• In recent weeks, a sophisticated phishing operation known as the ZipLine campaign has targeted U.S.-based manufacturing firms, leveraging supply-chain criticality and legitimate-seeming business communications to deploy an advanced in-memory implant dubbed MixShell.

    This threat actor reverses traditional phishing workflows by initiating contact through corporate “Contact Us” web forms, prompting victims to reach out first.

    Once dialogue is established, attackers pose as potential partners and engage the target in protracted email correspondence, often spanning two weeks, before delivering a weaponized ZIP archive hosted on a trusted Platform-as-a-Service domain.

    The ZIP archive conceals a malicious .lnk file and embedded PowerShell script, which obfuscates its true purpose by including harmless PDF and DOCX lure files alongside the payload.

    Upon execution, the .lnk file triggers a loader that scans common directories for the archive, extracts a marker-delimited PowerShell script, and injects it directly into memory, bypassing AMSI checks by forcing AmsiUtils.amsiInitFailed = $true.

    Picus Security analysts identified this memory-resident approach as a key factor in MixShell’s stealth, enabling rapid, fileless execution without touching disk.

    MixShell’s custom shellcode is unwrapped in memory using reflection and the System.Reflection.Emit API, dynamically resolving Windows API functions via a custom ROR4-based hashing algorithm.

    ZipLine infection chain (Source – CheckPoint)

    The implant’s configuration, stored immediately after the code section in an XOR-encrypted, hex-encoded block, provides DNS TXT tunnel parameters for command and control (C2).

    These parameters include prepend and append markers, an XOR key, and domain information, all of which facilitate covert data exchange over DNS queries.

    If DNS fails after six attempts, the implant shifts to HTTP fallback, maintaining the same encryption and framing format to blend malicious traffic with legitimate web requests.

    Beyond initial execution, MixShell establishes persistence by hijacking a COM object’s TypeLib registry entry.

    The PowerShell script writes a malicious XML scriptlet named Udate_Srv.sct to the ProgramData directory and points the CLSID {EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}—associated with Internet Explorer’s Web Browser control—to this file.

    On every system restart or when Explorer.exe triggers the hijacked COM object, the scriptlet launches cmd[.]exe /K set X=1&{shortcut}, re-running the payload without further user interaction.

    Infection Mechanism Deep Dive

    The infection chain of ZipLine is a masterclass in social engineering and technical evasion.

    Attackers first submit a form-based inquiry—often with an “AI Impact Assessment” pretext—to the target’s website. Once the victim responds, the attackers request an NDA and provide a link to a ZIP file on a legitimate Herokuapp subdomain.

    Delivery of the malicious NDA ZIP file (Source – CheckPoint)

    Within the archive, the PowerShell script locates the embedded payload marker xFIQCV, extracts the shellcode blob, and uses in-memory methods to allocate executable pages via VirtualAlloc and invoke the payload directly.

    MixShell’s ROR4 hash routine (def api_hash and def ror4) iterates over uppercase-converted API names, generating identifiers to resolve function pointers at runtime.

    MixShell’s configuration (Source – CheckPoint)

    This dynamic resolution avoids static imports, rendering common signature-based detections ineffective.

    By maintaining all malicious actions in volatile memory, MixShell leaves only minimal forensic artifacts, challenging incident responders to detect and remediate infected hosts before data exfiltration or lateral movement can occur.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post New ZipLine Campaign Attacks Critical Manufacturing Companies to Deploy In-memory Malware MixShell appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A large-scale cybercrime conspiracy known as ShadowCaptcha was made public by cybersecurity researchers at Israel’s National Digital Agency. This campaign exploits the ClickFix technique, deploying deceptive CAPTCHA interfaces mimicking legitimate services like Cloudflare or Google to manipulate users into running malicious commands. The operation, traced through compromised WordPress websites, represents a sophisticated blend of social […]

    The post ShadowCaptcha Exploit: Massive WordPress Site Compromise Used to Execute Malicious Commands on Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A whistleblower disclosure filed today alleges that the Department of Government Efficiency (DOGE) within the Social Security Administration (SSA) covertly created a live copy of the nation’s entire Social Security dataset in an unsecured cloud environment

    Chief Data Officer Charles Borges warned that, if malicious actors gain access, over 300 million Americans could face identity theft, loss of critical benefits, and the monumental task of re-issuing every Social Security number.

    Key Takeaways
    1. DOGE copied 300M SSNs into an unsecured AWS cloud.
    2. An automated ETL pipeline synced live SSN data despite a court order.
    3. The lapse risks mass identity theft and demands zero-trust security.

    Allegations of Unsecured Cloud Storage

    According to the protected disclosure submitted to the U.S. Office of Special Counsel, DOGE officials bypassed standard Information Security and Compliance (ISC) controls, including encryption-at-rest, role-based access control (RBAC), and continuous audit logging, when provisioning a cloud instance containing live Social Security Number (SSN) records. 

    Borges notes that neither independent vulnerability assessments nor penetration tests were conducted before spinning up the Amazon Web Services (AWS) S3 bucket storing PII, nor were strict Identity and Access Management (IAM) policies enforced. 

    The cloud environment lacked multi-factor authentication (MFA) on API endpoints and did not employ a secure key management service (KMS), rendering the SSN repository vulnerable to credential stuffing or API key leakage.

    Court records show that a lawsuit filed in March 2025 resulted in a temporary restraining order preventing DOGE from accessing production SSN systems until June 6, 2025. 

    However, internal logs reviewed by Borges indicate that DOGE engineers continued to synchronize data via an automated ETL pipeline—using Python scripts and the SSA’s internal RESTful APIs, effectively cloning the live database outside SSA’s Security Operations Center (SOC).

    Borges claims that DOGE’s actions constitute serious mismanagement and abuse of authority by bypassing the SSA’s Change Management Board (CMB) and violating federal Cloud Security advice (NIST SP 800-144).  

    “This operation not only breaches the Privacy Act but also exposes the public to a significant cyber-attack surface,” Borges wrote in his internal memo. 

    One SSA executive reportedly acknowledged the risk, stating that the agency might need to re-issue SSNs en masse should the data be compromised.

    Andrea Meza, counsel for the whistleblower, urged Congress and the Office of Special Counsel to launch immediate oversight. 

    She emphasized that mitigation measures such as enforcing zero-trust architecture, rotating access keys, and deploying real-time intrusion detection systems (IDS) must be implemented without delay to protect Americans’ most sensitive identifiers.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post DOGE Accused of Mimicking Country’s Social Security Info in Unsecured Cloud appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A widespread data theft campaign has allowed hackers to breach sales automation platform Salesloft to steal OAuth and refresh tokens associated with the Drift artificial intelligence (AI) chat agent. The activity, assessed to be opportunistic in nature, has been attributed to a threat actor tracked by Google Threat Intelligence Group and Mandiant, tracked as UNC6395. “Beginning as early as

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered five distinct activity clusters linked to a persistent threat actor known as Blind Eagle between May 2024 and July 2025. These attacks, observed by Recorded Future Insikt Group, targeted various victims, but primarily within the Colombian government across local, municipal, and federal levels. The threat intelligence firm is tracking the activity under

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly identified ransomware strain named Cephalus has emerged as a sophisticated threat, targeting organizations through compromised Remote Desktop Protocol (RDP) connections.

    The malware, which takes its name from Greek mythology referencing the son of Hermes who tragically killed his wife with an infallible javelin, represents a concerning evolution in ransomware deployment techniques.

    Cephalus distinguishes itself from other ransomware families through its unique infection methodology and sophisticated evasion tactics.

    The malware operators gain initial access to target networks by exploiting RDP credentials that lack multi-factor authentication (MFA), a vulnerability that continues to plague organizations worldwide.

    Once inside the network, attackers utilize the MEGA cloud storage platform for data exfiltration before deploying the ransomware payload.

    Process lineage showing use of MEGA (Source – Huntress)

    The ransomware deployment mechanism involves a particularly clever approach using DLL sideloading through legitimate security software components.

    Huntress analysts identified this technique during investigations of two separate incidents occurring on August 13 and August 16, 2025, where the malware successfully infiltrated organizations running legitimate SentinelOne security products.

    DLL Sideloading and Execution Chain

    The most technically intriguing aspect of Cephalus lies in its deployment strategy, which exploits a legitimate SentinelOne executable file called SentinelBrowserNativeHost.exe.

    The ransomware operators place this legitimate binary in the user’s Downloads folder, from where it loads a malicious DLL named SentinelAgentCore.dll.

    This DLL subsequently loads a file called data.bin containing the actual ransomware code, creating a multi-stage execution chain that helps evade detection.

    Upon successful execution, Cephalus immediately begins system recovery prevention by running embedded commands.

    The first command executed is vssadmin delete shadows /all /quiet, which eliminates volume shadow copies that could be used for file recovery.

    The malware then systematically disables Windows Defender through a series of PowerShell commands that create exclusions for critical system processes and file extensions including .cache, .tmp, .dat, and .sss files.

    The ransomware further modifies Windows Registry entries to disable real-time protection, behavior monitoring, and on-access protection features.

    It stops and disables Windows Defender services including SecurityHealthService, Sense, WinDefend, and WdNisSvc through PowerShell commands executed with hidden window styles and bypassed execution policies.

    Cephalus ransom note posted publicly on Twitter (Source – Huntress)

    Cephalus ransom notes contain a unique characteristic – they reference news articles about previous successful attacks, attempting to establish credibility and create urgency for victims.

    The malware encrypts files with the .sss extension and creates recover.txt files containing payment instructions.

    Organizations can protect themselves by implementing MFA for RDP access, monitoring for unauthorized use of legitimate security tool executables in unusual locations, and maintaining comprehensive endpoint detection capabilities.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical vulnerability in IPFire 2.29’s web-based firewall interface (firewall.cgi) allows authenticated administrators to inject persistent JavaScript code, leading to session hijacking, unauthorized actions, or internal network pivoting. Tracked as CVE-2025-50975, this stored cross-site scripting (XSS) flaw poses significant risk in environments where multiple administrators share firewall management duties. Details of the Flaw The vulnerability […]

    The post IPFire Firewall Admin Panel Vulnerability Enables Persistent JavaScript Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) released three Industrial Control Systems (ICS) advisories on August 26, 2025, detailing nine critical vulnerabilities in INVT VT-Designer and HMITool (CVSS v4 8.5). Multiple flaws in Schneider Electric Modicon M340 controllers (CVSS v4 scores up to 9.1), and several issues in Danfoss AK-SM 8xxA Series drives (CVSS v3.1 […]

    The post CISA Issues New ICS Advisories on Critical Vulnerabilities and Exploits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly documented cache deception attack leverages mismatches in path normalization and delimiter handling between caching layers and origin servers to expose sensitive endpoints and steal authentication tokens. Researchers have demonstrated how subtle discrepancies in URL processing can trick a content delivery network (CDN) into caching protected resources—only for an attacker to retrieve them later, […]

    The post New Cache Deception Attack Exploits Miscommunication Between Cache and Web Server appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Government Accountability Project submitted a protected disclosure from Charles Borges—SSA’s Chief Data Officer—to the Office of Special Counsel and congressional oversight committees. Borges reports that since DOGE’s inception in January 2025, its officials have systematically circumvented SSA’s normal review procedures and a March 20, 2025 temporary restraining order forbidding external access to live Social […]

    The post DOGE Allegedly Uploaded SSA’s Live Numident Database to Unsecured Cloud Server appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶