New ToneShell Backdoor With New Features Leverage Task Scheduler COM Service for Persistence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since its first appearance earlier this year, the ToneShell backdoor has demonstrated a remarkable capacity for adaptation, toyed with by the Mustang Panda group to maintain an enduring foothold in …

Samsung Zero-Day Vulnerability Actively Exploited to Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Samsung has released its September 2025 security update, addressing a critical zero-day vulnerability that is being actively exploited in the wild. The patch resolves a total of 25 Samsung Vulnerabilities …

K2 Think AI Model Jailbroken Within Hours After The Release

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Within mere hours of its public unveiling, the K2 Think model experienced a critical compromise that has sent ripples throughout the cybersecurity community. The newly launched reasoning system, developed by …

New HybridPetya Weaponizing UEFI Vulnerability to Bypass Secure Boot on Outdated Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In late July 2025, a series of ransomware samples surfaced on VirusTotal under filenames referencing the notorious Petya and NotPetya attacks. Unlike its predecessors, this new threat—dubbed HybridPetya by ESET …

New Clickfix Attack Promises “Free WiFi” But Delivers Powershell-Based Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecuritynews researcher team uncovered a sophisticated social engineering campaign that is exploiting the public’s need for free internet access, using deceptive Wi-Fi portals to trick users into downloading and …

Microsoft Patch for Old Flaw Reveals New Kernel Address Leak Vulnerability in Windows 11/Server 2022 24H2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new kernel address leak vulnerability has been discovered in the latest versions of Windows 11 (24H2) and Windows Server 2022 (24H2). The flaw, identified as CVE-2025-53136, was ironically introduced …

New Malware Using Azure Functions For Hosting Command And Control Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new, sophisticated malware campaign has been uncovered that leverages Microsoft’s Azure Functions for its command-and-control (C2) infrastructure, a novel technique that complicates detection and takedown efforts. According to the …

Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed four elevation of privilege vulnerabilities in its Windows Defender Firewall service, all rated as “Important” in severity. The security flaws were detailed in Microsoft’s September 9, 2025, …

Microsoft To Depreciate VBScript In Windows Warns Developers To Adapt Their Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially announced a multi-phase plan to deprecate VBScript in Windows, a move that signals a significant shift for developers, particularly those working with Visual Basic for Applications (VBA). …

Apple Warns Of Series Mercenary Spyware Attacks Targeting Users’ Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has issued a warning regarding highly sophisticated “mercenary spyware” attacks targeting a select group of its users. The company’s threat notification system is designed to alert and support individuals …