Phishing 3.0: The Fight Moves to Agent Versus Agent

A New Era of Cyber Warfare: Phishing 3.0 Puts Humans in the Crosshairs In a disturbing escalation of cyber threats, hackers have begun exploiting identity exposure to bypass traditional security measures and launch active attacks on unsuspecting users. Dubbed “Phishing 3.0,” this new wave of attacks sees malicious actors using compromised identities to infiltrate even … Read more

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Dahua Devices Compromised in Large-Scale Credential-Based Attack, Exposing Thousands of Users to Potential Risk A staggering 14,500+ Dahua security cameras and recorders have been compromised by hackers using a combination of credential attacks, authentication bypasses, and peer-to-peer (P2P) protocols. The breach is particularly concerning due to the widespread nature of the affected devices, which are … Read more

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

A sophisticated espionage campaign, dubbed SilkParasite, has been uncovered targeting central Asian governments with a suite of five custom-built Remote Access Trojans (RATs). The malware operation is believed to be state-sponsored and has been active since at least 2020. The attackers have honed in on high-value targets within the region’s governments, exploiting vulnerabilities in software … Read more

Microsoft fixes known issue causing Windows Defender crashes

A Critical Bug in Windows Defender Has Been Fixed, but What Does it Mean? A widespread issue with Microsoft’s Windows Defender security software has been resolved, following a string of problems that left users struggling to protect their devices from malware and viruses. The bug, which caused the program to crash on some systems, was … Read more

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A Clop-linked web shell, known as Windchill, has been discovered to not only decrypt credentials but also map sensitive engineering data on compromised networks. The malware’s capabilities have raised concerns about its potential use in active attack paths, putting enterprises and organizations at risk of severe breaches. The discovery was made after researchers identified a … Read more

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

**Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure, Exposing Widespread Identity Exposure** A disturbing discovery has been made by Microsoft’s threat intelligence team, linking over thirty rotating domains to a notorious malware infrastructure known as MacSync Stealer. This sophisticated cybercrime operation has been exploiting unsuspecting individuals and organizations by leveraging identity exposure, creating active … Read more

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

Critical Vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE Leave Systems Exposed to Attackers A critical vulnerability trifecta has been discovered in various popular software platforms, leaving users vulnerable to cyber attacks. The vulnerabilities, which affect macOS, SharePoint, vCenter, and Microsoft’s Internet Key Exchange (IKE), have already been actively exploited by attackers, putting countless systems … Read more

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

CyberNews.work Exclusive: Malware Campaign Utilizes Compromised WordPress Sites to Spread Malware and Steal Data A sophisticated malware campaign has been discovered using nearly 2,000 hacked WordPress sites to spread malicious code and steal sensitive data from unsuspecting users. Dubbed “StopAndProtect,” this operation demonstrates the ongoing threat of compromised web applications serving as a conduit for … Read more

CISA: Medusa ransomware hit over 500 critical infrastructure orgs

The Medusa Ransomware Gang Has Breached Over 500 Critical Infrastructure Organizations in the US A shocking revelation from the Cybersecurity and Infrastructure Security Agency (CISA) has exposed a massive cyber threat to the country’s critical infrastructure. The agency revealed on Tuesday that the Medusa ransomware gang has compromised more than 500 organizations since June 2021, … Read more

Windows 11 24H2 Home and Pro reach end of support in 2 months

As of October 13th, Microsoft will stop issuing security and non-security updates to systems running Home and Pro editions of Windows 11 version 24H2. This means that millions of devices worldwide will no longer receive critical protections against the latest threats, leaving them vulnerable to attacks. The warning comes from a message center update issued … Read more