Chinese PlushDaemon Hackers use EdgeStepper Tool to Hijack Legitimate Updates and Redirect to Malicious Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A China-aligned threat group known as PlushDaemon has been weaponizing a sophisticated attack method to infiltrate networks across multiple regions since 2018. The group’s primary strategy involves intercepting legitimate software …

Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber campaign known as Operation WrtHug has hijacked tens of thousands of ASUS WRT routers globally, turning them into potential espionage tools for suspected China-linked hackers. SecurityScorecard’s STRIKE …

Hackers Using Leverage Tuoni C2 Framework Tool to Stealthily Deliver In-Memory Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of cyberattacks has emerged using the Tuoni Command and Control (C2) framework, a sophisticated tool that allows threat actors to deploy malicious payloads directly into system memory. …

Microsoft Investigating Copilot Issue On Processing Files 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has launched an investigation into a widespread issue affecting Microsoft Copilot in Microsoft 365, where users are experiencing significant limitations when performing actions on files. The technology giant confirmed …

Destructive Akira Ransomware Attack with a Single Click on CAPTCHA in Malicious Website

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A global data storage and infrastructure company fell victim to a severe ransomware attack orchestrated by Howling Scorpius, the group responsible for distributing Akira ransomware. The incident began with what …

New Nova Stealer Attacking macOS Users by Swapping Legitimate Apps to Steal Cryptocurrency Wallet Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign targeting macOS users has emerged with a dangerous focus on cryptocurrency wallet theft. The malware, called Nova Stealer, uses a clever approach to trick victims by …

New ShadowRay Attack Exploit Ray AI-Framework Vulnerability to Attack AI Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered an active global hacking campaign leveraging a known flaw in Ray, an open-source AI framework widely used for managing distributed computing tasks. Dubbed ShadowRay 2.0, this …

CISA Warns of Fortinet FortiWeb OS Command Injection Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical vulnerability affecting Fortinet FortiWeb appliances that threat actors are currently exploiting in active attacks. The …

Microsoft Teams New Feature Let Users Report Messages Incorrectly Flagged as Security Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is introducing a new capability in Teams that allows users to report messages they believe were mistakenly flagged as security threats. The feature represents a significant step toward improving …