Indirect-Shellcode-Executor Tool Exploits Windows API Vulnerability to Evade AV and EDR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new offensive security tool developed in Rust is demonstrating a novel method for bypassing modern Endpoint Detection and Response (EDR) systems by exploiting an overlooked behavior in the Windows …

Microsoft Details Security Risks of New Agentic AI Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, discussions have centered on Microsoft’s experimental agentic AI feature, which has introduced both advanced task automation and significant security concerns. This agentic capability, available to Windows insiders …

Developers Expose Passwords and API Keys via Online Tools like JSONFormatter

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Developers are unintentionally exposing passwords, API keys, and sensitive data in production information into online formatting tools such as JSONFormatter and CodeBeautify. New research from watchTowr shows that thousands of …

HashJack: New Attack Technique Tricks AI Browsers Using a Simple ‘#’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Cato CTRL have discovered a new indirect prompt injection technique called HashJack, which weaponises legitimate websites to manipulate AI browser assistants. The attack conceals malicious instructions after the …

Tor Adopts Galois Onion Encryption to Strengthen Defense Against Online Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Tor Project has announced a significant cryptographic overhaul, retiring its legacy relay encryption algorithm after decades of service and replacing it with Counter Galois Onion (CGO). This research-backed encryption …

Microsoft Teams Introduces New Feature to Boost Performance and Startup Speed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced a significant update to the Teams Desktop Client for Windows that aims to enhance performance and reduce startup times for calling features. The update, detailed in the …

ASUS MyASUS Flaw Lets Hackers Escalate to SYSTEM-Level Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ASUS has disclosed a high security vulnerability in its MyASUS application that could allow local attackers to escalate their privileges to SYSTEM-level access on affected Windows devices. The flaw, tracked …

YAMAGoya – Real-Time Threat Monitoring Tool Using Sigma and YARA Rules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Modern cybersecurity faces an escalating challenge: fileless malware and obfuscation techniques increasingly bypass traditional file-based detection methods. To address this growing threat, JPCERT/CC has released YAMAGoya. This open-source threat hunting …

Cobalt Strike 4.12 Released With New Process Injection, UAC Bypasses and Malleable C2 Options

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New release brings significant improvements to the penetration testing framework, introducing enhanced GUI features, REST API support, and powerful new evasion techniques that security researchers can leverage for offensive operations. …

Apache Syncope Vulnerability Allows Attacker to Access Internal Database Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant issue has been disclosed that affects multiple versions of the identity and access management platform. The flaw stems from a hardcoded default encryption key used for password storage, …