InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 A North Korea-linked hacker group has quietly upgraded one of its most dangerous tools, making it harder for security software to detect. InvisibleFerret, an information-stealing malware tied to the threat actor known as Void Dokkaebi (also tracked …

Cloud Atlas APT Group Modifies termsrv.dll to Enable Multiple RDP Sessions on Victim Hosts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 A well-known advanced persistent threat group called Cloud Atlas has been caught using a dangerous technique to hijack Windows systems without alerting anyone on the network. The group modifies a core Windows file called termsrv.dll to unlock …

Russian Hacker Used Jailbroken Gemini to Steal Admin Credentials and Drain Crypto Wallets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 A solo Russian-speaking threat actor leveraged a jailbroken instance of Google Gemini to run a five-year MAGA-themed influence operation, crack WordPress administrator credentials, and empty at least one victim’s cryptocurrency wallet, all at near-zero cost using stolen …

Hackers Abuse Shared CDN Infrastructure to Bypass Domain Reputation Security Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 Hackers are actively abusing a flaw in shared Content Delivery Network (CDN) infrastructure to hide malicious traffic behind trusted, high-reputation domains, effectively slipping past the security tools that organizations rely on every day. The technique, now tracked …

KnowledgeDeliver LMS Zero-Day Exploited to Deploy BLUEBEAM Web Shell

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 A newly disclosed zero-day vulnerability in the KnowledgeDeliver Learning Management System (LMS) has been actively exploited in the wild to deploy the BLUEBEAM in-memory web shell, according to Mandiant’s incident response findings. The flaw, now tracked as …

Iranian APT Uses SEO Poisoning to Deliver Fake SQL Developer Malware Installer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 A well-known Iranian threat group has found a new way to push malware onto people’s machines. Instead of sending phishing emails, the group built a fake website that impersonated a real database software download page and used …

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus …

Kazuar Malware Evolves Into Modular Espionage Ecosystem for Secret Blizzard Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 A Russian state-sponsored threat group has quietly upgraded one of its most powerful cyber weapons, and the result is a spying tool that is harder to detect, harder to kill, and more capable than ever before. Security …

Hackers Actives Scanning SonicWall Firewall Interfaces – 597,000 Sessions Observed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 A sharp rise in internet-wide scanning activity targeting SonicWall firewall management interfaces has been detected, raising concerns about a potential pre-disclosure reconnaissance phase tied to new vulnerabilities. Threat intelligence firm GreyNoise reported a significant surge in scanning …

Italian Authorities Dismantled CINEMAGOAL App that Enables Access to Various Streaming Platforms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 Italian law enforcement has dismantled a large-scale audiovisual piracy network centered around a sophisticated application called CINEMAGOAL, which enabled users to access premium streaming services without authorization. The operation, codenamed “All Clear”, was led by the Ravenna Financial Police …