11,000 Android Devices Hacked by Chinese Threats Actors to Deploy PlayPraetor Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware-as-a-service operation orchestrated by Chinese-speaking threat actors has successfully compromised over 11,000 Android devices worldwide through the deployment of PlayPraetor, a powerful Remote Access Trojan designed for on-device …

Hackers Abuse Microsoft 365’s Direct Send Feature to Deliver Internal Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have discovered a sophisticated new attack vector by exploiting Microsoft 365’s Direct Send feature to deliver phishing campaigns that masquerade as legitimate internal communications. This emerging threat leverages a …

Storm-2603 Using Custom Malware That Leverages BYOVD to Tamper with Endpoint Protections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified threat actor designated Storm-2603 has emerged as a sophisticated adversary in the ransomware landscape, leveraging advanced custom malware to circumvent endpoint security protections through innovative techniques. The …

Secret Blizzard Group’s ApolloShadow Malware Install Root Certificates on Devices to Trust Malicious Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberespionage campaign targeting foreign embassies in Moscow has been uncovered, revealing the deployment of a custom malware strain designed to manipulate digital trust mechanisms. The Russian state-sponsored threat …

Threat Actors Leverage Compromised Email Accounts for Targeted Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly sophisticated in their phishing attacks, with threat actors now leveraging compromised email accounts from trusted sources to bypass security controls and enhance campaign legitimacy. Recent incident response …

Microsoft Teams New Option Let IT admins Run 60-second Silent Test Call

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced a new proactive network monitoring capability for Teams administrators, introducing 60-second silent test calls designed to assess network quality without disrupting user experiences.  The feature represents a …

Microsoft to Disable External Workbook Links to Blocked File Types By Default

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft announced a significant security enhancement for Microsoft 365 apps that will fundamentally change how external workbook links function.  Starting in October 2025, the company will disable external workbook links …

Threat Actors Impersonating Microsoft OAuth Applications to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign exploiting Microsoft OAuth applications has emerged as a significant threat to enterprise security, with cybercriminals successfully bypassing multifactor authentication systems to steal user credentials. The campaign, …

LLMs Accelerating Offensive R&D, Helps to Identify and Exploit Trapped COM Objects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has witnessed a significant evolution in offensive research methodologies with the integration of Large Language Models (LLMs) into malware development workflows. Security researchers at Outflank have pioneered …

APT36 Hackers Weaponizing PDF Files to Attack Indian Railways, Oil & Government Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Pakistan-linked Advanced Persistent Threat (APT) group APT36, also known as Transparent Tribe, has significantly expanded its cyber operations beyond traditional military targets to encompass critical Indian infrastructure including railway …