HackGPT: AI-Powered Penetration Testing Platform Includes GPT-4 and Other AI Engines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HackGPT Enterprise is a new tool made for security teams focuses on being scalable and compliant, meeting the growing need for effective vulnerability assessments. The platform supports multi-model AI, including OpenAI’s GPT-4 and local LLMs like Ollama, enabling pattern recognition, …

Cybersecurity News Weekly Newsletter – Android and Cisco 0-Day, Teams Flaws, HackedGPT, and Whisper Leak

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Welcome to this week’s edition of the Cybersecurity News Weekly Newsletter, where we dissect the latest threats shaking the digital landscape. As cyber risks evolve faster than ever, staying ahead means understanding the exploits that could target your devices, networks, …

New Whisper Leak Toolkit Exposes User Prompts to Popular AI Agents within Encrypted Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated side-channel attack that exposes the topics of conversations with AI chatbots, even when traffic is protected by end-to-end encryption. Dubbed “Whisper Leak,” this vulnerability allows eavesdroppers such as nation-state actors, ISPs, or Wi-Fi snoopers to infer sensitive prompt …

Seven QNAP Zero-Day Vulnerabilities Exploited at Pwn2Own 2025 Now Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP has addressed seven critical zero-day vulnerabilities in its network-attached storage (NAS) operating systems, following their successful exploitation by security researchers at Pwn2Own Ireland 2025. These flaws, identified as CVE-2025-62847, CVE-2025-62848, CVE-2025-62849, and associated ZDI canonical entries ZDI-CAN-28353, ZDI-CAN-28435, ZDI-CAN-28436, …

Google Maps Adds Feature for Businesses to Report Ransom Demands for Removing Bad Reviews

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Scammers are targeting businesses with a new extortion scheme, and Google Maps is fighting back with a dedicated reporting tool. Google has introduced a feature that allows business owners to report ransom demands directly to malicious actors who threaten them …

Hackers Hijack Samsung Galaxy Phones via 0-Day Exploit Using a Single WhatsApp Image

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated spyware operation targeting Samsung Galaxy devices, dubbed LANDFALL, which exploited a zero-day vulnerability to infiltrate phones through seemingly innocuous images shared on WhatsApp. This campaign, active since mid-2024, allowed attackers to deploy commercial-grade Android malware capable of full …

Threat Actors Leveraging RDP Credentials to Deploy Cephalus Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified ransomware group, Cephalus, has emerged as a significant threat to organizations worldwide, exploiting stolen Remote Desktop Protocol (RDP) credentials to gain access to networks and deploy powerful encryption attacks. The AhnLab researchers observed in mid-June 2025 that …

German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

German hosting provider aurologic GmbH has emerged as a central facilitator within the global malicious infrastructure ecosystem, providing upstream transit and data center services to numerous high-risk hosting networks. Operating from its primary facility at Tornado Datacenter GmbH & Co. …

ClickFix Attacks Evolved With Weaponized Videos That Tricks Users via Self-infection Process

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ClickFix attacks have experienced a dramatic surge over the past year, establishing themselves as a cornerstone of modern social engineering tactics. These sophisticated attacks manipulate victims into executing malicious code directly on their devices through deceptive copy-and-paste mechanisms. The threat …

Herodotus Android Banking Malware Takes Full Control Of Device Evading Antivirus

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated banking trojan named Herodotus has emerged as a significant threat to Android users worldwide. Operating as Malware-as-a-Service, this malicious application disguises itself as a legitimate tool to trick users into downloading and installing an APK file outside the …