New DNS Malware Detour Dog Delivers Strela Stealer Using DNS TXT Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated DNS-based malware campaign has emerged, utilizing thousands of compromised websites worldwide to deliver the Strela Stealer information-stealing malware through an unprecedented technique involving DNS TXT records. The threat, …

Hackers Abuse EV Certificates to Sign Completely Undetectable DMG Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, security analysts have observed a new wave of macOS attacks leveraging legitimately issued Extended Validation (EV) certificates to sign malicious disk images (DMGs). This technique allows malware …

Allianz Life Data Breach Exposes Personal Records of 1.5 Million Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Allianz Life Insurance Company of North America has reported a significant data security incident that has exposed the sensitive personal information of an estimated 1.5 million customers, financial professionals, and …

AI-Powered FunkLocker Ransomware Leverages Windows utilities to Disable Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ransomware strain, dubbed FunkLocker, is leveraging artificial intelligence to expedite its development, while relying on the abuse of legitimate Windows utilities to disable security defenses and disrupt systems. …

CISA Warns of Cisco IOS and IOS XE SNMP Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco’s Simple Network Management Protocol (SNMP) implementations in IOS and IOS XE have come under intense scrutiny following reports of active exploitation in the wild. First disclosed in August 2025, …

MatrixPDF Attacks Gmail Users Bypassing Email Filters and Fetch Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, a novel malware campaign dubbed MatrixPDF has surfaced, targeting Gmail users with carefully crafted emails that slip past conventional spam and phishing filters. This campaign has been …

WestJet Confirms Data Breach – Customers Personal Information Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WestJet announced a cybersecurity incident in which a sophisticated third-party actor gained unauthorized access to internal systems, exposing personal information of some customers.  The breach, discovered on June 13, 2025, …

Patchwork APT Using PowerShell Commands to Create Scheduled Task and Downloads Final Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since mid-2025, cybersecurity researchers have tracked a resurgence of Patchwork Advanced Persistent Threat (APT) campaigns targeting government and telecommunications sectors across Asia and Eastern Europe. Initially leveraging spear-phishing emails containing …

Red Hat Openshift AI Service Vulnerability Allow Attackers to Take Control of the Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Red Hat published security advisory CVE-2025-10725, detailing an Important severity flaw in the OpenShift AI Service that could enable low-privileged attackers to elevate their permissions to full cluster administrator and …

New Battering RAM Attack Bypasses Latest Defenses on Intel and AMD Cloud Processors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Confidential computing promised to protect sensitive workloads in the public cloud. Yet a new low-cost hardware attack, Battering RAM, demonstrates that even up-to-date memory-encryption schemes on Intel and AMD processors can be …