SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A suspected India-aligned threat group known as SloppyLemming has been conducting a sustained espionage campaign against government agencies, defense organizations, nuclear oversight bodies, and critical infrastructure operators in Pakistan and Bangladesh. Active since 2021 and also tracked as Outrider Tiger …

Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor tracked as D-Shortiez has been running a persistent malvertising campaign that turns a WebKit browser behavior into a trap, forcing iOS Safari users into scam pages with no easy way out. The campaign is not entirely new …

LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor operating under the alias FulcrumSec has publicly claimed responsibility for a fresh breach of LexisNexis Legal & Professional, the legal information division of RELX Group, alleging the exfiltration of 2.04 GB of structured data from the company’s …

Microsoft Warns of New Phishing Attack Exploiting OAuth in Entra ID to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing Attack Exploiting OAuth A new active phishing attack that exploits OAuth’s legitimate redirection behavior, allowing it to bypass traditional email and browser defenses without stealing any tokens. According to Microsoft Defender researchers, the campaigns primarily target government and public-sector …

Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Mirai-based botnet campaign known as Zerobot has resurfaced with renewed force, this time targeting critical flaws in Tenda AC1206 routers and the n8n workflow automation platform. The campaign, now operating on its ninth known iteration — dubbed zerobotv9 — …

Archipelo and Checkmarx Announce Partnership Connecting AppSec Detection with DevSPM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

San Francisco, CA, United States, March 3rd, 2026, CyberNewswire Archipelo and Checkmarx today announced a technical partnership focused on correlating application vulnerability findings with development-origin context within modern software delivery workflows. Application security platforms identify and prioritize vulnerabilities across repositories …

New ‘StegaBin’ Campaign Uses Malicious 26 npm Packages to Deploy Multi-Stage Credential Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new software supply-chain attack is abusing the npm ecosystem today, where a single mistaken dependency can quietly open a door into a developer’s machine. The activity, tracked as “StegaBin,” mixes familiar tricks like typosquatting with a staged delivery path …

Hackers Leverage Telegram for Initial Access to Corporate VPN, RDP, and Cloud Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Telegram, once widely recognized as a privacy-focused messaging application, has quietly transformed into one of the most powerful operational platforms used by cybercriminals today. What dark web forums once offered — anonymity, exclusive access, and a marketplace for stolen data …

Epic Fury/Roaring Lion Sparks Escalating Cyber Conflict as Iran Goes Offline, Hacktivists Step Up Retaliation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On February 28, 2026, the United States and Israel launched a coordinated offensive — code-named Operation Epic Fury by the U.S. and Operation Roaring Lion by Israel — setting off a wide-ranging cyber conflict that spread across the Middle East …

How to Cut MTTR by Improving Threat Visibility in Your SOC 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cut MTTR by Enhancing Threat Visibility in SOC In boardrooms and security operations centers alike, one metric has risen from a niche KPI to a defining measure of organizational resilience: Mean Time to Respond (MTTR). But why has this particular …