Iran-Linked Cyber Campaigns Converge With Electronic and Psychological Warfare as Regional Conflict Escalates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On February 28, 2026, a joint US-Israeli military operation launched strikes inside Iran, opening a conflict that rapidly extended into cyberspace. Iran responded with ballistic missiles and drone strikes across Bahrain, Kuwait, Iraq, Saudi Arabia, the UAE, Israel, and Qatar. …

Vidar Stealer 2.0 Spreads Through Fake Game Cheats Promoted on GitHub and Reddit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly updated version of the Vidar infostealer, dubbed Vidar 2.0, is actively spreading through hundreds of fake game cheat repositories on GitHub and targeted posts on Reddit. The malware disguises itself as free cheating software for popular online games, …

Malicious Telegram Download Site Pushes Multi-Stage Loader With In-Memory Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fake Telegram download website is actively pushing dangerous malware onto unsuspecting users by disguising a malicious installer as a legitimate setup file. The site, hosted at the domain telegrgam[.]com — just one letter off from the real Telegram address …

Boggy Serpens Targets Diplomats and Critical Infrastructure in Multi-Wave Espionage Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-resourced Iranian nation-state group known as Boggy Serpens — also tracked as MuddyWater — has sharply escalated its cyberespionage operations, running sustained and targeted campaigns against diplomatic missions, energy companies, maritime operators, and financial institutions. Attributed to Iran’s Ministry …

Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of targeted attacks is quietly hitting Argentina’s judicial system, using fake court documents to lure legal professionals into installing a dangerous piece of malware. The campaign, formally called Operation Covert Access, deploys a Rust-built Remote Access Trojan …

Microsoft to Stop Force Installation of 365 Copilot App on Windows Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has temporarily halted the automatic installation of the Microsoft 365 Copilot app on Windows devices. According to a recent update in the Microsoft 365 Message Center on March 16, 2026, the company paused the mandatory rollout, originally scheduled to …

Researchers Reveal ‘RegPwn,’ a Windows Registry Vulnerability That Granted SYSTEM Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

RegPwn Windows Registry Vulnerability A high-severity Windows vulnerability dubbed “RegPwn” (CVE-2026-24291) is an elevation-of-privilege flaw that allows low-privileged users to gain full SYSTEM access. The MDSec red team discovered the vulnerability and successfully used it in internal engagements since January …

Critical FortiClient SQL Injection Vulnerability Enables Arbitrary Database Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiClient SQL Injection vulnerability A critical SQL injection vulnerability in Fortinet’s FortiClient Endpoint Management Server (EMS). Tracked as CVE-2026-21643, this severe flaw carries a CVSS score of 9.1. It allows unauthenticated attackers to execute arbitrary SQL commands and access sensitive …

Ubuntu Desktop Systems Vulnerability Enables Attackers to Gain Full Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Local Privilege Escalation (LPE) vulnerability in default installations of Ubuntu Desktop 24.04 and later allows an unprivileged local attacker to gain full root access. Tracked as CVE-2026-3888, uncovered by The Qualys Threat Research Unit, the flaw exploits an unintended …

Microsoft Teams Support Call Leads to Quick Assist Compromise in New Vishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Detection and Response Team details a sophisticated voice phishing (vishing) campaign that successfully compromised a corporate environment in November 2025. Unlike conventional intrusions that rely on software exploits, this attack weaponized trust, collaboration platforms, and built-in Windows tooling to …