Threat Actors Using Malicious VSCode Extension to Deploy Anivia Loader and OctoRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fake Visual Studio Code extension has been used in a supply chain attack that targets developers through their editor. The rogue extension, named prettier-vscode-plus and posing as the trusted …

India’s New SIM-Binding Rule for WhatsApp, Signal, Telegram and Other Messaging Platforms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

India has implemented a mandatory SIM-binding requirement for messaging applications, including WhatsApp, Telegram, Signal, Snapchat, and others. The Department of Telecommunications issued a directive on November 28 requiring all app-based …

Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Industrial Video & Control’s Longwatch video surveillance system, allowing attackers to execute malicious code with elevated privileges remotely. The flaw, tracked as CVE-2025-13658, …

Hackers Can Weaponize Claude Skills to Execute MedusaLocker Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new feature in Anthropic’s Claude AI, known as Claude Skills, has been identified as a potential vector for ransomware attacks. This feature, designed to extend the AI’s capabilities through …

Hackers Exploit Critical Yearn Finance’s yETH Pool Vulnerability to Steal $9 Million in Ethereum

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The decentralized finance sector witnessed a devastating breach targeting Yearn Finance’s yETH pool, resulting in the theft of approximately $9 million on November 30, 2025. The attacker executed a highly …

29.7 Tbps DDoS Attack Via Aisuru Botnet Breaks Internet With New World Record

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new 29.7 Tbps distributed denial-of-service (DDoS) blast from the Aisuru botnet has set a new world record for attack volume, underscoring how fragile core internet infrastructure remains under extreme …

Hackers Using Calendly-Themed Phishing Attack to Steal Google Workspace Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged targeting business professionals with Calendly-themed emails, combining social engineering with advanced credential theft techniques. The attack specifically focuses on Google Workspace and Facebook Business …

K7 Antivirus Vulnerability Allows Attackers Gain SYSTEM-level Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious privilege escalation vulnerability in K7 Ultimate Security, an antivirus product from K7 Computing, was found by abusing named pipes with overly permissive access control lists. This flaw enables …

Shai-Hulud 2.0 Malware Attack Compromised 30,000 Repositories and Stolen 500 GitHub Usernames and Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant supply chain security breach has emerged with the discovery of Shai-Hulud 2.0, a sophisticated malware that has compromised over 30,000 GitHub repositories since its emergence on November 24, …

Malicious Rust Evm-Units Mimic as EVM Version Silently Executes OS-specific Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The open-source software supply chain recently encountered a deceptive threat in the form of evm-units, a malicious Rust crate published by the author ablerust. Masquerading as a standard utility for …