Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware landscape experienced a significant shift in the second quarter of 2025 as Qilin ransomware emerged as the dominant threat following the unexpected collapse of RansomHub, previously the most prolific ransomware-as-a-service operation. This transition has reshaped the cybercriminal ecosystem, …

LockBit Operators Using Stealthy DLL Sideloading Technique to Load Malicious App as Legitimate One

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LockBit ransomware operators have adopted an increasingly sophisticated approach to evade detection by leveraging DLL sideloading techniques that exploit the inherent trust placed in legitimate applications. This stealthy method involves tricking legitimate, digitally signed applications into loading malicious Dynamic Link …

11,000 Android Devices Hacked by Chinese Threats Actors to Deploy PlayPraetor Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware-as-a-service operation orchestrated by Chinese-speaking threat actors has successfully compromised over 11,000 Android devices worldwide through the deployment of PlayPraetor, a powerful Remote Access Trojan designed for on-device fraud. The campaign represents a significant escalation in mobile banking …

Hackers Abuse Microsoft 365’s Direct Send Feature to Deliver Internal Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have discovered a sophisticated new attack vector by exploiting Microsoft 365’s Direct Send feature to deliver phishing campaigns that masquerade as legitimate internal communications. This emerging threat leverages a legitimate Microsoft service designed for multifunction printers and legacy applications, …

Storm-2603 Using Custom Malware That Leverages BYOVD to Tamper with Endpoint Protections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified threat actor designated Storm-2603 has emerged as a sophisticated adversary in the ransomware landscape, leveraging advanced custom malware to circumvent endpoint security protections through innovative techniques. The group first gained attention during Microsoft’s investigation into the “ToolShell” …

Secret Blizzard Group’s ApolloShadow Malware Install Root Certificates on Devices to Trust Malicious Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberespionage campaign targeting foreign embassies in Moscow has been uncovered, revealing the deployment of a custom malware strain designed to manipulate digital trust mechanisms. The Russian state-sponsored threat group Secret Blizzard has been orchestrating an adversary-in-the-middle operation since …

Threat Actors Leverage Compromised Email Accounts for Targeted Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly sophisticated in their phishing attacks, with threat actors now leveraging compromised email accounts from trusted sources to bypass security controls and enhance campaign legitimacy. Recent incident response data reveals phishing remains a dominant attack vector, accounting for …

Microsoft Teams New Option Let IT admins Run 60-second Silent Test Call

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced a new proactive network monitoring capability for Teams administrators, introducing 60-second silent test calls designed to assess network quality without disrupting user experiences.  The feature represents a significant advancement in enterprise communication infrastructure management. Key Takeaways 1.  …

Microsoft to Disable External Workbook Links to Blocked File Types By Default

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft announced a significant security enhancement for Microsoft 365 apps that will fundamentally change how external workbook links function.  Starting in October 2025, the company will disable external workbook links to blocked file types by default, implementing a new group …

Threat Actors Impersonating Microsoft OAuth Applications to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign exploiting Microsoft OAuth applications has emerged as a significant threat to enterprise security, with cybercriminals successfully bypassing multifactor authentication systems to steal user credentials. The campaign, which began in early 2025 and remains ongoing, leverages fake …