Malicious VS Code on Microsoft Registry Captures Your Screen and Steals Your WiFi Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly weaponizing developer environments, as seen in a newly discovered malware campaign infiltrating the Visual Studio Code Marketplace. Unlike typical extensions that simply harvest credentials or mine cryptocurrency, …

GhostPenguin Backdoor With Zero-Detection Attacking Linux Servers Uncovered Using AI-Automated Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A previously undocumented Linux backdoor named GhostPenguin has been discovered evading detection for over four months. This multi-threaded C++ malware establishes remote shell access and file-system operations via encrypted UDP, …

Hackers Exploiting Vulnerabilities in Ivanti Connect Secure to Deploy MetaRAT Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A China-based attack group has launched a targeted campaign against Japanese shipping and transportation companies by exploiting critical vulnerabilities in Ivanti Connect Secure (ICS). The campaign, uncovered in April 2025, …

New Mirai Botnet Variant ‘Broadside’ Actively Attacking Users in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of the Mirai botnet, named “Broadside,” has emerged as an active threat targeting maritime shipping companies and vessel operators. The malware exploits a critical vulnerability in …

Microsoft Copilot Disruption in the UK: Users Face Access Issues and Degraded Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft 365 services encountered a snag today, leaving users in the United Kingdom struggling to access Microsoft Copilot or experiencing reduced functionality in key features. The outage, flagged on the …

AI-Powered Free Security-Audit Checklist for 2026 – ISO 27001, SOC 2, NIST, NIS 2 and GDPR Compliance 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In many companies, audit preparation in 2025 still feels like 2005: Excel lists, scattered evidence, copy & paste from old answers, long coordination loops. At the same time, requirements are …

Authorities Arrested Hackers With Specialized FLIPPER Hacking Equipment Used to Attack IT Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Authorities in Warsaw have arrested three suspected hackers found carrying specialized FLIPPER hacking equipment. Other tools are allegedly intended to attack IT and telecommunications systems. The suspects, all Ukrainian citizens …

Operation FrostBeacon Attacking Finance and Legal Departments with Cobalt Strike Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged targeting financial and legal sectors in the Russian Federation, delivering the notorious Cobalt Strike remote access tool to organizations handling sensitive business transactions. Security …

New Multi-stage JS#SMUGGLER Malware Attack Delivers ‘NetSupport RAT’ to Gain Full System Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign using multiple attack stages has been discovered that delivers NetSupport RAT through hidden web-based redirects and obfuscated code. The attack unfolds in three stages, starting with …

SAP Security Patch Day: Fix for Critical Vulnerabilities in SAP Solution Manager, NetWeaver, and Other Products

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SAP released 14 new security notes on its monthly Security Patch Day on December 9, 2025, addressing vulnerabilities across key products, including SAP Solution Manager, NetWeaver, Commerce Cloud, and more. …