New Clickfix Attack Uses DNS Hijacking to Spread Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Clickfix Attack DNS Hijacking spread malware A new evolution in the ClickFix social engineering campaign, which now employs a custom DNS hijacking technique to deliver malware. This attack method tricks …

Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat Actors Exploit Claude Artifacts Google Ads A sophisticated malware campaign targeting macOS users through Google-sponsored search results and legitimate platforms, including Anthropic’s Claude AI and Medium. The campaign has …

Threat Actor Allegedly Selling Critical Severity OpenSea 0-day Exploit Chain on Hacking Forums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor is reportedly selling a purported critical severity zero-day exploit chain targeting OpenSea for $100,000 USD in Bitcoin or Monero. The listing claims the vulnerability remains unpatched and …

CISA Warns of Microsoft Configuration Manager SQL Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns Microsoft Configuration Manager SQL Injection Vulnerability CISA has issued an urgent alert about a critical SQL injection vulnerability in Microsoft Configuration Manager (SCCM). Tracked as CVE-2024-43468, this flaw …

Malicious Chrome AI Extensions Attacking 260,000 Users via Injected IFrames

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious Chrome AI Extensions Attacking 260000 Users via Injected IFrames A coordinated campaign is using malicious Chrome extensions that impersonate popular AI tools like ChatGPT, Claude, Gemini, and Grok. These …

Chrome Extensions Infected 500K Users to Hijack VKontakte Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over half a million VKontakte users have fallen victim to a sophisticated malware campaign that silently hijacks accounts through seemingly harmless Chrome extensions. The malicious extensions, disguised as VK customization …

New ClickFix Attack Wave Targeting Windows Systems to Deploy StealC Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated social engineering campaign is targeting Windows users through fake CAPTCHA verification pages to deliver the StealC information stealer malware. The attack begins when victims visit compromised websites that …

Zimbra Security Update – Patch for XSS, XXE & LDAP Injection Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zimbra Security Update In a critical move for email server security, Zimbra released version 10.1.16 on February 4, 2026, tackling high-severity vulnerabilities including cross-site scripting (XSS), XML external entity (XXE), …

New XWorm RAT Campaign Uses Themed Phishing Lures and CVE‑2018‑0802 Excel Exploit to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign has been observed delivering an updated variant of XWorm, a Remote Access Trojan (RAT) that can give attackers full remote control of infected Microsoft Windows systems. …

OysterLoader Multi‑Stage Evasion Loader Uncovered with Advanced Obfuscation and Rhysida Ransomware Links

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware loader known as OysterLoader has emerged as a significant threat in the cybersecurity landscape, employing multiple layers of obfuscation to evade detection and deliver dangerous payloads. First …