News
Vimeo Confirms Data Breach After Hackers Access User Database
51+ min ago (481+ words) Vimeo has confirmed a data breach impacting portions of its user database, stemming from a compromise of its third-party analytics provider, Anodot. According to Vimeo, the breach did not originate within its own infrastructure but was the result of unauthorized…...
Kamasers DDo S Botnet With Loader Capabilities Attacking Organizations to Deploy Ransomware
20+ hour, 29+ min ago (688+ words) A newly analyzed DDo S botnet named Kamasers has emerged as one of the most operationally dangerous malware families observed in recent threat intelligence reporting, combining multi-vector distributed denial-of-service capabilities with a built-in loader function that opens infected systems to…...
Lofy Stealer Uses Node. js Loader Against Minecraft Gamers
4+ hour, 25+ min ago (426+ words) Cybersecurity threat hunters utilizing the ANY. The RUN interactive sandbox platform has uncovered an active infostealer campaign targeting the gaming community. The malware, identified as Lofy Stealer and also tracked as Grab Bot, disguises itself as a Minecraft hack named…...
Iranian APT Oil Rig Hides Malware Config Inside Google Drive Image
1+ day, 4+ hour ago (426+ words) A newly discovered cyberespionage campaign by the Iranian state-sponsored group APT-C-49, also known as Oil Rig or APT34, has revealed a highly sophisticated attack chain that hides malicious configurations inside seemingly harmless images hosted on Google Drive. Using recent Iranian protests…...
New Click Fix Campaign Uses Cmdkey and Regsvr32 To Evade Detection
1+ day, 4+ hour ago (358+ words) Cybersecurity researchers from Cyber Proof have identified a highly evasive variant of the Click Fix malware campaign. This new iteration abuses native Windows utilities, specifically the cmdkey and regsvr32 tools, to infect systems without dropping traditional malware files to the local…...
Whats App Tests In-House Cloud Backup Provider for Default End-to-End Encrypted Backups
23+ hour, 24+ min ago (333+ words) Whats App is advancing its privacy-first strategy by developing a proprietary cloud backup service with mandatory end-to-end encryption (E2 EE), aiming to eliminate reliance on third-party storage platforms like Google Drive and Apple i Cloud. Whats App is actively building an…...
AI Coding Agent Powered by Claude Opus 4. 6 Deletes Production Database in Just 9 Seconds
1+ day, 4+ hour ago (362+ words) A major incident involving a Claude Opus 4. 6-powered AI coding agent has raised serious concerns about AI safety and infrastructure security. The agent, operating through the Cursor editor, accidentally deleted the entire production database and backups of the Saa S…...
10, 000 Users Exposed As Fake Document Reader App Delivers Anatsa Banking Trojan
1+ day, 5+ hour ago (388+ words) Security researchers from Threat Labz have uncovered a deceptive threat hiding within the official Google Play Store. A fake document reader application, designed to look like a standard file management utility, was found secretly delivering the dangerous Anatsa Android banking…...
Linux ELF Malware Generator Evades ML Detection Using Semantic-Preserving Changes
1+ day, 22+ hour ago (399+ words) The study highlights growing concerns around the effectiveness of AI-driven security tools in detecting advanced threats targeting Linux environments. As Linux continues to dominate cloud infrastructure, high-performance computing, and Io T ecosystems, it has become an increasingly attractive target for…...
Microsoft Officially Shares Group Policy to Remove Windows 11 Copilot from Enterprise Devices
1+ day, 21+ hour ago (287+ words) Microsoft has officially introduced a new enterprise-focused policy that allows IT administrators to remove the Windows 11 Copilot app from managed devices, signaling a major shift toward greater control over AI feature deployment in corporate environments. The new policy, named Remove…...