Pig-Butchering Scams Operators Scaled Their Operations with The Support of AI-Assistants

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pig-butchering scams have grown into one of the most damaging global cybercrime threats, causing billions of dollars in losses every year. These long-term investment fraud schemes work by building trust through emotional grooming and fake trading platforms before draining victims …

Frentree Partners with AccuKnox to Expand Zero Trust CNAPP Security in South Korea

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Menlo Park, California, USA, November 17th, 2025, CyberNewsWire AccuKnox, a global leader in Zero Trust Cloud-Native Application Protection Platforms (CNAPP), today announced its distributor partnership with Frentree, a leading cybersecurity solutions provider in South Korea. The collaboration aims to strengthen …

TaskHound Tool – Detects Windows Scheduled Tasks Running with Elevated Privileges and Stored Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new open-source security tool, TaskHound, helps penetration testers and security professionals identify high-risk Windows scheduled tasks that could expose systems to attacks. The tool automatically discovers tasks running with privileged accounts and stored credentials, making it a valuable addition to …

Hackers Leverages Microsoft Entra Tenant Invitations to Launch TOAD Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign has emerged that weaponizes Microsoft Entra guest user invitations to deceive recipients into making phone calls to attackers posing as Microsoft support. The attack leverages a critical security gap in how Microsoft Entra communicates with external …

CISA Warns of Fortinet FortiWeb WAF Vulnerability Exploited in the Wild to Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent alert about a critical vulnerability in Fortinet’s FortiWeb Web Application Firewall (WAF), actively exploited by threat actors to seize administrative control of affected systems. Tracked as CVE-2025-64446, the flaw stems from a relative path traversal …

EVALUSION Campaign Using ClickFix Technique to deploy Amatera Stealer and NetSupport RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In November 2025, a new malware campaign emerged that combines social engineering tricks with advanced stealing tools. The attack starts when criminals trick users into running commands through the Windows Run window, a technique known as ClickFix. Once users follow …

North Korean Hackers Infiltrated 136 U.S. Companies to Generate $2.2 Million in Revenue

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Justice Department announced major actions against North Korean cybercrime, including five people admitting guilt and the government taking more than $15 million in property linked to the crimes. These operations reveal how the Democratic People’s Republic of Korea …

Hackers Exploiting XWiki Vulnerability in the Wild to Hire the Servers for Botnet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sharp increase in attacks targeting a critical vulnerability in XWiki servers. Multiple threat actors are actively exploiting CVE-2025-24893 to deploy botnets and coin miners, and to establish unauthorized server access across the internet. Since the initial discovery on October 28, 2025, …

Unremovable Spyware on Samsung Devices Comes Pre-installed on Galaxy Series Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Samsung has been accused of shipping budget Galaxy A and M series smartphones with pre-installed spyware that users can’t easily remove. The software in question, AppCloud, developed by the mobile analytics firm IronSource, has been embedded in devices sold primarily …

Hackers Allegedly Claim Leak of LG Source Code, SMTP, and Hardcoded Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as “888” has purportedly dumped sensitive data stolen from electronics giant LG Electronics, raising alarms in the cybersecurity community. The breach, first spotlighted on November 16, 2025, allegedly includes source code repositories, configuration files, SQL databases, …