Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two fake Chrome extensions named “Phantom Shuttle” are deceiving thousands of users by posing as legitimate VPN services while secretly intercepting their web traffic and stealing sensitive login information. These …

Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Ontinue’s Cyber Defense Center have uncovered a significant threat as attackers exploit Nezha, a legitimate open-source server monitoring tool, for post-exploitation access. The discovery reveals how sophisticated threat …

CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting Digiever DS-2105 Pro network video recorders was added to the Known Exploited Vulnerabilities (KEV) catalog on December 22, 2025, following evidence of active exploitation in the …

Hackers Using ClickFix Technique to Hide Images within the Image Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have evolved their attack strategies by combining the deceptive ClickFix social engineering lure with advanced steganography techniques to conceal malicious payloads within PNG image files. This sophisticated approach, …

Spotify Music Library With 86M Music Files Scraped by Hacktivist Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The shadow library known as Anna’s Archive has executed a massive scrape of Spotify, releasing a torrent collection containing approximately 86 million audio tracks and metadata for 256 million songs. …

Malicious NPM Package with 56K Downloads Steals WhatsApp Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous npm package named “lotusbail” has been stealing WhatsApp messages and user data from thousands of developers worldwide. The package, which has been downloaded over 56,000 times, disguises itself …

BlindEagle Hackers Attacking Government Agencies with Powershell Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BlindEagle, a South American threat group, has launched a sophisticated campaign against Colombian government agencies, demonstrating an alarming evolution in attack techniques. In early September 2025, the group targeted a …

Sleeping Bouncer Vulnerability Impacts Motherboards from Gigabyte, MSI, ASRock and ASUS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has emerged affecting motherboards from Gigabyte, MSI, ASRock, and ASUS. Riot Games analysts and researchers identified a critical flaw during their ongoing investigation into gaming system …

Docker Open Sources Production-Ready Hardened Images for Free

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Docker has announced a significant shift in its container security strategy, making its Docker Hardened Images (DHI) freely available to all developers. Previously a commercial-only offering, DHI provides a set of secure, …

Arcane Werewolf Hacker Group Added Loki 2.1 Malware Toolkit to their Arsenal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The threat actor group known as Arcane Werewolf, also tracked as Mythic Likho, has refreshed its attack capabilities by deploying a new version of its custom malware called Loki 2.1. …