CISA Warns of Google Chromium 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Chromium 0-Day Vulnerability An urgent warning regarding a newly discovered zero-day vulnerability in Google Chromium, which is reportedly under active exploitation in the wild. The vulnerability, tracked as CVE-2026-2441, affects …

Microsoft VS Code Extension with 11M Downloads Expose Developers to One-Click XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft VS Code Extension 11M Downloads A critical vulnerability discovered in Microsoft’s popular Visual Studio Code (VS Code) Live Preview extension, downloaded over 11 million times, exposes developers to one-click cross-site scripting (XSS) and local …

New Malware Campaign ‘CRESCENTHARVEST’ Exploits Iran Protest Sentiment to Deploy Information-Stealing RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign named ‘CRESCENTHARVEST’ has surfaced, strategically exploiting the geopolitical unrest in Iran to target dissidents and protest supporters. This cyberespionage operation leverages social engineering to deploy …

Cybercriminals Leverage Atlassian Cloud for Spam Campaigns Redirecting Targets to Fraudulent Investment Schemes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have launched a sophisticated spam campaign leveraging the trusted infrastructure of Atlassian Cloud. By abusing legitimate features within the platform, attackers are effectively bypassing traditional email security controls to …

Dell 0-Day Vulnerability Exploited by Chinese Hackers since mid-2024 to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dell 0-Day Vulnerability A critical zero-day exploitation campaign targeting Dell RecoverPoint for Virtual Machines. The vulnerability, tracked as CVE-2026-22769, carries a maximum CVSSv3.1 score of 10.0 and has been under …

Matanbuchus 3.0 Returns with ClickFix Social Engineering and Silent MSI Installations to Deploy AstarionRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Matanbuchus, a premium Malware-as-a-Service loader, has resurfaced in February 2026 following a nearly year-long hiatus. This latest iteration, version 3.0, features a complete code rewrite and now commands a subscription …

Threat Actors Advertising New ‘ClickFix’ Payload That Stores Malware within Browser Cache

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a new iteration of the ‘ClickFix’ social engineering campaign, which now employs a sophisticated technique to evade detection by storing malware directly within a victim’s browser …

Credit Card Fraud Emerges with a New Sophisticated Carding-as-a-Service Marketplaces

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Credit card fraud has persisted despite global mitigation efforts, evolving from scattered illegal trades into a highly organized Carding-as-a-Service (CaaS) economy. This underground structure now mirrors legitimate online marketplaces, providing …

DigitStealer Gains Attention as macOS-Targeting Infostealer Exposes Key Infrastructure Weaknesses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DigitStealer, a sophisticated information-stealing malware targeting macOS systems, has recently surged in activity, drawing significant attention from the cybersecurity community. First emerging in late 2025, this malicious software specifically targets …

Malware in the Wild as Malicious Fork of Legitimate Triton App Surfaces on GitHub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious fork of the legitimate macOS application Triton has surfaced on GitHub, exploiting open-source repositories to distribute malware. The fraudulent repository, created under the account “JaoAureliano,” appeared as a …