Threat Actors Impersonate as MalwareBytes to Attack Users and Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign has emerged that tricks people into downloading fake Malwarebytes software, putting their login credentials and cryptocurrency wallets at serious risk. Security researchers discovered this operation actively spreading between January 11 and January 15, 2026, using specially …

Attackers are Using WSL2 as a Stealthy Hideout Inside Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Subsystem for Linux 2 (WSL2) is meant to give developers a fast Linux environment on Windows. Now attackers are turning that benefit into a hiding place. By running tools and payloads inside the WSL2 virtual machine, they can operate …

Attackers Redirected Employee Paychecks Without Breaching a Single System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A seemingly simple phone call became the gateway to a sophisticated attack that diverted employee paychecks without any malware or network breach. An organization discovered this fraud when workers reported missing salary deposits. The attacker had modified direct-deposit information to …

New Spear-Phishing Attack Abusing Google Ads to Deliver EndRAT Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new spear-phishing campaign known as Operation Poseidon has emerged, exploiting Google’s advertising infrastructure to distribute EndRAT malware while evading traditional security measures. he attack leverages legitimate ad click tracking domains to disguise malicious URLs, making them appear as trustworthy …

Cloudflare Zero-Day Vulnerability Enables Any Host Access Bypassing Protections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in Cloudflare’s Web Application Firewall (WAF) allowed attackers to bypass security controls and directly access protected origin servers through a certificate validation path. Security researchers from FearsOff discovered that requests targeting the /.well-known/acme-challenge/ directory could reach …

Free Converter Apps that Convert your Clean System to Infected in Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious file converter applications distributed through deceptive advertisements are infecting thousands of systems with persistent remote access trojans (RATs). These seemingly legitimate productivity tools perform their advertised functions while secretly installing backdoors that give attackers continuous access to victim computers. …

Ukraine Police Exposed Russian Hacker Group Specializes in Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ukrainian and German law enforcement have disrupted a Russian‑affiliated hacker group that has been carrying out high‑impact ransomware attacks against organizations worldwide, causing losses estimated in the hundreds of millions of euros. According to Ukraine’s Cyber Police and the Main …

Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has been discovered in Livewire Filemanager, a widely used file management component embedded in Laravel web applications. Tracked as CVE-2025-14894 and assigned vulnerability note VU#650657, the flaw enables unauthenticated attackers to execute arbitrary code on vulnerable …

PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PDFSIDER is a newly exposed backdoor that gives attackers long term control of Windows systems while slipping past many antivirus and endpoint detection and response tools. It uses trusted software and strong encryption to hide its presence, letting intruders run …

Researchers Gained Access to Hacker Domain Server Using Name Server Delegation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent investigation into a deceptive push-notification network shows how a simple DNS mistake can open a window into criminal infrastructure. The campaign abused browser notifications to flood Android users with fake security alerts, gambling lures, and adult offers. Random-looking …