Cybercriminals Shift From Fake Login Pages to Infostealer Malware in Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Phishing attacks have always been one of the most common ways cybercriminals steal personal and business data. But something has quietly changed about how these attacks work. Instead of tricking people into typing passwords on fake websites, …

Proofpoint Warns TA4922 Deploys Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A sophisticated cybercrime group known as TA4922 is raising alarms across the global security community. The group has been deploying a growing arsenal of malware, including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT, against organizations in Japan, the …

Weaponized ChatGPT Download Site Delivers Malware Via Sponsored Search Results

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A new malvertising campaign is exploiting ChatGPT’s popularity by promoting a weaponized fake download site via sponsored search results, delivering malware to both Windows and macOS users. Security researchers from Evalian’s SOC team identified the operation, which …

Kali365 PhaaS Operation Expands Beyond Microsoft 365 to Target Okta and MAX Messenger

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A new and fast-growing phishing operation is making waves in the cybersecurity world, and it is moving far beyond its original targets. Kali365, a phishing-as-a-service (PhaaS) platform first spotted in April 2026, was initially built to steal …

Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin, allowing unauthenticated attackers to inject and execute arbitrary PHP code on vulnerable websites. The flaw, tracked as CVE-2026-3300 with …

Hackers Abusing Microsoft Teams and Google Drive to Deploy Remote Access Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Hackers are increasingly abusing trusted enterprise platforms such as Microsoft Teams and Google Drive to deploy stealthy remote access malware, with a newly observed campaign leveraging social engineering and cloud-based command-and-control to evade detection. In early April …

Cisco Unified Communications Manager Vulnerability Exposed Along With PoC Exploit Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Cisco has disclosed a critical server-side request forgery (SSRF) vulnerability in its Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). Tracked as CVE-2026-20230, with publicly available proof-of-concept (PoC) exploit code increasing the risk …

CISA Warns of Android Framework Integer Overflow Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly identified Android Framework vulnerability, tracked as CVE-2025-48595, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is actively exploited in the wild. The …

Hackers Use Fake Chrome Web Store Copyright Notices to Steal Google Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A new phishing campaign is targeting Chrome extension developers using fake copyright removal notices that look like official messages from the Chrome Web Store. The scam tricks developers into entering their Google credentials on a counterfeit sign-in …

Acer Working to Patch Wave 7 Router 0-day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Acer is preparing a firmware update to address a critical zero-day vulnerability affecting its Wave 7 routers, following disclosure by independent security researcher Gergo Pap. The issue affects devices running firmware versions earlier than and poses a …