Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale phishing campaign is targeting software developers on GitHub, using fake Visual Studio Code security alerts posted in GitHub Discussions to trick users into downloading malicious software. The attacks …

Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated evolution of Kerberoasting dubbed the “Ghost SPN” attack that allows adversaries to extract Active Directory credentials while erasing all traces of their activity, rendering traditional detection models effectively …

China-Linked Hackers Breach Southeast Asian Military Systems in Long-Running Spy Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated and long-running cyber espionage campaign, tracked as CL-STA-1087, has been quietly targeting military organizations across Southeast Asia since at least 2020. The operation, assessed with moderate confidence to be …

Open Directory Malware Campaign Uses Obfuscated VBS, PNG Loaders and RAT Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated multi-stage malware campaign has surfaced, deploying obfuscated Visual Basic Script (VBS) files, PNG-embedded loaders, and remote access trojans (RATs) to target systems without leaving a trace on disk. …

Linux Ransomware Pay2Key Attacking Organizations Ervers, Virtualization Hosts, and Cloud Workloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Linux has long been considered a more secure operating system than Windows, but that reputation is being tested. A ransomware group known as Pay2Key, attributed to Iranian threat actors, has …

macOS Threats Are the Biggest Security Gap in 2026: How SOC Teams Close It 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

macOS Threats: Closing Security Gaps in 2026 macOS has become a standard part of modern business environments, especially across engineering, product, and leadership teams. That makes it a growing security …

SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport RAT, StealC and Sectop RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat campaign known as SmartApeSG — also tracked under the names ZPHP and HANEYMANEY — has been observed pushing multiple strains of malware through a social engineering technique called …

Firefox 149.0 Released With Free Built-in VPN With 50 GB Monthly Data Limit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mozilla has officially rolled out Firefox 149.0 to the Release channel on March 24, 2026, delivering a massive update focused heavily on user privacy and security hardening. The standout addition …

New Research Maps How Infostealer Infections Turn Into Dark Web Exposure in 48 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The digital threat landscape has reached a point where a single careless download by one employee can hand criminal groups direct access to an entire corporate network in under two …

AI-Assisted ‘OpenClaw Trap’ Campaign Uses Trojanized GitHub Repos to Target Developers and Gamers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware campaign has been quietly spreading through fake GitHub repositories, targeting software developers, gamers, Roblox players, and crypto users at the same time. Tracked internally as TroyDen’s …