APT36 Malware Campaign Targeting Windows LNK Files to Attack Indian Government Entities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT36, also known as Transparent Tribe, has launched a new malware campaign that targets Indian government and strategic entities by abusing Windows LNK shortcut files. The attack starts with spear‑phishing emails that carry a ZIP archive named “Online JLPT Exam …

NeuroSploitv2 – AI-Powered Pentesting Tool With Claude, GPT, and Gemini models to Detect vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NeuroSploitv2 is an AI-powered penetration testing framework that automates critical aspects of offensive security operations through advanced language models. The framework, available on GitHub, integrates with multiple LLM providers, including Claude, GPT, Gemini, and Ollama, to enable specialized vulnerability analysis …

Threat Actors Advertising AI-Enhanced Metamorphic Crypter with Claims of Windows Defender Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dark web forums have become a marketplace for sophisticated malware tools, with threat actors continuously refining their capabilities to stay ahead of security solutions. The latest concerning development involves an emerging AI-powered crypter service that promises unprecedented evasion abilities, putting …

Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security patch addressing a critical privilege escalation vulnerability that allows unauthorized users to gain administrative access to the data streaming platform. The flaw, tracked as CVE-2025-47411 and rated important, affects Apache StreamPipes versions 0.69.0 through 0.97.0. The vulnerability stems …

Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes. The attack …

Hackers Advertised VOID ‘AV Killer’ with Kernel-level Termination Claims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybercriminal threat actor known as Crypt4You has recently emerged on underground forums and dark web marketplaces, advertising a sophisticated tool named VOID KILLER. This malicious software operates as a kernel-level antivirus and endpoint detection response (EDR) process killer, designed …

ESET Warns AI-driven Malware Attack and Rapidly Growing Ransomware Economy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has reached a critical turning point as artificial intelligence moves from theoretical threat to operational reality. In their H2 2025 Threat Report, ESET researchers have documented a disturbing shift in how attackers operate, revealing that AI-powered malware …

New Spear-Phishing Attack Targeting Security Individuals in Israel Region

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Israel’s National Cyber Directorate recently issued an urgent alert about a targeted spear-phishing attack aimed at people working in security and defense-related areas. The campaign uses WhatsApp messages that pretend to come from trusted organizations, inviting targets to professional conferences. …

European Space Agency Confirms Breach of Servers Outside the Corporate Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The European Space Agency (ESA) has confirmed a cybersecurity breach affecting a limited number of external servers, marking a rare public admission of vulnerability in the continent’s premier space organization. In an official statement released Tuesday, ESA disclosed: “ESA is …

Hackers Infiltrated Maven Central Masquerading as a Legitimate Jackson JSON Library

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign has successfully infiltrated Maven Central, one of the most trusted repositories for Java developers, by masquerading as a legitimate Jackson JSON library extension. The malicious package, published under the org.fasterxml.jackson.core/jackson-databind namespace, represents one of the first …