Threat Actors May Abuse VS Code Extensions to Deploy Ransomware and Use GitHub as C2 Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean threat actors are evolving their attack strategies by leveraging developer-focused tools as infection vectors. Recent security discoveries reveal that Kimsuky, a nation-state group operating since 2012, has been utilizing JavaScript-based malware to infiltrate systems and establish persistent command …

List of AI Tools Promoted by Threat Actors in Underground Forums and Their Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybercrime landscape has undergone a dramatic transformation in 2025, with artificial intelligence emerging as a cornerstone technology for malicious actors operating in underground forums. According to Google’s Threat Intelligence Group (GTIG), the underground marketplace for illicit AI tools has …

Airstalk Malware Leverages AirWatch API MDM Platform to Establish Covert C2 Communication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a sophisticated new malware family targeting enterprise environments through a supply chain compromise. The malware, tracked as Airstalk, represents a significant shift in how attackers exploit legitimate enterprise management tools to evade detection and maintain persistent …

Gootloader is Back with New ZIP File Trickery that Decive the Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Gootloader malware campaign has resurfaced with sophisticated evasion techniques that allow it to bypass automated security analysis. This persistent threat has been targeting victims for over five years using legal-themed search engine optimization poisoning tactics. The malware operators deploy …

SonicWall Confirms State-Sponsored Hackers Behind the Massive Firewall Backup Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall, a global cybersecurity company, confirmed that state-sponsored hackers were behind a recent incident involving unauthorized access to firewall backup files. The breach began in early September, when the company detected suspicious activity involving the download of backup firewall configuration …

Critical RCE Vulnerabilities in Claude Desktop Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution (RCE) flaw in three official extensions for Anthropic’s Claude Desktop. These vulnerabilities, affecting the Chrome, iMessage, and Apple Notes connectors, stem from unsanitized command injection and carry a high severity score of CVSS 8.9. Published …

Hyundai AutoEver Confirms Data Breach Exposing Users’ Personal Information and SSNs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hyundai AutoEver America has disclosed a significant data breach that compromised sensitive personal information of customers, including Social Security numbers and driver’s license details. The cybersecurity incident highlights growing concerns about data protection in the automotive technology sector.​ Hyundai AutoEver …

Cybersecurity Forecast 2026 – Google Warns Threat Actors Use AI to Enhance Speed and Effectiveness

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape stands at a critical inflection point as organizations prepare for unprecedented challenges in 2026. Google Cloud researchers have released their annual Cybersecurity Forecast, revealing a stark reality: threat actors are transitioning from experimenting with advanced technologies to …

NGate Malware Enables Unauthorized Cash Withdrawals at ATMs Using Victims’ Payment Cards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android-based NFC relay attack dubbed NGate has emerged as a serious threat to banking security across Poland, targeting financial institutions and their customers through coordinated social engineering and technical exploitation. Cert.PL analysts identified new malware samples in recent …

CISA Warns of Gladinet CentreStack and Triofox Files Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency has issued a critical warning regarding a newly identified vulnerability affecting Gladinet CentreStack and Triofox platforms. The flaw, tracked as CVE-2025-11371, exposes sensitive system files and directories to unauthorized external access, potentially compromising organizations …