Fake FileZilla Downloads Lead to RAT Infections Through Stealthy Multi-Stage Loader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign has been discovered delivering a Remote Access Trojan through fake websites impersonating the official FileZilla download page. Attackers designed these fraudulent sites to closely mirror the real FileZilla page, tricking users into downloading malicious installer files. …

New ACRStealer Variant Uses Syscall Evasion, TLS C2 and Secondary Payload Delivery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new variant of ACRStealer has emerged with upgraded capabilities that make it significantly harder to detect and more dangerous to the systems it targets. First reported by Proofpoint in early 2025 as a rebranded version of the Amatera Stealer, …

Microsoft Exchange Online Mailbox Access Outage Affects Users Globally

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is currently investigating a service disruption affecting Exchange Online users who are experiencing difficulties accessing their mailboxes through one or more connection methods. The issue, tracked under Microsoft 365’s service health dashboard, has prompted multiple status updates throughout Monday, …

Android 17 Advanced Protection Mode to Block Malicious Service Usage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Android 17 Advanced Protection Mode Google is preparing to launch Android 17, bringing a comprehensive set of new APIs and system capabilities to fundamentally improve device security, user privacy, and performance debugging. At the forefront of this release is the …

Attackers Abuse Microsoft Teams and Quick Assist to Drop Stealthy A0Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified backdoor called A0Backdoor has emerged as part of a calculated social-engineering campaign that abuses Microsoft Teams and the Windows remote assistance tool Quick Assist. The threat group is tracked under aliases including Blitz Brigantine, Storm-1811, and STAC5777, …

OpenClaw AI Agents Leaking Sensitive Data in Indirect Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenClaw AI Agents Leaking Sensitive Data Indirect Prompt Injection Attackers can exploit insecure defaults and prompt injection vulnerabilities to turn normal agent behavior into a silent data-exfiltration pipeline. The core issue is not just confusing the AI model; it is …

Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A set of nine novel cross-tenant vulnerabilities in Google Looker Studio, collectively dubbed “LeakyLooker,” that could have allowed attackers to run arbitrary SQL queries, exfiltrate sensitive data, and even modify or delete records across Google Cloud environments, all without victims …

Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows 11 and Server 2025 Automated Installation Microsoft has announced a two-phase plan to disable the hands-free deployment feature in Windows Deployment Services (WDS) following the discovery of a critical remote code execution (RCE) vulnerability tracked as CVE-2026-0386. The flaw, …

Meta to Permanently Remove End-to-End Encryption Feature in Instagram DMs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta has confirmed it will permanently remove end-to-end encryption (E2EE) support from Instagram direct messages, with the feature officially shutting down after May 8, 2026. The announcement, quietly posted on Instagram’s Help Center support page, marks a significant reversal from …

Microsoft Releases Out-of-Band Patch to Fix Critical RRAS RCE Vulnerabilities in Windows 11

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2. Tracked as KB5084597 and targeting OS Builds 26200.7982 and 26100.7982, this update patches three actively concerning flaws in the …