New CastleLoader Attack Using Cloudflare-Themed Clickfix Technique to Infect Windows Computers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CastleLoader, a rapidly evolving loader discovered in 2025, has surged across underground networks by weaponizing Cloudflare-themed “Clickfix” phishing pages and doctored GitHub repositories to compromise Windows hosts. The malware masquerades …

Hive0156 Hackers Attacking Government and Military Organizations to Deploy Remcos RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Russian-aligned threat actor known as Hive0156 has intensified its cyber espionage campaigns against Ukrainian government and military organizations, deploying the notorious Remcos Remote Access Trojan through carefully crafted …

Rise in Phishing Activity Using Spoofed SharePoint Domains With Sneaky2FA Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spoofed Microsoft SharePoint notifications have been a familiar lure for corporate users, but a wave of campaigns traced between March and July 2025 shows a sharp uptick in both volume …

Elephant APT Group Attacking Defense Industry Leveraging VLC Player, and Encrypted Shellcode

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Dropping Elephant advanced persistent threat group has launched a sophisticated cyber-espionage campaign targeting Turkish defense contractors, particularly companies manufacturing precision-guided missile systems. This malicious operation represents a significant evolution …

Hackers Injected Destructive System Commands in Amazon’s AI Coding Agent

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious pull request slipped through Amazon’s review process and into version 1.84.0 of the Amazon Q extension for Visual Studio Code, briefly arming the popular AI assistant with instructions …

TP-Link Network Video Recorder Vulnerability Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two high-severity vulnerabilities in TP-Link VIGI network video recorder (NVR) systems could allow attackers to execute arbitrary commands on affected devices.  The security flaws, identified as CVE-2025-7723 and CVE-2025-7724, impact …

SharePoint 0-day Vulnerability Exploited in Wild by All Sorts of Hacker Groups

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in Microsoft SharePoint servers has become a playground for threat actors across the cybercriminal spectrum, with attacks ranging from opportunistic hackers to sophisticated nation-state groups since …

First Known LLM-Powered Malware From APT28 Hackers Integrates AI Capabilities into Attack Methodology

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The newly revealed LAMEHUG campaign signals a watershed moment for cyber-def: Russian state-aligned APT28 has fused a large language model (LLM) directly into live malware, allowing each infected host to …