New Lampion Stealer Uses ClickFix Attack to Silently Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered a sophisticated campaign leveraging the Lampion banking trojan, a malware strain that has operated since 2019 with a renewed focus on Portuguese financial institutions. The threat actor …

New Agent-Aware Cloaking Leverages OpenAI ChatGPT Atlas Browser to Deliver Fake Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new agent-aware cloaking technique uses AI browsers like OpenAI’s ChatGPT Atlas to deliver misleading content. This method allows malicious actors to poison the information AI systems ingest, potentially manipulating …

New Windows-Based Airstalk Malware Employs Multi-Threaded C2 Communication to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered Windows malware family named Airstalk has emerged as a sophisticated threat capable of exfiltrating sensitive browser credentials through an innovative covert command-and-control channel. Available in PowerShell and …

700+ Malicious Android Apps Abusing NFC Relay to Exfiltrate Banking Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign exploiting Near Field Communication technology on Android devices has expanded dramatically since its emergence in April 2024. What began as isolated incidents has escalated into a …

RediShell RCE Vulnerability Exposes 8,500+ Redis Instances to Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape faced a critical threat in early October 2025 with the public disclosure of RediShell, a severe use-after-free vulnerability in Redis’s Lua scripting engine. Identified as CVE-2025-49844 and …

CISA Releases Best Security Practices Guide for Hardening Microsoft Exchange Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a timely response to escalating threats against email infrastructure, the Cybersecurity and Infrastructure Security Agency (CISA), alongside the National Security Agency (NSA), Australian Cyber Security Centre (ACSC), and Canadian …

New Malware Targeting WooCommerce Sites with Malicious Plugins Steals Credit Card Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged targeting WordPress e-commerce sites, particularly those leveraging the WooCommerce plugin to process customer transactions. The threat, discovered in August 2025, demonstrates advanced evasion capabilities …

12 Malicious Extension in VSCode Marketplace Steal Source Code and Exfiltrate Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent discovery has shaken the Visual Studio Code (VSCode) ecosystem, unveiling a sophisticated supply chain attack targeting developers worldwide. At least a dozen malicious extensions were identified in the …

Multiple Jenkins Vulnerability SAML Authentication Bypass And MCP Server Plugin Permissions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Jenkins project released Security Advisory 2025-10-29 on October 28, 2025, disclosing multiple vulnerabilities across 13 plugins that power the popular open-source automation server. These flaws range from high-severity authentication …

Critical Vulnerability in Chromium’s Blink Let Attackers Crash Chromium-based Browsers Within Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researcher Jofpin has disclosed “Brash,” a critical flaw in Google’s Blink rendering engine that enables attackers to crash Chromium-based browsers almost instantly. Affecting billions of users worldwide, this architectural …