ECScape: Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated technique dubbed “ECScape” that allows malicious containers running on Amazon Elastic Container Service (ECS) to steal AWS credentials from other containers sharing the same EC2 instance. The discovery …

Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercriminal operation known as GreedyBear has orchestrated one of the most extensive cryptocurrency theft campaigns to date, deploying over 650 malicious tools across multiple attack vectors to steal …

ChatGPT-5 Released: What’s New With the Next-Generation AI Agent

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has officially launched ChatGPT-5, a new generation of its AI agent that introduces a sophisticated, unified system designed to be faster, more intelligent, and significantly more useful for real-world …

CISA Releases Emergency Advisory Urges Feds to Patch Exchange Server Vulnerability by Monday

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an emergency advisory directing all Federal Civilian Executive Branch agencies to mitigate a newly disclosed Microsoft Exchange urgently hybrid-joined vulnerability, tracked as CVE-2025-53786, by 9:00 AM EDT …

Flipper Zero ‘DarkWeb’ Firmware Bypasses Rolling Code Security on Major Vehicle Brands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and custom firmware for the popular Flipper Zero multi-tool device is reportedly capable of bypassing the rolling code security systems used in most modern vehicles, potentially putting millions …

Hackers Weaponizing SVG Files With Malicious Embedded JavaScript to Execute Malware on Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have begun exploiting Scalable Vector Graphics (SVG) files as sophisticated attack vectors, transforming seemingly harmless image files into potent phishing weapons capable of executing malicious JavaScript on Windows systems. …

Hacker Extradited to US for Stealing Over $2.5 Million in Tax Fraud Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercriminal operation that targeted American tax preparation businesses through spearphishing campaigns has culminated in the extradition of Nigerian national Chukwuemeka Victor Amachukwu from France to face federal charges …

WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two malicious npm packages have emerged as sophisticated weapons targeting WhatsApp developers through a remote-controlled destruction mechanism that can completely wipe development systems. The packages, identified as naya-flore and nvlore-hsc, …

SonicWall Confirms No New SSLVPN 0-Day – Ransomware Attack Linked to Old Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity firm SonicWall has officially addressed recent concerns about a potential new zero-day vulnerability in its Secure Sockets Layer Virtual Private Network (SSLVPN) products. In a statement to Cybersecurity News, …