Roundcube Webmail Vulnerability Let Attackers Track Email Opens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Roundcube Webmail Vulnerability Roundcube, one of the world’s most popular open-source webmail solutions, has released critical security updates to address a privacy bypass vulnerability. The flaw detailed by NULL CATHEDRAL allowed attackers to load remote images and track email opens, …

New Node.js Based LTX Stealer Attack Users to Exfiltrate Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware strain dubbed “LTX Stealer” has emerged in the cyber threat landscape, utilizing a unique Node.js-based architecture to compromise Windows systems. First surfacing in early 2026, this malicious tool is designed to harvest sensitive user information, including …

European Commission Contains Cyber-Attack Targeting Staff Mobile Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

European Commission Cyber-Attack The European Commission has confirmed the detection and containment of a security incident affecting the central infrastructure that manages staff mobile devices. The breach, identified on January 30 through internal telemetry, resulted in unauthorized access to a …

Hackers Exploiting ClawHub Skills to Bypass VirusTotal Detections via Social Engineering

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have significantly evolved their attack strategies recently observed within the ClawHub ecosystem, moving away from easily detectable methods to more subtle techniques. Rather than embedding malicious payloads directly into files, they now host these dangers on convincing external …

Vortex Werewolf Attacking Organizations to Gain Tor-Enabled Remote Access Over the RDP, SMB, SFTP, and SSH Protocols

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new cyber espionage cluster has recently emerged, focusing its aggressive targeting on Russian government and defense organizations. Active since at least December 2025, the group, designated as Vortex Werewolf, employs a combination of social engineering and legitimate software utilities …

New RecoverIt Tool Exploits Windows Service Failure Recovery Functions to Execute Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

RecoverIt Tool A new open-source offensive security tool named “RecoverIt” has been released, offering Red Teamers and penetration testers a novel method for establishing persistence and executing lateral movement on compromised Windows systems. The tool, developed by security researcher TwoSevenOneT, …

Critical FortiClientEMS Vulnerability Let Attackers Execute Malicious Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiClientEMS RCE Vulnerability Fortinet has issued a critical security advisory warning administrators to immediately patch instances of FortiClientEMS, its central management solution for endpoint protection. The vulnerability, tracked as CVE-2026-21643, carries a CVSSv3 score of 9.1 and could allow unauthenticated, …

New Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Telegram phishing campaign has re-emerged, marking a significant evolution in how threat actors compromise user accounts. Unlike traditional credential harvesting, this operation does not rely on cloning login pages to steal passwords but instead manipulates the platform’s legitimate …

Ransomware Detection With Windows Minifilter by Intercepting File Filter and Change Events

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware continues to be the most financially damaging type of cyberattack affecting organizations around the world. One of the most effective tools for monitoring in Windows is the minifilter driver. By sitting directly in the file system I/O pipeline, a …

Black Basta Ransomware Actors Embeds BYOVD Defense Evasion Component with Ransomware Payload Itself

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware actors are constantly refining their arsenals to bypass modern defenses. A recent campaign by the Black Basta group has introduced a significant tactical shift by embedding a “Bring Your Own Vulnerable Driver” (BYOVD) component directly into the ransomware payload …