Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

**Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure, Exposing Widespread Identity Exposure** A disturbing discovery has been made by Microsoft’s threat intelligence team, linking over thirty rotating domains to a notorious malware infrastructure known as MacSync Stealer. This sophisticated cybercrime operation has been exploiting unsuspecting individuals and organizations by leveraging identity exposure, creating active … Read more

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

Critical Vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE Leave Systems Exposed to Attackers A critical vulnerability trifecta has been discovered in various popular software platforms, leaving users vulnerable to cyber attacks. The vulnerabilities, which affect macOS, SharePoint, vCenter, and Microsoft’s Internet Key Exchange (IKE), have already been actively exploited by attackers, putting countless systems … Read more

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

CyberNews.work Exclusive: Malware Campaign Utilizes Compromised WordPress Sites to Spread Malware and Steal Data A sophisticated malware campaign has been discovered using nearly 2,000 hacked WordPress sites to spread malicious code and steal sensitive data from unsuspecting users. Dubbed “StopAndProtect,” this operation demonstrates the ongoing threat of compromised web applications serving as a conduit for … Read more

CISA: Medusa ransomware hit over 500 critical infrastructure orgs

The Medusa Ransomware Gang Has Breached Over 500 Critical Infrastructure Organizations in the US A shocking revelation from the Cybersecurity and Infrastructure Security Agency (CISA) has exposed a massive cyber threat to the country’s critical infrastructure. The agency revealed on Tuesday that the Medusa ransomware gang has compromised more than 500 organizations since June 2021, … Read more

Windows 11 24H2 Home and Pro reach end of support in 2 months

As of October 13th, Microsoft will stop issuing security and non-security updates to systems running Home and Pro editions of Windows 11 version 24H2. This means that millions of devices worldwide will no longer receive critical protections against the latest threats, leaving them vulnerable to attacks. The warning comes from a message center update issued … Read more

Critical RCE flaw in Windows IKE Extension now actively exploited

Critical Windows Flaw Exploited in the Wild, CISA Warns A critical remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions component is being actively exploited by hackers. This means that anyone can send malicious packets to an unpatched Windows system, potentially allowing attackers to gain control of it. The vulnerability, … Read more

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Cybersecurity threat actors have been exploiting a previously unknown vulnerability in Windchill, a widely used product lifecycle management (PLM) software, according to a recent discovery. The issue, linked to the notorious Clop ransomware group, allows attackers to decrypt sensitive engineering data and gain unauthorized access to credentials. The vulnerable software, owned by PTC Inc., is … Read more

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

A sprawling cybercrime operation has been uncovered, with Microsoft linking over 30 rotating domains to a notorious malware infrastructure known as MacSync Stealer. This sophisticated threat affects users across multiple platforms, exploiting vulnerabilities in identity exposure and privilege escalation to unleash devastating attacks on unsuspecting victims. At the heart of this operation lies a cleverly … Read more

GitLab Patches Critical Code Injection Vulnerability

GitLab has issued patches for two critical vulnerabilities that can be exploited without authentication, allowing attackers to manipulate user data and public projects. The company’s Community Edition (CE) and Enterprise Edition (EE) users from version 18.2 onwards are impacted. The first vulnerability, tracked as CVE-2026-19478 with a CVSS score of 9.4, allows an unauthenticated attacker … Read more