Hackers Exploiting VMware ESXi Instances in the Wild Using zero-day Exploit Toolkit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are exploiting VMware ESXi instances in the wild with a zero-day exploit toolkit that chains multiple vulnerabilities for VM escapes. Cybersecurity firm Huntress disrupted one such attack, attributing initial access to a compromised SonicWall VPN.​ Threat actors gained a …

Hackers Using Malicious Imageless QR Codes to Render Phishing Attack Via HTML Table

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent phishing campaign is abusing QR codes in a new way, turning simple HTML tables into working codes that redirect users to malicious sites. Instead of embedding a QR image in the email body, the attackers build the code …

Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns Delivering Multiple Malware Families

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Windows packer known as pkr_mtsi has emerged as a powerful tool for delivering multiple malware families through widespread malvertising campaigns. First detected on April 24, 2025, this malicious packer continues to operate actively, distributing trojanized installers disguised as …

ownCloud Urges Users to Enable Multi-Factor Authentication Following Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ownCloud has urgently urged users of its Community Edition to enable multi-factor authentication (MFA). A threat intelligence report from Hudson Rock highlighted incidents in which attackers compromised self-hosted file-sharing platforms, including some ownCloud deployments, but ownCloud stresses that its platform …

GoBruteforcer Botnet brute-forces Passwords for FTP, MySQL, and phpMyAdmin on Linux Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Go-based botnet dubbed GoBruteforcer is aggressively targeting Linux servers worldwide, brute-forcing weak passwords on internet-exposed services including FTP, MySQL, PostgreSQL, and phpMyAdmin. Check Point Research recently documented a new 2025 variant of the malware that demonstrates significant technical …

From Tycoon2FA to Lazarus Group – Inside ANY.RUN’s Biggest Discoveries of 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ANY.RUN, the interactive malware analysis platform, has wrapped up 2025 with impressive growth figures and significant contributions to the cybersecurity community. The company’s annual report reveals how its global user base collectively spent over 400,000 hours analyzing threats—equivalent to more …

Researchers Manipulate Stolen Data to Corrupt AI Models and Generate Inaccurate Outputs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from the Chinese Academy of Sciences and Nanyang Technological University have introduced AURA, a novel framework to safeguard proprietary knowledge graphs in GraphRAG systems against theft and private exploitation. Published on arXiv just a week ago, the paper highlights …

Chinese Hackers Deploy NFC-enabled Android Malware to Steal Payment Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese threat actors have launched a sophisticated campaign using NFC-enabled Android malware called Ghost Tap to intercept and steal financial information from victims worldwide. The malware operates through a deceptive distribution model, where attackers trick users into downloading seemingly legitimate …

Threat Actors Leversges Google Cloud Services to Steal Microsoft 365 Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing campaign has emerged, leveraging the trusted infrastructure of Google Cloud services to bypass security filters and steal sensitive Microsoft 365 login credentials. By abusing legitimate workflow automation tools, threat actors are crafting convincing attacks that blend …

Microsoft to Cancel Plans Imposing Daily Limit For Exchange Online Bulk E-mails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced the indefinite cancellation of its Mailbox External Recipient Rate Limit in Exchange Online, reversing a previously planned restriction on bulk email sending. The decision comes after significant customer feedback highlighting operational disruptions caused by the proposed limitation. …