VMware vCenter and NSX Vulnerabilities Let Attackers Enumerate Valid Usernames

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware has disclosed critical security vulnerabilities in vCenter Server and NSX platforms that could allow attackers to enumerate valid usernames and manipulate system notifications.  The vulnerabilities, tracked as CVE-2025-41250, CVE-2025-41251, …

Hackers Trick Users to Download Weaponized Microsoft Teams to Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber campaign is exploiting the trust users place in popular collaboration software, tricking them into downloading a weaponized version of Microsoft Teams to gain remote access to their …

New Harrods Data Breach Exposes 430,000 Customer Personal Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Luxury department store Harrods has disclosed a significant data breach affecting approximately 430,000 customer records after a third-party provider was compromised. The hackers behind the attack have contacted the retailer, …

New Spear-Phishing Attack Delivers DarkCloud Malware to Steal Keystrokes, FTP Credentials and Others

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly observed spear-phishing campaign is leveraging sophisticated social engineering lures to distribute DarkCloud, a modular malware suite designed to harvest keystrokes, exfiltrate FTP credentials and gather system information. Over …

SVG Security Analysis Toolkit to Detect Malicious Scripts Hidden in SVG Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As attackers increasingly leverage Scalable Vector Graphics (SVG) for stealthy code injection, security researchers face mounting challenges in detecting obfuscated payloads embedded within SVG assets.  The SVG Security Analysis Toolkit …

New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged that weaponizes seemingly legitimate productivity tools to infiltrate systems and steal sensitive information. The TamperedChef malware represents a concerning evolution in threat actor tactics, …

New Malware-as-a-Service Olymp Loader Promises Defender-Bypass With Automatic Certificate Signing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community is currently observing a surge in interest around Olymp Loader, a recently unveiled Malware-as-a-Service (MaaS) platform written entirely in Assembly. First advertised on underground forums and Telegram …

Threat Actors Weaponizing Facebook and Google Ads as Financial Platforms to Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, cybersecurity teams have observed an alarming trend in which malicious actors exploit Facebook and Google advertising channels to masquerade as legitimate financial services. By promoting free or …

New ModStealer Evade Antivirus Detection to Attack macOS Users and Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cross-platform information stealer known as ModStealer has emerged, targeting macOS users and demonstrating concerning capabilities to evade Apple’s built-in security mechanisms. The malware represents the latest evolution …