Remcos RAT C2 Activity Mapped Along with The Ports Used for Communications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Remcos, a commercial remote access tool distributed by Breaking-Security and marketed as administrative software, has become a serious threat in the cybersecurity landscape. Developed in the mid-2010s, this malware enables …

Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Lazarus APT Group has unveiled a new Remote Access Trojan called ScoringMathTea, representing a significant advancement in their cyberattack capabilities. This C++ based malware was identified as part of …

W3 Total Cache Command Injection Vulnerability Exposes 1 Million WordPress Sites to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical command injection vulnerability has been discovered in the W3 Total Cache plugin, one of WordPress’s most popular caching solutions used by approximately 1 million websites. The vulnerability, tracked as CVE-2025-9501 with a …

Imunify AI-Bolit Vulnerability Let Execute Arbitrary Code and Escalate Privileges to Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious security flaw was discovered in the AI-Bolit component of Imunify products. This vulnerability allows attackers to run arbitrary code and even become root on a server. Imunify released …

Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Everest ransomware group has claimed responsibility for a major cyber breach against Under Armour, the global sportswear giant, alleging the theft of 343 GB of internal data that …

UNC1549 Hackers with Custom Tools Attacking Aerospace and Defense Systems to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since mid-2024, a sophisticated Iranian-backed threat group known as UNC1549 has been conducting targeted campaigns against aerospace, aviation, and defense organizations across the globe. The hackers employ an advanced dual …

Google Reveals Public Preview of Alert Triage and Investigation Agent for Security Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced the public preview of its Alert Triage and Investigation agent, a significant advancement in artificial intelligence-driven security operations. The intelligent agent is now embedded directly within Google Security …

CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about a severe vulnerability in Lynx+ Gateway devices that could expose sensitive information in clear text during transmission. …

Threat Actors Leveraging Compromised RDP Logins to Deploy Lynx Ransomware After Deleting Server Backups

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lynx ransomware has emerged as a significant threat to enterprise environments, with recent intrusions demonstrating sophisticated attack strategies that prioritize data exfiltration and infrastructure destruction. The malware campaign combines compromised …

IBM AIX Vulnerabilities Let Remote Attacker Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

IBM has released critical security updates addressing two severe vulnerabilities in its AIX operating system that could allow remote attackers to execute arbitrary commands on affected systems. Both vulnerabilities stem …