Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DragonForce is the latest ransomware brand to move from noisy forum posts to full RaaS operations, targeting both Windows and VMware ESXi environments. First seen in December 2023 on BreachForums, …

New One-Click Microsoft Copilot Vulnerability Grants Attackers Undetected Access to Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel single-click attack targeting Microsoft Copilot Personal that enables attackers to silently exfiltrate sensitive user data. The vulnerability, now patched, allowed threat actors to hijack sessions via a phishing …

North Korean Hackers use Code Abuse Tactics for ‘Contagious Interview’ Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean threat actors have launched a sophisticated social engineering campaign targeting software developers through fake recruitment offers. The campaign, known as Contagious Interview, uses malicious repositories disguised as technical …

SpyCloud Launches Supply Chain Solution to Combat Rising Third-Party Identity Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Austin, TX / USA, January 14th, 2026, CyberNewsWire New monitoring capability delivers unprecedented visibility into vendor identity exposures, moving enterprises and government agencies from static risk scoring to protecting against …

LLMs are Accelerating the Ransomware Lifecycle to Gain Speed, Volume, and Multilingual Reach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Large language models are changing how ransomware crews plan and run their attacks. Instead of inventing new kinds of malware, LLMs are speeding up every step of the existing ransomware …

As Third-Party Vulnerabilities Rise, CISOs Accelerate Push for Security Modernization  

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Panorays has just dropped the latest edition of its annual CISO Survey for Third-Party Cyber Risk Management, and it contains some major wakeup calls for security professionals. The biggest takeaway is that software supply …

VVS Stealer Attacking Discord Users to Exfiltrate Credentials and Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Discord users are facing a growing threat from VVS Stealer, a Python-based information-stealing malware that targets sensitive account data, including credentials and tokens. This stealer was actively marketed on Telegram …

Threat Actors Targeting Ukraine’s Defense Forces with Charity-Themed Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have launched a sophisticated malware campaign against members of Ukraine’s Defense Forces, exploiting charity operations as a cover for their attacks. Operating between October and December 2025, the …

Microsoft Warns Secure Boot May Be Bypassed as Windows UEFI Certificates Expire

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed a critical security feature bypass vulnerability in Windows Secure Boot certificates, tracked as CVE-2026-21265, through its January 2026 Patch Tuesday updates. The flaw stems from expiring 2011-era …

Researchers Proposed Game-Theoretic AI for Guiding Attack and Defense

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from Alias Robotics and Johannes Kepler University Linz have unveiled a groundbreaking approach to automated penetration testing that combines artificial intelligence with game theory. Led by Víctor Mayoral-Vilches, Mara …