Threat Actors Tricks Target Users Via Impersonation and Fictional Financial Aid Offers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An international ecosystem of sophisticated scam operations has emerged, targeting vulnerable populations through impersonation tactics and fraudulent financial aid promises. The campaign, dubbed “Vulnerability Vultures,” primarily focuses on older adults …

TransparentTribe Attack Linux-Based Systems of Indian Military Organizations to Deliver DeskRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TransparentTribe, a Pakistani-nexus intrusion set active since at least 2013, has intensified its cyber espionage operations targeting Linux-based systems of Indian military and defense organizations. The campaign, initially documented in …

Jingle Thief Attackers Exploiting Festive Season with Weaponized Gift Card Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As the festive season approaches, organizations are witnessing a disturbing increase in targeted attacks on digital gift card systems. The Jingle Thief campaign, orchestrated by financially motivated threat actors based …

Warlock Ransomware Actors Exploiting Sharepoint ToolShell Zero-Day Vulnerability in New Attack Wave

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape experienced a significant shift in July 2025 when threat actors associated with Warlock ransomware began exploiting a critical zero-day vulnerability in Microsoft SharePoint. Discovered on July 19, …

New Python RAT Mimic as Legitimate Minecraft App Steals Sensitive Data from Users Computer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Python-based remote access trojan has emerged in the gaming community, disguising itself as a legitimate Minecraft client to compromise unsuspecting users. The malware, identified as a multi-function RAT, …

SideWinder Hacking Group Uses ClickOnce-Based Infection Chain to Deploy StealerBot Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The SideWinder advanced persistent threat group has emerged with a sophisticated new attack methodology that leverages ClickOnce applications to deploy StealerBot malware against diplomatic and governmental targets across South Asia. …

MuddyWater Using New Malware Toolkit to Deliver Phoenix Backdoor Malware to International Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Advanced Persistent Threat group MuddyWater, widely recognized as an Iran-linked espionage actor, has orchestrated a sophisticated phishing campaign targeting more than 100 government entities and international organizations across the …

New Red Teaming Tool RedTiger Attacking Gamers and Discord Accounts in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

RedTiger is an open-source red-teaming tool repurposed by attackers to steal sensitive data from Discord users and gamers. Released in 2025 on GitHub, RedTiger bundles penetration-testing utilities, including network scanners …

Arsen Launches Smishing Simulation to Help Companies Defend Against Mobile Phishing Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Paris, France, October 24th, 2025, CyberNewsWire Arsen, the cybersecurity company dedicated to helping organizations defend against social engineering, today introduced its new Smishing Simulation module: a feature designed to let …

ChatGPT Atlas Stores OAuth Tokens Unencrypted Leads to Unauthorized Access to User Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability in OpenAI’s newly released ChatGPT Atlas browser reveals that it stores unencrypted OAuth tokens in a SQLite database with overly permissive file settings on macOS, potentially allowing …