Phishers Weaponize Safe Links With Multi-Layered URL Rewriting to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing attackers have found a way to turn a standard security feature against the very users it was built to protect. By abusing URL rewriting — a defensive mechanism embedded in most enterprise email gateways — threat actors are weaponizing …

New ‘Payload’ Ransomware Uses Babuk-Style Encryption Against Windows and ESXi Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified ransomware strain called “Payload” has emerged as a serious threat to organizations across multiple sectors, combining strong encryption techniques with advanced anti-forensic capabilities. The group behind it has been active since at least February 17, 2026 — …

CISA Warns of Chrome 0-Day Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns of Chrome 0-Day Vulnerabilities Exploit An urgent warning regarding two highly critical zero-day vulnerabilities affecting Google Chrome and related products. These flaws have been officially added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, indicating that malicious hackers are …

Attackers Hijacking Legitimate Websites to Attack Microsoft Teams users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A multi-vector phishing campaign using compromised WordPress sites to steal login credentials from Microsoft Teams and Xfinity users. By hijacking these trusted sites, attackers can bypass security filters and trick victims into disclosing sensitive information. The threat actors are not …

Malicious npm Packages Deliver PylangGhost RAT in New Software Supply Chain Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A remote access trojan known as PylangGhost has appeared on the npm registry for the first time, concealed inside two malicious JavaScript packages. The malware, first publicly disclosed by Cisco Talos in June 2025 and attributed to the North Korean …

Phishers Abuse LiveChat Support Tools to Steal Sensitive Data in New SaaS-Based Attack Tactic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified phishing campaign is turning legitimate customer service software into a weapon for stealing sensitive user data. Attackers have been found abusing LiveChat, a widely used Software-as-a-Service (SaaS) platform that businesses rely on for real-time customer support, to …

Researchers Decrypt and Exploit Encrypted Palo Alto Cortex XDR BIOC Rules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Methods Decrypt and Abuse Encrypted Palo Alto Cortex XDR BIOC Rules for Evasion Cybersecurity researchers have uncovered a critical evasion flaw in Palo Alto Networks’ Cortex XDR agent that allowed attackers to bypass behavioral detections completely. By reverse-engineering these encrypted …

New CondiBot Variant and ‘Monaco’ Cryptominer Expand Threats to Network Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Network infrastructure has become one of the most targeted areas in today’s threat landscape. Over recent years, attackers ranging from nation-state groups to financially driven criminal actors have steadily shifted their focus toward routers, firewalls, and other network devices. These …

Stryker Confirms Destructive Wiper Attack – Tens of Thousands of Devices Wiped

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Medical technology giant Stryker Corporation confirmed on March 11, 2026, that it suffered a significant cyberattack that disrupted its global Microsoft environment, with Iran-linked threat actor Handala claiming responsibility for what appears to be a politically motivated, destructive operation. Unlike …

Handala Hack Uses RDP, NetBird, and Parallel Wipers in MOIS-Linked Destructive Intrusions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An Iranian threat actor known as Handala Hack has carried out a series of destructive cyberattacks against organizations in Israel, Albania, and the United States, using remote desktop access, network tunneling, and multiple simultaneous data-wiping tools. The group operates under …