GOLD BLADE Using Custom QWCrypt Locker that Allows Data Exfiltration and Ransomware Deployment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The GOLD BLADE threat group has shifted from pure espionage to a hybrid model that combines data theft with targeted ransomware attacks using a custom locker called QWCrypt. This shift follows a long-running campaign tracked as STAC6565, which hit almost …

Ransomware Targeting Hyper-V and VMware ESXi Surges as Akira Group Exploits System Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of ransomware attacks targeting virtual machine platforms has emerged, with the Akira ransomware group leading a campaign against Hyper-V and VMware ESXi systems. These attacks pose a growing threat to enterprise environments that rely on virtualization for …

See Cyber Threats to Your Company’s Industry & Region in 2 Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security teams today struggle with a paradox. Threat volumes keep climbing, but most of what hits SIEMs and inboxes is noise: indicators stripped of meaning, alerts detached from context, and threat data that treats every organization as if it faces the same risks.  For …

Microsoft Teams New feature Allows Users to Flag Malicious Calls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is set to introduce a significant security enhancement to its Teams platform that will empower users to flag potentially malicious or unsolicited calls. This upcoming feature, “Report a Suspicious Call,” is designed to strengthen the platform’s defenses against fraudulent …

Critical Emby Server Vulnerability Let Attackers Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in Emby Server that allows unauthenticated attackers to gain full administrative access to affected systems. Tracked as CVE-2025-64113 with a severity score of 9.3 out of 10 (CVSS v4), this weakness affects both stable and beta …

New Vishing Attack Leverages Microsoft Teams Call and QuickAssist to Deploy .NET Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new vishing campaign has emerged, blending traditional voice phishing with modern collaboration tools to deploy stealthy malware. Attackers are leveraging Microsoft Teams calls and the remote support tool QuickAssist to bypass security perimeters. By impersonating senior IT staff, …

Ruby SAML Library Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in the Ruby SAML library that could allow attackers to bypass authentication mechanisms in affected applications completely. The flaw, tracked as CVE-2025-66567, impacts all versions up to and including 1.12.4 and has been assigned …

New Prompt Injection Attack via Malicious MCP Servers Let Attackers Drain Resources

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered critical vulnerabilities in the Model Context Protocol (MCP) sampling feature. Revealing how malicious servers can exploit LLM-integrated applications to conduct resource theft, conversation hijacking, and unauthorized system modifications. Attack Vector Mechanism Impact Resource theft Hidden instructions …

Proofpoint Acquires Hornetsecurity in $1.8 Billion Deal to Strengthen SMB Cybersecurity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Proofpoint, Inc., a pioneer in human-centric cybersecurity, has finalized its $1.8 billion acquisition of Hornetsecurity Group, a dominant European provider of AI-driven Microsoft 365 security solutions. The deal, announced today, catapults Proofpoint’s reach into the SMB market via MSP channels, …

Malicious VS Code on Microsoft Registry Captures Your Screen and Steals Your WiFi Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly weaponizing developer environments, as seen in a newly discovered malware campaign infiltrating the Visual Studio Code Marketplace. Unlike typical extensions that simply harvest credentials or mine cryptocurrency, this sophisticated attack actively captures screenshots of a victim’s desktop, …