Cyberattack
The latest Cyberattack coverage — news, analysis, and updates from the WindowsNews.AI desk.
Critical Windows Vulnerability CVE-2025-49690 Exposes Systems to Privilege Escalation Attacks
A newly discovered critical vulnerability in Windows' Capability Access Management Service (camsvc) could allow attackers to gain elevated privileges on affected systems. Designated as...
Call of Duty: WWII RCE Exploit Crisis Exposes Critical Legacy Game Security Flaws
The recent resurgence of Call of Duty: WWII's player base has been overshadowed by the discovery of a critical remote code execution (RCE) vulnerability, exposing thousands of players to potential...
DEVMAN Ransomware: How This New Threat Targets Windows 10/11 Systems
A new ransomware strain dubbed DEVMAN has surfaced, specifically targeting Windows 10 and 11 systems with sophisticated techniques. Derived from the notorious DragonForce ransomware family, DEVMAN...
Citrix NetScaler CVE-2025-6543: Critical Patch to Prevent Remote Code Execution Attacks
Citrix NetScaler ADC and Gateway products, widely used in enterprise environments for secure remote access and application delivery, are under active exploitation due to a newly discovered critical...
Microsoft 365 Direct Send Exploited for Advanced Phishing Attacks in 2025
Microsoft 365's Direct Send feature, designed to simplify email delivery for businesses, has become an unexpected weapon in the hands of cybercriminals. Security researchers have identified a surge...
Microsoft 365 Direct Send Exploit: How to Protect Your Business from Phishing Attacks
A sophisticated phishing campaign exploiting Microsoft 365's "Direct Send" feature has targeted over 70 organizations, primarily in the United States, highlighting critical vulnerabilities in...
YES24 Cyberattack Exposes Critical Ransomware Vulnerabilities in Global Digital Security
Four days of total digital silence. That was the stark reality for the 20 million users of YES24, South Korea’s largest online bookstore, after a catastrophic ransomware attack forced the entire...
BlueNoroff's Deepfake & Mac Malware Attacks: A New Era of Cyber Threats (2025)
North Korean hacking group BlueNoroff has escalated its cyber warfare tactics, combining deepfake technology with sophisticated macOS malware in a series of high-profile attacks targeting financial...
Microsoft Faces GitHub Data Breach Probe: NLRB Targeted in Alleged Cyberattack
Microsoft finds itself in the crosshairs of federal investigators after whistleblower allegations surfaced regarding GitHub repositories potentially containing tools for unauthorized data extraction...
WestJet breach reveals systemic aviation gaps as 25,000 passengers hit by 14-hour outage.
The recent cybersecurity breach at WestJet Airlines serves as a stark reminder of the vulnerabilities facing critical infrastructure sectors worldwide. On [DATE], passengers and employees discovered...
How Cybercriminals Exploit TeamFiltration for Office 365 Attacks: Detection & Prevention
Cybercriminals are increasingly leveraging TeamFiltration, a legitimate penetration testing tool, to launch large-scale attacks against Office 365 accounts. This sophisticated campaign highlights how...
EchoLeak: Microsoft Copilot's Zero-Click AI Vulnerability Exposed in 2025
In early 2025, cybersecurity researchers from Aim Labs made a startling discovery: a critical zero-click vulnerability in Microsoft Copilot, now known as 'EchoLeak.' Officially designated as...