campaign, active as recently as March 24, 2026, …

Firefox 149.0 Released With Free Built-in VPN With 50 GB Monthly Data Limit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mozilla has officially rolled out Firefox 149.0 to the Release channel on March 24, 2026, delivering a massive update focused heavily on user privacy and security hardening. The standout addition in this release is a free built-in VPN offering 50 GB of protected …

New Research Maps How Infostealer Infections Turn Into Dark Web Exposure in 48 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The digital threat landscape has reached a point where a single careless download by one employee can hand criminal groups direct access to an entire corporate network in under two days. New research published by Whiteintel’s Intelligence Division on March …

AI-Assisted ‘OpenClaw Trap’ Campaign Uses Trojanized GitHub Repos to Target Developers and Gamers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware campaign has been quietly spreading through fake GitHub repositories, targeting software developers, gamers, Roblox players, and crypto users at the same time. Tracked internally as TroyDen’s Lure Factory, the campaign deploys a custom LuaJIT trojan carefully …