Sunday, May 3, 2026
HomeCyber News

Cyber News

How SafePay Ransomware Exploits RDP and VPN to Breach Organizational Networks

A previously obscure ransomware group has rapidly emerged as one of the most dangerous threats on the global cybersecurity landscape in Q1 2025. SafePay ransomware has quietly built momentum, striking over 200 victims worldwide, including managed service providers (MSPs) and small to mid-sized businesses...

Malicious Hackers Exploit GitHub to Distribute VPN – Impersonating Malware

A newly-discovered malware campaign is exploiting the popularity of GitHub to distribute sophisticated malware disguised as “Free VPN for PC” and “Minecraft Skin Changer.” CYFIRMA’s latest technical analysis reveals how cybercriminals exploit social engineering, advanced obfuscation, and legitimate Windows processes to implant the notorious...

Rhadamanthys Infostealer Exploits ClickFix Method to Harvest Login Credentials

A sophisticated phishing campaign has been detected leveraging the domain ypp-studiocom to deliver the notorious Rhadamanthys infostealer, marking a new escalation in phishing and malware delivery tactics. Using advanced evasion methods and a novel ClickFix CAPTCHA delivery mechanism, this campaign poses a significant risk to individuals...

Qilin’s Evolving Attack Strategy Sparks Surge in Ransomware Operations

The ransomware landscape in June 2025 has shifted dramatically with Qilin, a notorious ransomware group, at the helm of a new, highly organized wave of cyberattacks. According to the latest Deep Web & Dark Web trend report, Qilin has rapidly ascended to dominate ransomware...

User Login Cyberattacks Surge 156%, with Infostealers and Phishing Tools Leading the Charge

A dramatic surge in identity-based cyberattacks has fundamentally transformed the threat landscape, with new research revealing a staggering 156% increase in identity-driven threats between 2023 and 2025. According to eSentire's Threat Response Unit (TRU), these attacks now account for 59% of all confirmed threat...

Cyberattack Alert – Hackers Leveraging GeoServer RCE Flaw to Install CoinMining Malware

AhnLab Security Intelligence Center (ASEC) has issued a critical warning about ongoing cyberattacks targeting unpatched GeoServer installations, with threat actors actively exploiting a remote code execution vulnerability to deploy cryptocurrency mining malware and backdoor tools. The attacks have been confirmed in South Korea, with...