APT36 Hackers Attacking Indian BOSS Linux Systems With Weaponized .desktop Shortcut Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In early August 2025, security researchers uncovered an unprecedented campaign targeting India’s BOSS Linux installations through seemingly innocuous shortcut files. These files, masquerading as PDF documents, leverage the .desktop format …

WhatsApp Desktop Users At Risk of Code Execution Attacks with Python on Windows PCs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp Desktop users who have Python installed on their Windows PCs are at risk of arbitrary code execution due to a flaw in how the application handles Python archive files.  …

OneFlip – New Attack Flips a Single Bit in Neural Networks for Stealthily Backdoor on AI Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In August 2025, researchers at George Mason University published a groundbreaking study at the 34th USENIX Security Symposium, introducing OneFlip, an inference-time backdoor attack that flips just one bit in …

PoC Exploit Released for Chrome 0-Day Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has disclosed a critical zero-day vulnerability in the V8 JavaScript engine used by Chrome, tracked as CVE-2025-5419.  Before a patch could be rolled out to all users, proof-of-concept (PoC) …

WinRAR 0-Day Vulnerabilities Exploited in Wild by Hackers – Detailed Case Study

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has been significantly impacted by the discovery and active exploitation of two critical zero-day vulnerabilities in WinRAR, one of the world’s most widely used file compression utilities.  …

French Retailer Auchan Cyberattack  – Thousands of Customers Personal Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Major French retail chain Auchan announced on August 21, 2025, that it suffered a significant cybersecurity incident resulting in the unauthorized access and theft of personal data from “several hundred …

X/Twitter The Most Aggressive Social Media App Collecting Users Location Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A comprehensive analysis of the top 10 social media platforms reveals that X (formerly Twitter) stands out as the most invasive collector of user location information, gathering both precise and …

Malicious Bing Ads deploy Weaponized PuTTY to Exploit Kerberos and Attack Active Directory services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malvertising campaign using sponsored results on Microsoft’s search platform delivered a weaponized PuTTY that established persistence, enabled hands-on keyboard control, and executed Kerberoasting to target Active Directory service accounts. …

Threat Actors Adapting Android Droppers Even to Deploy Simple Malware to Stay Future-Proof

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Android droppers have evolved from niche installers for heavyweight banking Trojans into universal delivery frameworks, capable of deploying even rudimentary spyware or SMS stealers. Initially, droppers served banking malware families …

Chinese UNC6384 Hackers Leverages Valid Code Signing Certificates to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A stealthy espionage campaign emerged in early 2025 targeting diplomats and government entities in Southeast Asia and beyond. At the heart of this operation lies STATICPLUGIN, a downloader meticulously disguised …