New Phantom Stealer Campaign Hits Windows Machines Through ISO Mounting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered a sophisticated phishing campaign originating in Russia that deploys the Phantom information-stealing malware via malicious ISO files. The attack, dubbed “Operation MoneyMount-ISO,” targets finance and accounting departments …

Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple patches two WebKit zero-day flaws actively exploited in sophisticated attacks targeting specific iPhone users running iOS versions prior to 26.​ The iOS 26.2 and iPadOS 26.2 updates, released December …

Kali Linux 2025.4 Released With 3 New Hacking Tools and Wifipumpkin3

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kali Linux 2025.4, released with substantial desktop environment improvements, full Wayland support across virtual machines, and three powerful new hacking tools, including the much-anticipated Wifipumpkin3.​ Released on December 12, 2025, …

Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Torrance, United States / California, December 12th, 2025, CyberNewsWire In December 2025, CVE-2025-55182 (React2Shell), a vulnerability in React Server Components (RSC) that enables remote code execution (RCE), was publicly disclosed. …

New JSCEAL Infostealer Malware Attacking Windows Systems to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

JSCEAL has emerged as a serious threat to Windows users, specifically targeting those who work with cryptocurrency applications and valuable accounts. First reported by Check Point Research in July 2025, …

New AiTM Attack Campaign That Bypasses MFA Targeting Microsoft 365 and Okta Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged that successfully bypasses multi-factor authentication, protecting Microsoft 365 and Okta users, representing a serious threat to organizations relying on these platforms for identity management. …

Top 20 Most Exploited Vulnerabilities of 2025: A Comprehensive Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape of 2025 has been marked by an unprecedented surge in vulnerability exploitation, with threat actors leveraging critical flaws across enterprise software, cloud infrastructure, and industrial systems. This …

CyberVolk Hackers Group With New VolkLocker Payloads Attacks both Linux and Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CyberVolk, a pro-Russia hacktivist group, has reemerged with a new ransomware platform called VolkLocker following a period of dormancy in 2025. The group, first documented in late 2024 for conducting …

New ConsentFix Attack Let Attackers Hijack Microsoft Accounts by Leveraging Azure CLI

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing attack technique called “ConsentFix” that combines OAuth consent phishing with ClickFix-style prompts to compromise Microsoft accounts without requiring passwords or multi-factor authentication. The attack leverages the …

NANOREMOTE Malware Leverages Google Drive API for Command-and-Control (C2) to Attack Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Windows backdoor named NANOREMOTE emerged in October 2025, presenting a significant threat to enterprise environments by leveraging legitimate cloud infrastructure for malicious purposes. This fully-featured malware utilizes …