Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Cyber Security News
cyberpress.org > new-ruby-rce-gadget-chain-marshal-load-command-execution

New Ruby RCE Gadget Chain Turns Unsafe Marshal.load Into Command Execution

1+ day, 6+ hour ago   (481+ words) A newly disclosed universal deserialization gadget chain demonstrates that a single unsafe Marshal.load operation can lead to remote command execution on Ruby 4.0.6. The chain reportedly also works unchanged on Ruby versions as far back as 3.3, renewing concerns that Ruby’s…...

Cyber Security News
cyberpress.org > microsoft-updates-copilot-app-merges-personal-chats

Microsoft Updates Copilot App, Merges Personal Chats and Retires Key AI Features

1+ day, 5+ hour ago   (459+ words) Microsoft is consolidating its consumer and productivity-focused AI experiences through a major update to the Copilot app, combining chat histories and content for personal users while retiring several high-profile features, including Podcasts, Deep Research, and Group Chat. The changes arrive…...

Cyber Security News
cyberpress.org > dcrat-hides-inside-windows

DCRat Malware Uses DLL Sideloading and Process Hollowing to Hide Inside Trusted Windows Process

2+ day, 2+ hour ago   (359+ words) The attack ultimately hides a remote-access trojan inside a legitimate Windows-related process, helping it blend into normal endpoint activity. The campaign uses a fake legal-notice lure named “Resolución Denuncia Jurídica,” designed to exploit fear and urgency. Victims receive a phishing…...

Cyber Security News
cyberpress.org > poisoned-npm-token-theft

Poisoned npm Packages Steal AI Tokens and Spread Them Across Developer Build Environments

2+ day, 5+ hour ago   (349+ words) The stolen tokens can be abused directly or fed into underground “transfer stations” that resell discounted access to expensive AI models. AI token jacking is becoming a costly risk as companies rapidly adopt large language models, automated agents, and AI-powered…...

Cyber Security News
cyberpress.org > rental-malware-defeats-antivirus

Cybercriminals Can Now Rent Malware That Re-Encrypts Itself to Keep Evading Antivirus

2+ day, 3+ hour ago   (437+ words) Cybercriminals are renting services that help malware change its appearance and avoid detection. Cruciferra, a crypter-as-a-service platform linked to campaigns that used tax-themed emails to target victims, including Indian taxpayers and finance professionals. The service is not the final malware....

Cyber Security News
cyberpress.org > shipmonk-data-breach

ShipMonk Data Breach Exposes 13,689 Trezor Customers’ Personal Information

2+ day, 4+ hour ago   (435+ words) Hardware wallet maker Trezor has disclosed a third-party data breach affecting approximately 13,689 customers after unauthorized actors accessed systems operated by its shipping and fulfillment provider, ShipMonk. Trezor said ShipMonk notified the company of unauthorized access to systems holding customer information…...

Cyber Security News
cyberpress.org > litellm-breach-steals-ci-cd-credentials

LiteLLM Supply Chain Breach Spreads Credential Stealer Across Thousands of Enterprise CI/CD Environments

3+ day, 1+ hour ago   (325+ words) A major software supply chain breach involving LiteLLM has reportedly exposed credentials, cloud keys, API tokens, and internal configuration data from thousands of enterprise CI/CD environments. Forensic investigations by Snyk, Trend Micro, and Cycode show that LiteLLM was not…...

Google News
cyberpress.org > likho-abuses-github-c2

Armored Likho Abuses GitHub as Backup C2 Channel for Audio Surveillance Malware

3+ day, 2+ hour ago   (320+ words) Armored Likho, also known as Eagle Werewolf, has launched a new cyber-espionage campaign targeting individuals and organizations in Russia. The group used fake donation applications as bait, but its latest malware toolkit is the bigger concern. The attackers can steal…...

Google News
cyberpress.org > 548-building-devices-unpatched

548 Internet-Exposed Building Automation Devices Run End-of-Life Products With No Future Security Patches

3+ day, 3+ hour ago   (438+ words) A new security study has found that 548 internet-exposed building automation devices near U.S. data centers are running end-of-life products that will not receive future security patches. The affected devices belong to three legacy product lines: Tridium NiagaraAX 3.x, Trane Tracer SC,…...

Cyber Security News
cyberpress.org > phantom-stealer-global-campaign

Phishing, Cracked Software and Discord Links Spread Phantom Stealer Across Multiple Countries

3+ day, 5+ hour ago   (359+ words) The malware is designed to silently collect browser credentials, saved passwords, cookies, cryptocurrency wallet data, system details, and other sensitive information from infected Windows devices. Its modular structure, flexible delivery methods, and strong focus on credential theft make it a…...