Researchers Decrypt and Exploit Encrypted Palo Alto Cortex XDR BIOC Rules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Methods Decrypt and Abuse Encrypted Palo Alto Cortex XDR BIOC Rules for Evasion Cybersecurity researchers have uncovered a critical evasion flaw in Palo Alto Networks’ Cortex XDR agent that allowed attackers to bypass behavioral detections completely. By reverse-engineering these encrypted …

New CondiBot Variant and ‘Monaco’ Cryptominer Expand Threats to Network Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Network infrastructure has become one of the most targeted areas in today’s threat landscape. Over recent years, attackers ranging from nation-state groups to financially driven criminal actors have steadily shifted their focus toward routers, firewalls, and other network devices. These …

Stryker Confirms Destructive Wiper Attack – Tens of Thousands of Devices Wiped

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Medical technology giant Stryker Corporation confirmed on March 11, 2026, that it suffered a significant cyberattack that disrupted its global Microsoft environment, with Iran-linked threat actor Handala claiming responsibility for what appears to be a politically motivated, destructive operation. Unlike …

Handala Hack Uses RDP, NetBird, and Parallel Wipers in MOIS-Linked Destructive Intrusions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An Iranian threat actor known as Handala Hack has carried out a series of destructive cyberattacks against organizations in Israel, Albania, and the United States, using remote desktop access, network tunneling, and multiple simultaneous data-wiping tools. The group operates under …

CamelClone Spy Campaign Abuses Public File-Sharing Sites and Rclone in Government-Focused Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated espionage campaign, tracked as Operation CamelClone, has been actively targeting government agencies, defense institutions, and diplomatic bodies across multiple countries, including Algeria, Mongolia, Ukraine, and Kuwait. The operation relies on spear-phishing emails carrying malicious ZIP archives disguised as …

Fake Shipment Tracking Scams Surge in MEA, Stealing Banking Data Through Real-Time Phishing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every day, billions of people rely on postal and courier services to deliver everything from personal letters to online orders. This dependence has grown steadily alongside the global rise of e-commerce. The 2024 Universal Postal Union report found that postal …

IBM Uncovers ‘Slopoly,’ Likely AI-Generated Malware Used in Hive0163 Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A concerning development has emerged in early 2026, as IBM X-Force uncovered a likely AI-generated malware strain they named “Slopoly,” deployed during a ransomware attack by the financially motivated threat group Hive0163. The group is primarily focused on large-scale data …

Qihoo 360 Leaked Its Own Wildcard SSL Private Key Inside Public AI Installer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China’s largest cybersecurity firm, Qihoo 360, has inadvertently exposed its own wildcard SSL private key by bundling it directly inside the public installer of its newly launched AI assistant, 360Qihoo (Security Claw). The flaw discovered on March 16, 2026, is …

Fake FileZilla Downloads Lead to RAT Infections Through Stealthy Multi-Stage Loader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign has been discovered delivering a Remote Access Trojan through fake websites impersonating the official FileZilla download page. Attackers designed these fraudulent sites to closely mirror the real FileZilla page, tricking users into downloading malicious installer files. …

New ACRStealer Variant Uses Syscall Evasion, TLS C2 and Secondary Payload Delivery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new variant of ACRStealer has emerged with upgraded capabilities that make it significantly harder to detect and more dangerous to the systems it targets. First reported by Proofpoint in early 2025 as a rebranded version of the Amatera Stealer, …