GhostChat Spyware Attacking Android Users Via WhatsApp to Exfiltrate Sensitive Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Android spyware campaign has emerged, targeting users in Pakistan through a sophisticated romance scam that uses fake dating profiles to steal personal information. The malicious application, known as …

Critical Ivanti Endpoint Manager 0-day RCE Vulnerabilities Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical code-injection vulnerabilities have been disclosed in the Endpoint Manager Mobile (EPMM) platform, which are currently being actively exploited in real-world attacks. The security flaws, tracked as CVE-2026-1281 and …

Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a sophisticated traffic distribution network leveraging deceptive education-themed domains to deliver malware and phishing attacks. The operation, tracked under infrastructure indicators pointing to TOXICSNAKE, uses legitimate-looking …

Hackers Weaponized Open VSX Extension with Sophisticated Malware After Reaching 5066 Downloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has infiltrated the Open VSX extension marketplace, compromising over 5,000 developer workstations through a fake Angular Language Service extension. The malicious package disguised itself as legitimate …

3,280,081 Fortinet Devices Online With Exposed Web Properties Under Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 3,280,081 Fortinet Devices Were exposed, with web properties running vulnerable Fortinet devices affected by CVE-2026-24858, a severe authentication-bypass flaw actively exploited in the wild. The vulnerability, rated 9.4 on the …

Wireshark 4.6.3 Released With Vulnerabilities Dissector and Parser Crash

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Wireshark Foundation has officially released Wireshark 4.6.3, the latest update to the world’s most popular network protocol analyzer. This release is critical for network administrators, security analysts, and developers, …

Microsoft Releases Update for Windows 11, version 25H2 and 24H2 Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially released the optional non-security preview update KB5074105 for Windows 11, versions 25H2 and 24H2. This release, part of the January 2026 “C-week” schedule, focuses on functionality enhancements, …

Exposed Open Directory Leaks BYOB Framework Across Windows, Linux, and macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat researchers have uncovered an actively serving command and control server hosting a complete deployment of the BYOB framework following the discovery of an exposed open directory. The server, located …

Threat Actors Leverage Google Search Ads for ‘Mac Cleaner’ to Direct Users to Malicious Websites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are taking advantage of Google Search Ads to trick Mac users into visiting fake websites that promise to clean their computers. These sponsored ads appear when users search for …

Python-based PyRAT with Cross-Platform Capabilities and Extensive Remote Access Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Python-based remote access trojan has emerged, targeting both Windows and Linux systems with sophisticated surveillance and data theft capabilities. The malware operates by establishing command-and-control communication through unencrypted …