Microsoft Windows 11 October Update Breaks Localhost (127.0.0.1) Connections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s October 2025 cumulative update for Windows 11 has disrupted localhost functionality, preventing developers and users from accessing local web applications and services via 127.0.0.1. The issue, tied to update …

Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are exploiting TikTok’s massive user base to distribute sophisticated malware campaigns that promise free software activation but deliver dangerous payloads instead. The attack leverages social engineering tactics reminiscent of …

Threat Actors Leveraging ClickFake Interview Attack to Deploy OtterCandy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals associated with the North Korean threat group WaterPlum, also known as Famous Chollima or PurpleBravo, have escalated their activities with a sophisticated new malware strain called OtterCandy. This cross-platform …

Hackers Using AI to Automate Vulnerability Discovery and Malware Generation – Microsoft Report

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security teams around the world are grappling with a new breed of cyber threats that leverage advanced automation to identify software weaknesses and craft malicious payloads at unprecedented speed. Over …

New Tech Support Scam with Microsoft’s Logo Tricks Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new campaign has emerged that weaponizes Microsoft’s familiar branding to lure unsuspecting users into a sophisticated tech support scam. Victims receive a seemingly legitimate email, complete with Microsoft’s official …

Windows Rust-based Kernel GDI Vulnerability Leads to Crash and Blue Screen of Death Error

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A vulnerability in Microsoft’s newly implemented Rust-based kernel component for the Graphics Device Interface (GDI) in Windows. This flaw, which could trigger a system-wide crash via a Blue Screen of …

APT28 With Weaponized Office Documents Delivers BeardShell and Covenant Modules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russia’s APT28 has resurfaced in mid-2025 with a sophisticated spear-phishing campaign that weaponizes Office documents to deploy two novel payloads: BeardShell, a C-based backdoor leveraging IceDrive as a command-and-control channel, …

Critical ConnectWise Vulnerabilities Allow Attackers To Inject Malicious Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ConnectWise released a critical security update for its Automate platform on October 16, 2025. The patch, version 2025.9, addresses serious flaws in agent communications that could let attackers intercept sensitive …

Email Bombs Exploit Lax Authentication in Zendesk

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Cybercriminals are abusing a widespread lack of authentication in the customer service platform Zendesk to flood targeted email inboxes with menacing messages that come from hundreds of Zendesk corporate customers …

LinkPro Rootkit Attacking GNU/Linux Systems Using eBPF Module to Hide Malicious Activities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated rootkit targeting GNU/Linux systems has emerged, leveraging advanced eBPF (extended Berkeley Packet Filter) technology to conceal malicious activities and evade traditional monitoring tools. The threat, known as LinkPro, …