Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iran-linked hackers have expanded an espionage effort with a Windows backdoor and reverse SSH tunnelling utility. The activity is tied to Tortoiseshell, also tracked as Mirage Kitten, UNC1549 and Nimbus …

Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access malware. The campaign turns a familiar AI software search into a …

24 Malicious npm Packages Abuse Trusted Mirrors to Host ClickFix Phishing Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing pages. The campaign does not infect a developer by installing a package. …

Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A phishing operation is abusing legitimate remote monitoring and management tools to give attackers direct control over victim systems. The campaign uses convincing document lures, rapidly changing hosting infrastructure, and …

SonicWall NetExtender Vulnerabilities Allow an Attacker to Write Arbitrary Files as Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has disclosed two security vulnerabilities in its NetExtender Linux client, including a critical path traversal flaw that could allow an attacker to write arbitrary files with root privileges. The …

WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites. The flaw, tracked as CVE-2026-19632, affects TranslatePress versions up …

Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iran-linked operators are using a trusted developer tool to conceal a backdoor called Dindoor inside Windows environments. The malware uses the Deno JavaScript and TypeScript runtime to execute encoded code, …

Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers tie the LinX Coders phishing-as-a-service toolkit to 9,332 compromise events across 94 countries, with 63.7% of victims in the United States and stolen session cookies accounting for more than …

Google Chrome 152 Released With 327 Security Fixes, Including 10 Critical Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome 152 for Windows, macOS, and Linux, delivering 327 security fixes and improvements. The update addresses 10 critical vulnerabilities, making it an important security release for individual …

28,000 Exposed Git Repositories Reveal API Keys, Bank Details and Employee Disciplinary Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A routine development mistake has exposed thousands of software repositories. Researchers found 28,000 publicly reachable .git repositories containing credentials, financial information and internal employee records that could give criminals a …