GlassWorm Infiltrated VSX Extensions with More than 22,000 Downloads to Attack Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GlassWorm has emerged as a serious threat to developers using the Open VSX Registry, where popular VSX extensions were silently turned into delivery vehicles for malware. Threat actors compromised a trusted publisher account and pushed poisoned updates that looked like …

Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Infostealer campaigns that once focused mainly on Windows are now expanding aggressively to macOS, using Python and trusted platforms to reach new victims. Recent attacks show a clear shift: threat actors are abusing online ads, fake apps, and familiar tools …

Beware of Fake Dropbox Phishing Attack that Harvest Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are launching a dangerous phishing campaign that tricks users into giving away their login credentials by impersonating Dropbox. This attack uses a multi-stage approach to bypass email security checks and content scanners. The threat actors exploit trusted cloud platforms …

Hackers Exploiting React Native’s Metro Server in the Wild to Attack Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are actively exploiting a critical remote code execution vulnerability in React Native’s Metro Development Server to deliver advanced malware payloads across Windows and Linux systems. VulnCheck’s Canary honeypot network first detected operational exploitation of CVE-2025-11953 dubbed “Metro4Shell” on …

Foxit PDF Editor Vulnerabilities Let Attackers Execute Arbitrary JavaScript

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security updates addressing critical cross-site scripting (XSS) vulnerabilities in Foxit PDF Editor Cloud that could allow attackers to execute arbitrary JavaScript code in users’ browsers. The vulnerabilities were discovered in the application’s File Attachments list and Layers panel, where insufficient …

Stronger Incident Prevention Takes Just One CISO Decision 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

There is a comforting illusion in cybersecurity leadership: when things get noisy, you add more people. More analysts. More shifts. More headcount. It feels decisive. It looks responsible. It even photographs well for internal reports.  But SOC inefficiency is rarely a …

Beware of New Compliance Emails Weaponizing Word/PDF Files to Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targeting macOS users has emerged, using fake compliance emails as a delivery mechanism for advanced malware. Chainbase Lab recently detected this campaign, which impersonates legitimate audit and compliance notifications to deceive users. The attack chain combines …

PDFly Variant Uses Custom PyInstaller Modification, Forcing Analysts to Reverse-Engineer Decryption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new variant of the PDFly malware has emerged with advanced techniques that challenge traditional analysis methods. The malware uses a modified PyInstaller executable that prevents standard extraction tools from working properly. This makes it difficult for security teams to …

French Authorities Raid X Office Following Cybercrime Allegations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

French authorities raided the Paris headquarters of Elon Musk’s social media platform X today, escalating a year-old cybercrime probe into alleged algorithmic manipulation and illicit content distribution. The operation, led by the Paris prosecutor’s cybercrime unit alongside France’s national cybercrime …

Microsoft to Disable NTLM by Default as a Step Towards More Secure Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The transition away from NTLM (New Technology LAN Manager), a legacy authentication protocol that has existed in Windows for over three decades, is being accelerated. The company has announced a phased roadmap to reduce, restrict, and ultimately disable NTLM by …