Fake FileZilla Downloads Lead to RAT Infections Through Stealthy Multi-Stage Loader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign has been discovered delivering a Remote Access Trojan through fake websites impersonating the official FileZilla download page. Attackers designed these fraudulent sites to closely mirror the …

New ACRStealer Variant Uses Syscall Evasion, TLS C2 and Secondary Payload Delivery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new variant of ACRStealer has emerged with upgraded capabilities that make it significantly harder to detect and more dangerous to the systems it targets. First reported by Proofpoint in …

Microsoft Exchange Online Mailbox Access Outage Affects Users Globally

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is currently investigating a service disruption affecting Exchange Online users who are experiencing difficulties accessing their mailboxes through one or more connection methods. The issue, tracked under Microsoft 365’s …

Android 17 Advanced Protection Mode to Block Malicious Service Usage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Android 17 Advanced Protection Mode Google is preparing to launch Android 17, bringing a comprehensive set of new APIs and system capabilities to fundamentally improve device security, user privacy, and …

Attackers Abuse Microsoft Teams and Quick Assist to Drop Stealthy A0Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified backdoor called A0Backdoor has emerged as part of a calculated social-engineering campaign that abuses Microsoft Teams and the Windows remote assistance tool Quick Assist. The threat group …

OpenClaw AI Agents Leaking Sensitive Data in Indirect Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenClaw AI Agents Leaking Sensitive Data Indirect Prompt Injection Attackers can exploit insecure defaults and prompt injection vulnerabilities to turn normal agent behavior into a silent data-exfiltration pipeline. The core …

Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A set of nine novel cross-tenant vulnerabilities in Google Looker Studio, collectively dubbed “LeakyLooker,” that could have allowed attackers to run arbitrary SQL queries, exfiltrate sensitive data, and even modify …

Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows 11 and Server 2025 Automated Installation Microsoft has announced a two-phase plan to disable the hands-free deployment feature in Windows Deployment Services (WDS) following the discovery of a critical …

Meta to Permanently Remove End-to-End Encryption Feature in Instagram DMs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta has confirmed it will permanently remove end-to-end encryption (E2EE) support from Instagram direct messages, with the feature officially shutting down after May 8, 2026. The announcement, quietly posted on …

Microsoft Releases Out-of-Band Patch to Fix Critical RRAS RCE Vulnerabilities in Windows 11

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2. Tracked as KB5084597 and targeting OS Builds 26200.7982 and …