Threat actor PCPJack hijacked 230 AWS, Google Cloud, and Microsoft Azure servers to establish a covert SMTP relay network, according to Hunt.io findings.
A new supply chain attack called Miasma has compromised Red Hat npm packages to steal credentials, target CI/CD environments, and deploy a self propagating malware campaign affecting developers and cloud systems.
Iran linked hacking group MuddyWater has launched a cyber espionage campaign targeting organizations across nine countries using DLL side loading, credential theft, and covert access techniques.
This week’s cybersecurity developments included Linux kernel flaws, Microsoft Defender zero days, GitHub supply chain compromises, active router botnets, and increasing exploitation of vulnerabilities worldwide.
European and North American authorities have dismantled First VPN Service, a criminal VPN infrastructure reportedly used by 25 ransomware groups to conceal cyberattacks, fraud, and data theft operations.
New cybersecurity research highlights how vulnerable Windows kernel mode drivers may remain exploitable without dedicated hardware, raising concerns around BYOVD attacks and endpoint security risks.
Security researchers have disclosed new Windows zero day vulnerabilities affecting BitLocker and CTFMON, exposing privilege escalation and encryption bypass risks across Windows 11 and Windows Server systems.
Cybersecurity researchers have identified a new TrickMo Android banking trojan variant that uses TON based command and control infrastructure, SOCKS5 proxying, and SSH tunnelling to target banking and cryptocurrency users in Europe.
NDS Technologies and Dell Technologies hosted a Meet and Greet session discussing cyber resilience, data protection, and business continuity with industry professionals and customers.
A malvertising campaign targets U.S. users searching for tax forms, delivering ScreenConnect malware and HwAudKiller to bypass EDR using a Huawei driver.
Salesforce warns of large scale scanning attempts targeting misconfigured Experience Cloud sites using a modified AuraInspector tool capable of extracting sensitive data from public endpoints.
Researchers uncover a new MacSync macOS stealer variant distributed via a signed and notarized Swift app, abusing Apple trust mechanisms to evade Gatekeeper and deliver malware.