Attackers Using DNS TXT Records in ClickFix Script to Execute Powershell Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has darkened with the sophisticated evolution of the KongTuke campaign. Active since mid-2025, this threat actor group has continuously refined its techniques to bypass conventional enterprise security filters. Their primary weapon remains the “ClickFix” strategy, a social …

Amaranth-Dragon Exploiting WinRAR Vulnerability to Gain Persistent to Victim Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber-espionage group known as Amaranth-Dragon has launched a series of highly targeted attacks against government and law enforcement agencies across Southeast Asia. Active throughout 2025, these campaigns have demonstrated a keen interest in geopolitical intelligence, often timing their …

CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware ESXi 0-day Ransomware Attack The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability. This flaw, patched by Broadcom in March 2025, enables attackers to …

Multiple TP-Link OS Command Injection Vulnerabilities Let Attackers Gain Admin Control of the Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TP-Link OS Command Injection Vulnerabilities TP-Link has released urgent firmware updates for its Archer BE230 Wi-Fi 7 routers to address multiple high-severity security flaws. These vulnerabilities could allow authenticated attackers to execute arbitrary operating system (OS) commands, effectively granting them …

SystemBC Botnet Hijacked 10,000 Devices Worldwide to Use for DDoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The SystemBC malware family, a persistent threat first documented in 2019, has evolved into a massive botnet infrastructure controlling over 10,000 hijacked devices globally. Functioning primarily as a SOCKS5 proxy and a backdoor, this malware enables threat actors to mask …

PhantomVAI Custom Loader Uses RunPE Utility to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated custom loader named PhantomVAI has emerged in global phishing campaigns, delivering various stealers and remote access trojans (RATs) to compromised systems. This malware loader operates by masquerading as legitimate software and employing process hollowing techniques to inject malicious …

Interlock Ransomware Actors New Tool Exploiting Gaming Anti-Cheat Driver 0-Day to Disable EDR and AV

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Interlock ransomware group has emerged as a distinct threat in the cybersecurity landscape, particularly targeting the education sector in the United States and United Kingdom. Unlike many contemporary ransomware operations that function under a Ransomware-as-a-Service (RaaS) model, Interlock operates …

False Negatives Are a New SOC Headache. Here’s the Fast Way to Fix It 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

False negatives are becoming the most expensive “quiet” failure in SOCs. In 2026, AI-generated phishing and multi-stage malware chains are built to look clean on the outside, behave normally at first, and only reveal intent after real interaction. The result …

MomentProof Deploys Patented Digital Asset Protection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Washington, DC, February 4th, 2026, CyberNewsWire MomentProof, Inc., a provider of AI-resilient digital asset certification and verification technology, today announced the successful deployment of MomentProof Enterprise for AXA, enabling cryptographically authentic, tamper-proof digital assets for insurance claims processing. MomentProof’s patented …

Supply Chain Attack Abused Notepad++ Update Infrastructure to Deliver Targeted Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The developers of Notepad++ disclosed a critical security breach on February 2, 2026, affecting their update infrastructure. The popular text editor, widely used by developers worldwide, became the target of a sophisticated supply chain attack that remained undetected for several …