XLoader Malware Upgrades Obfuscation Tactics and Hides C2 Traffic Behind Decoy Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known information-stealing malware called XLoader has received significant upgrades in its latest versions, making it considerably harder to detect and analyze than before. Originally derived from a malware family …

Mercor AI Confirms Data Breach Following Lapsus$ Claims of 4TB Data Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mercor AI has officially confirmed a severe data breach following claims by the notorious Lapsus$ hacking group that they stole 4 terabytes of sensitive company data. The incident, stemming from …

Hackers Weaponize Legitimate Windows Tools to Disable Antivirus Before Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware attacks have gone far beyond simple malicious code. Today, attackers operate with the precision of a well-planned business, using trusted Windows tools to quietly tear down defenses before ransomware …

Google Unveils Ransomware Detection and File Restoration for Google Drive

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially moved its ransomware detection and file restoration features for Google Drive into General Availability. Originally launched in beta in September 2025, the updated security controls offer organizations …

Hackers Deploy Telegram-Based ResokerRAT With Screenshot and Persistence Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new remote access trojan known as ResokerRAT has come to light, using Telegram’s bot API as its core communication channel to silently monitor and control infected Windows machines. What …

Anthropic’s Claude Code Source Code Reportedly Leaked Via Their npm Registry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic’s proprietary Claude Code CLI tool has had its full TypeScript source code inadvertently exposed through a misconfigured npm package, after a security researcher discovered a leaked .map file referencing …

WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity security flaw has been disclosed in Smart Slider 3, one of the most widely used WordPress slider builder plugins. With over 800,000 active installations, this vulnerability leaves a massive …

EvilTokens Emerges as New Phishing-as-a-Service Platform for Microsoft Account Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and dangerous phishing toolkit has entered the cybercrime scene. In early 2026, a Phishing-as-a-Service platform called EvilTokens began circulating in underground cybercrime communities, offering criminals a ready-to-use kit …

ChatGPT Vulnerability Let Attackers Silently Exfiltrate User Prompts and Other Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Users routinely trust AI assistants with highly sensitive information, including medical records, financial documents, and proprietary business code. Check Point Research recently disclosed a critical vulnerability in ChatGPT’s architecture that …