Operation DupeHike Attacking Employees Using Weaponized Documents DUPERUNNER Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack campaign known as Operation DupeHike has emerged as a significant threat to Russian corporate environments, specifically targeting employees within human resources, payroll, and administrative departments. The campaign, …

Critical React and Next.js Enables Remote Attackers to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in React and Next.js could let remote attackers run malicious code on servers without logging in. The issue affects React Server Components (RSC) and the “Flight” …

Threat Actors Using Malicious VSCode Extension to Deploy Anivia Loader and OctoRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fake Visual Studio Code extension has been used in a supply chain attack that targets developers through their editor. The rogue extension, named prettier-vscode-plus and posing as the trusted …

India’s New SIM-Binding Rule for WhatsApp, Signal, Telegram and Other Messaging Platforms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

India has implemented a mandatory SIM-binding requirement for messaging applications, including WhatsApp, Telegram, Signal, Snapchat, and others. The Department of Telecommunications issued a directive on November 28 requiring all app-based …

Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Industrial Video & Control’s Longwatch video surveillance system, allowing attackers to execute malicious code with elevated privileges remotely. The flaw, tracked as CVE-2025-13658, …

Hackers Can Weaponize Claude Skills to Execute MedusaLocker Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new feature in Anthropic’s Claude AI, known as Claude Skills, has been identified as a potential vector for ransomware attacks. This feature, designed to extend the AI’s capabilities through …

Hackers Exploit Critical Yearn Finance’s yETH Pool Vulnerability to Steal $9 Million in Ethereum

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The decentralized finance sector witnessed a devastating breach targeting Yearn Finance’s yETH pool, resulting in the theft of approximately $9 million on November 30, 2025. The attacker executed a highly …

29.7 Tbps DDoS Attack Via Aisuru Botnet Breaks Internet With New World Record

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new 29.7 Tbps distributed denial-of-service (DDoS) blast from the Aisuru botnet has set a new world record for attack volume, underscoring how fragile core internet infrastructure remains under extreme …

Hackers Using Calendly-Themed Phishing Attack to Steal Google Workspace Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged targeting business professionals with Calendly-themed emails, combining social engineering with advanced credential theft techniques. The attack specifically focuses on Google Workspace and Facebook Business …

K7 Antivirus Vulnerability Allows Attackers Gain SYSTEM-level Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious privilege escalation vulnerability in K7 Ultimate Security, an antivirus product from K7 Computing, was found by abusing named pipes with overly permissive access control lists. This flaw enables …