Hackers Leverage Malicious PyPI Package to Attack Users and Steal Cryptocurrency Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has surfaced targeting cryptocurrency users through a deceptive Python package hosted on the PyPI repository. The threat actors disguised their malicious code within a fake spell-checking tool, mimicking the legitimate pyspellchecker package that boasts over 18 …

New EtherHiding Attack Uses Web-Based Attacks to Deliver Malware and Rotate Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat known as EtherHiding is reshaping how malware spreads through the internet. Unlike older methods that rely on traditional servers to deliver harmful code, this attack uses blockchain smart contracts to store and update malware payloads. The approach …

ToddyCat APT Accessing Organizations Internal Communications of Employees at Target Companies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ToddyCat APT group has developed new ways to access corporate email communications at target organizations. Email remains the main way companies handle business communications, whether through their own servers like Microsoft Exchange or through cloud services such as Microsoft …

Zapier’s NPM Account Hacked and Multiple Packages Infected with Self-propogating Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive supply chain attack targeting the NPM accounts of automation giant Zapier and the Ethereum Name Service (ENS). Identified by Aikido Security, the campaign is being orchestrated by the same threat actors responsible for the “Shai Hulud” self-propagating worm …

Threats Actors Leverage Python-based Malware to Inject Process into a Legitimate Windows Binary

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated Python-based malware that employs process injection techniques to hide inside legitimate Windows binaries. This threat represents a new evolution in fileless attack strategies, combining multi-layer obfuscation with trusted system utilities to evade detection. The …

Hackers Replace ‘m’ with ‘rn’ in Microsoft(.)com to Steal Users’ Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign is currently leveraging a subtle typographical trick to bypass user vigilance, deceiving victims into handing over sensitive login credentials. Attackers utilize the domain “rnicrosoft.com” to impersonate the tech giant. By replacing the letter ‘m’ with the …

vLLM Vulnerability Enables Remote Code Execution Via Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical memory corruption vulnerability in vLLM versions 0.10.2 and later allows attackers to achieve remote code execution through the Completions API endpoint by sending maliciously crafted prompt embeddings. The vulnerability resides in the tensor deserialization process within vLLM’s entrypoints/renderer.py …

Beware of North Korean Fake Job Platform Targeting U.S. Based AI-Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated recruitment scam linked to North Korea has emerged, targeting American artificial intelligence developers, software engineers, and cryptocurrency professionals through an elaborate fake job platform. Validin security researchers have uncovered a new variant of what they call the “Contagious …

DeepSeek-R1 Makes Code for Prompts With Severe Security Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A concerning vulnerability in DeepSeek-R1, a Chinese-developed artificial intelligence coding assistant. When the AI model encounters politically sensitive topics related to the Chinese Communist Party, it produces code with severe security flaws at rates up to 50% higher than usual. …

Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Wireshark Foundation has rolled out a crucial security update for its widely used network protocol analyzer, addressing multiple vulnerabilities that could lead to denial-of-service conditions. The latest release, version 4.6.1, specifically targets flaws discovered in the Bundle Protocol version …