Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor tracked as D-Shortiez has been running a persistent malvertising campaign that turns a WebKit browser behavior into a trap, forcing iOS Safari users into scam pages with …

LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor operating under the alias FulcrumSec has publicly claimed responsibility for a fresh breach of LexisNexis Legal & Professional, the legal information division of RELX Group, alleging the …

Microsoft Warns of New Phishing Attack Exploiting OAuth in Entra ID to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing Attack Exploiting OAuth A new active phishing attack that exploits OAuth’s legitimate redirection behavior, allowing it to bypass traditional email and browser defenses without stealing any tokens. According to …

Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Mirai-based botnet campaign known as Zerobot has resurfaced with renewed force, this time targeting critical flaws in Tenda AC1206 routers and the n8n workflow automation platform. The campaign, now …

Archipelo and Checkmarx Announce Partnership Connecting AppSec Detection with DevSPM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

San Francisco, CA, United States, March 3rd, 2026, CyberNewswire Archipelo and Checkmarx today announced a technical partnership focused on correlating application vulnerability findings with development-origin context within modern software delivery …

New ‘StegaBin’ Campaign Uses Malicious 26 npm Packages to Deploy Multi-Stage Credential Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new software supply-chain attack is abusing the npm ecosystem today, where a single mistaken dependency can quietly open a door into a developer’s machine. The activity, tracked as “StegaBin,” …

Hackers Leverage Telegram for Initial Access to Corporate VPN, RDP, and Cloud Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Telegram, once widely recognized as a privacy-focused messaging application, has quietly transformed into one of the most powerful operational platforms used by cybercriminals today. What dark web forums once offered …

Epic Fury/Roaring Lion Sparks Escalating Cyber Conflict as Iran Goes Offline, Hacktivists Step Up Retaliation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On February 28, 2026, the United States and Israel launched a coordinated offensive — code-named Operation Epic Fury by the U.S. and Operation Roaring Lion by Israel — setting off …

Malvertising Campaign Delivers AMOS ‘malext’ macOS Infostealer via Fake Text‑Sharing Lures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malvertising campaign is actively targeting macOS users worldwide, delivering a new variant of the AMOS infostealer called “malext.” Attackers are purchasing Google Search ads that push victims toward …