Lumma Affiliates Using Advanced Evasion Tools Designed to Ensure Stealth and Continuity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Lumma information stealer has evolved from its 2022 origins into one of the most sophisticated malware-as-a-service (MaaS) ecosystems in the cybercriminal landscape. Operating through a vast network of affiliates, Lumma has established itself as the dominant infostealer platform, accounting …

BQTLOCK Ransomware Operates as RaaS With Advanced Evasion Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new ransomware strain named BQTLOCK has emerged in the cyberthreat landscape since mid-July 2025, operating under a comprehensive Ransomware-as-a-Service (RaaS) model that democratizes access to advanced encryption capabilities for cybercriminals. The malware, associated with ‘ZerodayX’, the alleged leader …

Malicious Go Module Package as Fast SSH Brute Forcer Exfiltrates Passwords via Telegram

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has emerged targeting developers through a malicious Go module package that masquerades as a legitimate SSH brute forcing tool while covertly stealing credentials for cybercriminal operations. The package, named “golang-random-ip-ssh-bruteforce,” presents itself as a fast …

South Asian APT Hackers Using Novel Tools to Compromise Phones of Military-Adjacent Members

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated South Asian Advanced Persistent Threat (APT) group has been conducting an extensive espionage campaign targeting military personnel and defense organizations across Sri Lanka, Bangladesh, Pakistan, and Turkey. The threat actors have deployed a multi-stage attack framework combining targeted …

Windows Docker Desktop Vulnerability Leads to Full Host Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in Docker Desktop for Windows has revealed how a simple Server-Side Request Forgery (SSRF) attack could lead to complete host system compromise.  CVE-2025-9074, discovered by Felix Boulet and reported on August 21, 2025, affects all Docker …

UAC-0057 Hackers Weaponizing PDF Invitation Files to Execute Shell Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber espionage campaign has emerged targeting Ukrainian and Polish organizations through weaponized PDF invitation files designed to execute malicious shell scripts. The campaign, active since April 2025, demonstrates a calculated approach to infiltrating government and private sector networks …

NIST Releases Control Overlays to Manage Cybersecurity Risks in Use and Developments of AI Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The National Institute of Standards and Technology (NIST) has unveiled a comprehensive concept paper outlining proposed NIST SP 800-53 Control Overlays for Securing AI Systems, marking a significant milestone in establishing standardized cybersecurity frameworks for artificial intelligence applications.  Released on …

Colt Confirms Customer Data Stolen in Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Telecommunications giant Colt Technology Services has confirmed that customer data was compromised in a sophisticated cyber attack that began on August 12, 2025.  The company disclosed that threat actors accessed sensitive files containing customer information and subsequently posted document titles …

Azure’s Default API Connection Vulnerability Enables Full Cross-Tenant Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Microsoft Azure’s API Connection infrastructure enabled attackers to compromise resources across different Azure tenants worldwide.  The flaw, which earned Gulbrandsrud a $40,000 bounty and a Black Hat presentation slot, exploited Azure’s shared API Management (APIM) instance …

Microsoft Warns of Hackers Using ClickFix Technique to Attack Windows and macOS Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified a sophisticated social engineering technique called ClickFix that has been rapidly gaining traction among threat actors since early 2024. This deceptive attack method targets both Windows and macOS devices, tricking users into executing malicious commands through …