GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture to orchestrate security tools via natural-language prompts.​ Developed by GH05TCREW, …

Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP has patched multiple security vulnerabilities in its License Center application that could allow attackers to access sensitive information or disrupt services on affected NAS devices. The issues, tracked as CVE-2025-52871 and CVE-2025-53597, were disclosed on January 3, 2026. QNAP rated the flaws as Moderate severity and confirmed that the issues have …

Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Resecurity deploys synthetic data honeypots to outsmart threat actors, turning reconnaissance into actionable intelligence. A recent operation not only trapped an Egyptian-linked hacker but also duped the ShinyHunters group into false breach claims.​ Resecurity has refined deception technologies for counterintelligence, …

Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous cybercrime feedback loop has emerged where stolen credentials from infostealer malware enable attackers to hijack legitimate business websites and turn them into malware distribution platforms. Recent research by the Hudson Rock Threat Intelligence Team reveals this self-sustaining cycle …

Finland Arrests Two Cargo Ship Crew Members Over Undersea Cable Damage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Finnish authorities have detained all 14 crew members of a cargo vessel suspected of deliberately damaging an undersea telecommunications cable connecting Helsinki to Estonia. The ship, named Fitburg, was sailing from St. Petersburg, Russia, to Haifa, Israel, under a St. …

VVS Stealer Uses PyArmor Obfuscation to Evade Static Analysis and Signature Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape is witnessing a rise in sophisticated malware that leverages legitimate tools to mask malicious intent. A prime example is VVS Stealer (also styled VVS $tealer). This Python-based malware family has been actively marketed on Telegram since April …

The Kimwolf Botnet is Stalking Your Local Network

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. The vulnerability at issue has been exploited for months already, and it’s time for a broader awareness of the threat. The …

10,000+ Fortinet Firewalls Still Exposed to 5-year Old MFA Bypass Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 10,000 Fortinet firewalls worldwide remain vulnerable to CVE-2020-12812, a multi-factor authentication (MFA) bypass flaw disclosed over five and a half years ago. Shadowserver recently added the issue to its daily Vulnerable HTTP Report, highlighting persistent exposure amid active exploitation …

Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In December 2025, the Iranian-linked hacking group Handala claimed to have fully compromised the mobile devices of two prominent Israeli political figures. However, detailed analysis by Kela cyber intelligence researchers revealed a more limited scope—the breaches targeted Telegram accounts specifically, …

Hackers Abusing Google Tasks Notification for Sophisticated Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have launched a sophisticated phishing campaign exploiting Google Tasks notifications to target over 3,000 organizations worldwide, primarily in the manufacturing sector. The December 2025 attacks signal a dangerous shift in email-based threats, in which attackers abuse legitimate Google infrastructure …