New PhantomCaptcha RAT Weaponized PDFs to Deliver Malware Using ‘ClickFix’-Style Cloudflare Captcha Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated spearphishing campaign has emerged targeting humanitarian organizations and Ukrainian government agencies, leveraging weaponized PDF attachments and fake Cloudflare verification pages to distribute a dangerous WebSocket-based remote access trojan. …

Amazon Uncovers Root Cause of Major AWS Outage That Brokes The Internet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon Web Services (AWS), the backbone for countless websites and services, faced a severe outage last weekend that disrupted operations for millions. The incident, which unfolded in the early hours …

Threat Actors Advancing Email Phishing Attacks to Bypass Security Filters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Email phishing attacks have reached a critical inflection point in 2025, as threat actors deploy increasingly sophisticated evasion techniques to circumvent traditional security infrastructure and user defenses. The threat landscape …

Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has rolled out an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting the Windows Server Update Services (WSUS). Identified as CVE-2025-59287, the issue stems from the …

Toys “R” Us Canada Confirms Data Breach – Customers Personal Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Toys “R” Us Canada has alerted customers to a significant data breach that potentially exposed their personal information, marking another blow to consumer trust in retail data security. In emails …

New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Remcos, a commercial remote access tool marketed as legitimate surveillance software, has become the leading infostealer in malware campaigns during the third quarter of 2025, accounting for approximately 11 percent …

HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The HP OneAgent software update has disconnected Windows devices from Microsoft Entra ID. As a result, users can no longer access their corporate identities. Version 1.2.50.9581 of the agent, pushed …

Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified a sophisticated campaign where threat actors are leveraging compromised credentials to infiltrate Azure Blob Storage containers, targeting organizations’ critical code repositories and sensitive data. This emerging …

New PDF Tool to Detect Malicious PDF Using PDF Object Hashing Technique

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new open-source tool called PDF Object Hashing is designed to detect malicious PDFs by analyzing their structural “fingerprints.” Released by Proofpoint, the tool empowers security teams to create robust …

SharkStealer Using EtherHiding Pattern to Resolves Communications With C2 Channels

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated information-stealing malware written in Golang has emerged, leveraging blockchain technology to establish covert command-and-control channels. SharkStealer represents a significant evolution in malware design, utilizing the BNB Smart Chain …