Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malvertising campaign identified in September 2025 has brought a significant threat to Windows users worldwide. Attackers created fake PDF editing applications and promoted them through Google Ads to distribute a dangerous information-stealing malware called TamperedChef. The malware targets users …

Pulsar RAT Using Memory-Only Execution & HVNC to Gain Invisible Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pulsar RAT has emerged as a sophisticated derivative of the open-source Quasar RAT, introducing dangerous enhancements that enable attackers to maintain invisible remote access through advanced evasion techniques. This modular Windows-focused remote administration tool represents a significant evolution in threat …

ChatGPT Go Launched for $8 USD/month With Support for Ads and Privacy Risks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI’s global rollout of its budget-friendly ChatGPT Go subscription at $8 USD monthly introduces significant data privacy and security considerations for cybersecurity professionals monitoring AI platform access controls. The tiered pricing structure, which includes an ad-supported model for free and …

Apache bRPC Vulnerability Enables Remote Command Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote command-injection vulnerability has been discovered in Apache bRPC’s built-in heap profiler service, affecting all versions before 1.15.0 across all platforms. The vulnerability allows unauthenticated attackers to execute arbitrary system commands by manipulating the profiler’s parameter validation mechanisms. …

Google Gemini Privacy Controls Bypassed to Access Private Meeting Data Using Calendar Invite

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability within the Google ecosystem allowed attackers to bypass Google Calendar’s privacy controls using a standard calendar invitation. The discovery highlights a growing class of threats known as “Indirect Prompt Injection,” where malicious instructions are hidden within legitimate …

Remcos RAT Masquerade as VeraCrypt Installers Steals Users Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign targeting South Korean users has emerged, distributing the Remcos remote access trojan (RAT) through deceptive installers disguised as legitimate VeraCrypt encryption software. This ongoing attack campaign primarily focuses on individuals connected to illegal online gambling platforms, …

Threat Actors Weaponizing Visual Studio Code to Deploy a Multistage Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are turning Visual Studio Code into an attack platform, using its rich extension ecosystem to slip multistage malware into developer workstations. The latest campaign, dubbed Evelyn Stealer, hides behind a malicious extension that delivers a stealthy information stealing …

Inside the Leaks that Exposed the Hidden Infrastructure Behind a Ransomware Operation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybercrime world operates in shadows, but when insiders turn against each other, those shadows shrink. In February 2025, an individual using the alias ExploitWhispers surfaced on Telegram and released internal communications from the BlackBasta ransomware group. The leak contained …

Threat Actors Impersonate as MalwareBytes to Attack Users and Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign has emerged that tricks people into downloading fake Malwarebytes software, putting their login credentials and cryptocurrency wallets at serious risk. Security researchers discovered this operation actively spreading between January 11 and January 15, 2026, using specially …

Attackers are Using WSL2 as a Stealthy Hideout Inside Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Subsystem for Linux 2 (WSL2) is meant to give developers a fast Linux environment on Windows. Now attackers are turning that benefit into a hiding place. By running tools and payloads inside the WSL2 virtual machine, they can operate …