RainyDay, Turian and Naikon Malwares Abuse DLL Search Order to Execute Malicious Loaders

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three sophisticated malware families have emerged as significant threats to telecommunications and manufacturing sectors across Central and South Asia, representing a coordinated campaign that exploits legitimate system processes to deliver powerful backdoor capabilities. RainyDay, Turian, and a new variant of …

New North Korean IT Worker With Innocent Job Application Get Access to Organization’s Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, a sophisticated threat actor leveraging North Korean IT worker employment fraud has surfaced, demonstrating how social engineering can bypass traditional security controls. The adversary’s modus operandi involves posing as remote software engineers, submitting legitimate-looking résumés, completing coding …

Hackers Can Compromise Chromium Browsers in Windows by Loading Arbitrary Extensions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chromium-based browsers, including Chrome, Edge, and Brave, manage installed extensions via JSON preference files stored under %AppData%GoogleUser DataDefaultPreferences (for domain-joined machines) or Secure Preferences (for standalone systems).  Synacktiv research indicates that by directly altering these files, attackers can make the browser …

UK Police Arrested Man Linked to Ransomware Attack That Crippeled European Airports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A man in his forties has been arrested in West Sussex, England, in connection with a cyber-attack that has caused days of widespread disruption at several major European airports, including London’s Heathrow. The UK’s National Crime Agency (NCA) confirmed the …

Hackers Can Bypass EDR by Downloading a Malicious File as an In-Memory PE Loader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated technique that allows attackers to execute malicious code directly in memory is gaining traction, posing a significant challenge to modern Endpoint Detection and Response (EDR) solutions. This method, which involves an in-memory Portable Executable (PE) loader, enables a …

Weaponized Malwarebytes, LastPass, Citibank, SentinelOne, and Others on GitHub Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, cybersecurity teams have observed a surge in malicious GitHub repositories masquerading as legitimate security and financial software. Threat actors have crafted convincing forks of projects bearing names like Malwarebytes, LastPass, Citibank, and SentinelOne, populated with trojanized installers …

OnePlus OxygenOS Vulnerability Allows Any App to Read SMS Data Without Permission

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe security vulnerability in OnePlus OxygenOS has been discovered that allows any installed application to read SMS and MMS messages without requesting permission or notifying users.  The flaw, designated CVE-2025-10184, affects multiple OnePlus devices running OxygenOS versions 12 through …

Salesforce CLI Installer Vulnerability Let Attackers Execute Code and Gain SYSTEM-Level Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Salesforce CLI installer (sf-x64.exe) enables attackers to achieve arbitrary code execution, privilege escalation, and SYSTEM-level access on Windows systems.  Tracked as CVE-2025-9844, the flaw stems from improper handling of executable file paths by the installer, …

Hackers Exploiting Libraesva Email Security Gateway Vulnerability to Inject Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Libraesva has issued an emergency patch for a significant command injection vulnerability in its Email Security Gateway (ESG) after confirming state-sponsored hackers exploited it. The flaw, identified as CVE-2025-59689, allowed attackers to execute arbitrary commands by sending a malicious email …

ShadowV2 Botnet Exploits Docker Containers on AWS to Turn Thems as Infected System for DDoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercrime campaign has emerged that transforms legitimate AWS infrastructure into weaponized attack platforms through an innovative combination of containerization and distributed denial-of-service capabilities. The ShadowV2 botnet represents a significant evolution in cyber threats, leveraging exposed Docker daemons on …