Indian Income Tax-Themed Attacking Businesses with a Multi-Stage Infection Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have increasingly weaponized the Income Tax Return (ITR) filing season to orchestrate sophisticated phishing campaigns targeting Indian businesses. By exploiting public anxiety surrounding tax compliance and refund timelines, attackers …

University of Phoenix Data Breach – 3.5 Million+ Individuals Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

University of Phoenix, one of the largest for-profit educational institutions in the United States, disclosed a significant data breach affecting approximately 3.5 million individuals on December 22, 2025. The breach …

Critical n8n Automation Platform Vulnerability Enables RCE Attacks – 103,000+ Instances Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability has been discovered in n8n, the open-source workflow automation platform, exposing over 103,000 potentially vulnerable instances worldwide. Tracked as CVE-2025-68613 with a maximum CVSS …

New GhostLocker Tool that Uses Windows AppLocker to Neutralize and Control EDR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new tool named GhostLocker has been released, demonstrating a novel technique to neutralize Endpoint Detection and Response (EDR) systems by weaponizing the native Windows AppLocker feature. Developed by security …

Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two fake Chrome extensions named “Phantom Shuttle” are deceiving thousands of users by posing as legitimate VPN services while secretly intercepting their web traffic and stealing sensitive login information. These …

Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Ontinue’s Cyber Defense Center have uncovered a significant threat as attackers exploit Nezha, a legitimate open-source server monitoring tool, for post-exploitation access. The discovery reveals how sophisticated threat …

CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting Digiever DS-2105 Pro network video recorders was added to the Known Exploited Vulnerabilities (KEV) catalog on December 22, 2025, following evidence of active exploitation in the …

Hackers Using ClickFix Technique to Hide Images within the Image Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have evolved their attack strategies by combining the deceptive ClickFix social engineering lure with advanced steganography techniques to conceal malicious payloads within PNG image files. This sophisticated approach, …

Spotify Music Library With 86M Music Files Scraped by Hacktivist Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The shadow library known as Anna’s Archive has executed a massive scrape of Spotify, releasing a torrent collection containing approximately 86 million audio tracks and metadata for 256 million songs. …

Malicious NPM Package with 56K Downloads Steals WhatsApp Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous npm package named “lotusbail” has been stealing WhatsApp messages and user data from thousands of developers worldwide. The package, which has been downloaded over 56,000 times, disguises itself …