Rogue VM Linked to Muddled Libra in VMware vSphere Attack, Revealing Key TTPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a September 2025 incident response case, investigators found a rogue virtual machine inside a VMware vSphere environment and tied it with high confidence to Muddled Libra, also tracked as Scattered Spider and UNC3944. The VM acted like a quiet …

WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw in the WPvivid Backup & Migration WordPress plugin can let an unauthenticated attacker upload files and run code on the server, a path that often ends in full site takeover. The issue is tracked as CVE-2026-1357, scored …

Chrome Security Update – Patch for Vulnerabilities that Enables Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chrome Security Update Patch Vulnerabilities Google has released Chrome 145 to the stable channel for Windows, Mac, and Linux, addressing 11 security vulnerabilities that could enable attackers to execute malicious code on user systems. The update, rolling out over the …

Sophisticated ‘duer-js’ NPM Package Distributes ‘Bada Stealer’ Malware Targeting Windows and Discord Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has emerged on the NPM package registry, putting thousands of developers and Windows users at risk. The malicious package, known as “duer-js,” was published by a user named “luizaearlyx” and disguised itself as a legitimate console …

Google Warns of Hackers Leveraging Gemini AI Model for All Stages of Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Gemini AI Model Cyberattacks Threat actors have begun leveraging Google’s Gemini API to dynamically generate C# code for multi-stage malware, evading traditional detection methods. The Google Threat Intelligence Group (GTIG) detailed this in its February 2026 AI Threat Tracker report, …

Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Exploits GitHub, npm, and PyPI to Distribute Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The North Korean state-sponsored hacking team, Lazarus Group, has launched a sophisticated fake recruiter campaign targeting cryptocurrency developers through a malicious operation called “graphalgo.” Active since May 2025, this coordinated attack uses fraudulent job offers to distribute remote access trojans …

Adblock Filters Exposes Reveal User Location Despite VPN Protection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adblock Filters Exposes User Location Many internet users believe VPNs make them completely anonymous online. While VPNs hide your IP address and encrypt traffic, a new fingerprinting technique reveals they cannot protect against all tracking methods. Country-specific AdBlock filter lists …

Fake CAPTCHA Attacks Emerge as Key Entry Point for LummaStealer Malware Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LummaStealer, a notorious information-stealing malware, has made a significant comeback following a major law enforcement disruption in 2025. This resurgence is characterized by a shift in distribution tactics, moving away from traditional exploit kits towards aggressive social engineering campaigns. Cybercriminals …

Microsoft Outlook Add-in Stolen 4,000 Microsoft account Credentials and Credit Card Numbers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Outlook Add-in Stolen Credentials Security researchers have identified the first documented instance of a malicious Microsoft Outlook add-in being used against users in real-world scenarios. A compromised meeting scheduler named AgreeTo was used to steal over 4,000 Microsoft account credentials, credit …

Promptware – Hackers Can Use Google Calendar Invites to Stream Victims’ Cameras via Zoom

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Promptware Hackers Can Weaponize Google Calendar A new and dangerous class of cyberattack called “Promptware” has been discovered, capable of turning your personal AI assistant into a sleeper agent that spies on you. Security researchers from Ben-Gurion University, Tel Aviv …