New Phishing Attack Via OneDrive Attacking C-level Employees for Corporate Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated spear-phishing campaign has emerged targeting senior executives and C-suite personnel across multiple industries, leveraging Microsoft OneDrive as the primary attack vector. The campaign utilizes carefully crafted emails masquerading as internal HR communications about salary amendments to trick high-profile …

New Report on Commercial Spyware Vendors Detailing Their Targets and Infection Chains

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Commercial surveillance vendors have evolved from niche technology suppliers into a sophisticated multi-billion-dollar ecosystem that poses unprecedented threats to journalists, activists, and civil society members worldwide. A comprehensive new report by Sekoia.io’s Threat Detection & Research team reveals how these …

Iran-Nexus Hackers Abuses Omani Mailbox to Target Global Governments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated spear-phishing campaign orchestrated by Iranian-aligned operators has been identified targeting diplomatic missions worldwide through a compromised Ministry of Foreign Affairs of Oman mailbox. The attack, discovered in August 2025, represents a continuation of tactics associated with the Homeland …

How IOC Feeds Streamline Incident Response and Threat Hunting for Best SOC Teams 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

When you’re in a SOC, speed is everything. The earlier you detect and confirm an intrusion, the faster you can contain it, and the less damage it does to your organization. But raw indicators of compromise (IOCs) like hashes, IPs, …

Ukrainian Networks Launch Massive Brute-Force and Password-Spraying Campaigns Targeting SSL VPN and RDP Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated network of Ukrainian-based autonomous systems has emerged as a significant cybersecurity threat, orchestrating large-scale brute-force and password-spraying attacks against SSL VPN and RDP infrastructure. Between June and July 2025, these malicious networks launched hundreds of thousands of coordinated …

Jaguar Land Rover Confirms Cybersecurity Incident Impacts Global IT Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Luxury automaker Jaguar Land Rover (JLR) has been forced to halt production at its Halewood plant and shut down its global IT infrastructure following a significant cybersecurity incident. The breach, which was first reported on Monday, September 1, has led …

New WhatsApp Scam Alert Tricks Users to Get Complete Access to Your WhatsApp Chats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered WhatsApp scam has begun circulating on messaging platforms, exploiting the popular device linking feature to seize full control of user accounts. The attack unfolds when recipients receive what appears to be a harmless message from a known …

New ClickFix Attack Mimic as AnyDesk Leverages Windows Search to Drop MetaStealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel variant of the ClickFix attack has recently emerged, masquerading as a legitimate AnyDesk installer to spread the MetaStealer infostealer. This campaign exploits a fake Cloudflare Turnstile verification page to lure victims into executing a crafted Windows protocol handler, …

Palo Alto Networks Confirms Data Breach: Hackers Stole Customer Data from Salesforce Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks has confirmed it is one of hundreds of organizations impacted by a significant supply chain attack that resulted in the theft of customer data from its Salesforce instances. The breach originated from a compromised third-party application, Salesloft’s …

Microsoft to Kill Popular Editor Browser Extensions on Edge and Chrome

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On August 29, 2025, Microsoft announced the retirement of its popular Microsoft Editor browser extensions for Microsoft Edge and Google Chrome.  The Editor extensions will be officially deprecated on October 31, 2025, as part of Microsoft’s strategy to integrate AI-powered …