VVS Stealer Uses PyArmor Obfuscation to Evade Static Analysis and Signature Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape is witnessing a rise in sophisticated malware that leverages legitimate tools to mask malicious intent. A prime example is VVS Stealer (also styled VVS $tealer). This Python-based malware family has been actively marketed on Telegram since April …

10,000+ Fortinet Firewalls Still Exposed to 5-year Old MFA Bypass Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 10,000 Fortinet firewalls worldwide remain vulnerable to CVE-2020-12812, a multi-factor authentication (MFA) bypass flaw disclosed over five and a half years ago. Shadowserver recently added the issue to its daily Vulnerable HTTP Report, highlighting persistent exposure amid active exploitation …

Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In December 2025, the Iranian-linked hacking group Handala claimed to have fully compromised the mobile devices of two prominent Israeli political figures. However, detailed analysis by Kela cyber intelligence researchers revealed a more limited scope—the breaches targeted Telegram accounts specifically, …

Hackers Abusing Google Tasks Notification for Sophisticated Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have launched a sophisticated phishing campaign exploiting Google Tasks notifications to target over 3,000 organizations worldwide, primarily in the manufacturing sector. The December 2025 attacks signal a dangerous shift in email-based threats, in which attackers abuse legitimate Google infrastructure …

Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign is currently circulating within the Cardano community, posing significant risks to users seeking to download the newly announced Eternl Desktop application. The attack leverages a professionally crafted email claiming to promote a legitimate wallet solution designed …

Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign is currently circulating within the Cardano community, posing significant risks to users seeking to download the newly announced Eternl Desktop application. The attack leverages a professionally crafted email claiming to promote a legitimate wallet solution designed …

Threat Actors Testing Modified and Highly Obfuscated Version of Shai Hulud Strain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified a new variant of the Shai Hulud malware that reveals important insights into how threat actors are evolving their attack strategies. The malware, first observed in recent security analysis, demonstrates significant changes from its original version, …

Cognizant Hit With Multiple US Class-Action Lawsuits Following TriZetto Data Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cognizant Technology Solutions is facing multiple class-action lawsuits following a significant data breach at TriZetto Provider Solutions (TPS), its healthcare claims processing subsidiary. The lawsuits, filed in federal courts in New Jersey and Missouri, allege that the company failed to …

CISA Warns of WHILL Model C2 Wheelchairs Vulnerability Let Attackers Take Control of Product

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security advisory warned of severe vulnerabilities in WHILL electric wheelchairs that could allow attackers to hijack the devices via Bluetooth remotely. The alert affects two popular models used worldwide: the WHILL Model C2 Electric Wheelchair and Model F …

Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community was alarmed in late December 2025 when MongoDB announced a serious vulnerability called “Mongobleed” (CVE-2025-14847). This high-severity flaw allows unauthenticated attackers to steal sensitive data directly from server memory. With a CVSS score of 8.7 and over …