Bloody Wolf Hackers Mimic as Government Agencies to Deploy NetSupport RAT via Weaponized PDF’s

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Advanced Persistent Threat group known as Bloody Wolf has intensified its cyber espionage operations across Central Asia, targeting government and private sectors. Since late June 2025, the group has orchestrated spear-phishing campaigns primarily focusing on organizations within Kyrgyzstan …

Coupang Data Breach Exposed Personal Data of 33.7 Million Customers Personal Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

South Korean e-commerce giant Coupang has confirmed a massive security incident affecting approximately 33.7 million customers, nearly the company’s entire user base. The breach, which exposed names, phone numbers, email addresses, shipping addresses, and order histories, has been traced back …

4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

“ShadyPanda,” a sophisticated threat actor responsible for a seven-year campaign that has successfully infected 4.3 million Chrome and Edge users. By exploiting the inherent trust in browser marketplaces, ShadyPanda weaponized “Featured” and “Verified” extensions to deploy remote code execution (RCE) …

Hackers are Moving to “Living Off the Land” Techniques to Attack Windows Systems Bypassing EDR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have found a more effective method to compromise Windows computers while evading detection by security software. Ivan Spiridonov observed that uploading malicious tools, hackers are now using legitimate Windows programs already installed on target systems, a tactic known as …

OpenAI Codex CLI Command Injection Vulnerability Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has patched a command injection flaw in its Codex CLI tool that allowed attackers to execute arbitrary commands on developers’ machines simply by getting a malicious configuration file into a project repository. The issue, now fixed in Codex CLI …

Microsoft Azure API Management Flaw Enables Cross-Tenant Account Creation, Bypassing Admin Restrictions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Microsoft Azure API Management (APIM) Developer Portal enables attackers to register accounts across different tenant instances, even when administrators have explicitly disabled user signup through the portal interface. The flaw, which Microsoft has classified as …

Tomiris Hacker Group Added New Tools and Techniques to Attack Organizations Globally

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Tomiris hacker group has resurfaced with a sophisticated campaign targeting foreign ministries and government entities worldwide. Beginning in early 2025, this advanced persistent threat (APT) actor shifted its operational strategy to focus on high-value diplomatic infrastructure. By leveraging a …

Mystery OAST With Exploit for 200 CVEs Leveraging Google Cloud to Launch Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat has emerged in the cybersecurity landscape as security experts discover a private Out-of-Band Application Security Testing (OAST) service operating on Google Cloud infrastructure. This mystery operation stands out from typical exploit scanning activities because it uses custom …

APT36 Hackers Used Python-Based ELF Malware to Target Indian Government Entities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pakistan-based threat actor APT36, also known as Transparent Tribe, has launched a sophisticated cyber-espionage campaign against Indian government institutions using a newly developed Python-based ELF malware. The attack marks a significant escalation in the group’s capabilities, demonstrating their growing technical …

Kevin Lancaster Joins the usecure Board to Accelerate North American Channel Growth

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claymont, Delaware, December 1st, 2025, CyberNewsWire Lancaster’s arrival brings significant North American channel experience and expertise, supporting usecure’s ambition to cement its position as the market-leading human risk management solution for MSPs. usecure today announced the appointment of Kevin Lancaster …