Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A wave of cyberattacks across the US and Europe in August exploited the trust businesses place in everyday tools, turning Microsoft 365 logins, remote-management software, and routine business documents into …

Dropbox Says 5,000 Accounts Were Compromised Through Lenovo ID Authentication Flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dropbox has disclosed that approximately 5,000 user accounts were compromised in August after attackers exploited a weakness involving its Lenovo ID sign-in integration. The incident highlights the security risks that …

Russian Hacker Indicted for Using Excel Malware to Target 80,000 Freelancers With TVRAT and DarkVNC

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Russian national has been indicted in the United States over an alleged malware operation that targeted roughly 80,000 freelance workers worldwide. Prosecutors say the campaign used fake accounts and …

Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware operators are using a previously undocumented remote-control framework called TukTuk to steal credentials, watch compromised machines, and weaken protections. The discovery links the tool to activity associated with the …

BREEZE COMET Hackers Use AI-Assisted Malware to Target Brazil Banks for Fraudulent Transfers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Brazilian banks and payment companies are facing a more direct form of cybercrime. BREEZE COMET, a financially motivated group formerly tracked as UNC5669, targets the systems that move money instead …

Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in Cleo Harmony, a widely deployed managed file transfer and integration platform, is putting enterprise networks at risk after security researchers confirmed that remote attackers can …

FBI and CrowdStrike Disrupt 20-Year-Old Sality Botnet Controlling 15,000+ Infected Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Department of Justice has confirmed a coordinated international takedown of the Sality botnet, a peer-to-peer malware network that has plagued victims worldwide since 2003. The operation spanned the United …

Claude AI Builds Pre-Auth RCE Exploit for WAGO PLC to Execute ARM Shellcode Without Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers used Claude AI to help port a pre-authentication remote code execution exploit to a WAGO programmable logic controller, demonstrating how AI can assist with low-level operational technology exploitation. The …

FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly. FreeRDP is widely used …

Palo Alto Networks Acquires Console to Build AI Agents for Autonomous Security Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks has acquired Console, an AI-native platform that will strengthen Cortex by enabling AI-driven security workflows to investigate, prioritize, and remediate threats at machine speed. The acquisition comes …