SmartApeSG Campaign Leverages ClickFix Technique to Deploy NetSupport RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The SmartApeSG campaign, also known as ZPHP or HANEY MANEY, continues to evolve its attack methods to compromise Windows systems with malicious remote access tools. First reported in June 2024, …

Threat Actors Leverage JSON Storage Services to Host and Deliver Malware Via Trojanized Code Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated campaign where threat actors abuse legitimate JSON storage services to deliver malware to software developers. The campaign, known as Contagious Interview, represents a significant …

Multiple vulnerabilities in Cisco Unified CCX Allow Attackers to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has released security updates to address two critical vulnerabilities in Unified Contact Center Express (Unified CCX) that could allow unauthenticated attackers to execute arbitrary commands with root privileges and …

Hackers Flooded npm Registry Over 43,000 Spam Packages Survived for Almost Two Years

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researcher Paul McCarty uncovered a significant coordinated spam campaign targeting the npm ecosystem. The IndonesianFoods worm, as it has been named, consists of more than 43,000 spam packages published …

Washington Post Oracle E-Suite 0-Day Hack Impacts 9K+ Employees and Contractors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Washington Post has publicly disclosed a significant data breach involving external hacking of its Oracle E-Suite system, impacting over 9,700 employees and contractors worldwide. The breach notification, filed with …

Critical Imunify360 AV Vulnerability Exposes 56 Million+ Linux-hosted Websites to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe remote code execution (RCE) vulnerability has been discovered in Imunify360 AV, a widely used malware scanner protecting approximately 56 million websites. The security flaw, recently patched by CloudLinux, …

Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A deceptive Chrome extension named Safery: Ethereum Wallet has emerged as a serious threat to cryptocurrency users. Published on the Chrome Web Store on November 12, 2024, this extension masquerades …

Cl0P Ransomware Group Allegedly Claims Breach of Entrust in Oracle 0-Day EBS Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Cl0P ransomware group has claimed responsibility for breaching digital security firm Entrust, exploiting a critical zero-day vulnerability in Oracle E-Business Suite (EBS). The attack, tied to CVE-2025-61882, marks …

Kraken Cross-Platform Ransomware Attacking Windows, Linux, and VMware ESXi Systems in Enterprise Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In August 2025, a new ransomware threat emerged with capabilities that fundamentally changed how organizations should approach enterprise security. Kraken, a Russian-speaking cybercriminal group, began executing sophisticated attacks targeting large …

New ClickFix Attack Targeting Windows and macOS Users to Deploy Infostealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A growing social engineering technique called ClickFix has emerged as one of the most successful methods for distributing malware in recent months. This attack tricks users into copying and running …