FBI Warns of Fake Internet Crime Complaint Center (IC3) Website Used for Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Bureau of Investigation (FBI) has issued urgent warnings about cybercriminals spoofing the official Internet Crime Complaint Center (IC3) website to conduct phishing attacks and steal sensitive personal information. These fake sites mimic the legitimate www.ic3.gov portal with near-perfect …

Akira Ransomware Uses SonicWall VPN Exploit to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Akira ransomware group has begun weaponizing vulnerabilities in SonicWall SSL VPN devices, turning merger-and-acquisition (M&A) processes into high-speed launchpads for cyberattacks. This trend exposes dangerous blind spots for businesses acquiring smaller companies, as inherited SonicWall devices often serve as …

New “JackFix” Attack Leverages Windows Updates into Executing Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated ClickFix campaign dubbed “JackFix” that uses fake adult websites to hijack screens with realistic Windows Update prompts, tricking users into running multistage malware payloads. Attackers mimic popular adult sites like xHamster clones to lure victims, likely via malvertising …

Hackers Exploit NTLM Authentication Flaws to Target Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

More than two decades after its initial discovery, the NTLM authentication protocol continues to plague Windows systems worldwide. What started in 2001 as a theoretical vulnerability has evolved into a widespread security crisis, with attackers actively weaponizing multiple NTLM flaws …

Hackers Sell Lifetime Access to WormGPT and KawaiiGPT for Just $220

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are now selling lifetime access to malicious AI chatbots WormGPT and KawaiiGPT for as little as $220, marking a dangerous new chapter in AI-powered cybercrime. These tools remove all ethical restrictions found in mainstream AI models, enabling attackers to …

Indirect-Shellcode-Executor Tool Exploits Windows API Vulnerability to Evade AV and EDR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new offensive security tool developed in Rust is demonstrating a novel method for bypassing modern Endpoint Detection and Response (EDR) systems by exploiting an overlooked behavior in the Windows API. Dubbed Indirect-Shellcode-Executor, the tool leverages the ReadProcessMemory function to …

Microsoft Details Security Risks of New Agentic AI Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, discussions have centered on Microsoft’s experimental agentic AI feature, which has introduced both advanced task automation and significant security concerns. This agentic capability, available to Windows insiders as part of Copilot Labs, is designed to allow digital …

Developers Expose Passwords and API Keys via Online Tools like JSONFormatter

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Developers are unintentionally exposing passwords, API keys, and sensitive data in production information into online formatting tools such as JSONFormatter and CodeBeautify. New research from watchTowr shows that thousands of secrets from critical organizations have been publicly accessible for years …

HashJack: New Attack Technique Tricks AI Browsers Using a Simple ‘#’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Cato CTRL have discovered a new indirect prompt injection technique called HashJack, which weaponises legitimate websites to manipulate AI browser assistants. The attack conceals malicious instructions after the “#” symbol within trusted URLs, enabling threat actors to conduct …

Tor Adopts Galois Onion Encryption to Strengthen Defense Against Online Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Tor Project has announced a significant cryptographic overhaul, retiring its legacy relay encryption algorithm after decades of service and replacing it with Counter Galois Onion (CGO). This research-backed encryption design defends against a broader class of sophisticated online attackers. …