New Moonwalk++ PoC Shows How Malware Can Spoof Windows Call Stacks and Evade Elastic-Inspired Rules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated proof-of-concept demonstrating how malware can bypass advanced call stack detection mechanisms increasingly adopted by enterprise security vendors like Elastic. The new Moonwalk++ technique extends prior stack-spoofing research and reveals critical …

New ClickFix ‘Word Online’ Message Tricks Users into Installing DarkGate Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated social engineering campaign dubbed “ClickFix” has emerged, targeting users with deceptive “Word Online” error messages to distribute the formidable DarkGate malware. Unlike traditional drive-by downloads, this attack relies …

Chrome Zero-Day Vulnerabilities Exploited in 2025 – A Comprehensive Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Throughout 2025, Google addressed a significant wave of actively exploited zero-day vulnerabilities affecting its Chrome browser, patching a total of eight critical flaws that threatened billions of users worldwide. These …

Cellik Android Malware with One-Click APK Builder Let Attackers Wrap its Payload Inside with Google Play Store Apps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cellik represents a significant evolution in Android Remote Access Trojan capabilities, introducing sophisticated device control and surveillance features previously reserved for advanced spyware. This newly identified RAT combines full device …

NVIDIA Isaac Lab Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security update addressing a dangerous deserialization vulnerability in NVIDIA Isaac Lab, a component of the NVIDIA Isaac Sim framework. The flaw could allow attackers to execute arbitrary code …

New GhostPoster Attack Leverages PNG Icon to Infect 50,000 Firefox Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign dubbed “GhostPoster” has been uncovered, leveraging a clever steganography technique to compromise approximately 50,000 Firefox users. The attack vector primarily involves seemingly innocent browser extensions, …

Chrome Security Update – Patch for Critical Vulnerabilities that Enables Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome version 143.0.7499.146/.147 to address critical security vulnerabilities that could enable remote code execution on affected systems. The update is now rolling out to Windows and Mac …

BlindEagle Hackers Attacking Organization to Abuse Trust and Bypass Email Security Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated cyberespionage campaign, the BlindEagle threat actor has once again targeted Colombian government institutions. This latest operation specifically zeroed in on an agency under the Ministry of Commerce, …

APT-C-35 Infrastructure Activity Leveraged Using Apache HTTP Response Indicators

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant discovery in threat intelligence reveals that APT-C-35, commonly known as DoNot, continues to maintain an active infrastructure footprint across the internet. Security researchers have identified new infrastructure clusters …

Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Russian state-sponsored hacking group has been targeting network edge devices in Western critical infrastructure since 2021, with operations intensifying throughout 2025. The campaign, linked to Russia’s Main Intelligence Directorate …