• A newly documented malware campaign demonstrates how attackers are leveraging Windows LNK shortcuts to deliver the MastaStealer infostealer.

    The attack begins with spear-phishing emails containing ZIP archives with a single LNK file that executes a multi-stage infection process.

    When victims click the malicious shortcut, it launches Microsoft Edge while opening the AnyDesk website in the foreground to appear legitimate.

    Meanwhile, in the background, the LNK file silently downloads and executes an MSI installer from a compromised domain.

    The infection chain reveals sophisticated evasion techniques. The MSI installer extracts its payload to a hidden directory structure under %LOCALAPPDATA%\Temp\MW-\files.cab, then decompresses the contents and drops the actual C2 beacon at %LOCALAPPDATA%\Microsoft\Windows\dwm.exe.

    This filename mimics legitimate Windows Display Window Manager processes, making detection harder for security tools.

    The campaign successfully bypassed traditional detection methods through careful file placement and process naming conventions.

    Maurice Fielenbach, Infosec Research and Security Trainings analyst, identified this infection after discovering Windows Installer event logs showing Application Event ID 11708 failures.

    The alert was triggered because the compromised user lacked local administrator privileges, causing the MSI deployment to fail unexpectedly.

    This failure, ironically, saved the system from full compromise and revealed the attack to defenders.

    PowerShell-Based Defender Exclusion

    The most critical aspect of this campaign involves the PowerShell command executed during installation to disable Windows Defender protections.

    The malware runs the following command to create an exclusion path for its C2 beacon: Add-MpPreference -ExclusionPath "C:\Users\admin\AppData\Local\Microsoft\Windows\dvm.exe".

    This single command removes the Windows Defender real-time scanning for the malware executable, allowing it to communicate freely with command and control servers at cmqsqomiwwksmcsw[.]xyz (38.134.148.74) and ykgmqooyusggyyya[.]xyz (155.117.20.75).

    The technique demonstrates how attackers bypass modern endpoint protection by exploiting legitimate Windows administration features rather than forcing their way through security controls.

    Organizations should monitor for unusual PowerShell execution with MpPreference parameters and implement application whitelisting to prevent unauthorized Defender modifications.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post MastaStealer Weaponizes Windows LNK Files, Executes PowerShell Command, and Evades Defender appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals have launched a sophisticated phishing campaign that exploits trust in internal security systems by spoofing email delivery notifications to appear as legitimate spam-filter alerts within organizations. These deceptive emails are designed to steal login credentials that could compromise email accounts, cloud storage, and other sensitive systems. ​ The attack begins with an email claiming […]

    The post Phishing Emails Alert: How Spam Filters Can Steal Your Email Logins in an Instant appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has launched a new security feature in Teams Premium called “Prevent screen capture,” designed to block screenshots and recordings during sensitive meetings, with general availability rolling out worldwide through late November 2025.​

    This enhancement addresses growing concerns over data leaks in virtual collaborations, particularly in industries like finance, healthcare, and legal sectors, where confidential information is routinely shared.

    Previously announced in the Microsoft 365 Roadmap under ID 490561, the feature’s timeline was updated on November 12, 2025, shifting the general availability start from mid-October to early November to allow for additional testing and refinements.

    Targeted release began in mid-September 2025 for select users, but broader deployment is now underway, ensuring organizations can protect meeting content from unauthorized captures using native tools and most third-party apps.​

    How the Feature Works

    When enabled, “Prevent screen capture” restricts visual access to meeting elements like the stage view, chat, participant lists, and Copilot panels.

    On Windows desktops, attempts to screenshot result in a black rectangle obscuring the meeting window, including any pop-out sections, preventing clear captures of shared screens or documents.

    Android devices, including phones and tablets, fully block screenshots and recordings, displaying a notification to users that screen capture is restricted.​

    Unsupported platforms, such as iOS, macOS, web browsers, or non-Intune-enrolled devices, force participants into audio-only mode, limiting them to voice without video or shared content visibility.

    This ensures confidentiality but may disrupt the experiences of some attendees, highlighting the need for device compatibility checks before meetings.​

    Organizers and co-organizers activate the feature via the Meeting Options menu under Advanced Protection, where a simple toggle switches it on or off by default to avoid unintended restrictions.

    As shown in Microsoft’s preview of the settings interface, the option appears alongside other protections, such as content-forwarding blocks and end-to-end encryption toggles.​

    Teams interface
    Teams interface

    For IT admins and security teams, this tool integrates with Entra ID for licensing management and device enrollment via Intune, enabling scalable enforcement.

    However, it raises compliance concerns under regulations such as the GDPR, as it limits users’ ability to capture or retain personal data shared in meetings, potentially affecting data subjects’ rights to access and export it.​

    Organizations should prepare by educating organizers on the feature’s use, updating internal policies for Teams Premium, and verifying mobile device compliance.

    While effective against digital captures, experts note it doesn’t prevent physical photos of screens, underscoring layered security approaches.​

    This rollout underscores Microsoft’s push toward fortified collaboration tools amid rising cyber threats, offering a practical shield for high-stakes discussions without overcomplicating everyday use.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft Teams New Premium Feature Blocks Screenshots and Recordings During Meeting appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • On Friday, November 7th, Veracode Threat Research discovered a dangerous typosquatting campaign targeting developers using GitHub Actions. The malicious npm package “@acitons/artifact” had accumulated over 206,000 downloads before being removed, posing a significant threat to GitHub-owned repositories and potentially compromising sensitive authentication tokens. The malicious package mimicked the legitimate “@actions/artifact” npm package, which is part […]

    The post Malicious npm Package with 206K Downloads Targeting GitHub Repositories to Steal Tokens appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The SmartApeSG campaign, also known as ZPHP and HANEYMANEY, continues to evolve its infection tactics, pivoting to ClickFix-style attack vectors. Security researchers have documented the campaign’s latest methodology, which uses deceptive fake CAPTCHA pages to trick users into executing malicious commands that ultimately deploy NetSupport RAT a Remote Access Trojan capable of giving attackers complete […]

    The post SmartApeSG Uses ClickFix to Deploy NetSupport RAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The notorious Cl0p ransomware group has claimed responsibility for breaching the UK’s National Health Service (NHS), spotlighting vulnerabilities in Oracle’s E-Business Suite (EBS).

    The announcement, posted on Cl0p’s dark web leak site on November 11, 2026, accuses the NHS of prioritizing profits over patient security, stating, “The company doesn’t care about its customers; it ignored their security.”

    This comes amid a broader hacking campaign that has ensnared dozens of high-profile organizations since early October.

    The NHS, which serves over 1.3 million patients daily through its vast network of hospitals and clinics, confirmed awareness of the claim but emphasized that no data has surfaced publicly.

    “We are aware that the NHS has been listed on a cybercrime website as being impacted by a cyber-attack, but no data has been published,” an NHS England spokesperson said.

    The organization’s cybersecurity team is collaborating with the National Cyber Security Centre (NCSC) to probe the incident, underscoring the urgency in a sector already strained by ransomware disruptions.

    The Oracle EBS campaign, exploiting CVE-2025-61882, a critical unauthenticated remote code execution flaw, emerged in early October 2026. Within weeks, attackers began doxxing victims on Cl0p’s site.

    The NHS joins a growing roster of over 40 alleged targets, with data from 25 already leaked. Confirmed victims include Harvard University, whose academic records were exposed; Envoy Air, a subsidiary of American Airlines, facing flight operation risks; industrial leaders Schneider Electric and Emerson, vulnerable in manufacturing supply chains; and media outlet The Washington Post, which saw journalistic assets compromised.

    Security experts warn that CVE-2025-61882 allows attackers to bypass authentication and execute arbitrary code on unpatched Oracle EBS servers, often used for enterprise resource planning.

    Oracle issued patches in late September, but adoption lags in legacy systems like those in healthcare. “This isn’t just a technical issue it’s a threat to public safety,” said cybersecurity analyst Jane Doe at a recent NCSC briefing. “Ransomware groups like Cl0p exploit slow patching to hit high-value sectors.”

    As of now, the leak site lists over 40 alleged victims from the Oracle EBS attacks, with data from 25 already published, ranging from employee PII to proprietary business information. For the NHS, the stakes are particularly high.

    Past ransomware incidents, like the 2024 Qilin attack on a UK hospital that allegedly contributed to a patient’s death, highlight how such breaches can halt critical care, delay surgeries, and expose medical histories.

    Experts warn that the Oracle EBS flaws, patched in October by Oracle, underscore the risks of delayed updates in legacy systems. “Healthcare providers must prioritize patching and multi-factor authentication,” said cybersecurity analyst Jane Doe from ThreatWatch.

    The NHS investigation continues, with no confirmation of data exfiltration yet, but the incident serves as a stark reminder of ransomware’s growing menace to public services.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post NHS Investigating Oracle EBS Hack Following Cl0p Ransomware Group Claim appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated campaign attributed to North Korean-aligned threat actors is weaponizing legitimate JSON storage services as an effective vector for deploying advanced malware to software developers worldwide. The “Contagious Interview” operation demonstrates how threat actors continue to innovate in their abuse of trusted infrastructure to evade security controls and establish persistent system access. The Contagious […]

    The post Threat Actors Use JSON Storage for Hosting and Delivering Malware via Trojanized Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researcher Paul McCarty has uncovered a massive coordinated spam campaign targeting the npm ecosystem. The IndonesianFoods worm, comprising over 43,000 malicious packages published across at least 11 user accounts, remained active in the registry for nearly two years before detection. The campaign derives its distinctive name from its unique package naming scheme. The embedded […]

    The post Hackers Infiltrate npm Registry with 43,000 Spam Packages, Linger for Nearly Two Years appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have successfully extracted the system prompt from OpenAI’s Sora 2 video generation model by exploiting cross-modal vulnerabilities, with audio transcription proving to be the most effective extraction method. Sora 2, OpenAI’s state-of-the-art multimodal model for generating short video content, was thought to keep its system prompt secure. However, researchers discovered that by chaining […]

    The post OpenAI Sora 2 Vulnerability Allows Exposure of Hidden System Prompts from Audio Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitLab has released urgent security patches addressing multiple vulnerabilities affecting both the Community Edition and the Enterprise Edition.

    The company released versions 18.5.2, 18.4.4, and 18.3.6 to fix critical security issues that could allow attackers to compromise sensitive information and bypass access controls.

    The most concerning vulnerability involves prompt injection attacks in GitLab Duo’s review feature. Attackers can inject hidden malicious prompts directly into merge request comments.

    These hidden instructions trick the AI system into leaking sensitive information from confidential issues. This vulnerability affects GitLab Enterprise Edition versions 17.9 and later, potentially exposing classified project data to unauthorized users.

    Beyond prompt injection, GitLab patched nine additional vulnerabilities ranging from high to low severity.

    CVE IDVulnerability TitleTypeSeverityCVSS Score
    CVE-2025-11224Cross-site scripting issue in k8s proxyXSSHigh7.7
    CVE-2025-11865Incorrect Authorization issue in workflowsAuthorization BypassMedium6.5
    CVE-2025-2615Information Disclosure issue in GraphQL subscriptionsInformation DisclosureMedium4.3
    CVE-2025-7000Information Disclosure issue in access controlInformation DisclosureMedium4.3
    CVE-2025-6945Prompt Injection issue in GitLab Duo reviewPrompt InjectionLow3.5
    CVE-2025-6171Information Disclosure issue in packages API endpointInformation DisclosureLow3.1
    CVE-2025-11990Client Side Path Traversal issue in branch namesPath TraversalLow3.1
    CVE-2025-7736Improper Access Control issue in GitLab PagesAccess ControlLow3.1
    CVE-2025-12983Denial of service issue in markdownDenial of ServiceLow3.1

    cross-site scripting (XSS) vulnerability in the Kubernetes proxy allows authenticated users to execute malicious scripts, affecting versions 15.10 and later.

    An authorization bypass in workflows lets users remove AI flows belonging to other users, compromising workflow integrity. Information disclosure vulnerabilities also pose serious risks.

    Attackers can access sensitive data through multiple vectors: blocked users establishing GraphQL subscriptions, unauthorized viewing of branch names through access control weaknesses, and information leakage via the packages API endpoint, even when repository access is disabled.

    Additional vulnerabilities include path-traversal issues affecting branch names, improper access control in GitLab Pages that allows OAuth authentication bypasses, and denial-of-service attacks via specially crafted Markdown content.

    GitLab strongly recommends upgrading to the patched versions immediately. The company has already updated GitLab.com, and GitLab Dedicated customers require no action.

    Self-managed installations must prioritize immediate upgrades, as these vulnerabilities directly affect customer data security. The patches include database migrations that may affect upgrade processes.

    Single-node instances will experience downtime during updates, while multi-node installations can implement zero-downtime upgrades using proper procedures.

    GitLab researchers discovered most vulnerabilities through the HackerOne bug bounty program. The company commits to releasing security details 30 days after each patch on its public issue tracker.

    All affected organizations should review their current GitLab versions and deploy patches without delay to protect against these escalating security threats.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Multiple GitLab Vulnerabilities Let Attackers Inject Malicious Prompts to Steal Sensitive Data appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶