Cellik Android Malware with One-Click APK Builder Let Attackers Wrap its Payload Inside with Google Play Store Apps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cellik represents a significant evolution in Android Remote Access Trojan capabilities, introducing sophisticated device control and surveillance features previously reserved for advanced spyware. This newly identified RAT combines full device takeover with an integrated Google Play Store connection, allowing attackers …

NVIDIA Isaac Lab Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security update addressing a dangerous deserialization vulnerability in NVIDIA Isaac Lab, a component of the NVIDIA Isaac Sim framework. The flaw could allow attackers to execute arbitrary code on affected systems, prompting the company to take immediate action. …

New GhostPoster Attack Leverages PNG Icon to Infect 50,000 Firefox Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign dubbed “GhostPoster” has been uncovered, leveraging a clever steganography technique to compromise approximately 50,000 Firefox users. The attack vector primarily involves seemingly innocent browser extensions, such as “Free VPN Forever,” which conceal malicious payloads within …

Chrome Security Update – Patch for Critical Vulnerabilities that Enables Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome version 143.0.7499.146/.147 to address critical security vulnerabilities that could enable remote code execution on affected systems. The update is now rolling out to Windows and Mac users, with Linux receiving version 143.0.7499.146. Full deployment is expected …

BlindEagle Hackers Attacking Organization to Abuse Trust and Bypass Email Security Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated cyberespionage campaign, the BlindEagle threat actor has once again targeted Colombian government institutions. This latest operation specifically zeroed in on an agency under the Ministry of Commerce, Industry, and Tourism, leveraging a highly effective strategy to bypass …

APT-C-35 Infrastructure Activity Leveraged Using Apache HTTP Response Indicators

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant discovery in threat intelligence reveals that APT-C-35, commonly known as DoNot, continues to maintain an active infrastructure footprint across the internet. Security researchers have identified new infrastructure clusters linked to this India-based threat group, which has long been …

Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Russian state-sponsored hacking group has been targeting network edge devices in Western critical infrastructure since 2021, with operations intensifying throughout 2025. The campaign, linked to Russia’s Main Intelligence Directorate (GRU) and the notorious Sandworm group, represents a major shift …

LLMs are Accelerating the Ransomware Operations with Functional Tools and RaaS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The integration of Large Language Models (LLMs) into ransomware operations marks a pivotal shift in the cybercrime landscape, functioning as a potent operational accelerator rather than a fundamental revolution. This technology dramatically lowers barriers to entry, enabling even low-skill actors …

Hackers Can Manipulate Internet-Based Solar Panel Systems to Execute Attacks in Minutes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new class of internet-based attacks is turning solar power infrastructure into a high‑risk target, allowing hackers to disrupt energy production in minutes using nothing more than open ports and free tools. Modern solar farms rely on networked operational technology, …

Microsoft Details Mitigations Against React2Shell RCE Vulnerability in React Server Components

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released comprehensive mitigations for a critical vulnerability dubbed React2Shell (CVE-2025-55182), which poses severe risks to React Server Components and Next.js environments. With a maximum CVSS score of 10.0, this pre-authentication remote code execution flaw allows threat actors to …