Category: CyberSecurityNews

Google Chrome 0-Day Vulnerability Actively Exploited in the Wild
18
Sep
2025

Google Chrome 0-Day Vulnerability Actively Exploited in the Wild

Google has released an emergency security update for its Chrome web browser to address a high-severity zero-day vulnerability that is…

China-Aligned TA415 Hackers Uses Google Sheets and Google Calendar for C2 Communications
18
Sep
2025

China-Aligned TA415 Hackers Uses Google Sheets and Google Calendar for C2 Communications

The Chinese state-sponsored threat actor TA415 has evolved its tactics, techniques, and procedures by leveraging legitimate cloud services like Google…

MuddyWater Hackers Using Custom Malware With Multi-Stage Payloads and Uses Cloudflare to Mask Fingerprints
18
Sep
2025

MuddyWater Hackers Using Custom Malware With Multi-Stage Payloads and Uses Cloudflare to Mask Fingerprints

Since early 2025, cybersecurity teams have observed a marked resurgence in operations attributed to MuddyWater, an Iranian state–sponsored advanced persistent…

BeaverTail Variant via Malicious Repositories Targeting Retail Sector Organizations
17
Sep
2025

BeaverTail Variant via Malicious Repositories Targeting Retail Sector Organizations

A sophisticated North Korean nation-state threat actor campaign has emerged, distributing an evolved variant of the BeaverTail malware through deceptive…

New Magecart Skimmer Attack With Malicious JavaScript Injection to Skim Payment Data
17
Sep
2025

New Magecart Skimmer Attack With Malicious JavaScript Injection to Skim Payment Data

The threat landscape for e-commerce websites has once again shifted with the emergence of a sophisticated Magecart-style attack campaign, characterized…

Microsoft Dismantles 300+ Websites Used to Distribute RaccoonO365 Phishing Service
17
Sep
2025

Microsoft Dismantles 300+ Websites Used to Distribute RaccoonO365 Phishing Service

Since mid-2024, cybercriminals have leveraged a subscription-based phishing platform known as RaccoonO365 to harvest Microsoft 365 credentials at scale. Emerging…

Agentless Access, Sensitive Data Masking, and Smooth Session Playback
17
Sep
2025

Agentless Access, Sensitive Data Masking, and Smooth Session Playback

Syteca, a global cybersecurity provider, introduced the latest release of its platform, continuing the mission to help organizations reduce insider…

224 Malicious Android Apps on Google Play With 38 Million Downloads Delivering Malicious Payloads
17
Sep
2025

224 Malicious Android Apps on Google Play With 38 Million Downloads Delivering Malicious Payloads

A sophisticated mobile ad fraud operation dubbed “SlopAds” has infiltrated Google Play Store with 224 malicious applications that collectively amassed…

Hackers Exploit RTL/LTR Scripts and Browser Gaps to Hide Malicious URLs
17
Sep
2025

Hackers Exploit RTL/LTR Scripts and Browser Gaps to Hide Malicious URLs

A decade-old Unicode vulnerability known as BiDi Swap allows attackers to spoof URLs for sophisticated phishing attacks. By exploiting how…

PureHVNC RAT Developers Leverage GitHub Host Source Code
17
Sep
2025

PureHVNC RAT Developers Leverage GitHub Host Source Code

The PureHVNC remote administration tool (RAT) has emerged as a sophisticated component of the Pure malware family, gaining prominence in…

Threat Actors Abuse Adtech Companies to Target Users With Malicious Ads
17
Sep
2025

Threat Actors Abuse Adtech Companies to Target Users With Malicious Ads

The digital advertising ecosystem has become a prime hunting ground for cybercriminals, who are increasingly exploiting advertising technology companies to…

Python Based XillenStealer Attacking Windows Users to Steal Sensitive Data
17
Sep
2025

Python Based XillenStealer Attacking Windows Users to Steal Sensitive Data

In recent weeks, cybersecurity researchers have observed the emergence of XillenStealer, a Python-based information stealer publicly hosted on GitHub and…