Weaponized Putty and Teams Ads Deliver Malware Allowing Hackers to Access Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An ongoing malicious advertising campaign is weaponizing legitimate software downloads to deploy OysterLoader malware, previously identified as Broomstick and CleanUpLoader. This sophisticated initial access tool enables cybercriminals to establish footholds …

AMD Zen 5 Processors RDSEED Vulnerability Breaks Integrity With Randomness

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AMD has disclosed a critical vulnerability affecting its Zen 5 processor lineup that compromises the reliability of random number generation, a fundamental security feature in modern computing. The flaw, tracked …

Apple Patches Multiple Critical Vulnerabilities in iOS 26.1 and iPadOS 26.1

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple released iOS 26.1 and iPadOS 26.1, addressing multiple vulnerabilities that could lead to privacy breaches, app crashes, and potential data leaks for iPhone and iPad users. The update targets …

New TruffleNet BEC Campaign Leverages AWS SES Using Stolen Credentials to Compromise 800+ Hosts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Identity compromise has become one of the most significant threats facing cloud infrastructure, particularly when attackers gain access to legitimate credentials. These valid access keys enable adversaries to bypass traditional …

Hackers Can Manipulate Claude AI APIs with Indirect Prompts to Steal User Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers can exploit Anthropic’s Claude AI to steal sensitive user data. By leveraging the model’s newly added network capabilities in its Code Interpreter tool, attackers can use indirect prompt injection …

Microsoft Patch for WSUS Vulnerability has Broken Hotpatching on Windows Server 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a recent setback for Windows administrators, Microsoft’s October 2025 security update addressing a critical vulnerability in Windows Server Update Services (WSUS) has inadvertently broken hotpatching functionality on a subset …

Beware of New Phishing Attack that Abuses Cloudflare and ZenDesk Pages to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged, exploiting the trust placed in legitimate cloud hosting services. Threat actors are leveraging Cloudflare Pages and ZenDesk platforms to conduct large-scale credential theft operations …

New Business Email Protection Technique Blocks the Phishing Email Behind NPM Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Supply chain attacks targeting the JavaScript ecosystem have evolved into sophisticated operations combining domain manipulation with social engineering. On September 8, 2025, threat actors launched a coordinated phishing campaign aimed …

Conti Group Member Responsible for Deploying Ransomware Extradited to USA

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Ukrainian national accused of playing a key role in the notorious Conti ransomware operation has been extradited from Ireland to face federal charges in the United States. Oleksii Oleksiyovych …

Hackers Deliver SSH-Tor Backdoor Via Weaponized Military Documents in ZIP Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In October 2025, threat researchers at Cyble Research and Intelligence Labs uncovered a sophisticated cyber attack leveraging weaponized military documents to distribute an advanced SSH-Tor backdoor targeting defense sector personnel. …