SideWinder Hacker Group Hosting Fake Outlook/Zimbra Portals to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT SideWinder, a state-sponsored threat actor long associated with espionage across South Asia, has recently launched a campaign deploying phishing portals that mimic legitimate Outlook and Zimbra webmail services. Emerging in mid-2025, this operation uses free hosting platforms such as …

Threat Actors Leveraging WhatsApp Messages to Attack Windows Systems With SORVEPOTEL Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Enterprise networks worldwide are facing an aggressive, self-propagating malware campaign that exploits WhatsApp as its primary delivery mechanism. First observed in early September 2025 targeting Brazilian organizations, SORVEPOTEL spreads through convincing phishing messages carrying malicious ZIP attachments. Upon execution, the …

New ‘Point-and-Click’ Phishing Kit Bypasses User Awareness and Security Filters to Deliver Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel phishing kit has surfaced that enables threat actors to craft sophisticated lures with minimal technical expertise. This “point-and-click” toolkit combines an intuitive web interface with powerful payload delivery mechanisms. Attackers can select from preconfigured templates, customize branding elements, …

Rhadamanthys Stealer Available on Dark Web Prices Ranging from $299 to $499

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Rhadamanthys, a sophisticated multi-modular information stealer, first emerged in September 2022 and has since evolved into one of the most commercially advanced malware offerings on underground forums. Originally advertised by the actor “kingcrete2022,” its initial design drew heavily on the …

Hundreds of Free VPN Apps for Both Android and iOS Leaks Users Personal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mobile VPN apps promise to protect privacy and secure communications on smartphones, but a comprehensive analysis of nearly 800 free Android and iOS VPN applications reveals a troubling reality: many of these tools expose sensitive information rather than shield it. …

HackerOne Paid $81 In Bug Bounty With Emergence of Bionic Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HackerOne, a leading platform in offensive security, announced it has paid out a total of $81 million in bug bounties to its global community of white-hat hackers over the past year. This figure, detailed in the company’s 9th annual Hacker-Powered …

Confucius Hacker Group Attacking Weaponizing Documents to Compromised Windows Systems With AnonDoor Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Confucius hacker group, active since 2013, has recently escalated its operations by weaponizing malicious Office documents to compromise Windows endpoints with a new Python-based backdoor, dubbed AnonDoor. Historically known for deploying document stealers such as WooperStealer, the threat actor …

Signal Enhances Security With New Hybrid PQ Ratchet to Compact Quantum Computing Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Signal has announced a groundbreaking advancement in secure messaging with the introduction of the Sparse Post Quantum Ratchet (SPQR), a revolutionary cryptographic enhancement designed to protect against future quantum computing threats.  This latest security upgrade represents a significant milestone in …

Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle Corporation has officially acknowledged that cybercriminals are targeting customers of its E-Business Suite (EBS) platform through sophisticated extortion campaigns.  The company’s Chief Security Officer, Rob Duhart, confirmed that hackers have been exploiting previously identified vulnerabilities that were addressed in …

Red Hat Confirms Data Breach After Hackers Claim to Steal 570GB of Private GitHub Repositories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Red Hat, the world’s leading enterprise open-source software provider, has officially confirmed a significant security incident involving unauthorized access to its internal GitLab instance used by the Red Hat Consulting team.  This confirmation comes after the threat actor group known …