Exposed Server Reveals TheGentlemen Ransomware Toolkit, Victim Credentials, and Ngrok Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A misconfigured server hosted on a Russian bulletproof hosting provider has exposed the complete operational toolkit of a TheGentlemen ransomware affiliate, including harvested victim credentials and plaintext authentication tokens used to establish hidden remote access tunnels. TheGentlemen ransomware group operates …

North Korean IT Worker Allegedly Used Stolen Identity and AI Resume in Job Application Scam

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A suspected North Korean operative tried to sneak into a remote job at a cybersecurity firm by using a stolen identity, a fake AI-generated resume, and a VoIP phone number. The case, uncovered in June 2025, shows how North Korea’s …

CrySome RAT Emerges as Advanced .NET Malware With AV Killer and HVNC Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and dangerous piece of malware has surfaced in the threat landscape, and it is built to stay hidden, stay running, and stay in control of any system it infects. CrySome RAT is written in C# and targets the …

New ClickFix Variant Uses Rundll32 and WebDAV to Evade PowerShell Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and more dangerous version of the ClickFix attack technique has been found actively targeting Windows users. Unlike older versions that used PowerShell or mshta to run malicious commands, this new variant takes a different path. It uses rundll32.exe …

TA446 Hackers Deploying DarkSword Exploit Kit to Attack iOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A known threat group called TA446 has been caught using a newly discovered exploit kit called DarkSword to target iOS users. This development marks a significant shift in the group’s tactics, as previous activity from TA446 showed no signs of …

New Homoglyph Attack Techniques Help Cybercriminals Spoof Trusted Domains

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have found a clever way to trick people by swapping real letters in website addresses with characters that look almost the same. These are called homoglyph attacks, and they are becoming a growing problem across the internet. A single …

Hackers Backdoor Telnyx Python SDK on PyPI to Steal Cloud and Dev Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widely used Python package was quietly turned into a weapon, and most developers who got hit had no idea it happened. On March 27, 2026, a threat actor known as TeamPCP uploaded two malicious versions of the Telnyx Python …

Open VSX’s New Scanner Vulnerability Allows Malicious Extension Goes Live

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious security flaw was recently found in Open VSX, the extension marketplace used by popular code editors like Cursor and Windsurf, as well as the broader VS Code fork ecosystem. The vulnerability was found inside the platform’s newly introduced …

BlankGrabber Stealer Uses Fake Certificate Loader to Hide Malware Delivery Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Python-based information stealer known as BlankGrabber has been caught using a deceptive certificate loader trick to hide a multi-stage malware delivery chain. First identified in 2023, this threat has grown more complex over time and keeps targeting everyday users …

Stored XSS Bug in Jira Work Management Could Lead to Full Organization Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A popular collaboration tool within the Atlassian ecosystem is widely used by organizations to track projects, manage approvals, and manage daily tasks. Recently, security researchers at Snapsec uncovered a critical Stored Cross-Site Scripting (XSS) vulnerability within the platform. By exploiting a …