New ClickFix Attack Targeting Windows and macOS Users to Deploy Infostealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A growing social engineering technique called ClickFix has emerged as one of the most successful methods for distributing malware in recent months. This attack tricks users into copying and running …

Android Photo Frames App Downloads Malware, Giving Hackers Control of The Device Without User Interaction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Digital photo frames have become a standard household device for displaying family memories, and most users assume these simple gadgets prioritize simplicity over complexity. However, a troubling discovery reveals that …

Beware of Fake Bitcoin Tool That Hides DarkComet RAT Malware With it

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The rise of cryptocurrency has created new opportunities for cybercriminals to exploit unsuspecting users. Attackers are now disguising the notorious DarkComet remote access trojan as Bitcoin-related applications, targeting cryptocurrency enthusiasts …

Critical Fortinet FortiWeb Vulnerability Exploited in the Wild to Create Admin Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Fortinet’s FortiWeb Web Application Firewall (WAF) is being actively exploited by threat actors, potentially as a zero-day attack vector. The flaw, which enables unauthenticated attackers to …

Checkout.com Hacked – ShinyHunters Breached Cloud Storage, Company Refuses Ransom

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Payment processor Checkout.com revealed on Thursday that notorious hacking group ShinyHunters had infiltrated a legacy third-party cloud file storage system, exposing internal documents from years past. The breach, which the …

FortiWeb Authentication Bypass Vulnerability Exploited – Script to Detect Vulnerable Appliances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are actively exploiting a critical authentication bypass vulnerability in Fortinet’s FortiWeb web application firewall (WAF) worldwide, prompting defenders to heighten vigilance. Researchers at watchTowr Labs have responded by …

Hackers Exploiting RMM Tools LogMeIn and PDQ Connect to Deploy Malware as a Normal Program

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are now exploiting remote monitoring and management tools to spread dangerous malware while avoiding detection by security systems. The attack campaign targets users who download what appears to be …

New Wave of Steganography Attacks: Hackers Hiding XWorm in PNGs 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ANY.RUN experts recently uncovered a new XWorm campaign that uses steganography to conceal malicious payloads inside seemingly harmless PNG images. What appears to be an ordinary graphic actually contains encrypted loaders that execute entirely in …

Google Sues ‘Lighthouse’ Phishing-as-a-service Kit Behind Massive Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google security researchers recently uncovered a sophisticated criminal operation called “Lighthouse” that has victimized over one million people across more than 120 countries. This phishing-as-a-service platform represents one of the …

MastaStealer Weaponizes Windows LNK Files, Executes PowerShell Command, and Evades Defender

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly documented malware campaign demonstrates how attackers are leveraging Windows LNK shortcuts to deliver the MastaStealer infostealer. The attack begins with spear-phishing emails containing ZIP archives with a single …