PDFly Variant Uses Custom PyInstaller Modification, Forcing Analysts to Reverse-Engineer Decryption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new variant of the PDFly malware has emerged with advanced techniques that challenge traditional analysis methods. The malware uses a modified PyInstaller executable that prevents standard extraction tools from …

French Authorities Raid X Office Following Cybercrime Allegations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

French authorities raided the Paris headquarters of Elon Musk’s social media platform X today, escalating a year-old cybercrime probe into alleged algorithmic manipulation and illicit content distribution. The operation, led …

Microsoft to Disable NTLM by Default as a Step Towards More Secure Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The transition away from NTLM (New Technology LAN Manager), a legacy authentication protocol that has existed in Windows for over three decades, is being accelerated. The company has announced a …

Mozilla Unveils Kill Switch to Disable All Firefox AI features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Firefox 148 introduces comprehensive AI controls, giving users greater control over artificial intelligence features built into the browser. The new security-focused setting provides a centralized toggle to block current and …

Beware of Malicious Party Invitations that Tricks Users into Installing Remote Access Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign is tricking people with fake party invitations that secretly install remote access software on Windows computers. The attack uses social engineering to deliver ScreenConnect, a legitimate …

Apache Syncope Vulnerability Let Attackers Hijack User Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical XML External Entity (XXE) vulnerability has been disclosed in the Syncope identity management console. The flaw could allow administrators to expose sensitive user data and compromise session security …

APT28 Hackers Exploiting Microsoft Office 0-Day in the Wild to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT28, the Russia-linked advanced persistent threat group, has launched a sophisticated campaign targeting Central and Eastern Europe using a zero-day vulnerability in Microsoft Office. The threat actors leveraged specially crafted …

Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous banking malware called Anatsa has been discovered spreading through the Google Play Store, reaching more than fifty thousand downloads before detection. The malicious application was cleverly hidden as …

Hikvision Wireless Access Points Vulnerability Enables Malicious Command Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authenticated command execution vulnerability has been disclosed affecting multiple Hikvision Wireless Access Point (WAP) models. The flaw, tracked as CVE-2026-0709, stems from insufficient input validation in device firmware, …

OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hundreds of malicious skills designed to deliver trojans, infostealers, and backdoors disguised as legitimate automation tools. VirusTotal has uncovered a significant malware distribution campaign targeting OpenClaw, a rapidly growing personal …