APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian state-sponsored actors known as APT28 have initiated a sophisticated cyber espionage campaign targeting high-value government and military entities across Europe. The primary targets include maritime and transport organizations in …

New 3 Step Malvertising Chain Abusing Facebook Paid Ads to Push Tech Support #Scam Kit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cyber threat has emerged within the digital advertising ecosystem, specifically targeting users through the vast reach of Facebook’s paid advertising platform. Malicious actors are increasingly weaponizing social …

Attackers Using DNS TXT Records in ClickFix Script to Execute Powershell Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has darkened with the sophisticated evolution of the KongTuke campaign. Active since mid-2025, this threat actor group has continuously refined its techniques to bypass conventional enterprise security …

Amaranth-Dragon Exploiting WinRAR Vulnerability to Gain Persistent to Victim Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber-espionage group known as Amaranth-Dragon has launched a series of highly targeted attacks against government and law enforcement agencies across Southeast Asia. Active throughout 2025, these campaigns have …

CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware ESXi 0-day Ransomware Attack The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability. This …

Multiple TP-Link OS Command Injection Vulnerabilities Let Attackers Gain Admin Control of the Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TP-Link OS Command Injection Vulnerabilities TP-Link has released urgent firmware updates for its Archer BE230 Wi-Fi 7 routers to address multiple high-severity security flaws. These vulnerabilities could allow authenticated attackers …

SystemBC Botnet Hijacked 10,000 Devices Worldwide to Use for DDoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The SystemBC malware family, a persistent threat first documented in 2019, has evolved into a massive botnet infrastructure controlling over 10,000 hijacked devices globally. Functioning primarily as a SOCKS5 proxy …

PhantomVAI Custom Loader Uses RunPE Utility to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated custom loader named PhantomVAI has emerged in global phishing campaigns, delivering various stealers and remote access trojans (RATs) to compromised systems. This malware loader operates by masquerading as …

Interlock Ransomware Actors New Tool Exploiting Gaming Anti-Cheat Driver 0-Day to Disable EDR and AV

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Interlock ransomware group has emerged as a distinct threat in the cybersecurity landscape, particularly targeting the education sector in the United States and United Kingdom. Unlike many contemporary ransomware …

False Negatives Are a New SOC Headache. Here’s the Fast Way to Fix It 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

False negatives are becoming the most expensive “quiet” failure in SOCs. In 2026, AI-generated phishing and multi-stage malware chains are built to look clean on the outside, behave normally at …