Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

After a decade of disappearing from the cybersecurity landscape, the Careto threat group, also known as “The Mask,” has resurfaced with sophisticated new attack methods targeting high-profile organizations. Security researchers have identified fresh evidence of Careto’s activity, revealing how the …

Apache NuttX Vulnerability Let Attackers to Crash Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed use-after-free vulnerability in Apache NuttX RTOS could allow attackers to cause system crashes and unintended filesystem operations, prompting urgent security warnings for users running network-exposed services. The flaw, tracked as CVE-2025-48769 and rated moderate in severity, affects …

Top 10 High-Risk Vulnerabilities Of 2025 that Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape in 2025 has been marked by an unprecedented surge in critical vulnerabilities, with over 21,500 CVEs disclosed in the first half of the year alone, representing a 16-18% increase compared to 2024. Among these, a select group …

WhatsApp Crypt Tool to Encrypt and Decrypt WhatsApp Backups

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An open-source solution for handling encrypted WhatsApp backups. The wa-crypt-tools suite, hosted on GitHub, decrypts and encrypts .crypt12, .crypt14, and .crypt15 files from WhatsApp and WhatsApp Business, provided users supply the required key file or 64-character key.​ wa-crypt-tools simplifies access …

Two U.S. CyberSecurity Pros Plead Guilty for Working as ALPHV/BlackCat Affiliates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A federal court in the Southern District of Florida has accepted guilty pleas from two cybersecurity professionals who used their expertise to conduct ransomware attacks rather than stop them. Ryan Goldberg, 40, from Georgia, and Kevin Martin, 36, from Texas, …

Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of GlassWorm malware has emerged, marking a significant shift in targeting strategy from Windows to macOS systems. This self-propagating worm, distributed through malicious VS Code extensions on the Open VSX marketplace, has already accumulated over 50,000 downloads. …

New Cybercrime Tool ErrTraffic Let Attackers Automate ClickFix Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous cybercrime tool known as ErrTraffic has appeared in underground forums, making it easier for attackers to trick users into running harmful software on their devices. The tool automates what security experts call ClickFix attacks, where fake error messages …

DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered DarkSpectre, a well-funded Chinese threat actor responsible for infecting over 8.8 million users across Chrome, Edge, and Firefox browsers through a series of highly coordinated malware campaigns spanning seven years. The discovery reveals a level of operational …

Critical IBM API Connect Vulnerability Let Attackers Bypass Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security alert regarding a severe vulnerability in the IBM API Connect platform that could allow remote attackers to bypass authentication mechanisms. Discovered during internal testing, the flaw poses a significant risk to organizations relying on the platform for …

Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Large Language Models (LLMs) have revolutionized software development, democratizing coding capabilities for non-programmers. However, this accessibility has introduced a severe security crisis. Advanced AI tools, designed to assist developers, are now being weaponized to automate the creation of sophisticated exploits …