New “JackFix” Attack Leverages Windows Updates into Executing Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated ClickFix campaign dubbed “JackFix” that uses fake adult websites to hijack screens with realistic Windows Update prompts, tricking users into running multistage malware payloads. Attackers mimic popular adult …

Hackers Exploit NTLM Authentication Flaws to Target Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

More than two decades after its initial discovery, the NTLM authentication protocol continues to plague Windows systems worldwide. What started in 2001 as a theoretical vulnerability has evolved into a …

Hackers Sell Lifetime Access to WormGPT and KawaiiGPT for Just $220

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are now selling lifetime access to malicious AI chatbots WormGPT and KawaiiGPT for as little as $220, marking a dangerous new chapter in AI-powered cybercrime. These tools remove all …

Indirect-Shellcode-Executor Tool Exploits Windows API Vulnerability to Evade AV and EDR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new offensive security tool developed in Rust is demonstrating a novel method for bypassing modern Endpoint Detection and Response (EDR) systems by exploiting an overlooked behavior in the Windows …

Microsoft Details Security Risks of New Agentic AI Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, discussions have centered on Microsoft’s experimental agentic AI feature, which has introduced both advanced task automation and significant security concerns. This agentic capability, available to Windows insiders …

Developers Expose Passwords and API Keys via Online Tools like JSONFormatter

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Developers are unintentionally exposing passwords, API keys, and sensitive data in production information into online formatting tools such as JSONFormatter and CodeBeautify. New research from watchTowr shows that thousands of …

HashJack: New Attack Technique Tricks AI Browsers Using a Simple ‘#’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Cato CTRL have discovered a new indirect prompt injection technique called HashJack, which weaponises legitimate websites to manipulate AI browser assistants. The attack conceals malicious instructions after the …

Tor Adopts Galois Onion Encryption to Strengthen Defense Against Online Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Tor Project has announced a significant cryptographic overhaul, retiring its legacy relay encryption algorithm after decades of service and replacing it with Counter Galois Onion (CGO). This research-backed encryption …

Microsoft Teams Introduces New Feature to Boost Performance and Startup Speed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced a significant update to the Teams Desktop Client for Windows that aims to enhance performance and reduce startup times for calling features. The update, detailed in the …

ASUS MyASUS Flaw Lets Hackers Escalate to SYSTEM-Level Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ASUS has disclosed a high security vulnerability in its MyASUS application that could allow local attackers to escalate their privileges to SYSTEM-level access on affected Windows devices. The flaw, tracked …