Hackers Can Attack Active Directory Sites to Escalate Privileges and Compromise the Domain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Active Directory sites are designed to optimize network performance across geographically separated organizations by managing replication and authentication across multiple locations. The Synacktiv security researchers have demonstrated that these supposedly safe network management tools can be weaponized to launch powerful …

New Analysis Uncovers LockBit 5.0 Key Capabilities and Two-Stage Execution Model

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LockBit 5.0 made its debut in late September 2025, marking a significant upgrade for one of the most notorious ransomware-as-a-service (RaaS) groups. With roots tracing back to the ABCD ransomware in 2019, LockBit rapidly grew in sophistication, consistently updating its …

New Android Malware ‘Fantasy Hub’ Intercepts SMS Messages, Contacts and Call Logs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian-based threat actors are distributing a sophisticated Android Remote Access Trojan through underground channels, offering it as a subscription service to other criminals. The malware, identified as Fantasy Hub, enables attackers to conduct widespread surveillance operations on compromised mobile devices, …

Microsoft Teams’ New “Chat with Anyone” Feature Exposes Users to Phishing and Malware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s upcoming Teams update, set for targeted releases in early November 2025 and worldwide by January 2026, will allow users to initiate chats with only an email address, even if the recipient isn’t a Teams user. This feature raises security …

15+ Weaponized npm Packages Attacking Windows Systems to Deliver Vidar Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply-chain attack has emerged targeting Windows systems through compromised npm packages, marking a critical vulnerability in open-source software distribution. Between October 21 and 26, 2025, threat actors published 17 malicious npm packages containing 23 releases designed to deliver …

New Phising Attack Targeting Travellers from Hotel’s Compromised Booking.com Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign is actively targeting hotel establishments and their guests through compromised Booking.com accounts, according to research uncovered by security experts. The campaign, dubbed “I Paid Twice” due to evidence of victims paying twice for their reservations, has …

Chinese Hackers Organization Influence U.S. Government Policy on International Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China-linked threat actors have intensified their focus on influencing American governmental decision-making processes by targeting organizations involved in shaping international policy. In April 2025, a sophisticated intrusion into a U.S. non-profit organization revealed the persistent efforts of these attackers to …

Researchers Evaded Elastic EDR’s Call Stack Signatures by Exploiting Call Gadgets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have successfully evaded Elastic EDR’s call stack signature detection by exploiting a technique involving “call gadgets” to bypass the security tool’s behavioral analysis. The Almond research builds on Elastic’s transparent approach to security, as the company publicly shares …

LeakyInjector and LeakyStealer Malwares Attacks Users to Steal Crypto’s and Browser History

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous two-stage malware threat, LeakyInjector and LeakyStealer, that targets cryptocurrency wallets and personal browser information explicitly. The malware duo works in tandem to steal sensitive data from infected Windows computers. The attack begins when LeakyInjector, the first stage, quietly …

Cavalry Werewolf Attacking Government Organizations to Deploy Backdoor for Network Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In July 2025, a sophisticated hacker group known as Cavalry Werewolf executed a targeted campaign against Russian government institutions, compromising critical infrastructure through coordinated phishing operations. The discovery of this campaign reveals a complex attack chain designed to establish persistent …