ZCyberNews
中文

Articles

460 articles

Kyber Ransomware Deploys Dual Payloads for Windows and VMware ESXiHIGH
Malware

Kyber Ransomware Deploys Dual Payloads for Windows and VMware ESXi

Kyber ransomware deploys two distinct payloads to encrypt both Windows systems and VMware ESXi servers, using a custom tool to wipe ESXi snapshots and hinder recovery. The attack chain begins with compromised RDP credentials.

3 min readKyber
Malicious Crypto Apps Hijack Recovery Phrases from Apple App StoreHIGH
Malware

Malicious Crypto Apps Hijack Recovery Phrases from Apple App Store

Apple removed 45 malicious cryptocurrency apps from its App Store after they stole recovery phrases and private keys from users, mimicking legitimate wallets like MetaMask and Coinbase.

3 min read
NGate Malware Trojanizes HandyPay App to Steal Brazilian NFC DataHIGH
Malware

NGate Malware Trojanizes HandyPay App to Steal Brazilian NFC Data

NGate malware, using AI-generated code, has infected the legitimate HandyPay NFC app to steal payment card data and PINs from over 220,000 Android users in Brazil, according to ESET.

3 min readNGate
NGate Malware Uses AI to Evade Detection in Trojanized NFC AppsHIGH
Malware

NGate Malware Uses AI to Evade Detection in Trojanized NFC Apps

NGate malware version 2.0, built with AI assistance, hides in a trojanized NFC payment app to steal SMS, contacts, and crypto wallet data from Android devices while evading security software.

3 min read
Ofcom Investigates Telegram for CSAM Sharing and Encryption Non-ComplianceINFORMATIONAL
Industry News

Ofcom Investigates Telegram for CSAM Sharing and Encryption Non-Compliance

UK regulator Ofcom launches a formal investigation into Telegram over evidence of child sexual abuse material (CSAM) sharing and potential breaches of the Online Safety Act's encryption reporting rules.

2 min read
PureRAT Malware Evades Detection with PNG-Stashed PayloadsHIGH
Malware

PureRAT Malware Evades Detection with PNG-Stashed Payloads

PureRAT hides its Windows PE payloads inside PNG files and executes them filelessly in memory, a technique detailed by cybersecurity researchers analyzing a new sophisticated campaign.

3 min read
Windows Snipping Tool Vulnerability Leaks NTLM Hashes via Malicious LinksHIGH
Vulnerabilities

Windows Snipping Tool Vulnerability Leaks NTLM Hashes via Malicious Links

CVE-2026-33829 in Windows Snipping Tool allows attackers to steal NTLMv2 hashes via malicious links. A public PoC exploit targets the ms-screensketch protocol to enable credential relay attacks.

CVE-2026-33829
3 min read
Datto Warns Traditional Backups Fail to Maintain Business Operations DuringHIGH
Industry News

Datto Warns Traditional Backups Fail to Maintain Business Operations During

Datto's 2026 report reveals 43% of businesses with backups still face over 24 hours of downtime after an attack, highlighting the critical gap between data backup and true business continuity and disaster recovery (BCDR).

3 min read
FakeWallet Crypto Stealer Infects iOS Devices via Apple App StoreHIGH
Malware

FakeWallet Crypto Stealer Infects iOS Devices via Apple App Store

Kaspersky discovered 22 malicious iOS apps on the official App Store impersonating crypto wallets like MetaMask and Coinbase, stealing seed phrases and private keys from over 1,000 victims.

3 min readFakeWallet
Gh0st RAT and CloverPlus Adware Deployed in Dual-Payload CampaignHIGH
Malware

Gh0st RAT and CloverPlus Adware Deployed in Dual-Payload Campaign

A new malware campaign deploys both Gh0st RAT and CloverPlus adware via a single obfuscated loader, giving attackers persistent remote control and a revenue stream from a single infection.

3 min read
MiningDropper Framework Delivers Infostealers, RATs to Android DevicesHIGH
Malware

MiningDropper Framework Delivers Infostealers, RATs to Android Devices

MiningDropper, a multi-stage Android malware framework, delivers infostealers, RATs, and banking trojans to devices via disguised apps, according to CyberSecurity News researchers.

3 min read
NIST Abandons Comprehensive NVD Analysis for Risk-Based PrioritizationINFORMATIONAL
Industry News

NIST Abandons Comprehensive NVD Analysis for Risk-Based Prioritization

NIST will no longer analyze all 263,000+ annual CVE submissions, shifting to a risk-based model to prioritize high-impact flaws as submissions surge 263% since 2020.

3 min read
← PrevPage 29 of 39Next →