Malicious npm Packages Deliver PylangGhost RAT in New Software Supply Chain Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A remote access trojan known as PylangGhost has appeared on the npm registry for the first time, concealed inside two malicious JavaScript packages. The malware, first publicly disclosed by Cisco Talos in June 2025 and attributed to the North Korean …

Phishers Abuse LiveChat Support Tools to Steal Sensitive Data in New SaaS-Based Attack Tactic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified phishing campaign is turning legitimate customer service software into a weapon for stealing sensitive user data. Attackers have been found abusing LiveChat, a widely used Software-as-a-Service (SaaS) platform that businesses rely on for real-time customer support, to …

Researchers Decrypt and Exploit Encrypted Palo Alto Cortex XDR BIOC Rules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Methods Decrypt and Abuse Encrypted Palo Alto Cortex XDR BIOC Rules for Evasion Cybersecurity researchers have uncovered a critical evasion flaw in Palo Alto Networks’ Cortex XDR agent that allowed attackers to bypass behavioral detections completely. By reverse-engineering these encrypted …

New CondiBot Variant and ‘Monaco’ Cryptominer Expand Threats to Network Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Network infrastructure has become one of the most targeted areas in today’s threat landscape. Over recent years, attackers ranging from nation-state groups to financially driven criminal actors have steadily shifted their focus toward routers, firewalls, and other network devices. These …

Stryker Confirms Destructive Wiper Attack – Tens of Thousands of Devices Wiped

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Medical technology giant Stryker Corporation confirmed on March 11, 2026, that it suffered a significant cyberattack that disrupted its global Microsoft environment, with Iran-linked threat actor Handala claiming responsibility for what appears to be a politically motivated, destructive operation. Unlike …

Handala Hack Uses RDP, NetBird, and Parallel Wipers in MOIS-Linked Destructive Intrusions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An Iranian threat actor known as Handala Hack has carried out a series of destructive cyberattacks against organizations in Israel, Albania, and the United States, using remote desktop access, network tunneling, and multiple simultaneous data-wiping tools. The group operates under …

CamelClone Spy Campaign Abuses Public File-Sharing Sites and Rclone in Government-Focused Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated espionage campaign, tracked as Operation CamelClone, has been actively targeting government agencies, defense institutions, and diplomatic bodies across multiple countries, including Algeria, Mongolia, Ukraine, and Kuwait. The operation relies on spear-phishing emails carrying malicious ZIP archives disguised as …

Fake Shipment Tracking Scams Surge in MEA, Stealing Banking Data Through Real-Time Phishing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every day, billions of people rely on postal and courier services to deliver everything from personal letters to online orders. This dependence has grown steadily alongside the global rise of e-commerce. The 2024 Universal Postal Union report found that postal …

IBM Uncovers ‘Slopoly,’ Likely AI-Generated Malware Used in Hive0163 Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A concerning development has emerged in early 2026, as IBM X-Force uncovered a likely AI-generated malware strain they named “Slopoly,” deployed during a ransomware attack by the financially motivated threat group Hive0163. The group is primarily focused on large-scale data …

Qihoo 360 Leaked Its Own Wildcard SSL Private Key Inside Public AI Installer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China’s largest cybersecurity firm, Qihoo 360, has inadvertently exposed its own wildcard SSL private key by bundling it directly inside the public installer of its newly launched AI assistant, 360Qihoo (Security Claw). The flaw discovered on March 16, 2026, is …