• Leading a Security Operations Center has never been more challenging.

    SOC managers today juggle expanding attack surfaces, remote workforces, cloud migrations, and an explosion of security tools. All while trying to keep pace with increasingly automated attacks.  
     
    Every day feels like a mix of firefighting and long-term planning that never fully materializes. Under this pressure, it’s easy to assume that the biggest challenges come from whatever attack makes the headlines this week. 

    But in reality, the true weak point in many SOCs hides deeper in the foundation of their operations. 

    The Usual Suspects: What SOCs Blame for Trouble 

    When SOC leaders are asked what keeps them up at night, the answers often revolve around specific threats and resource limitations. 

    A survey of the customers of a cybersecurity solutions provider ANY.RUN illustrates their main concerns:  

    • The next zero-day exploit lurking in the shadows, ready to bypass all defenses before signatures exist to detect it. 
    • Notorious malware families like ransomware variants that threaten to cripple operations and demand hefty payments. 
    • Advanced Persistent Threats (APTs) from nation-state actors with unlimited resources and patience, slowly infiltrating networks. 
    • Novel attack techniques that evade traditional detection methods, exploiting vulnerabilities before they’re even discovered. 
    • Budget constraints that prevent hiring more analysts, purchasing better tools, or expanding coverage. 

    These concerns are legitimate. Each represents a real risk that can lead to costly breaches.

    However, focusing exclusively on these threats misses a more fundamental problem that undermines the effectiveness of even the best-resourced SOCs. 

    The Real Gap: Quality Threat Intelligence

    The factor that quietly undermines detection, investigation, and response is insufficient access to fresh, actionable, context-rich threat intelligence. 

    SOCs rarely fail because analysts lack talent. They fail because analysts lack clarity. Without trustworthy, up-to-date insights into active malware behavior, real-world campaigns, and current attacker tooling, SOC teams are forced to guess.

    And guessing is expensive — both in time and in business risk. 

    The true gap isn’t a particular adversary or a specific attack. It’s the absence of high-quality, continuously updated data that helps analysts understand what they’re looking at and how to react. 

    Three Critical SOC Problems That Threat Intelligence Solves 

    1. Alert Fatigue and Investigation Burnout 

    When every alert looks the same and lacks context, analysts waste hours chasing false positives.

    Quality threat intelligence dramatically reduces this burden: Is this IP associated with known malware families? What attack techniques does it use? Has it been seen in recent campaigns targeting similar organizations? 

    With enriched threat data, analysts can quickly triage alerts, distinguishing between noise and genuine threats. This means faster responses to real incidents. 

    2. Detection Gaps and Blind Spots 

    Traditional signature-based detection, firewalls, and endpoint detection cannot discover unknown threats, making it difficult for SOCs to defend against zero-day attacks. 

    When threat intelligence includes Tactics, Techniques, and Procedures (TTPs) from recent attacks, SOCs can build detection rules that identify malicious behavior rather than just known signatures.

    This shifts defense from reactive to proactive, catching threats even when they use new infrastructure or modified payloads. 

    Detect emerging threats early with real-time intelligence from Threat Intelligence Feeds -> Request trial for your team  

    3. Slow Incident Response and Investigation Times 

    When an alert triggers, speed matters. But without proper context, investigations drag on while analysts hunt for information across multiple sources.

    Quality threat intelligence accelerates response by providing everything analysts need in one place: related file hashes to search for across systems, associated domains and IPs to block, links to full sandbox analysis showing exactly how the threat behaves, and attribution to known threat actors or campaigns. 

    This contextual enrichment transforms investigation workflows from hours of research to minutes of decision-making, dramatically reducing Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). 

    Fresh Intelligence from the Front Lines 

    ANY.RUN’s Threat Intelligence Feeds address these challenges by providing something unique in the TI market: real-time indicators extracted from actual malware analysis sessions conducted by a global network of over 15K SOC teams who upload and analyze real-world malware and phishing samples daily. 

    Threat Intelligence Feeds: IOC and context sources  

    Key advantages include: 

    • Live behavior-driven indicators: IOCs generated by real executions of active malware samples. 
    • Context-rich detections: Each indicator comes with metadata, including links to sandbox sessions with behaviors and TTPs. 
    • Instant visibility into emerging activity: Newly uploaded samples trigger immediate analysis, allowing the feed to reflect what attackers are using right now. 
    • Coverage across many malware families: From commodity stealers and loaders to more targeted threats. 
    • High signal-to-noise ratio: Because the data is collected from real sandbox runs, it avoids inflated or outdated information that clutters many traditional feeds. 

    All of this results in intelligence that analysts can trust and act on immediately. 

    TI Feeds data: fullness and accuracy 
     
    Implementing ANY.RUN’s Threat Intelligence Feeds delivers measurable business outcomes that extend beyond technical metrics: 

    • Reduce incident response costs by enabling faster, more confident investigation. 
    • Lower risk of operational disruption by improving early detection of active threats. 
    • Optimize SOC efficiency so teams spend less time chasing false leads. 
    • Enhance strategic planning through visibility into persistent attacker tooling. 
    • Support compliance and audit readiness with evidence-based threat monitoring. 
    • Strengthen security investments by informing which controls need tuning, updating, or replacing. 

    Threat Intelligence Feeds business benefits 

    Conclusion 

    The biggest gap in most SOCs isn’t a missing tool or even a missing person. it’s missing data: fresh, detailed, actionable intelligence on the exact threats that are actively targeting organizations like yours right now. 
     
    By equipping analysts with reliable intelligence drawn from real malware behavior, ANY.RUN’s TI Feeds close this gap.

    They empower teams to respond faster, eliminate uncertainty, and support business leadership with clearer insights and stronger results. When a SOC has the right intelligence at its core, everything else, from day-to-day operations to long-term strategy, becomes far more effective.  

    Cut MTTR, expand threat coverage, reduce business risks  -> Get your trial & ask any questions 

    The post #1 Gap in Your SOCs Is Probably Not What You Think  appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • KawaiiGPT, a free malicious large language model (LLM) first spotted in July 2025 and now at version 2.5, empowers novice cybercriminals with tools for phishing emails, ransomware notes, and attack scripts, drastically lowering the entry barrier for cybercrime.

    Unlike paid rivals like WormGPT 4, which charges $50 monthly for similar capabilities, KawaiiGPT’s open-source availability on GitHub allows quick Linux setups in under five minutes, attracting hundreds of users via Telegram channels.​

    KawaiiGPT stands out for its simplicity and zero cost, hosted on public repositories that bypass dark web hurdles. Security researchers note its lightweight CLI deploys effortlessly, enabling even script kiddies to generate sophisticated attacks without deep coding skills.

    The tool masks malice with playful responses like “Owo! okay! here you go… 😀,” yet delivers functional Python scripts for lateral movement via paramiko SSH modules or data exfiltration using os.walk and smtplib.​

    This ease of access accelerates breaches: attackers can authenticate remotely, escalate privileges, deploy backdoors, and steal files seamlessly. Over 500 registered users, including 180 in an active Telegram group as of early November 2025, share tips to enhance its offensive features.​

    Phishing and Social Engineering Attack

    Prompted for a spear-phishing email mimicking a bank, KawaiiGPT crafts convincing lures like “Urgent: Verify Your Account Information,” linking to fake sites harvesting credentials via hxxps[:]//fakebankverify[.]com/updateinfo. These evade filters through flawless grammar and context, far surpassing traditional low-quality scams.​

    Its code generation covers key attack phases, automating network pivots that once demanded expertise. By blending legitimate libraries, outputs mimic normal traffic, aiding evasion of data loss prevention tools.​

    KawaiiGPT produces complete ransomware workflows, including threatening notes claiming “military-grade encryption” on files, with 72-hour deadlines and Bitcoin payment steps to attacker wallets. Scripts encrypt PDFs with AES-256, support Tor exfiltration, and guide novices from breach to extortion, Unit 42 observed.

    Data theft demos target Windows EML files, recursively scanning drives to email attachments stealthily. Customizable for compression or evasion, these tools weaponize Python standards, enabling rapid campaigns.​

    KawaiiGPT exemplifies AI’s dual-use risks, shifting threats from skilled actors to the masses via commercialization and democratization. While WormGPT monetizes advanced PowerShell ransomware, KawaiiGPT’s free model expands reach, fostering illicit communities.​

    Defenders must adapt: traditional signs like poor code vanish, demanding AI-resilient filters, anomaly detection, and prompt monitoring. Palo Alto Networks’ Unit 42 warns of compressed attack cycles, urging ethical AI safeguards and global disruption of these services.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post KawaiiGPT – New Black-Hat AI Tool Used by Hackers to Launch Cyberattacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • State-sponsored hacking groups have historically operated in isolation, each pursuing its own national agenda. However, new evidence reveals that two of the world’s most dangerous advanced persistent threat (APT) actors may now be working together.

    Russia-aligned Gamaredon and North Korea’s Lazarus group appear to be sharing operational infrastructure, marking a significant shift in the global cyber threat landscape.

    Russia and North Korea have maintained strong political and military ties for decades. In 2024, both nations renewed their alliance through a Comprehensive Strategic Partnership that includes mutual defense commitments.

    North Korean soldiers have reportedly been deployed alongside Russian forces in Ukraine, demonstrating their deepening cooperation on the battlefield.

    Gendigital security researchers identified this potential collaboration on July 28, 2025, when their monitoring systems detected a shared IP address linking both APT groups.

    The server at 144[.]172[.]112[.]106 was first flagged while tracking Gamaredon’s Command-and-Control infrastructure through known Telegram and Telegraph channels.

    Blocked IP address (Source - GenDigital)
    Blocked IP address (Source – GenDigital)

    Just four days later, the same server was found hosting an obfuscated version of InvisibleFerret malware attributed to Lazarus.

    The malware payload was delivered through a URL structure matching previous Lazarus campaigns, specifically the ContagiousInterview operation that targeted job seekers with fake recruitment messages.

    The payload hash (SHA256: 128da948f7c3a6c052e782acfee503383bf05d953f3db5c603e4d386e2cf4b4d) confirmed its attribution to Lazarus tooling and matched known samples from earlier attacks.

    Shared Infrastructure and Malware Delivery Mechanism

    The discovery of shared infrastructure carries major implications for global cybersecurity defenders. Gamaredon has been active since 2013 and focuses primarily on cyber espionage against Ukrainian government agencies.

    The Security Service of Ukraine linked the group to Russia’s Federal Security Service (FSB) in 2021, attributing over 5,000 cyberattacks to the group.

    Lazarus, operational since 2009, has shifted from espionage to financially motivated attacks, stealing over $1.7 billion in cryptocurrency from platforms including Bybit, WazirX, and AtomicWallet.

    The malware payload found on the shared server used an identical delivery path observed in previous Lazarus operations:-

    http[://]144[.]172[.]112[.]106/payload/99/81

    If confirmed, this Gamaredon-Lazarus overlap would represent the first documented case of Russian-North Korean cyber collaboration in the wild.

    Security teams should enhance infrastructure correlation analysis and prioritize cross-sector intelligence sharing to detect such emerging alliances early and protect critical assets from these coordinated threats.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Russian and North Korean Hackers Form Alliances to Attack Organizations Worldwide appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers are calling attention to a new campaign that’s leveraging a combination of ClickFix lures and fake adult websites to deceive users into running malicious commands under the guise of a “critical” Windows security update. “Campaign leverages fake adult websites (xHamster, PornHub clones) as its phishing mechanism, likely distributed via malvertising,” Acronis said in a

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new chain of five critical vulnerabilities discovered in Fluent Bit has exposed billions of containerized environments to remote compromise.

    Fluent Bit, an open-source logging and telemetry agent deployed over 15 billion times globally, sits at the core of modern cloud infrastructure.

    The tool collects, processes, and forwards logs across banking systems, cloud platforms like AWS and Microsoft Azure, and Kubernetes environments.

    When failures occur at this scale, they do not just affect individual systems but ripple across the entire cloud ecosystem.

    These newly disclosed flaws allow attackers to bypass authentication, perform unauthorized file operations, achieve remote code execution, and cause denial-of-service attacks through unsanitized tag manipulation.

    The attack surface extends across multiple critical functionalities. Attackers exploiting these vulnerabilities could disrupt cloud services, tamper with data, and execute malicious code while hiding their tracks.

    By controlling logging service behavior, adversaries gain the ability to inject fake telemetry, reroute logs to unauthorized destinations, and alter which events get recorded.

    Some vulnerabilities have remained unpatched for over eight years, leaving cloud environments exposed to determined attackers. Security researchers at Oligo Security identified these flaws in collaboration with AWS through coordinated vulnerability disclosure.

    The research demonstrates how weaknesses in foundational infrastructure components can enable sophisticated attack chains affecting millions of deployments worldwide.

    Oligo Security analysts identified the vulnerabilities after conducting thorough security assessments of Fluent Bit’s input and output plugins.

    The research team discovered that authentication mechanisms, input validation, and buffer handling contained critical security gaps.

    Their findings prompted immediate coordination with AWS and the Fluent Bit maintainers, resulting in fixes released in version 4.1.1.

    Technical Breakdown of Path Traversal and File Write Vulnerabilities

    CVE-2025-12972 represents one of the most dangerous flaws in the chain. The File output plugin in Fluent Bit writes logs directly to the filesystem using two configuration parameters: Path and File.

    Many common configurations use only the Path option and derive filenames from record tags. However, the plugin fails to sanitize these tags before constructing file paths. Attackers can inject path traversal sequences like “../” within tag values to escape the intended directory and write files anywhere on the system.

    Flaw chain (Source - Oligo)
    Flaw chain (Source – Oligo)

    Since attackers maintain partial control over data written to these files through log content manipulation, they can create malicious configuration files, scripts, or executables in critical system locations.

    When Fluent Bit runs with elevated privileges, this leads to remote code execution. The vulnerability becomes trivially exploitable when HTTP input is configured with Tag_Key settings and File output lacks an explicit File parameter.

    Configurations using the forward input combined with file output are equally vulnerable, enabling unauthenticated attackers to inject malicious tags and write arbitrary files.

    CVE IDVulnerability TypeAffected ComponentCVSS SeverityImpact
    CVE-2025-12972Path Traversal File Writeout_file pluginCriticalRCE, Log Tampering
    CVE-2025-12970Stack Buffer Overflowin_docker pluginCriticalDoS, RCE
    CVE-2025-12978Partial String ComparisonHTTP/Splunk/Elasticsearch inputsCriticalTag Spoofing
    CVE-2025-12977Improper Input ValidationHTTP/Splunk/Elasticsearch inputsCriticalInjection Attacks
    CVE-2025-12969Missing Authenticationin_forward pluginCriticalUnauthorized Access

    Immediate patching to version 4.1.1 or 4.0.12 is critical for all organizations running Fluent Bit. Organizations should prioritize updating production deployments and implement configuration changes to limit attack exposure.

    Static, predefined tags eliminate untrusted input from influencing routing and file operations. Setting explicit Path and File parameters in output configurations prevents dynamic tag-based path construction.

    Running Fluent Bit with non-root privileges and read-only mounted configuration files significantly reduces the impact of successful exploitation. AWS has already secured its internal systems and recommends all customers upgrade immediately.

    The security community views these vulnerabilities as evidence of systemic challenges in open-source security reporting, where critical infrastructure components often rely on volunteer maintainers with limited resources to address coordinated security disclosures.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Critical FluentBit Vulnerabilities Let Attackers to Cloud Environments Remotely appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity authorities have raised fresh alarms over the spread of advanced commercial spyware targeting secure messaging apps like Signal and WhatsApp.

    According to a recent CISA advisory, multiple cyber threat actors actively deploy this sophisticated malware to compromise users’ smartphones, using methods designed to bypass established security protections.

    These threats first emerged in 2025, with attackers exploiting vulnerabilities and social engineering tactics to infect mobile devices, often targeting high-value targets.

    Attackers have used deceptive techniques, such as malicious device-linking QR codes and phishing schemes, to spread spyware, sometimes integrating zero-click exploits that allow infection even if users take no direct action.

    Once inside a victim’s device, the spyware can evade detection for long periods and deploy hidden payloads to compromise private messaging communications fully.

    The impact is profound—victims may unknowingly lose control of sensitive material, risking exposure of confidential conversations and data.

    CISA security analysts identified this malware after analyzing a surge in infections reported by U.S., Middle Eastern, and European organizations.

    Their investigation revealed that adversaries increasingly target high-ranking government, military, and civil society officials, exploiting technical loopholes and user behavior to infiltrate protected messaging channels quietly.

    The persistent nature of the threat prompted CISA to urge all messaging app users to review best-practice guidance on mobile security and malware mitigation.

    Infection Mechanism: How the Spyware Operates

    A deeper technical breakdown shows that once installed, the malware leverages Android’s service and broadcast receiver components to maintain control and persist after reboot.

    The infection sequence typically begins with a disguised download—either through a phishing link or device-link QR code.

    The malicious app requests excessive permissions, such as SMS access and device administrator rights, enabling silent data exfiltration, contact extraction, and message interception.

    Code Snippet Example:-

    java
    // Main spyware service initializing after install
    public void onStart(Intent intent, int startId) {
    exfiltrateMessages();
    extractContacts();
    hideFromLauncher();
    }

    As noted by CISA, the combination of stealthy entry, exploitation of core Android features, and aggressive privilege escalation makes this spyware an ongoing risk to secure communications apps worldwide.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post CISA Warns of Threat Actors Leveraging Commercial Spyware to Target Users of Signal and WhatsApp appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fortra has officially released Cobalt Strike 4.12, introducing a comprehensive suite of new features designed to enhance red team operations and offensive security research. The update delivers a modernized GUI, a groundbreaking REST API, User Defined Command and Control (UDC2), advanced process injection techniques, new UAC bypasses, and enhanced evasion capabilities via drip-loading Malleable C2 options. […]

    The post Cobalt Strike 4.12 Adds New Injection, UAC Bypasses & C2 Features appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A recently discovered malicious Visual Studio Code (VSCode) extension masquerading as the well-known “Prettier” formatter briefly infiltrated the official VSCode Marketplace, delivering a variant of the Anivia Stealer malware in a targeted attack to steal sensitive login credentials and private data from developers’ systems. Thanks to the vigilance of the Checkmarx Zero research team specifically […]

    The post VSCode Marketplace Hit by Rogue Prettier Extension Delivering Anivia Stealer appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals have discovered a new attack vector targeting the creative design community by exploiting Blender, a widely used open-source 3D modeling application.

    Threat actors are uploading malicious files to popular asset platforms like CGTrader, containing embedded Python scripts that execute automatically when users open the files in Blender.

    This sophisticated campaign, uncovered through ongoing threat investigations, demonstrates how attackers continue to adapt their tactics to compromise unsuspecting users across Windows, macOS, and Linux systems.

    The operation has been active for at least six months and connects to previously identified Russian-linked campaigns that used similar evasion techniques and decoy documentation methods.

    These malicious .blend files are weaponized to steal sensitive information from victim machines, including passwords, cryptocurrency wallets, and authentication credentials from multiple browsers and applications.

    The threat represents a significant risk to the creative industry, where Blender’s free and powerful capabilities make it an essential tool for professionals and hobbyists alike.

    Morphisec security researchers identified and tracked this campaign after analyzing the infection chain and command and control infrastructure.

    The research revealed direct connections to StealC V2, a dangerous information-stealing malware that has become increasingly popular in underground criminal markets since its emergence in April 2025.

    Understanding the Infection Mechanism

    When users open a compromised .blend file with Blender’s Auto Run Python Scripts setting enabled, the embedded Rig_Ui.py script executes automatically.

    The malware then fetches a PowerShell loader from remote servers controlled by the attackers. This loader downloads multiple archive files containing a fully functional Python environment preloaded with StealC V2 and additional stealing components.

    Attack Chain (Source - Morphisec)
    Attack Chain (Source – Morphisec)

    The extracted files create hidden shortcut files (LNK) that are copied to the Windows Startup folder, ensuring the malware persists across system reboots.

    The attack chain involves multiple stages of obfuscation and uses encrypted communication channels.

    Python scripts download encrypted payloads using ChaCha20 encryption through the Pyramid command and control infrastructure, making detection and analysis significantly more challenging.

    StealC V2 itself targets over 23 web browsers, more than 100 browser extensions, 15 desktop cryptocurrency wallets, messaging applications like Telegram and Discord, and VPN clients.

    The malware includes updated privilege escalation techniques and maintains low detection rates on security analysis platforms, allowing it to evade traditional security solutions.

    Users should disable Blender’s Auto Run feature for untrusted file sources and exercise caution when downloading 3D models from community platforms.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Threat Actors Leverage Blender Foundation Files to Deliver Notorious StealC V2 Infostealer appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft is sounding the alarm on critical security considerations as it introduces agentic AI capabilities to Windows through experimental features like Copilot Actions. The company is rolling out a new agent workspace feature in private preview that establishes isolated environments for AI agents to operate, but the tech giant is being transparent about the novel […]

    The post Microsoft Warns of Security Risks in New Agentic AI Feature appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶