Threat Actors Using CrossC2 Tool to Expand Cobalt Strike to Operate on Linux and macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated threat campaign has emerged that leverages CrossC2, an unofficial extension tool that expands Cobalt Strike’s notorious capabilities beyond Windows systems to target Linux and macOS environments. Between September …

Mobile Phishers Target Brokerage Accounts in ‘Ramp and Dump’ Cashout Scheme

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

August 15, 2025 0 Comments Cybercriminal groups peddling sophisticated phishing kits that convert stolen card data into mobile wallets have recently shifted their focus to targeting customers of brokerage services, …

New Clever Phishing Attack Uses Japanese Character “ん” to Mimic Forward Slash

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a sophisticated new phishing campaign that exploits the Japanese hiragana character “ん” to create deceptively authentic-looking URLs that can fool even vigilant internet users. The attack, …

HexStrike AI Connects ChatGPT, Claude, Copilot with 150+ Security Tools like Burp Suite and Nmap

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new AI tool named HexStrike AI has been launched, designed to bridge the gap between large language models (LLMs) and practical cybersecurity operations. The latest release, v6.0, equips AI …

Cisco Secure Firewall Snort 3 Detection Engine Vulnerability Enables DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security flaw CVE-2025-20217 allows unauthenticated attackers to trigger denial-of-service conditions in Cisco’s widely deployed firewall systems Cisco has disclosed a high-severity vulnerability in its Secure Firewall Threat Defense (FTD) …

CVE-2025-8088 – WinRAR 0-Day Path Traversal Vulnerability Exploited to Execute Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A zero-day vulnerability in WinRAR allows malware to be deployed on unsuspecting users’ systems, highlighting the ongoing threats to popular software. Tracked as CVE-2025-8088, this path traversal flaw affects the …

Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign targeting Windows systems has emerged, employing a multi-stage framework dubbed “PS1Bot” that combines PowerShell and C# components to conduct extensive information theft operations. The malware …

New HTTP/2 MadeYouReset Vulnerability Enables Large-Scale DDoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified a new denial-of-service (DoS) vulnerability in HTTP/2 implementations, referred to as MadeYouReset (CVE-2025-8671). This discovery represents a notable escalation in the threats associated with web protocols. …

New NFC-Driven PhantomCard Android Malware Attacking Banking Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Android malware dubbed PhantomCard has emerged from the shadows of Brazil’s cybercriminal underground, representing a significant evolution in mobile banking threats. This malicious application leverages Near Field …