APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Advanced persistent threat actors operating from Pakistan have launched coordinated attacks against Indian government organizations using newly discovered tools and malware designed to bypass security defenses. The campaign, identified as Gopher Strike, emerged in September 2025 and represents a significant …

Multiple Vulnerabilities in React Server Components Enable DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical security vulnerabilities have recently been disclosed in React Server Components, enabling threat actors to launch Denial-of-Service (DoS) attacks against vulnerable servers. The flaws, tracked as CVE-2026-23864 with a CVSS score of 7.5, are due to incomplete patches from …

China-Aligned APTs Use PeckBirdy C&C Framework in Multi-Vector Attacks, Exploiting Stolen Certificates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since 2023, a dangerous malware framework called PeckBirdy has emerged as a primary weapon used by Chinese-aligned hacking groups. This JavaScript-based tool serves as a command-and-control platform designed to work across multiple system environments, giving attackers remarkable flexibility in how …

Threat Actors Using Fake Notepad++ and 7-zip Websites to Deploy Remote Monitoring Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly distributing malicious Remote Monitoring and Management (RMM) tools through fake websites that mimic popular software download pages. These deceptive sites impersonate legitimate utilities like Notepad++ and 7-Zip, tricking users into installing remote access tools such as LogMeIn …

Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released emergency out-of-band security updates on January 26, 2026, to address CVE-2026-21509, a zero-day security feature bypass vulnerability in Microsoft Office that attackers are actively exploiting. The flaw, rated “Important” with a CVSS v3.1 base score of 7.8, relies …

New Lawsuit Claims that Meta Can Read All the WhatsApp Users Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new class-action lawsuit accuses Meta Platforms of misleading billions of WhatsApp users by claiming their messages are protected by unbreakable end-to-end encryption. Filed in the San Francisco federal court, the suit alleges the company secretly stores, analyzes, and grants …

Best VPN Services of 2026: Fast, Secure & Affordable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In today’s digital world, online privacy and security have never been more important. With cybercrime on the rise and government surveillance becoming more common, protecting your personal information online is crucial. Whether you’re browsing on public Wi-Fi, shopping online, or …

Hundreds of Exposed Clawdbot Gateways Leave API Keys and Private Chats Vulnerable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Clawdbot, the surging open-source AI agent gateway, faces escalating security concerns, with 900+ unauthenticated instances exposed online and multiple code flaws that enable credential theft and remote code execution. Clawdbot is an open-source personal AI assistant that integrates with messaging …

Who Operates the Badbox 2.0 Botnet?

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0, a vast China-based botnet powered by malicious software …

Nova Ransomware Allegedly Claiming Breach of KPMG Netherlands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major accounting firm in the Netherlands has reportedly become the latest victim of Nova, an active ransomware operation. The breach was discovered and indexed by ransomware live on January 23, 2026, with the estimated attack date coinciding with the …