Hackers Abuse Microsoft 365 Exchange Direct Send to Bypass Content Filters and Harvest Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft 365 Exchange Online’s Direct Send feature, originally designed to enable legacy devices and applications to send emails without authentication, has become an exploitable pathway for cybercriminals conducting sophisticated phishing and business email compromise attacks. The feature allows multifunction printers, …

Bitter APT Hackers Exploit WinRAR Zero-Day Via Weaponized Word Documents to Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Bitter APT group, also tracked as APT-Q-37 and known in China as 蔓灵花, has launched a sophisticated cyberespionage campaign targeting government agencies, military installations, and critical infrastructure across China and Pakistan. The threat actor has deployed weaponized Microsoft Office …

AI Sidebar Spoofing Attack: SquareX Uncovers Malicious Extensions that Impersonate AI Browser Sidebars

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SquareX released critical research exposing a new class of attack targeting AI browsers. The AI Sidebar Spoofing attack leverages malicious browser extensions to impersonate trusted AI sidebar interfaces, which is used to trick users into executing dangerous commands that can …

Hackers Can Access Microsoft Teams Chat and Emails by Retrieving Access Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new technique allows hackers to extract encrypted authentication tokens from Microsoft Teams on Windows, enabling unauthorized access to chats, emails, and SharePoint files. In a blog post dated October 23, 2025, Brahim El Fikhi explains how these tokens, stored …

Vidar Stealer Bypassing Browser Security Via Direct Memory Injection to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated information-stealing malware known as Vidar Stealer has undergone a complete architectural transformation with the release of version 2.0, introducing advanced capabilities that enable it to bypass Chrome’s latest security protections through direct memory injection techniques. Released on October …

Threat Actors With Stealer Malwares Processing Millions of Credentials a Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The stealer malware ecosystem has evolved into a sophisticated criminal enterprise capable of processing hundreds of millions of credentials daily. Over the past several years, threat actors have transformed the landscape of credential theft through specialized malware families and underground …

New Rust-Based ChaosBot Malware Leverages Discord for Stealthy Command and Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new threat has emerged in the cybersecurity landscape, leveraging the popular communication platform Discord to conduct covert operations. ChaosBot, a Rust-based malware strain, represents an evolution in adversarial tactics by hiding malicious command and control traffic within legitimate …

Salt Typhoon Using Zero-Day Exploits and DLL Sideloading Techniques to Attack Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Salt Typhoon, a China-linked advanced persistent threat (APT) group active since 2019, has emerged as one of the most sophisticated cyber espionage operations targeting global critical infrastructure. Also tracked as Earth Estries, GhostEmperor, and UNC2286, the group has conducted high-impact …

Microsoft Enhances Windows Security by Turning Off File Previews for Downloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a move to tighten defenses against credential theft, Microsoft has rolled out a significant change to Windows File Explorer starting with security updates released on and after October 14, 2025. The update automatically disables the preview pane for files …

Hackers Exploited Samsung Galaxy S25 0-Day Vulnerability to Enable Camera and Track Location

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

At Pwn2Own Ireland 2025, cybersecurity researchers Ben R. and Georgi G. from Interrupt Labs showcased an impressive achievement by successfully exploiting a zero-day vulnerability in the Samsung Galaxy S25. This allowed them to gain full control over the device, enabling …