New Phishing Attack Leverages Popular Brands to Harvest Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged, targeting organizations across Central and Eastern Europe by impersonating legitimate global brands to deceive users into surrendering their login credentials. The attack utilizes self-contained …

Microsoft Investigating Teams Issue that Disables Users from Opening Apps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed it is investigating a significant issue affecting Microsoft Teams for Education, which is particularly impacting users’ ability to access critical features such as assignments and grades. The …

Hackers Weaponize AppleScript to Creatively Deliver macOS Malware Mimic as Zoom/Teams Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors continue to evolve their techniques for bypassing macOS security controls, shifting away from traditional attack vectors that Apple has systematically patched. Following Apple’s removal of the “right-click and …

Tor Browser 15.0.1 Released With Fix for Multiple Security Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tor Browser 15.0.1 is now available for download, bringing essential security patches and bug fixes to users across all platforms. The latest release includes critical security updates from Firefox 140.5.0esr, …

Authentication Coercion Attack Tricks Windows Machines into Revealing Credentials to Attack-controlled Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Authentication coercion represents a sophisticated and evolving threat targeting Windows and Active Directory environments across organizations globally. This attack method exploits the fundamental communication mechanisms embedded within every Windows operating …

ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Server-Side Request Forgery (SSRF) vulnerability in OpenAI’s ChatGPT. The flaw, lurking in the Custom GPT “Actions” feature, allowed attackers to trick the system into accessing internal cloud metadata, potentially …

New KomeX Android RAT Advertised on Hacker Forums with Multiple Subscription Options

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified Android remote access trojan (RAT) dubbed KomeX has surfaced on underground hacker forums, generating widespread concern within the cybersecurity community. Marketed by a threat actor under the …

New Phishing Attack Targeting Meta Business Suite Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale phishing campaign has emerged, exploiting Meta’s Business Suite to compromise credentials across thousands of small and medium-sized businesses worldwide. Check Point security researchers identified approximately 40,000 phishing emails …

Windows Remote Desktop Services Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has disclosed a significant vulnerability in Windows Remote Desktop Services (RDS) that could allow authorized attackers to escalate their privileges on affected systems. Tracked as CVE-2025-60703, the flaw stems from …

SecureVibes – AI-backed Tool Uses Claude AI Agents to Scan for Vulnerabilities Across 11 Languages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the fast-paced world of “vibecoding,” where developers use AI to build applications rapidly, a new open-source tool is stepping up to tackle security risks. SecureVibes, created by developer Anshuman …