Security
-
Cybercriminals have developed a new malware attack that hides harmful software inside JPEG image files, allowing them to steal passwords from unsuspecting victims. By using steganography, a technique that hides data inside images, hackers can bypass security defenses and infect devices.
-
A new ransomware strain called Ebyte is rapidly spreading across North America and Europe, encrypting critical files and demanding high ransom payments. Security experts warn that this malware is highly advanced, making data recovery nearly impossible without paying the attackers.
-
Microsoft has uncovered a large-scale malware attack, named Storm-0408, that infected nearly one million devices worldwide. The attackers used malvertising on illegal streaming sites to spread malware hosted on GitHub, Discord, and Dropbox. The malware stole personal data, browser credentials, and even disabled security protections.
-
A new phishing scam is targeting YouTube creators using AI-generated deepfake videos of YouTube CEO Neal Mohan. Attackers trick creators into sharing login credentials by pretending to send a private video about monetization updates. Once hacked, accounts are used for scams and malware attacks.
-
Cybercriminals have found a new way to trick companies into paying fake ransoms – by sending physical letters in the mail. Instead of hacking networks or deploying ransomware, fraudsters are simply claiming they have stolen sensitive data and demanding money to prevent its release.
-
Cybercriminals are using stolen browser fingerprints to bypass security checks and impersonate users. The ScreamedJungle attack targets outdated Magento e-commerce platforms to inject malicious scripts that steal unique digital identifiers. This allows hackers to evade security systems, including multi-factor authentication (MFA) and device reputation checks.
-
Cybercriminals are abusing PayPal’s address settings to send scam emails that look like official notifications. These emails claim a new shipping address has been added to your PayPal account and include a fake purchase confirmation for a MacBook M4. The goal is to trick users into calling a fake PayPal support number, where scammers try to gain remote access to their devices.
-
A dangerous Wi-Fi password-stealing tool has been found on GitHub. This Python-based script can extract saved Wi-Fi credentials from Windows devices, making it a serious security risk. While labeled as an "educational tool," it can easily be misused by hackers to gain unauthorized network access.
-
Raymond Limited, a well-known textile and clothing company, has confirmed a cyber attack on its IT systems. The breach impacted some internal infrastructure, but the company's retail stores, supply chain, and digital services continue to operate normally. The attack was detected during routine security monitoring, and immediate action was taken to isolate affected systems.
-
Cybercriminals have exploited over 150 Indian government and financial websites to trick users into fake gambling and investment scams. By injecting malicious code into trusted domains, they manipulate search engine rankings, redirecting visitors to fraudulent rummy and casino websites. This attack highlights the urgent need for stronger cybersecurity measures to protect public sector platforms.