Microsoft Security Keys May Require PIN After Recent Windows Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed that FIDO2 security keys on Windows 11 may now prompt users to set up a PIN during authentication following specific recent updates, aligning with WebAuthn standards for enhanced user verification. The change began with the September 29, …

INE Expands Cross-Skilling Innovations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cary, North Carolina, USA, November 26th, 2025, CyberNewsWire New courses, certifications, and hands-on training strengthen workforce readiness. INE, the leading provider of hands-on IT and Cybersecurity training and industry-recognized certification prep, today announced a significant expansion of its learning portfolio, …

Scaling SOC Team Expertise With AI-powered Insights for Faster, Easier Understanding of Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Building analyst expertise is a race against time that many Security Operations Centers (SOCs) are losing. New hires often require over six months to handle complex incidents with confidence, creating a bottleneck where senior analysts must compensate for the skills …

Malicious Prettier Extension on VSCode Marketplace Delivers Anivia Stealer Malware to Exfiltrate Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has targeted thousands of developers through a fake extension on the Visual Studio Code Marketplace. On November 21, 2025, security researchers discovered a malicious extension named “prettier-vscode-plus” designed to trick developers into installing it by mimicking …

FBI Warns of Fake Internet Crime Complaint Center (IC3) Website Used for Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Bureau of Investigation (FBI) has issued urgent warnings about cybercriminals spoofing the official Internet Crime Complaint Center (IC3) website to conduct phishing attacks and steal sensitive personal information. These fake sites mimic the legitimate www.ic3.gov portal with near-perfect …

Akira Ransomware Uses SonicWall VPN Exploit to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Akira ransomware group has begun weaponizing vulnerabilities in SonicWall SSL VPN devices, turning merger-and-acquisition (M&A) processes into high-speed launchpads for cyberattacks. This trend exposes dangerous blind spots for businesses acquiring smaller companies, as inherited SonicWall devices often serve as …

New “JackFix” Attack Leverages Windows Updates into Executing Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated ClickFix campaign dubbed “JackFix” that uses fake adult websites to hijack screens with realistic Windows Update prompts, tricking users into running multistage malware payloads. Attackers mimic popular adult sites like xHamster clones to lure victims, likely via malvertising …

Hackers Exploit NTLM Authentication Flaws to Target Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

More than two decades after its initial discovery, the NTLM authentication protocol continues to plague Windows systems worldwide. What started in 2001 as a theoretical vulnerability has evolved into a widespread security crisis, with attackers actively weaponizing multiple NTLM flaws …

Hackers Sell Lifetime Access to WormGPT and KawaiiGPT for Just $220

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are now selling lifetime access to malicious AI chatbots WormGPT and KawaiiGPT for as little as $220, marking a dangerous new chapter in AI-powered cybercrime. These tools remove all ethical restrictions found in mainstream AI models, enabling attackers to …

Indirect-Shellcode-Executor Tool Exploits Windows API Vulnerability to Evade AV and EDR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new offensive security tool developed in Rust is demonstrating a novel method for bypassing modern Endpoint Detection and Response (EDR) systems by exploiting an overlooked behavior in the Windows API. Dubbed Indirect-Shellcode-Executor, the tool leverages the ReadProcessMemory function to …