Hackers Leveraging Windows Screensaver to Deploy RMM Tools and Gain Remote Access to Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity threats are constantly evolving, and a recent campaign highlights a deceptive new tactic where attackers leverage Windows screensaver (.scr) files to compromise systems. This method allows threat actors to …

New Epstein Tool Searches LinkedIn Connections Against 3.5 Million Pages Epstein Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Epstein Tool A new open-source Python tool named EpsteIn enables users to check if their LinkedIn connections appear in over 3.5 million pages of Jeffrey Epstein court documents recently released …

Spam Campaign Distributes Fake PDFs, Installing Remote Monitoring Tools for Persistent Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security teams have discovered an active spam campaign that uses fake PDF documents to trick users into installing remote monitoring and management (RMM) software. The campaign targets organizations by sending …

New CentOS 9 Vulnerability Lets Attackers Escalate to Root Privileges – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CentOS 9 Vulnerability A critical use-after-free (UAF) vulnerability in the Linux kernel’s sch_cake queuing discipline (Qdisc) affects CentOS 9, allowing local users to gain root privileges. Security firm SSD Secure …

Betterment Data Breach Exposes 1.4 million Customers Personal Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Betterment Data Breach Betterment has disclosed a social engineering–driven data breach that exposed personal information for approximately 1.4 million customer accounts, significantly expanding the fallout from a January 2026 security …

Attackers Mimic RTO Challan Notifications to Deliver Android Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android malware campaign targeting Indian users has emerged, disguising itself as legitimate Regional Transport Office (RTO) challan notifications. The malicious applications are distributed outside the Google Play Store, …

ShadowSyndicate Using Server Transition Technique in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ShadowSyndicate, a malicious activity cluster first identified in 2022, has evolved its infrastructure management techniques by adopting a server transition method that allows the threat actor to rotate SSH keys …

WatchGuard VPN Client for Windows Vulnerability Enables Command Execution With SYSTEM Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WatchGuard VPN Client Windows Vulnerability A security advisory addressing a significant privilege-escalation vulnerability affecting its Mobile VPN with an IPSec client for Windows. The flaw, identified as WGSA-2026-00002, allows local …

Critical n8n Vulnerability Enables System Command Execution Via Weaponized Workflows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

n8n Vulnerability A critical remote code execution (RCE) vulnerability in n8n, the popular workflow automation platform. This flaw allows authenticated attackers to execute arbitrary system commands on the host server …

Microsoft to Add Sysmon Threat Detection Feature Natively to Windows 11

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Add Sysmon Windows 11 A major upgrade has been announced to enhance capabilities for cybersecurity defenders and threat hunters in the Windows ecosystem. With the release of Windows 11 …