Hackers Using ClickFix Technique to Hide Images within the Image Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have evolved their attack strategies by combining the deceptive ClickFix social engineering lure with advanced steganography techniques to conceal malicious payloads within PNG image files. This sophisticated approach, …

Spotify Music Library With 86M Music Files Scraped by Hacktivist Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The shadow library known as Anna’s Archive has executed a massive scrape of Spotify, releasing a torrent collection containing approximately 86 million audio tracks and metadata for 256 million songs. …

Malicious NPM Package with 56K Downloads Steals WhatsApp Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous npm package named “lotusbail” has been stealing WhatsApp messages and user data from thousands of developers worldwide. The package, which has been downloaded over 56,000 times, disguises itself …

BlindEagle Hackers Attacking Government Agencies with Powershell Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BlindEagle, a South American threat group, has launched a sophisticated campaign against Colombian government agencies, demonstrating an alarming evolution in attack techniques. In early September 2025, the group targeted a …

Sleeping Bouncer Vulnerability Impacts Motherboards from Gigabyte, MSI, ASRock and ASUS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has emerged affecting motherboards from Gigabyte, MSI, ASRock, and ASUS. Riot Games analysts and researchers identified a critical flaw during their ongoing investigation into gaming system …

Docker Open Sources Production-Ready Hardened Images for Free

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Docker has announced a significant shift in its container security strategy, making its Docker Hardened Images (DHI) freely available to all developers. Previously a commercial-only offering, DHI provides a set of secure, …

Arcane Werewolf Hacker Group Added Loki 2.1 Malware Toolkit to their Arsenal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The threat actor group known as Arcane Werewolf, also tracked as Mythic Likho, has refreshed its attack capabilities by deploying a new version of its custom malware called Loki 2.1. …

Lies-in-the-Loop Attack Turns AI Safety Dialogs into Remote Code Execution Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered attack technique has exposed a critical weakness in artificial intelligence code assistants by weaponizing their built-in safety features. The attack, known as Lies-in-the-Loop, manipulates the trust users …

Multiple Exim Server Vulnerabilities Let Attackers Seize Control of the Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at the National Institute of Standards and Technology (NIST) have uncovered critical security flaws in the Exim mail server. That could allow remote attackers to take complete control …

Hackers Using Phishing Tools to Access M365 Accounts via OAuth Device Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are now targeting Microsoft 365 accounts using a growing attack method known as OAuth device code phishing. This technique takes advantage of the OAuth 2.0 device authorization flow, …