SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

A sophisticated espionage campaign, dubbed SilkParasite, has been uncovered targeting central Asian governments with a suite of five custom-built Remote Access Trojans (RATs). The malware operation is believed to be state-sponsored and has been active since at least 2020. The attackers have honed in on high-value targets within the region’s governments, exploiting vulnerabilities in software … Read more

Microsoft fixes known issue causing Windows Defender crashes

A Critical Bug in Windows Defender Has Been Fixed, but What Does it Mean? A widespread issue with Microsoft’s Windows Defender security software has been resolved, following a string of problems that left users struggling to protect their devices from malware and viruses. The bug, which caused the program to crash on some systems, was … Read more

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A Clop-linked web shell, known as Windchill, has been discovered to not only decrypt credentials but also map sensitive engineering data on compromised networks. The malware’s capabilities have raised concerns about its potential use in active attack paths, putting enterprises and organizations at risk of severe breaches. The discovery was made after researchers identified a … Read more

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

**Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure, Exposing Widespread Identity Exposure** A disturbing discovery has been made by Microsoft’s threat intelligence team, linking over thirty rotating domains to a notorious malware infrastructure known as MacSync Stealer. This sophisticated cybercrime operation has been exploiting unsuspecting individuals and organizations by leveraging identity exposure, creating active … Read more

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

Critical Vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE Leave Systems Exposed to Attackers A critical vulnerability trifecta has been discovered in various popular software platforms, leaving users vulnerable to cyber attacks. The vulnerabilities, which affect macOS, SharePoint, vCenter, and Microsoft’s Internet Key Exchange (IKE), have already been actively exploited by attackers, putting countless systems … Read more

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

CyberNews.work Exclusive: Malware Campaign Utilizes Compromised WordPress Sites to Spread Malware and Steal Data A sophisticated malware campaign has been discovered using nearly 2,000 hacked WordPress sites to spread malicious code and steal sensitive data from unsuspecting users. Dubbed “StopAndProtect,” this operation demonstrates the ongoing threat of compromised web applications serving as a conduit for … Read more

CISA: Medusa ransomware hit over 500 critical infrastructure orgs

The Medusa Ransomware Gang Has Breached Over 500 Critical Infrastructure Organizations in the US A shocking revelation from the Cybersecurity and Infrastructure Security Agency (CISA) has exposed a massive cyber threat to the country’s critical infrastructure. The agency revealed on Tuesday that the Medusa ransomware gang has compromised more than 500 organizations since June 2021, … Read more

Windows 11 24H2 Home and Pro reach end of support in 2 months

As of October 13th, Microsoft will stop issuing security and non-security updates to systems running Home and Pro editions of Windows 11 version 24H2. This means that millions of devices worldwide will no longer receive critical protections against the latest threats, leaving them vulnerable to attacks. The warning comes from a message center update issued … Read more

Critical RCE flaw in Windows IKE Extension now actively exploited

Critical Windows Flaw Exploited in the Wild, CISA Warns A critical remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions component is being actively exploited by hackers. This means that anyone can send malicious packets to an unpatched Windows system, potentially allowing attackers to gain control of it. The vulnerability, … Read more

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Cybersecurity threat actors have been exploiting a previously unknown vulnerability in Windchill, a widely used product lifecycle management (PLM) software, according to a recent discovery. The issue, linked to the notorious Clop ransomware group, allows attackers to decrypt sensitive engineering data and gain unauthorized access to credentials. The vulnerable software, owned by PTC Inc., is … Read more