News

Cyber Security News
cyberpress. org > palo-alto-warns-of-actively-exploited

Palo Alto Warns of Actively Exploited Global Protect VPN Vulnerability

4+ hour, 16+ min ago  (327+ words) The vulnerability was originally assigned a CVSSv4 score of 4. 7 (medium), but following confirmed in-the-wild exploitation, Palo Alto Networks revised the score to7. 8 (high)on May 29, 2026, the same day CISA added it to the Known Exploited Vulnerabilities (KEV)catalog. When the certificate used…...

Symbols: nasdaq:panw
Google News
cyberpress. org > ad-blockers-steal-ai-chats

Malicious Ad Blocker Extensions Intercept AI Conversations From 90, 000 Browser Users

5+ hour, 16+ min ago  (437+ words) Operating under the guise of two malicious ad-blocking extensions, the campaign captures sensitive chat logs, account metadata, and model usage from eight major AI platforms while maintaining a completely legitimate appearance. The operation, internally tracked as Panel 231, successfully targets Chat…...

Symbols: btc-usd
Cyber Security News
cyberpress. org > apt28-steals-net-ntlmv2-hashes-via-outlook-flaw

APT28 Weaponizes Outlook Zero-Click Flaw to Steal Net-NTLMv2 Hashes From NATO Targets

3+ day, 1+ hour ago  (407+ words) Russian state-sponsored threat actor APT28, also known as Fancy Bear or Forest Blizzard, has aggressively shifted its cyber espionage tactics to focus on zero-click vulnerabilities and edge infrastructure. Recent threat intelligence reveals that the group, publicly attributed to the GRU's Unit…...

Symbols: cert-ua
Cyber Security News
cyberpress. org > fake-spotify-tutorials-infect

Fake Spotify Premium Tutorials Use Power Shell Commands to Infect Windows Users With Malware

3+ day, 5+ hour ago  (349+ words) Moving away from traditional phishing emails, threat actors are now leveraging the algorithms of popular social media applications to trick unsuspecting users into compromising their own systems. By exploiting the viral nature of short videos, attackers are successfully luring victims…...

Symbols: cefe-ai
Cyber Security News
cyberpress. org > sniperdz-powers-brand-impersonation

Hackers Abuse Sniper Dz Phaa S for Brand Impersonation Attacks

3+ day, 23+ hour ago  (416+ words) Recently observed targeting users in the Middle East and North Africa (MENA), these campaigns trick victims into clicking fake promotional offers. Instead of receiving free internet or financial aid, victims are pulled into a massive fraud ecosystem. Sniper Dz acts…...

Cyber Security News
cyberpress. org > jdy-botnet-targets-flaws

JDY Botnet Expands With 1, 500 Compromised Devices Targeting Fresh Vulnerabilities

4+ day, 6+ hour ago  (458+ words) A significant resurgence of the JDY botnet, a covert reconnaissance network linked to China-nexus threat groups such as Volt Typhoon. Originally part of the larger KV-botnet ecosystem that was heavily disrupted by U. S. government takedowns in early 2024, the JDY cluster managed…...

Symbols: aic.sh,ncsc-uk
Cyber Security News
cyberpress. org > viral-reels-spread-malware

Hackers Exploit Viral Reels and Tik Toks to Promote Malware-Laced Software Downloads

5+ day, 5+ hour ago  (399+ words) Social media algorithms are designed to serve up exactly what you want to see. However, threat actors are now manipulating these systems to deliver malware. By leveraging short-form videos on platforms like Tik Tok and Instagram Reels, attackers are pushing…...

Cyber Security News
cyberpress. org > tax-phishing-drops-malware

Tax-Themed Phishing Emails Deliver In-Memory Malware to Windows Users

5+ day, 5+ hour ago  (428+ words) Cybersecurity researchers have uncovered a highly sophisticated phishing campaign that uses tax-themed emails to deliver advanced in-memory malware to Windows users. The malicious operation relies heavily on social engineering and government impersonation to trick victims into compromising their own systems....

Symbols: cert-ua
Cyber Security News
cyberpress. org > magicad-malware-floods-android

Android Malware Magic Ad Delivers Aggressive Ad Flooding Campaign

6+ day, 18+ min ago  (379+ words) Threat actors initially distributed the malware through official channels, including the Samsung Galaxy Store and Xiaomi's Get Apps application catalog. To avoid premature detection, the attackers disguised the Trojan within more than 50 different games and utility programs. These infected apps…...

Cyber Security News
cyberpress. org > microsoft-365-phishing-attack

New Browser-in-the-Browser Phishing Attack Targets Microsoft 365 Login Credentials

6+ day, 2+ hour ago  (393+ words) Cybercriminals have launched a highly deceptive phishing campaign targeting Microsoft 365 users. This operation utilizes a sophisticated technique known as a Browser-in-the-Browser (Bit B) attack to steal sensitive corporate data. With cloud-based operations serving as the backbone for many modern businesses, compromising…...