Google Chrome 0-Day Vulnerability Actively Exploited in the Wild – Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an emergency security update for its Chrome web browser to address a high-severity zero-day vulnerability that is being actively exploited in the wild. Users are strongly urged …

MuddyWater Hackers Using Custom Malware With Multi-Stage Payloads and Uses Cloudflare to Mask Fingerprints

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since early 2025, cybersecurity teams have observed a marked resurgence in operations attributed to MuddyWater, an Iranian state–sponsored advanced persistent threat (APT) actor. Emerging initially through broad remote monitoring and …

BeaverTail Variant via Malicious Repositories Targeting Retail Sector Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated North Korean nation-state threat actor campaign has emerged, distributing an evolved variant of the BeaverTail malware through deceptive fake hiring platforms and ClickFix social engineering tactics. This latest …

China-Aligned TA415 Hackers Uses Google Sheets and Google Calendar for C2 Communications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Chinese state-sponsored threat actor TA415 has evolved its tactics, techniques, and procedures by leveraging legitimate cloud services like Google Sheets and Google Calendar for command and control communications in …

New Magecart Skimmer Attack With Malicious JavaScript Injection to Skim Payment Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The threat landscape for e-commerce websites has once again shifted with the emergence of a sophisticated Magecart-style attack campaign, characterized by the deployment of obfuscated JavaScript to harvest sensitive payment …

224 Malicious Android Apps on Google Play With 38 Million Downloads Delivering Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated mobile ad fraud operation dubbed “SlopAds” has infiltrated Google Play Store with 224 malicious applications that collectively amassed over 38 million downloads across 228 countries and territories. The …

New in Syteca Release 7.21: Agentless Access, Sensitive Data Masking, and Smooth Session Playback

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Syteca, a global cybersecurity provider, introduced the latest release of its platform, continuing the mission to help organizations reduce insider risks and ensure sensitive data protection. Syteca 7.21 is a …

Hackers Exploit RTL/LTR Scripts and Browser Gaps to Hide Malicious URLs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A decade-old Unicode vulnerability known as BiDi Swap allows attackers to spoof URLs for sophisticated phishing attacks. By exploiting how browsers render mixed Right-to-Left (RTL) and Left-to-Right (LTR) language scripts, …

Microsoft Dismantles 300+ Websites Used to Distribute RaccoonO365 Phishing Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since mid-2024, cybercriminals have leveraged a subscription-based phishing platform known as RaccoonO365 to harvest Microsoft 365 credentials at scale. Emerging as an off-the-shelf service, RaccoonO365 requires minimal technical skill, allowing …

Threat Actors Abuse Adtech Companies to Target Users With Malicious Ads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The digital advertising ecosystem has become a prime hunting ground for cybercriminals, who are increasingly exploiting advertising technology companies to distribute malware and conduct malicious campaigns. Rather than simply abusing …