Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Facebook users are increasingly becoming targets of a sophisticated phishing technique that bypasses conventional security measures. With over three billion active users on the platform, Facebook represents an attractive target for attackers seeking to compromise accounts and harvest personal credentials. …

100,000+ n8n Instances Exposed to Internet Vulnerable to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting the popular n8n workflow automation platform has put over 100,000 internet-exposed instances at severe risk. Security researchers from The Shadowserver Foundation discovered that 105,753 unique n8n instances are vulnerable to remote code execution (RCE) attacks through …

AsyncRAT Leveraging Cloudflare’s Free-Tier Services to Mask Malicious Activities and Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent AsyncRAT campaign is using Cloudflare’s free tier services and TryCloudflare tunnels to hide remote access activity inside normal looking cloud traffic. In these attacks, threat actors send phishing emails that link to a Dropbox hosted ZIP archive named …

Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hikvision, a leading provider of surveillance and access control systems, faces serious security risks from two newly disclosed stack overflow vulnerabilities. These flaws, tracked as CVE-2025-66176 and CVE-2025-66177, allow attackers on the same local area network (LAN) to trigger device …

Malicious Chrome Extension Steals Wallet Login Credentials and Enables Automated Trading

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious Chrome extension called MEXC API Automator is abusing trust in browser add-ons to steal cryptocurrency trading access from MEXC users. Posed as a tool that helps automate trading and API key creation, it quietly takes control of newly …

Hackers Infiltrated n8n’s Community Node Ecosystem With a Weaponized npm Package

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers have successfully infiltrated n8n’s community node ecosystem using a malicious npm package disguised as a legitimate Google Ads integration tool. The attack reveals a critical vulnerability in how workflow automation platforms handle third-party integrations and user credentials. The malicious …

Telegram Exposes Real Users IP Addresses, Bypassing Proxies on Android and iOS in 1-click

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A stealthy flaw in Telegram’s mobile clients that lets attackers unmask users’ real IP addresses with a single click, even those hiding behind proxies. Dubbed a “one-click IP leak,” the vulnerability turns seemingly innocuous username links into potent tracking weapons. …

InvisibleJS Tool Hides Executable ES Modules in Empty Files Using Zero-Width Steganography

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

InvisibleJS, a new open-source tool that conceals JavaScript code using invisible zero-width Unicode characters, raises alarms about potential misuse in malware campaigns. InvisibleJS, hosted on GitHub by developer With alias oscarmine, employs steganography to embed source code into seemingly blank …

YARA-X 1.11.0 Released With a New Hash Function Warnings

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VirusTotal has released YARA-X version 1.11.0, introducing an important new feature designed to improve rule reliability and reduce false negatives in malware detection. The latest update introduces hash-function warnings that help security researchers catch common mistakes when writing YARA detection rules. …

Google Integrating Gemini With Gmail With New features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google announced Monday it’s integrating its Gemini AI model into Gmail, introducing features that transform the email service into a proactive personal assistant for its 3 billion users. The company is launching AI Overviews, a feature that synthesizes long email threads …