Hackers Using PUP Advertisements to Silently Drop Windows Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, cybersecurity investigators have uncovered a novel campaign in which hackers leverage seemingly benign potentially unwanted program (PUP) advertisements to deliver stealthy Windows malware. The lure typically begins with ads promoting free PDF tools or desktop assistants that …

Chinese APT Hackers Using Proxy and VPN Service to Anonymize Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, cybersecurity researchers have observed a surge in targeted campaigns by a sophisticated Chinese APT group leveraging commercial proxy and VPN services to mask their attack infrastructure. The emergence of this tactic coincides with a broader shift toward …

New Android Spyware Disguised as an Antivirus Attacking Business Executives

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security teams have observed the emergence of a highly versatile Android backdoor, Android.Backdoor.916.origin, masquerading as a legitimate antivirus application. Distributed via private messaging services under the guise of “GuardCB,” its icon closely mimics the emblem of the …

Kimsuky APT Data Leak – GPKI Certificates, Rootkits and Cobalt Strike Personal Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In late June 2025, a significant operational dump from North Korea’s Kimsuky APT group surfaced on a dark-web forum, exposing virtual machine images, VPS infrastructure, customized malware and thousands of stolen credentials. This leak offers an unprecedented window into the …

Beware of Website Mimicking Google Play Store Pages to Deliver Android Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android malware campaign has resurfaced, exploiting deceptive websites that perfectly mimic legitimate Google Play Store application pages to distribute the notorious SpyNote Remote Access Trojan (RAT). This malicious operation targets unsuspecting users by creating static HTML clones of …

5 Common Back-to-School Online Scams Powered Using AI and How to Avoid Them

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As students return to campus and online learning platforms, cybercriminals are increasingly leveraging artificial intelligence to create sophisticated scams targeting the education sector. These AI-enhanced attacks have become more convincing and harder to detect, making them particularly dangerous for students, …

Threat Actors Weaponizes AI Generated Summaries With Malicious Payload to Execute Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel adaptation of the ClickFix social engineering technique has been identified, leveraging invisible prompt injection to weaponize AI summarization systems in email clients, browser extensions, and productivity platforms.  By embedding malicious step-by-step instructions within hidden HTML elements—using CSS obfuscation …

0-Click Zendesk Account Takeover Vulnerability Enables Access to all Zendesk Tickets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Zendesk’s Android SDK implementation that allows attackers to perform mass account takeovers without any user interaction.  The flaw, which earned a $3,000 bug bounty payout, stems from predictable token generation mechanisms that …

New Stealthy Malware Exploiting Cisco, TP-Link and Other Routers to Gain Remote Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly observed malware campaign has emerged targeting a broad range of network appliances, including routers from DrayTek, TP-Link, Raisecom, and Cisco. Throughout July 2025, threat researchers observed a stealthy loader spread by exploiting unauthenticated command injection flaws in embedded …

Multiple vtenext Vulnerabilities Let Attackers Bypass Authentication and Execute Remote Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A comprehensive security analysis of vtenext CRM version 25.02 has revealed multiple critical vulnerabilities that allow unauthenticated attackers to bypass authentication mechanisms through three distinct attack vectors, ultimately leading to remote code execution on target systems.  The Italian CRM solution, …