New Malware Campaigns Turn Network Devices Into DDoS Nodes and Crypto-Mining Bots

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Network security has taken another hard hit. Two previously unknown malware strains have emerged, quietly turning routers, IoT devices, and enterprise network equipment into weapons for large-scale distributed denial-of-service (DDoS) attacks and cryptocurrency mining operations. These campaigns mark a clear …

FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious operational security failure by Russian state-linked hacking group FancyBear has given security researchers an unusually clear view into an active espionage campaign targeting government and military organizations across Europe. On March 11, 2026, threat intelligence firm Hunt.io published …

Critical Telnetd Vulnerability Enables Remote Attacker to Execute Arbitrary Code via Port 23

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical buffer overflow vulnerability in the GNU Inetutils telnetd daemon. Tracked as CVE-2026-32746, this flaw allows an unauthenticated remote attacker to execute arbitrary code and gain root access to affected systems. The vulnerability requires zero user interaction and possesses …

ForceMemo Hijacks GitHub Accounts, Backdoors Hundreds of Python Repos via Force-Push

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign tracked as ForceMemo is quietly compromising hundreds of GitHub accounts and injecting hidden malicious code into Python repositories, leaving almost no visible trace. The earliest confirmed infections date back to March 8, 2026, and the campaign …

Iran-Linked Cyber Campaigns Converge With Electronic and Psychological Warfare as Regional Conflict Escalates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On February 28, 2026, a joint US-Israeli military operation launched strikes inside Iran, opening a conflict that rapidly extended into cyberspace. Iran responded with ballistic missiles and drone strikes across Bahrain, Kuwait, Iraq, Saudi Arabia, the UAE, Israel, and Qatar. …

Vidar Stealer 2.0 Spreads Through Fake Game Cheats Promoted on GitHub and Reddit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly updated version of the Vidar infostealer, dubbed Vidar 2.0, is actively spreading through hundreds of fake game cheat repositories on GitHub and targeted posts on Reddit. The malware disguises itself as free cheating software for popular online games, …

Malicious Telegram Download Site Pushes Multi-Stage Loader With In-Memory Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fake Telegram download website is actively pushing dangerous malware onto unsuspecting users by disguising a malicious installer as a legitimate setup file. The site, hosted at the domain telegrgam[.]com — just one letter off from the real Telegram address …

Boggy Serpens Targets Diplomats and Critical Infrastructure in Multi-Wave Espionage Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-resourced Iranian nation-state group known as Boggy Serpens — also tracked as MuddyWater — has sharply escalated its cyberespionage operations, running sustained and targeted campaigns against diplomatic missions, energy companies, maritime operators, and financial institutions. Attributed to Iran’s Ministry …

Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of targeted attacks is quietly hitting Argentina’s judicial system, using fake court documents to lure legal professionals into installing a dangerous piece of malware. The campaign, formally called Operation Covert Access, deploys a Rust-built Remote Access Trojan …

Microsoft to Stop Force Installation of 365 Copilot App on Windows Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has temporarily halted the automatic installation of the Microsoft 365 Copilot app on Windows devices. According to a recent update in the Microsoft 365 Message Center on March 16, 2026, the company paused the mandatory rollout, originally scheduled to …