Attackers Redirected Employee Paychecks Without Breaching a Single System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A seemingly simple phone call became the gateway to a sophisticated attack that diverted employee paychecks without any malware or network breach. An organization discovered this fraud when workers reported …

New Spear-Phishing Attack Abusing Google Ads to Deliver EndRAT Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new spear-phishing campaign known as Operation Poseidon has emerged, exploiting Google’s advertising infrastructure to distribute EndRAT malware while evading traditional security measures. he attack leverages legitimate ad click tracking …

Cloudflare Zero-Day Vulnerability Enables Any Host Access Bypassing Protections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in Cloudflare’s Web Application Firewall (WAF) allowed attackers to bypass security controls and directly access protected origin servers through a certificate validation path. Security researchers from …

Free Converter Apps that Convert your Clean System to Infected in Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious file converter applications distributed through deceptive advertisements are infecting thousands of systems with persistent remote access trojans (RATs). These seemingly legitimate productivity tools perform their advertised functions while secretly …

Ukraine Police Exposed Russian Hacker Group Specializes in Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ukrainian and German law enforcement have disrupted a Russian‑affiliated hacker group that has been carrying out high‑impact ransomware attacks against organizations worldwide, causing losses estimated in the hundreds of millions …

Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has been discovered in Livewire Filemanager, a widely used file management component embedded in Laravel web applications. Tracked as CVE-2025-14894 and assigned vulnerability note VU#650657, the …

PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PDFSIDER is a newly exposed backdoor that gives attackers long term control of Windows systems while slipping past many antivirus and endpoint detection and response tools. It uses trusted software …

Researchers Gained Access to Hacker Domain Server Using Name Server Delegation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent investigation into a deceptive push-notification network shows how a simple DNS mistake can open a window into criminal infrastructure. The campaign abused browser notifications to flood Android users …

Windows SMB Client Vulnerability Enables Attacker to Own Active Directory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Windows SMB client authentication that enables attackers to compromise Active Directory environments through NTLM reflection exploitation. Classified as an improper access control vulnerability, this vulnerability allows …

CrashFix – Hackers Using Malicious Extensions to Display Fake Browser Warnings

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have discovered a sophisticated malware campaign using an unusual but effective tactic: deliberately crashing users’ browsers. The threat, named CrashFix, operates through a malicious Chrome extension disguised as …