Beware of Fake Traffic Ticket Portals that Harvest Your PII and Credit Card Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targeting Canadian citizens has emerged, using fake traffic ticket payment portals to steal personal and financial information. The attackers employ SEO poisoning techniques to manipulate search …

Hackers Exploit SonicWall SSLVPN Credentials to Deploy EDR Killer and Bypass Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

EDR Killer Via SonicWall SSLVPN Threat actors are actively leveraging compromised SonicWall SSLVPN credentials to breach networks and deploy a sophisticated “EDR killer” that can blind endpoint security solutions. In …

DragonForce Ransomware Attacking Critical Business to Exfiltrate Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ransomware operation known as DragonForce has emerged as a major threat to organizations worldwide since its appearance in late 2023. This sophisticated malware campaign targets critical business infrastructure …

Beware of Weaponized Voicemail Messages that Allows Hackers to Remote Access to Your System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly shifting tactics toward social engineering to bypass traditional security defenses, catching many users off guard. A sophisticated new campaign dubbed “Voicemail Trap” explicitly targets users with fake …

APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian state-sponsored actors known as APT28 have initiated a sophisticated cyber espionage campaign targeting high-value government and military entities across Europe. The primary targets include maritime and transport organizations in …

New 3 Step Malvertising Chain Abusing Facebook Paid Ads to Push Tech Support #Scam Kit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cyber threat has emerged within the digital advertising ecosystem, specifically targeting users through the vast reach of Facebook’s paid advertising platform. Malicious actors are increasingly weaponizing social …

Attackers Using DNS TXT Records in ClickFix Script to Execute Powershell Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has darkened with the sophisticated evolution of the KongTuke campaign. Active since mid-2025, this threat actor group has continuously refined its techniques to bypass conventional enterprise security …

Amaranth-Dragon Exploiting WinRAR Vulnerability to Gain Persistent to Victim Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber-espionage group known as Amaranth-Dragon has launched a series of highly targeted attacks against government and law enforcement agencies across Southeast Asia. Active throughout 2025, these campaigns have …

CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware ESXi 0-day Ransomware Attack The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability. This …

Multiple TP-Link OS Command Injection Vulnerabilities Let Attackers Gain Admin Control of the Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TP-Link OS Command Injection Vulnerabilities TP-Link has released urgent firmware updates for its Archer BE230 Wi-Fi 7 routers to address multiple high-severity security flaws. These vulnerabilities could allow authenticated attackers …