QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QuasarRAT, initially surfacing in 2014 under the alias xRAT, began its lifecycle as a legitimate remote administration tool for Windows environments. Over the last decade, however, its open-source nature and accessibility have facilitated its transformation into a potent instrument for …

NVIDIA and Lakera AI Propose Unified Framework for Agentic System Safety

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As artificial intelligence systems become more autonomous, their ability to interact with digital tools and data introduces complex new risks. Recognizing this challenge, researchers from NVIDIA and Lakera AI have collaborated on a new paper proposing a unified framework for …

Hackers Can Leverage Delivery Receipts on WhatsApp and Signal to Extract User Private Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have exposed a critical privacy flaw dubbed “Careless Whisper” that lets attackers monitor user activity on WhatsApp and Signal through silent delivery receipts, without alerting victims or needing prior contact. By crafting stealthy messages like reactions to nonexistent …

Hackers Leverage Multiple Ad Networks to Attack Adroid Users With Triada Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mobile security continues to face significant challenges as sophisticated malware campaigns evolve to bypass traditional defenses. The Triada Trojan, a persistent threat to Android users for nearly a decade, has resurfaced with a highly coordinated operation targeting advertising networks. This …

CISA Adds Critical React2Shell Vulnerability to KEV Catalog Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting Meta React Server Components has been added to the Known Exploited Vulnerabilities catalog, signalling widespread active exploitation by CISA. Tracked as CVE-2025-55182, this remote code execution vulnerability poses an immediate threat to organizations that rely on …

Critical Cal.com Vulnerability Let Attackers Bypass Authentication Via Fake TOTP Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe authentication bypass vulnerability has been discovered in cal.com, the popular open-source scheduling platform. Allowing attackers to gain unauthorized access to user accounts by submitting fake TOTP codes. According to GitHub, flaw tracked as CVE-2025-66489, this critical flaw affects versions …

US Accounts for 44% of Cyber Attacks; Financial Gain Targets Public Administration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The United States continues to face an unprecedented surge in cyber threats, accounting for nearly half of all documented cyber attacks globally between 2024 and 2025. Recent data from the Cyber Events Database reveals that the US experienced 646 reported …

The ‘Kitten’ Project – Hacktivist Groups Carrying Out Attacks Targeting Israel

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Kitten Project has emerged as a coordinated hacktivist platform operating at the intersection of activism and technical operations. This initiative represents a shift in how cyber-focused groups organize their campaigns, moving beyond isolated attacks toward centralized infrastructure that facilitates …

LOLPROX Exposes Hidden Exploitation Paths that Can Enable Stealthy Hypervisor Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Proxmox Virtual Environment has become a popular choice for organizations building private cloud infrastructure and virtual machine management systems. However, a new analysis reveals significant security gaps in how the hypervisor can be exploited once an attacker gains initial access …

Hackers Compromising Developers with Malicious VS Code, Cursor AI Extensions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The developer tools used by millions of programmers worldwide have become a prime target for attackers seeking to compromise entire organizations. Visual Studio Code and AI-powered IDEs like Cursor AI, when combined with their extension marketplaces, present a critical vulnerability …