ExpressVPN Windows Client Vulnerability Exposes Users Real IP Addresses With RDP Connection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in ExpressVPN Windows desktop application that could expose users’ real IP addresses when using Remote Desktop Protocol (RDP) connections.  The flaw, discovered through the company’s bug …

Threat Actors Combine Android Malware With Click Fraud Apps to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fresh wave of malicious Android Package Kit (APK) files is weaving together two of cybercrime’s most reliable revenue streams—click-fraud advertising and credential theft—into a single, adaptable threat that has …

GLOBAL GROUP’s Golang Ransomware Attacks Windows, Linux, and macOS Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new ransomware threat has emerged from the cybercriminal underground, targeting organizations across multiple operating systems with advanced cross-platform capabilities. In June 2025, a ransomware actor operating under the …

Wireshark 4.4.8 Released With Bug Fixes and Updated Protocol Support

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Wireshark Foundation has announced the availability of Wireshark 4.4.8, the latest maintenance release of the world’s most widely used network-protocol analyzer. Although the update does not introduce brand-new protocols, it …

Dior, a Louis Vuitton Brand, Alerts Customers Following Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Christian Dior Couture, the luxury fashion house owned by Louis Vuitton, has begun notifying customers of a major cybersecurity incident that exposed sensitive personal information of clients.  The breach, discovered …

Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Thousands of organizations worldwide face active cyberattacks targeting Microsoft SharePoint servers through two critical vulnerabilities, prompting urgent government warnings and emergency patches. Microsoft confirmed over the weekend that threat actors …

Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financially motivated threat group dubbed Greedy Sponge has been systematically targeting Mexican financial institutions and organizations since 2021 with a heavily modified version of the AllaKore remote access trojan …

DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing campaign has emerged, delivering the DeerStealer malware through weaponized .LNK shortcut files that exploit legitimate Windows binaries in a technique known as “Living off the Land” …

Threat Actors Hijack Popular npm Packages to Steal The Project Maintainers’ npm Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has compromised several widely-used npm packages, including eslint-config-prettier and eslint-plugin-prettier, after threat actors successfully stole maintainer authentication tokens through a targeted phishing campaign. The attack …

Developers Beware of npm Phishing Email That Steal Your Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged targeting Node.js developers through a meticulously crafted attack that impersonates the official npm package registry. The malicious operation utilizes the typosquatted domain npnjs.com, substituting …