ClickFix Attack Uses Steganography to Hide Malicious Code in Fake Windows Security Update Screen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of ClickFix attacks is abusing highly realistic fake Windows Update screens and PNG image steganography to secretly deploy infostealing malware such as LummaC2 and Rhadamanthys on victim …

NVIDIA’s Isaac-GROOT Robotics Platform Vulnerability Let Attackers Inject Malicious Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NVIDIA has disclosed two critical code injection vulnerabilities affecting its Isaac-GR00T robotics platform. The vulnerabilities, tracked as CVE-2025-33183 and CVE-2025-33184, exist within Python components and could allow authenticated attackers to …

Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign targeting Brazilian users has emerged, using WhatsApp as its primary distribution channel to spread banking trojans and harvest sensitive information. This sophisticated attack leverages social engineering …

Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tel Aviv, Israel, November 24th, 2025, CyberNewsWire Blast is introducing a new operating model for cloud security with a first-of-its-kind Preemptive Cloud Defense Platform, replacing reactive response with continuous prevention. …

PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept exploit has been publicly released for CVE-2025-9501, a critical, unauthenticated command-injection vulnerability affecting W3 Total Cache, one of WordPress’s most widely deployed caching plugins. With over 1 million …

Sha1-Hulud Supply Chain Attack: 800+ npm Packages and Thousands of GitHub Repos Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive resurgence of the Sha1-Hulud supply chain malware has struck the open-source ecosystem, compromising over 800 npm packages and tens of thousands of GitHub repositories in a campaign the …

Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

India-aligned threat group Dropping Elephant has launched a sophisticated multi-stage cyberattack targeting Pakistan’s defense sector using a Python-based remote access trojan disguised within an MSBuild dropper. Idan Tarab has identified …

APT35 Hacker Groups Internal Documents Leak Exposes their Targets and Attack Methods

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In October 2025, a significant breach exposed the internal workings of APT35, also known as Charming Kitten, a cyber unit operating within Iran’s Islamic Revolutionary Guard Corps Intelligence Organization. Thousands …

Tenda N300 Vulnerabilities Let Attacker to Execute Arbitrary Commands as Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tenda N300 wireless routers and 4G03 Pro portable LTE devices face severe security threats from multiple command injection vulnerabilities that allow attackers to execute arbitrary commands with root privileges. The …