• Cybersecurity researchers have discovered a new vulnerability in OpenAI’s ChatGPT Atlas web browser that could allow malicious actors to inject nefarious instructions into the artificial intelligence (AI)-powered assistant’s memory and run arbitrary code. “This exploit can allow attackers to infect systems with malicious code, grant themselves access privileges, or deploy malware,” LayerX

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In March 2025, security researchers at Kaspersky detected a sophisticated campaign exploiting a previously unknown Chrome vulnerability to deliver advanced spyware to high-profile targets. The attack, dubbed Operation ForumTroll, leveraged personalized phishing links to compromise organizations across Russia, including media outlets, universities, research centers, government agencies, and financial institutions. A single click on a malicious […]

    The post Critical Chrome 0-Day Under Attack: Mem3nt0 Mori Hackers Actively Exploiting Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In March 2025, security researchers at Kaspersky detected a sophisticated campaign exploiting a previously unknown Chrome vulnerability to deliver advanced spyware to high-profile targets. The attack, dubbed Operation ForumTroll, leveraged personalized phishing links to compromise organizations across Russia, including media outlets, universities, research centers, government agencies, and financial institutions. A single click on a malicious […]

    The post Critical Chrome 0-Day Under Attack: Mem3nt0 Mori Hackers Actively Exploiting Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft is actively probing a glitch in its Teams platform that’s disrupting text-to-speech features, leaving users frustrated during critical auto-attendant calls.

    The company confirmed the problem via its official Microsoft 365 Status account on X (formerly Twitter) on October 27, 2025, urging administrators to check incident TM1180557 in the admin center for updates.

    This outage highlights ongoing challenges in Microsoft’s cloud-based communication tools, which millions rely on for business operations.

    The issue specifically affects text-to-speech conversion in auto-attendant scenarios, where Teams is configured to handle incoming calls with automated voice responses.

    Users report that the functionality fails to process scripted messages, resulting in silent or incomplete greetings that derail customer service flows and internal communications.

    Early complaints surfaced on forums like Reddit and Microsoft’s community boards, with some organizations noting disruptions since early Monday.

    For enterprises using Teams as a primary VoIP solution, this means potential lost productivity and strained client interactions, especially in high-volume call centers.

    Microsoft’s status update indicates the investigation is underway, but no estimated resolution time has been provided. The glitch appears isolated to text-to-speech during auto-attendant use and does not impact core calling or video features.

    Still, it underscores vulnerabilities in AI-driven voice tech, which has become integral to hybrid work environments post-pandemic. This incident arrives amid Microsoft’s push to enhance Teams with advanced AI integrations, including Copilot for voice assistance.

    Analysts suggest the bug could stem from recent updates to the platform’s speech synthesis engine, possibly tied to compatibility issues with certain server configurations.

    Microsoft advises affected users to monitor the admin center and consider temporary workarounds, such as fallback to manual attendant scripts.

    As the probe continues, businesses are bracing for prolonged effects, with hopes for a swift patch to restore seamless operations.

    Update – Microsoft confirms the issue is fixed and the functionality is operational now.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft Investigation Teams text-to-speech Functionality Issue Impacting Users – Update appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Qilin ransomware has emerged as one of the most devastating threats in the second half of 2025, operating at an alarming pace with over 40 victim disclosures per month on its public leak site.

    Originally tracked under the name Agenda before rebranding to Qilin around July 2022, this ransomware-as-a-service platform has evolved into a global menace affecting organizations across multiple continents and industrial sectors.

    The group’s dual-extortion model combines file encryption with data theft and public disclosure, creating compounded pressure on victims to pay extortion demands.

    Manufacturing represents the hardest-hit sector at 23% of all cases, trailed by professional services at 18%, while the United States faces the highest concentration of attacks.

    The threat landscape reveals Qilin’s sophisticated attack infrastructure spanning from initial access through data exfiltration to final encryption and persistence mechanisms.

    Cisco Talos analysts identified that attackers typically gain network entry through compromised VPN credentials sourced from dark web leaks, combined with the absence of multi-factor authentication protections.

    Initial intrusion via VPN (Source – Cisco Talos)

    Once inside victim networks, operators perform extensive reconnaissance using legitimate Windows utilities like nltest.exe and net.exe to map domain infrastructure and identify high-value targets.

    The investigation uncovered that Qilin operators employ a methodical data harvesting approach before deploying encryption payloads, allowing them to identify and exfiltrate the most sensitive company information before triggering system-wide encryption.

    Cisco Talos analysts identified a particularly ingenious technique where attackers leverage built-in Windows applications to locate sensitive files during the reconnaissance phase.

    The research reveals that artifact logs consistently show mspaint.exe and notepad.exe being executed to manually inspect and view high-sensitivity information across network storage systems.

    Rather than relying solely on automated file discovery scripts, operators use these seemingly innocuous applications to open and review files, perhaps to verify data quality before compression and exfiltration.

    This manual inspection approach allows attackers to prioritize the most valuable intellectual property, financial records, and confidential documents while avoiding common security signatures associated with automated data discovery tools.

    Dual-Encryptor Deployment Strategy

    The dual-encryptor deployment strategy further demonstrates operational sophistication within the Qilin ecosystem.

    The first variant, encryptor_1.exe, spreads laterally using PsExec across compromised hosts with administrator privileges and internal password specifications hardcoded into the binary.

    The second variant, encryptor_2.exe, operates from a single system to encrypt multiple network shares simultaneously, maximizing coverage and impact across distributed infrastructure.

    Before encryption initiates, operators establish persistence through scheduled tasks named TVInstallRestore and registry modifications under RUN keys, ensuring ransomware survives system reboots.

    The malware specifically targets critical infrastructure including Cluster Shared Volumes hosting Hyper-V virtual machines and databases while deliberately excluding system files required for boot functionality, a calculated approach ensuring victims cannot easily recover through operating system reinstallation.

    For data exfiltration, Qilin operators employ Cyberduck, an open-source file transfer utility that obscures malicious activity within legitimate cloud service traffic directed toward Backblaze servers.

    Before data departure, administrators deploy WinRAR with specialized parameters excluding base folders and disabling recursive subdirectory processing, creating optimized archive configurations.

    The combination of manual file inspection using standard Windows applications, sophisticated deployment tactics, and cloud-based exfiltration represents a mature threat operation demanding comprehensive detection and response capabilities from organizations worldwide.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Qilin Ransomware Leveraging Mspaint and Notepad to Find Files with Sensitive Information appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • As iOS 26 is being rolled out, a critical forensic challenge has emerged: the operating system now automatically overwrites the shutdown.log file on every reboot, effectively erasing crucial evidence of Pegasus and Predator spyware infections. This development represents a significant setback for forensic investigators and users seeking to determine whether their devices have been compromised—particularly […]

    The post iOS 26 Overwrites ‘shutdown.log’ on Reboot, Erasing Forensic Evidence of Pegasus and Predator Spyware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • As iOS 26 is being rolled out, a critical forensic challenge has emerged: the operating system now automatically overwrites the shutdown.log file on every reboot, effectively erasing crucial evidence of Pegasus and Predator spyware infections. This development represents a significant setback for forensic investigators and users seeking to determine whether their devices have been compromised—particularly […]

    The post iOS 26 Overwrites ‘shutdown.log’ on Reboot, Erasing Forensic Evidence of Pegasus and Predator Spyware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Famous Chollima, a threat group affiliated with North Korea’s Reconnaissance General Bureau, has significantly expanded its operational capabilities by integrating two potent malware strains: BeaverTail and OtterCookie.

    This convergence marks a critical evolution in the group’s attack methodology, targeting cryptocurrency and blockchain sectors with renewed sophistication.

    The merging of these toolsets reflects a deliberate shift toward JavaScript-based malware delivery, reducing dependency on Python while maintaining broad operational flexibility across multiple platforms and target profiles.

    The group’s latest campaign, tracked as Contagious Interview, exploits legitimate job-seeking platforms and recruitment channels to distribute trojanized applications.

    Recent discoveries reveal that organizations face compromise through seemingly innocuous supply chain vectors, with a cryptocurrency-themed chess platform serving as an initial infection point.

    The malicious payload infiltrated systems through dependency resolution when developers cloned a Bitbucket repository for Chessfi, inadvertently pulling the compromised node-nvm-ssh package from public NPM repositories.

    This technique demonstrates how credential theft operations now seamlessly blend social engineering with technical supply chain exploitation.

    Polyswarm Threat Response Unit analysts identified the converged malware architecture during investigations of a Sri Lanka-based compromise, where post-install scripts executed obfuscated JavaScript payloads embedded in seemingly legitimate package dependencies.

    The attack sequence revealed sophisticated modular construction combining both BeaverTail and OtterCookie capabilities into a unified information-stealing framework targeting cryptocurrency wallets and sensitive documents.

    Technical Convergence and Capability Fusion

    The integration of BeaverTail and OtterCookie represents a deliberate architectural consolidation rather than coincidental overlap.

    BeaverTail handles initial reconnaissance, enumerating browser profiles and targeting cryptocurrency wallet extensions across Chrome, Brave, and Edge browsers, specifically hunting MetaMask, Phantom, and Solflare installations.

    The component downloads Python-based InvisibleFerret modules from command-and-control servers over port 1224, bootstrapping complete Python distributions on target Windows systems to enable full execution capabilities.

    OtterCookie complements this infrastructure through modular extensions providing remote shell access via socket.io-client for command execution and system fingerprinting, file enumeration scanning drives for documents and credentials, and a dedicated cryptocurrency extension stealer mirroring BeaverTail’s wallet targeting logic.

    A novel keylogging module first observed in April 2025 captures keystroke data and screenshot images, buffering exfiltrated information in temporary files before transmission to command infrastructure.

    The malware implements anti-analysis countermeasures including environment checking and error-handler eval mechanisms for dynamic code execution, evolving from earlier HTTP cookie-based payload delivery to modular string execution paradigms across five iterations since late 2024.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post North Korean Chollima Actors Added BeaverTail and OtterCookie to Its Arsenal appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have developed a sophisticated new tool called EDR-Redir that can bypass Endpoint Detection and Response (EDR) systems by exploiting Windows’ Bind Filter and Cloud Filter drivers. This technique represents a significant advancement in evasion methods that operate entirely in user mode without requiring kernel privileges. The Windows Bind Link feature, introduced in Windows […]

    The post New EDR-Redir Tool Bypasses EDRs by Exploiting Bind Filter and Cloud Filter Driver appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security, trust, and stability — once the pillars of our digital world — are now the tools attackers turn against us. From stolen accounts to fake job offers, cybercriminals keep finding new ways to exploit both system flaws and human behavior. Each new breach proves a harsh truth: in cybersecurity, feeling safe can be far more dangerous than being alert. Here’s how that false sense of security

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶