Hackers Exploiting RMM Tools LogMeIn and PDQ Connect to Deploy Malware as a Normal Program

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are now exploiting remote monitoring and management tools to spread dangerous malware while avoiding detection by security systems. The attack campaign targets users who download what appears to be …

New Wave of Steganography Attacks: Hackers Hiding XWorm in PNGs 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ANY.RUN experts recently uncovered a new XWorm campaign that uses steganography to conceal malicious payloads inside seemingly harmless PNG images. What appears to be an ordinary graphic actually contains encrypted loaders that execute entirely in …

Google Sues ‘Lighthouse’ Phishing-as-a-service Kit Behind Massive Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google security researchers recently uncovered a sophisticated criminal operation called “Lighthouse” that has victimized over one million people across more than 120 countries. This phishing-as-a-service platform represents one of the …

MastaStealer Weaponizes Windows LNK Files, Executes PowerShell Command, and Evades Defender

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly documented malware campaign demonstrates how attackers are leveraging Windows LNK shortcuts to deliver the MastaStealer infostealer. The attack begins with spear-phishing emails containing ZIP archives with a single …

Microsoft Teams New Premium Feature Blocks Screenshots and Recordings During Meeting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has launched a new security feature in Teams Premium called “Prevent screen capture,” designed to block screenshots and recordings during sensitive meetings, with general availability rolling out worldwide through …

NHS Investigating Oracle EBS Hack Following Cl0p Ransomware Group Claim

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Cl0p ransomware group has claimed responsibility for breaching the UK’s National Health Service (NHS), spotlighting vulnerabilities in Oracle’s E-Business Suite (EBS). The announcement, posted on Cl0p’s dark web …

Multiple GitLab Vulnerabilities Let Attackers Inject Malicious Prompts to Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released urgent security patches addressing multiple vulnerabilities affecting both the Community Edition and the Enterprise Edition. The company released versions 18.5.2, 18.4.4, and 18.3.6 to fix critical security …

Multiple Kibana Vulnerabilities Enables SSRF and XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elastic Security has disclosed critical vulnerabilities affecting Kibana that could enable attackers to execute Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS) attacks against vulnerable deployments. The vulnerabilities stem from …

Microsoft Defender for O365 New Feature Allows Security Teams to Trigger Automated Investigations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has rolled out enhanced remediation capabilities in Defender for Office 365 (O365), enabling security teams to initiate automated investigations and other actions directly from the Advanced Hunting interface. This …