ZCyberNews
中文

Articles

460 articles

MITRE F3 Framework Bridges Cybersecurity and Fraud AnalysisINFORMATIONAL
Tools & Techniques

MITRE F3 Framework Bridges Cybersecurity and Fraud Analysis

MITRE released the Fight Fraud Framework (F3), a unified knowledge base mapping the intersection of cyber attack tactics and financial fraud, aiming to close the operational gap between security and fraud teams.

3 min read
Obsidian Plugin Ecosystem Abused to Deliver PhantomPulse RAT in Targeted CampaignHIGH
Malware

Obsidian Plugin Ecosystem Abused to Deliver PhantomPulse RAT in Targeted Campaign

REF6598 threat group weaponizes Obsidian notes plugins to drop the PhantomPulse RAT on fintech and crypto professionals — TTP breakdown, IOCs, and what security teams should look for.

4 min readREF6598
Orthanc DICOM CVE-2023-26012: Pre-Auth RCE on Imaging ServersHIGH
Vulnerabilities

Orthanc DICOM CVE-2023-26012: Pre-Auth RCE on Imaging Servers

Three flaws in Orthanc DICOM server let unauthenticated attackers crash, read, or take over hospital imaging systems. Affected versions and patch details inside.

CVE-2023-26012CVE-2023-26013CVE-2023-26014
2 min read
VIPERTUNNEL Python Backdoor Evades Detection via Fake DLL and Obfuscated LoaderHIGH
Malware

VIPERTUNNEL Python Backdoor Evades Detection via Fake DLL and Obfuscated Loader

Threat actors deploy VIPERTUNNEL, a Python backdoor, using a fake DLL and multi-stage obfuscated loader to establish stealthy SOCKS5 proxy tunnels for persistent network access.

4 min read
WhatsApp's End-to-End Encryption Claims Challenged as 'Major Consumer Fraud'MEDIUM
Industry News

WhatsApp's End-to-End Encryption Claims Challenged as 'Major Consumer Fraud'

Telegram founder Pavel Durov alleges WhatsApp's default end-to-end encryption is misleading, as unencrypted cloud backups can expose billions of user messages.

4 min read
Adobe Patches Critical Acrobat Reader Flaw Under Active ExploitationCRITICAL
Vulnerabilities

Adobe Patches Critical Acrobat Reader Flaw Under Active Exploitation

Adobe has released emergency updates for a critical vulnerability (CVE-2026-34621) in Acrobat Reader that is being actively exploited to execute arbitrary code.

CVE-2026-34621
3 min read
ClickFix Malware Campaign Evades macOS Defenses via Script EditorHIGH
Malware

ClickFix Malware Campaign Evades macOS Defenses via Script Editor

A ClickFix social engineering campaign bypasses macOS security warnings by using Script Editor to execute malicious commands, marking a significant evolution in Mac-targeting malware.

4 min readClickFix
Cloudflare Block Disrupts Docker Hub Access in Spain During Football MatchMEDIUM
Industry News

Cloudflare Block Disrupts Docker Hub Access in Spain During Football Match

A Cloudflare IP block intended to prevent illegal football streaming inadvertently blocked access to Docker Hub and other services in Spain, highlighting collateral damage from blunt security measures.

4 min read
Fake Claude AI Site Delivers PlugX Malware in Trojanized InstallerHIGH
Malware

Fake Claude AI Site Delivers PlugX Malware in Trojanized Installer

A sophisticated phishing campaign uses a counterfeit Claude AI website to distribute a trojanized installer, deploying the remote access trojan PlugX to establish persistent backdoor access.

4 min read
FINRA Launches Intelligence Fusion Center to Counter Financial Cyber ThreatsINFORMATIONAL
Industry News

FINRA Launches Intelligence Fusion Center to Counter Financial Cyber Threats

The Financial Industry Regulatory Authority has established a new intelligence hub to centralize analysis of cyber threats and fraud targeting broker-dealers and capital markets.

4 min read
Iranian Internet Outage Exceeds 1,000 Hours Amid State-Imposed CensorshipHIGH
Industry News

Iranian Internet Outage Exceeds 1,000 Hours Amid State-Imposed Censorship

A state-directed internet blackout in Iran has surpassed 1,000 cumulative hours, marking a significant escalation in digital censorship and control tactics.

3 min read
Juniper Patches Critical RCE Flaw in Junos OS, Dozens of Other VulnerabilitiesCRITICAL
Vulnerabilities

Juniper Patches Critical RCE Flaw in Junos OS, Dozens of Other Vulnerabilities

Juniper Networks has released patches for a critical, pre-authentication remote code execution vulnerability in Junos OS, alongside dozens of other security fixes.

CVE-2024-2973
3 min read
← PrevPage 38 of 39Next →