Vortex Werewolf Attacking Organizations to Gain Tor-Enabled Remote Access Over the RDP, SMB, SFTP, and SSH Protocols

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new cyber espionage cluster has recently emerged, focusing its aggressive targeting on Russian government and defense organizations. Active since at least December 2025, the group, designated as Vortex Werewolf, employs a combination of social engineering and legitimate software utilities …

New RecoverIt Tool Exploits Windows Service Failure Recovery Functions to Execute Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

RecoverIt Tool A new open-source offensive security tool named “RecoverIt” has been released, offering Red Teamers and penetration testers a novel method for establishing persistence and executing lateral movement on compromised Windows systems. The tool, developed by security researcher TwoSevenOneT, …

Critical FortiClientEMS Vulnerability Let Attackers Execute Malicious Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiClientEMS RCE Vulnerability Fortinet has issued a critical security advisory warning administrators to immediately patch instances of FortiClientEMS, its central management solution for endpoint protection. The vulnerability, tracked as CVE-2026-21643, carries a CVSSv3 score of 9.1 and could allow unauthenticated, …

New Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Telegram phishing campaign has re-emerged, marking a significant evolution in how threat actors compromise user accounts. Unlike traditional credential harvesting, this operation does not rely on cloning login pages to steal passwords but instead manipulates the platform’s legitimate …

Ransomware Detection With Windows Minifilter by Intercepting File Filter and Change Events

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware continues to be the most financially damaging type of cyberattack affecting organizations around the world. One of the most effective tools for monitoring in Windows is the minifilter driver. By sitting directly in the file system I/O pipeline, a …

Black Basta Ransomware Actors Embeds BYOVD Defense Evasion Component with Ransomware Payload Itself

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware actors are constantly refining their arsenals to bypass modern defenses. A recent campaign by the Black Basta group has introduced a significant tactical shift by embedding a “Bring Your Own Vulnerable Driver” (BYOVD) component directly into the ransomware payload …

OpenClaw Becomes New Target in Rising Wave of Supply Chain Poisoning Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenClaw, a rapidly growing open-source AI agent platform, faces severe supply chain risks as attackers poison its ClawHub plugin marketplace with malicious skills. Security firms SlowMist and Koi Security have uncovered hundreds of compromised extensions deploying infostealers like Atomic Stealer. …

Hackers Attacking IT & OSINT Professionals with New PyStoreRAT to Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new supply chain attack is targeting Information Technology administrators and Open Source Intelligence (OSINT) professionals. This campaign leverages the reputation of the trusted development platform GitHub to distribute a stealthy backdoor. Unlike typical opportunistic attacks, this operation employs …

Beware of Apple Pay Phishing Attack that Aims to Steal Your Payment Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign is currently targeting Apple Pay users, utilizing deceptive emails and phone calls to steal sensitive financial information. The attack typically begins with an email that appears boringly familiar, featuring the official Apple logo and a clean, …

Hackers Leveraging Free Firebase Developer Accounts to Send Phishing Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The landscape of digital threats is constantly shifting, with cybercriminals increasingly adopting “living off the cloud” strategies to bypass security perimeters. By exploiting the infrastructure of trusted service providers, attackers can effectively cloak their malicious activities, making detection significantly more …