Microsoft 365 Direct Send Weaponized to Bypass Email Security Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated spear phishing campaign that weaponizes Microsoft 365’s Direct Send feature to bypass traditional email security defenses and conduct hyper-personalized credential theft attacks. The campaign demonstrates an alarming evolution in attack sophistication, combining technical exploitation …

New Ghost Calls Attack Abuses Web Conferencing for Covert Command & Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new attack technique called “Ghost Calls” exploits web conferencing platforms to establish covert command and control (C2) channels.  Presented by Adam Crosser from Praetorian at Black Hat USA 2025, this groundbreaking research demonstrates how attackers can leverage the …

CISA Warns of ‘ToolShell’ Exploits Chain Attacks SharePoint Servers – Discloses IOCs and detection signatures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released an urgent analysis in early July 2025, detailing a sophisticated exploit chain targeting on-premises Microsoft SharePoint servers. Dubbed “ToolShell,” the campaign leverages two fresh vulnerabilities—CVE-2025-49706, a network spoofing flaw, and CVE-2025-49704, …

WhatsApp Has Taken Down 6.8 Million Accounts Linked to Malicious Activities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp has successfully dismantled 6.8 million accounts linked to fraudulent activities during the first half of 2024, representing a significant escalation in the platform’s fight against organized cybercrime.  The takedown operation, announced by parent company Meta, specifically targeted scam centers …

New Active Directory Lateral Movement Techniques that Bypasses Authentication and Exfiltrate Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sophisticated attack vectors unveiled that exploit hybrid Active Directory and Microsoft Entra ID environments, demonstrating how attackers can achieve complete tenant compromise through previously unknown lateral movement techniques. These methods, presented at Black Hat USA 2025, expose critical vulnerabilities in …

10 Best Data Loss Prevention Software in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Data Loss Prevention (DLP) software is a critical cybersecurity solution designed to protect sensitive data from leaving an organization’s network. In an era where data is a company’s most valuable asset, and regulatory penalties for data breaches are severe, DLP …

HeartCrypt-Packed EDR Killer Tools ‘AVKiller’ Actively Used in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity teams have confronted a rising threat from a novel “EDR killer” payload in recent months, commonly referred to as AVKiller, which has been observed disabling endpoint defenses to facilitate the deployment of ransomware. First detected in mid-2024, this tool …

Nvidia Says No Backdoors, No Kill Switches, and No Spyware in its Chips

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Nvidia Corporation has issued a strong statement asserting that its graphics processing units (GPUs) contain no backdoors, kill switches, or spyware, directly addressing growing concerns from policymakers about potential hardware-based control mechanisms.  The semiconductor giant’s declaration comes as some industry …

SocGholish Leverages Parrot and Keitaro TDS Systems to Push Fake Updates and Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware operation known as SocGholish has emerged as one of the internet’s most persistent and deceptive threats, masquerading as legitimate software updates to compromise unsuspecting users’ systems. The malware, operated by the cybercriminal group TA569, has evolved from …

HashiCorp Vault 0-Day Vulnerabilities Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers uncovered a series of critical zero-day vulnerabilities in HashiCorp Vault in early August 2025, the widely adopted secrets management solution. These flaws, spanning authentication bypasses, policy enforcement inconsistencies, and audit-log abuse, create end-to-end attack paths that culminate in …