First Large-scale Cyberattack Using AI Tools With Minimal Human Input

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese government-backed hackers used Anthropic’s Claude Code tool to carry out advanced spying on about thirty targets worldwide, successfully breaking into several major organizations. The first documented large-scale cyberattack executed …

Highly Sophisticated macOS DigitStealer Employs Multi-Stage Attacks to Evade detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware family targeting macOS systems has emerged with advanced detection evasion techniques and multi-stage attack chains. Named DigitStealer, this information stealer uses multiple payloads to steal sensitive data …

Formbook Malware Delivered Using Weaponized Zip Files and Multiple Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of Formbook malware attacks has appeared, using weaponized ZIP archives and multiple script layers to bypass security controls. The attacks begin with phishing emails containing ZIP files …

A Multi-Stage Phishing Kit Using Telegram to Harvest Credentials and Bypass Automated Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing attacks continue to be one of the most persistent threats targeting organizations worldwide. Cybercriminals are constantly improving their methods to steal sensitive information, and a recently discovered phishing kit …

Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments – New CISA Report

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new advisory from the Cybersecurity and Infrastructure Security Agency reveals that Akira ransomware has become one of the most active threats targeting businesses worldwide. Since March 2023, this ransomware …

Lumma Stealer Uses Browser Fingerprinting to Collect Data and for Stealthy C&C Server Communications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lumma Stealer has emerged as a serious threat in the cybercrime world, targeting users through fake software updates and cracked applications. This information-stealing malware targets the collection on login details, …

Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has issued an urgent advisory warning of a critical vulnerability in its FortiWeb web application firewall (WAF) product, which attackers are actively exploiting in the wild. Identified as CVE-2025-64446, …

Beware of Phishing Emails as Spam Filter Alerts Steal Your Email Logins in a Blink

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have launched a new phishing campaign that tricks users by impersonating legitimate spam-filter notifications from their own company. These fake emails claim that your organization recently upgraded its Secure …

Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On November 7th, security researchers discovered a dangerous malicious npm package called “@acitons/artifact” that had already been downloaded more than 206,000 times. The package was designed to look like the …

NVIDIA NeMo Framework Vulnerabilities Allows Code Injection and Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NVIDIA has issued a critical security update addressing two high-severity vulnerabilities in its NeMo Framework that could allow attackers to execute malicious code and escalate privileges on affected systems. The …