SEO Poisoning Campaign Impersonates 25+ Popular Apps to Deliver AsyncRAT Since October 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated SEO poisoning campaign has been quietly targeting Windows users since at least October 2025, luring them into downloading trojanized installers for more than 25 popular software applications. The …

Critical QNAP QVR Pro Vulnerability Let Remote Attackers Gain Access to the System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP QVR Pro Vulnerability QNAP has released a critical security advisory addressing a severe vulnerability in its QVR Pro surveillance software. Tracked as CVE-2026-22898, this flaw allows remote, unauthenticated attackers …

Libyan Oil Refinery Hit in Long-Running Espionage Campaign Using AsyncRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Libyan oil refinery, a telecoms organization, and a state institution fell victim to a coordinated espionage campaign between November 2025 and February 2026. The attacks delivered AsyncRAT, a publicly …

MacOS Stealer MioLab Adds ClickFix Delivery, Wallet Theft and Team API Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated macOS infostealer known as MioLab — also tracked as Nova — has emerged as one of the most advanced Malware-as-a-Service (MaaS) platforms targeting Apple users. Advertised on Russian-speaking …

Oblivion RAT Turns Fake Play Store Updates Into a Full-Service Android Spyware Operation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered Android remote access trojan known as Oblivion RAT has emerged on cybercrime networks as a complete malware-as-a-service (MaaS) platform, turning fake Google Play Store update pages into …

Trivy Supply Chain Attack Expands as Compromised Docker Images Hit Docker Hub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A supply chain attack targeting Trivy, the widely used open-source vulnerability scanner, has grown well beyond its initial scope. What started as a GitHub Actions compromise has now extended to …

Windows 11 Emergency Update to Fix ‘No Internet’ Sign-In Errors for OneDrive, Teams, and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released an out-of-band (OOB) update, KB5085516, for Windows 11 versions 25H2 and 24H2 to address a critical sign-in issue introduced by the March 2026 Patch Tuesday update. The …

CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Craft CMS (CVE-2025-32432) has been added to the Known Exploited Vulnerabilities catalog following confirmed active exploitation in the wild. Security teams and system administrators are advised …

$30 IP-KVM Flaws Could Give Attackers BIOS-Level Control Across Enterprise Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

$30 IP-KVM Flaws Attackers BIOS-Level Control Across Enterprise Networks A recent security assessment by researchers has uncovered nine severe vulnerabilities across four popular low-cost IP-KVM devices. These flaws uncovered by …