-
A critical security flaw has been disclosed in Apache Tika that could result in an XML external entity (XXE) injection attack. The vulnerability, tracked as CVE-2025-66516, is rated 10.0 on the CVSS scoring scale, indicating maximum severity. “Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
This week in cybersecurity from the editors at Cybercrime Magazine
Sausalito, Calif. – Dec. 5, 2025– Read the full story in Bolde
High school students and parents, listen up!
Some fields are skyrocketing in demand, offering promising career prospects and competitive salaries. However, gaining entry into college programs often requires a solid GPA to ensure you’re prepared for the rigorous coursework ahead. Cybersecurity is one of the most in demand fields that require you to study hard to ensure you get the GPA you need to make your academic dreams a reality, according to a recent Bolde article.
In an age where data breaches are increasingly common, cybersecurity is more critical than ever. This field focuses on protecting computer systems and networks from digital attacks. To enter a reputable cybersecurity program, you’ll need a GPA of around 3.0, with more competitive programs requiring higher. The coursework includes computer science, network security, and ethical hacking.
Beyond academic credentials, problem-solving skills and an analytical mindset are essential. According to Cybersecurity Ventures, the field is expected to see millions of unfilled jobs in the coming years, underscoring the growing demand. Internships and certifications can significantly boost your employability in this fast-paced industry. If you’re someone who loves a good challenge and wants to keep data safe, cybersecurity is an exciting and ever-evolving field to consider.
The tech industry is booming, and computer science is at the heart of it all. Whether you’re interested in software development, AI, or cybersecurity, a degree in computer science can open countless doors. Most reputable programs look for a GPA of at least 3.0, although the more competitive institutions may require a 3.5 or higher. The curriculum is heavy on math and logic, so it’s critical to bring your analytical A-game.
Bolde also takes a look at other in demand fields including nursing, data science, finance, engineering, psychology, business administration, environmental science, marketing, education, and healthcare administration.
Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:
- SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
- NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
- HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
- VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
- M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
- BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
- PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
- PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
- RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.
Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.
The post Here’s What GPA You Need To Study In The Cybersecurity Field appeared first on Cybercrime Magazine.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday shopping season: Phishing kits for mass-creating fake but convincing e-commerce websites that convert customer payment card data into mobile wallets from Apple and Google. Experts say these same phishing groups also are now using SMS lures that promise unclaimed tax refunds and mobile rewards points.
Over the past week, thousands of domain names were registered for scam websites that purport to offer T-Mobile customers the opportunity to claim a large number of rewards points. The phishing domains are being promoted by scam messages sent via Apple’s iMessage service or the functionally equivalent RCS messaging service built into Google phones.

An instant message spoofing T-Mobile says the recipient is eligible to claim thousands of rewards points.
The website scanning service urlscan.io shows thousands of these phishing domains have been deployed in just the past few days alone. The phishing websites will only load if the recipient visits with a mobile device, and they ask for the visitor’s name, address, phone number and payment card data to claim the points.

A phishing website registered this week that spoofs T-Mobile.
If card data is submitted, the site will then prompt the user to share a one-time code sent via SMS by their financial institution. In reality, the bank is sending the code because the fraudsters have just attempted to enroll the victim’s phished card details in a mobile wallet from Apple or Google. If the victim also provides that one-time code, the phishers can then link the victim’s card to a mobile device that they physically control.
Pivoting off these T-Mobile phishing domains in urlscan.io reveals a similar scam targeting AT&T customers:

An SMS phishing or “smishing” website targeting AT&T users.
Ford Merrill works in security research at SecAlliance, a CSIS Security Group company. Merrill said multiple China-based cybercriminal groups that sell phishing-as-a-service platforms have been using the mobile points lure for some time, but the scam has only recently been pointed at consumers in the United States.
“These points redemption schemes have not been very popular in the U.S., but have been in other geographies like EU and Asia for a while now,” Merrill said.
A review of other domains flagged by urlscan.io as tied to this Chinese SMS phishing syndicate shows they are also spoofing U.S. state tax authorities, telling recipients they have an unclaimed tax refund. Again, the goal is to phish the user’s payment card information and one-time code.

A text message that spoofs the District of Columbia’s Office of Tax and Revenue.
CAVEAT EMPTOR
Many SMS phishing or “smishing” domains are quickly flagged by browser makers as malicious. But Merrill said one burgeoning area of growth for these phishing kits — fake e-commerce shops — can be far harder to spot because they do not call attention to themselves by spamming the entire world.
Merrill said the same Chinese phishing kits used to blast out package redelivery message scams are equipped with modules that make it simple to quickly deploy a fleet of fake but convincing e-commerce storefronts. Those phony stores are typically advertised on Google and Facebook, and consumers usually end up at them by searching online for deals on specific products.

A machine-translated screenshot of an ad from a China-based phishing group promoting their fake e-commerce shop templates.
With these fake e-commerce stores, the customer is supplying their payment card and personal information as part of the normal check-out process, which is then punctuated by a request for a one-time code sent by your financial institution. The fake shopping site claims the code is required by the user’s bank to verify the transaction, but it is sent to the user because the scammers immediately attempt to enroll the supplied card data in a mobile wallet.
According to Merrill, it is only during the check-out process that these fake shops will fetch the malicious code that gives them away as fraudulent, which tends to make it difficult to locate these stores simply by mass-scanning the web. Also, most customers who pay for products through these sites don’t realize they’ve been snookered until weeks later when the purchased item fails to arrive.
“The fake e-commerce sites are tough because a lot of them can fly under the radar,” Merrill said. “They can go months without being shut down, they’re hard to discover, and they generally don’t get flagged by safe browsing tools.”
Happily, reporting these SMS phishing lures and websites is one of the fastest ways to get them properly identified and shut down. Raymond Dijkxhoorn is the CEO and a founding member of SURBL, a widely-used blocklist that flags domains and IP addresses known to be used in unsolicited messages, phishing and malware distribution. SURBL has created a website called smishreport.com that asks users to forward a screenshot of any smishing message(s) received.
“If [a domain is] unlisted, we can find and add the new pattern and kill the rest” of the matching domains, Dijkxhoorn said. “Just make a screenshot and upload. The tool does the rest.”

The SMS phishing reporting site smishreport.com.
Merrill said the last few weeks of the calendar year typically see a big uptick in smishing — particularly package redelivery schemes that spoof the U.S. Postal Service or commercial shipping companies.
“Every holiday season there is an explosion in smishing activity,” he said. “Everyone is in a bigger hurry, frantically shopping online, paying less attention than they should, and they’re just in a better mindset to get phished.”
SHOP ONLINE LIKE A SECURITY PRO
As we can see, adopting a shopping strategy of simply buying from the online merchant with the lowest advertised prices can be a bit like playing Russian Roulette with your wallet. Even people who shop mainly at big-name online stores can get scammed if they’re not wary of too-good-to-be-true offers (think third-party sellers on these platforms).
If you don’t know much about the online merchant that has the item you wish to buy, take a few minutes to investigate its reputation. If you’re buying from an online store that is brand new, the risk that you will get scammed increases significantly. How do you know the lifespan of a site selling that must-have gadget at the lowest price? One easy way to get a quick idea is to run a basic WHOIS search on the site’s domain name. The more recent the site’s “created” date, the more likely it is a phantom store.
If you receive a message warning about a problem with an order or shipment, visit the e-commerce or shipping site directly, and avoid clicking on links or attachments — particularly missives that warn of some dire consequences unless you act quickly. Phishers and malware purveyors typically seize upon some kind of emergency to create a false alarm that often causes recipients to temporarily let their guard down.
But it’s not just outright scammers who can trip up your holiday shopping: Often times, items that are advertised at steeper discounts than other online stores make up for it by charging way more than normal for shipping and handling.
So be careful what you agree to: Check to make sure you know how long the item will take to be shipped, and that you understand the store’s return policies. Also, keep an eye out for hidden surcharges, and be wary of blithely clicking “ok” during the checkout process.
Most importantly, keep a close eye on your monthly statements. If I were a fraudster, I’d most definitely wait until the holidays to cram through a bunch of unauthorized charges on stolen cards, so that the bogus purchases would get buried amid a flurry of other legitimate transactions. That’s why it’s key to closely review your credit card bill and to quickly dispute any charges you didn’t authorize.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Building a Secure Foundation for the Future of Autonomous Transactions

–Dr. Alissa Abdullah, Deputy Chief Security Officer, Mastercard
San Jose, Calif. – Dec. 4, 2025
Agentic commerce is changing the way we shop and interact online. Imagine telling your digital assistant to find the best deal on running shoes, make the purchase, and arrange delivery—all without you having to do a thing. This isn’t just a glimpse of the future; it’s happening now. At Mastercard, we’re excited about the possibilities, but we also know that security must keep pace with innovation.
What Is Agentic Commerce—and Why Does Security Matter?
Agentic commerce uses advanced AI agents to act on your behalf, making decisions and completing transactions autonomously. These agents can access sensitive information, negotiate with merchants, and handle complex tasks across different platforms. The benefits are clear: speed, personalization, and convenience. But with these advances come new cybersecurity challenges that we need to tackle head-on.
How Mastercard Is Protecting Agentic Commerce
At Mastercard, we focus on four key areas to keep agentic commerce secure:
- Identity and Authentication
We make sure AI agents can reliably verify who you are before taking any action. Multi-factor authentication and ongoing identity checks help prevent unauthorized transactions and keep your accounts safe. - Data Privacy
Agents handle a lot of personal and financial data. Protecting this information is a top priority. We use advanced encryption and privacy-preserving technologies to secure your data, whether it’s being sent or stored. - Transaction Security
Autonomous payments need strong protocols to block interception or fraud. Our Agent Pay solution and the Agent Payments Protocol (AP2) are designed to authenticate every transaction and provide traceability, so you can trust the process from start to finish. - Accountability and Transparency
When agents act independently, it’s important to have clear records of every action. Our systems log all activity, making it easier to resolve disputes and assign responsibility if something goes wrong. You also have control over what your agents can do and can review your transaction history anytime.
Building Trust in Autonomous Agents
Trust is the foundation of agentic commerce, but as these systems grow, it’s essential to achieve trust at scale. At Mastercard, we’re committed to building security into every layer of our systems—from the AI models that make decisions to the payment protocols that move your money.
We also believe security is a shared responsibility. Consumers should stay informed about how their data is used and take advantage of available controls. Businesses need to invest in cybersecurity and foster transparency.
Looking Ahead
Agentic commerce isn’t just a technological leap—it’s a transformation of the digital economy. As AI agents become more capable, cyber attackers will look for new ways to exploit them. Our job is to stay ahead of these threats, continuously improving our defenses and empowering users to transact with confidence.
If you’re interested in a deeper dive into the architecture, protocols, and real-world examples of agentic commerce, I encourage you to read the latest Mastercard Signals report.
At Mastercard, we believe the future of commerce should be both innovative and secure. By prioritizing cybersecurity, we’re helping unlock the full potential of autonomous agents—making commerce faster, smarter, and safer for everyone.
–Dr. Alissa Abdullah, Deputy Chief Security Officer, Mastercard
SPONSORED BY MASTERCARDMastercard works to connect and power an inclusive digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company.
The post Cybersecurity in Agentic Commerce: Safeguarding the Autonomous Future appeared first on Cybercrime Magazine.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
- Identity and Authentication
-
This week in cybersecurity from the editors at Cybercrime Magazine
Sausalito, Calif. – Dec. 4, 2025– Read the full story from BreachLock
Cybersecurity is no longer considered a “technical issue managed by IT departments, according to IBM. Rather, it “dominates concerns among the C-suite.”
A recent survey names “cyber incidents” as the number one global business risk.
These findings indicate the rising profile of cybersecurity and underscore that it is well on its way to becoming a strategic imperative and leadership priority.
Despite this, security staff in many organizations struggle to get cybersecurity budgets approved by senior leaders.
To stay ahead of adversaries and their cyber-weapons of mass destruction, companies must also continuously test existing controls against real-world threats.
Knowing that security gaps exist and how to patch them is one thing, but getting the funds approved to implement these patches can be a challenge. A blog post from the experts at BreachLock explores how technical security practitioners and leaders can leverage insights from offensive security tools to obtain cybersecurity budget approval.
With continuous pentesting and adversarial exposure validation (AEV), security teams have a unique opportunity to reframe budget requests from opinion-based “we think we need this” requests to evidence-based requests focused on business impact, dramatically increasing the likelihood of leadership approval.
Will businesses actually approve the spend? Cybersecurity Ventures predicts that the world will spend $522 billion on cybersecurity products and services in 2026.
Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:
- SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
- NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
- HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
- VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
- M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
- BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
- PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
- PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
- RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.
Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.
The post How To Reframe Cybersecurity Budget Requests And Get Them Approved appeared first on Cybercrime Magazine.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. proposal to establish a military presence at an airbase near Damascus is a welcome sign of deepening cooperation with Syria’s new government, but it may be insufficient to secure regional U.S. interests. A Damascus presence should complement—not replace—the U.S. partnership with the Syrian Democratic Forces, or SDF, which remains essential to preventing a resurgence of the Islamic State, or ISIS, and constraining Iranian activity.
The ISIS challenge is concentrated in northeastern Syria, where detention facilities hold about 9,000 ISIS fighters and family members. Nearly 85 percent of the fighters are held in two prisons near Hasakah and Shaddadi. These facilities are vulnerable targets, as shown by the 2022 Hasakah prison break that took two weeks to contain, even with U.S. air and intelligence support. The SDF, aided by U.S. funding and training, has carried the primary burden of physically securing these sites for more than a decade.
But the threat extends beyond the northeast’s detention sites. In March, an ISIS suicide bomber attacked a church in Damascus, killing 25 and injuring 63. Syrian authorities recently disrupted two ISIS plots targeting President Sharaa and arrested more than 70 ISIS suspects in nationwide raids. And the In January, ISIS-inspired attack in New Orleans—along with multiple arrests of ISIS-inspired Americans in recent months—illustrates the group’s continued ability to radicalize individuals far beyond Syria. These developments underscore why maintaining pressure on ISIS and supporting local partners remains essential.
The United States should continue to build on the “by, with, and through” partnership that has made the SDF the most effective counter-ISIS force in Syria. Sustaining this relationship—through training, intelligence sharing, and support to detention operations—is the best way to prevent ISIS from reconstituting. It also signals to regional partners that the United States remains committed to a stable transition in Syria rather than stepping back prematurely.
At the same time, Washington must push for greater international burden-sharing in managing detained ISIS fighters. Only 36 countries have repatriated any nationals from northeast Syria, while 21 have yet to begin. Prolonged detention increases the risk of radicalization and creates a long-term humanitarian and security challenge for the region. Iraq’s repatriation of roughly 25,000 citizens—about 80 percent of Iraqis detained in Syria—demonstrates what committed action can achieve. The United States should apply the same diplomatic urgency it uses in negotiating criminal deportation agreements to secure fiscal contributions and accelerate repatriation efforts, easing pressure on the SDF and reducing the long-term threat posed by these populations.
Broader counterterrorism objectives also depend on preventing Iranian rearmament of Hezbollah, which would destabilize the region. Israeli intelligence reports indicate that the group has begun restoring supply lines through Syrian territory. Although Iran and Hezbollah have suffered setbacks—and Russia’s diminished role has further constrained their operating space—Tehran continues to seek opportunities to rebuild its networks.
This makes it vital for the United States to sustain its partnership with the SDF, which, according to the Lead Inspector General for Operation Iraqi Freedom, currently controls most Iraqi-border crossings in eastern Syria—positioning it as the first line of defense against the flow of Iranian weapons into Lebanon. Beyond the SDF partnership, Washington should work with the Syrian government and Israel to disrupt these flows. Washington’s provision of intelligence, deconfliction, and diplomatic coordination to the Syrians and Israelis can complicate and disrupt Iran’s efforts. Strengthening these channels of cooperation with the new Syrian government is especially important now as Syria seeks to consolidate control and demonstrate its independence from Tehran.
Syria’s shift away from Iran and Russia and toward greater cooperation with Western partners presents a strategic opportunity. The government has a vested interest in limiting extremist groups, restoring security, and preventing Syria from becoming a conduit for Iranian influence. Its decision to join the Global Coalition to Defeat ISIS demonstrates a willingness to work with international partners, and the Interior Ministry has already carried out joint counter-ISIS missions with U.S. troops. This alignment of interests remains nascent, but it offers a real chance for the United States to advance both counterterrorism priorities and regional stability.
ISIS prison breaks and Iranian rearmament are preventable, but averting them requires sustaining the SDF partnership, advancing international burden sharing, and countering Iranian weapons flows. Leaving before Syria can stand on its own will not end America’s involvement in the country—it will simply set the stage for a more costly return.
Thomas Bergeson, a retired U.S. Air Force lieutenant general, served as deputy commander of U.S. Central Command. He participated in the Jewish Institute for National Security of America’s 2023 Generals and Admirals program.
Jonah Brody is a policy analyst at JINSA.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Air Force leaders are axing more major organizational changes started under the Biden administration such as reorienting commands, creating new offices, and shifting combat forces for a potential fight with China, the service’s top leaders said Tuesday.
The service will no longer stand up Air Development Command, which aimed to subsume Air Education and Training Command and further combine the service’s force-development efforts, consolidate its functional managers, and create several new centers of excellence for certain career fields. Instead, AETC will retain its name and responsibilities, Air Force Secretary Troy Meink and Chief of Staff Gen. Ken Wilsbach said in a press release that described a memo sent to their service the previous day.
Nor will the service reorient Air Combat Command to “focus on generating and presenting ready forces,” but rather keep it working to “organize, train, and equip combat ready Airmen,” the release said.
The service will:
- Stop establishing its Air Base Wing concept.
- Cancel plans for a new Program Assessment and Evaluation Office to handle resource analysis.
- Not create an Air Force Materiel Command Information Dominance Systems Center, Air Force Nuclear Systems Center, or an Air Dominance Systems Support Center to sustain and improve aircraft and intercontinental ballistic missiles.
These steps are the latest in Meink and Wilsbach’s efforts to undo “Reoptimization for Great Power Competition," a 24-point plan released in early 2024 by then-Air Force Secretary Frank Kendall. Execution of the plan, which aimed to prepare the Air Force for a potential fight against China, was put on hold in February by Defense Secretary Pete Hegseth.
For months, it wasn’t clear what initiatives Meink, who took office in May, would keep or gut. In September, the Air Force secretary told reporters that he was “getting close” to making decisions on the reorganization plans tied to China, but hinted that he wasn’t “a big believer in the competition side of the house.”
In the press release, he and Wilsbach appeared to allude to the Trump administration’s decisions to shift national-security focus to the Americas.
“As our adversaries and the strategic environment continue to evolve, our approach to ensuring a credible and ready force must also adjust. Air superiority is not guaranteed,” the service leaders wrote. “Through flexibility and clear-eyed assessment, our Air Force will continue to fly, fix, and fight now and into the future.”
In October, the service spiked plans for a new Integrated Capabilities Command intended to speed up the acquisition of new technologies and weapons.
One former defense official familiar with the past efforts said it wasn’t clear how the current Air Force leaders intend to improve such integration.
“There's different ways to solve that problem and it is not shocking to me that they would choose a different way than what was chosen by the previous team, but the question remains. How are you going to do it?” the former defense official said. “The announcements that I've seen do not explain how it's going to be done, and so my concern would be if they just don't do it, if they don't provide that integration function, it will knock back our ability to compete with China.”
The official added that Hegseth’s mandate to reduce the number of general and flag officers across the military services likely sealed the fate for many of those commands and centers the Air Force hoped to create.
The memo also scraps a plan to to change Air Forces Central Command and Air Forces Northern Command/Air Forces Space from numbered Air Forces into Service Component Commands that report to the Air Force Secretary through the Air Force Chief of Staff.
Those will remain as numbered Air Forces. Similarly, Air Forces Southern Command will remain the air component to U.S. Southern Command and the 12th Air Force will be re-established as a numbered Air Force inside Air Combat Command, the release said.
The memo noted that Meink and Wilsbach were keeping some elements of the reoptimization plan, including keeping warrant officers focused on cyber missions, wing units of actions, large-scale exercises and keeping various smaller integrated development and capabilities offices.
The former defense official said it was encouraging to see some of those ideas kept, and believes some of those smaller offices could take on some roles that those centers would have taken on for the service’s integration efforts.
“They can beef up those organizations to perform more of the functions that you would have seen, for example, in the system centers,” the former defense official said. “That's certainly a possible solution, and I hope they do that.”
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Dashcams have become essential devices for drivers worldwide, serving as reliable witnesses in case of accidents or roadside disputes.
However, a team of Singaporean cybersecurity researchers has uncovered a disturbing reality: these seemingly harmless devices can be hijacked within seconds and turned into powerful surveillance tools.
The findings, presented at the Security Analyst Summit 2025, reveal how attackers can bypass authentication mechanisms to access high-resolution video footage, audio recordings, and precise GPS data stored on these devices.
The research examined two dozen dashcam models from approximately 15 different brands, starting with the popular Thinkware dashcam.
Most dashcams, even those without cellular connectivity, feature built-in Wi-Fi that allows smartphone pairing through mobile apps.
This connectivity creates a significant attack surface that malicious actors can exploit to download stored data remotely.
Kaspersky security researchers identified that many dashcam models use hardcoded default passwords and similar hardware architectures, making them vulnerable to mass exploitation.
Once connected, attackers gain access to an ARM processor running a lightweight Linux build, opening doors to various proven exploitation techniques commonly seen in IoT device attacks.
Authentication Bypass Techniques
The researchers discovered several methods attackers use to bypass manufacturer authentication. Direct file access allows hackers to request video downloads without password verification, as the web server only checks credentials at the main entry point.
MAC address spoofing enables attackers to intercept and replicate the owner’s smartphone identifier, while replay attacks involve recording legitimate Wi-Fi exchanges for later exploitation.
Perhaps most concerning is the worm-like propagation capability the researchers developed.
They wrote code that operates directly on infected dashcams, allowing compromised devices to automatically attack nearby dashcams while vehicles travel at similar speeds in traffic.
A single malicious payload designed to attempt multiple passwords and attack methods could successfully compromise roughly a quarter of all dashcams in an urban environment.
The harvested data enables complete movement tracking, conversation monitoring, and passenger identification.
Using GPS metadata extraction, text recognition from road signs, and OpenAI models for audio transcription, attackers can generate detailed trip summaries, effectively de-anonymizing victims through analyzed behavioral patterns.
Drivers should disable Wi-Fi when not in use, change default passwords, and regularly update firmware to mitigate these risks.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.
The post Hackers can Hijack Your Dash Cams in Seconds and Weaponize it for Future Attacks appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Insider threats remain one of the most challenging security problems that organizations face today. These threats typically do not show obvious warning signs at first.
Instead, they reveal themselves through small, unusual activities that often blend into normal daily operations.
Many companies struggle to identify these early indicators because they occur within legitimate user accounts and approved systems.
Without proper monitoring and analysis, these warning signs go unnoticed until serious damage has already occurred, including data loss, brand damage, or system disruption.
The core challenge in detecting insider threats stems from a fundamental attribution problem. When an employee accesses company systems or moves data between authorized locations, their actions appear completely normal.
Traditional security tools focus on blocking obvious threats but frequently miss the subtle behavioral patterns that suggest malicious intent.
This gap becomes even larger when organizations fail to connect what happens inside their network with activities occurring outside, such as employees communicating on dark web forums or selling company secrets to competitors.
Nisos security analysts noted that meaningful insider threat indicators often emerge weeks or even months before any actual data theft or system compromise occurs.
These indicators become clearer when organizations examine multiple data sources together, combining internal activity logs with external intelligence gathered from public sources.
Warning signs
The research identifies six critical warning signs that security teams must understand and monitor carefully.
Here they are mentioned below:-
- Unusual Authentication and Access Behavior
- Data Movement Outside Established Norms
- Shifts in Digital Behavior That Indicate Interest in Sensitive Assets
- Indicators That Suggest Data Exfiltration Planning
- External Activity That Aligns With Internal Anomalies
- Attempts to Conceal Activity
The most revealing early indicator appears in unusual authentication and access behavior. Nisos researchers identified that employees planning to steal data frequently attempt to access company systems from unexpected locations, log in rapidly across multiple platforms, or change their normal access timing patterns.
One user might suddenly log in from three different countries within a few hours, or access files at unusual times outside their typical work schedule.
While a single strange login might reflect normal business travel, repeated patterns of this behavior signal that deeper investigation is necessary.
These actions often precede larger data collection activities because insiders need to test whether they can move through systems without triggering automatic alerts.
Understanding these authentication anomalies requires context and correlation with other activities. Organizations that focus exclusively on these individual incidents often miss the broader pattern.
When companies combine unusual access patterns with information about employees discussing their company online or appearing in breach databases, a much clearer picture emerges.
This integrated approach transforms isolated events into meaningful threat indicators that security teams can act upon before damage occurs.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.
The post Nisos Details Earlier Signs of Insider Detection via Authentication and Access Controls appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ukraine-linked hackers are stepping up cyberattacks against Russian aerospace and wider defence-related companies, using new custom malware to steal designs, schedules, and internal emails.
The campaign targets both prime contractors and smaller suppliers, aiming to map production chains and expose weak points in Russia’s war industry. The tools used in this campaign are simple, but they are used with care and good planning.
.webp)
Defaced homepage of KrasAvia’s website (Source – Intrinsec) The malware first appeared in late 2024 in spear-phishing waves sent to engineers and project managers working on avionics, guidance systems, and satellite links.
Lures used fake job offers, conference invites, and contract updates, with attached documents that exploited outdated office software on Windows hosts. Once opened, the file quietly dropped a small loader that set the stage for the main payload.
Intrinsec security analysts identified the malware after seeing repeated outbound traffic from a defence integrator’s remote office to rare command servers hosted on bulletproof infrastructure.
Their complete technical breakdown shows that the attackers carefully tuned each payload to the victim’s role, adding custom modules for email scraping, document theft, and credential capture.
,%20and%20the%20phishing%20page%20(right)%20(Source%20-%20Intrinsec).webp)
Content of the email (left), and the phishing page (right) (Source – Intrinsec) The operation hits research labs, testing ranges, and logistics firms that support aircraft, drones, and missile systems. Stolen data can reveal parts shortages, delivery delays, and software bugs, giving Ukrainian planners a clearer view of Russian combat readiness.
Infection chain and command execution
The infection chain is simple but smart. The first loader, often a small DLL, runs in memory only and pulls a second-stage script from a hard-coded URL.
That script injects the final payload into a trusted process such as explorer.exe, which helps it blend with normal user activity.
Intrinsec researchers noted that the payload uses a compact command loop to stay flexible. A typical routine, as seen in memory dumps, looks like this:-
while (connected) { cmd = recv(); if (cmd == "exfil") run_exfil(); if (cmd == "shell") open_shell(); }This simple logic lets the operator switch between silent data theft and hands-on keyboard control. Each stage is built to keep noise low on the host.
Despite its clear design, the malware avoids noisy persistence tricks, instead relying on scheduled tasks and hijacked update tools to return after reboots while staying hard to spot.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.
The post Ukraine Hackers Attacking Russian Aerospace Companies and Other Defence-Related Sectors appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


