• The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new Oracle vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that attackers are already exploiting it in real-world attacks. The bug, tracked as CVE-2025-61757, affects Oracle Identity Manager, part of Oracle Fusion Middleware. The flaw is rated as a “missing authentication for critical […]

    The post CISA Issues Warning as Hackers Target Oracle Identity Manager RCE Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Salesforce has disclosed a significant security incident involving unauthorized access to customer data through compromised Gainsight-published applications. The breach, detected in mid-November 2025, potentially exposed sensitive information from over 200 organizations that use the customer success platform integrated with Salesforce. Threat actors linked to the notorious ShinyHunters group exploited OAuth tokens to gain unauthorized access […]

    The post Hackers Use Salesforce Gainsight Breach to Access Data from More Than 200 Companies appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity giant CrowdStrike has terminated an employee who allegedly shared sensitive internal system information with a notorious hacking collective. The incident involved the leak of internal screenshots posted on a public Telegram channel operated by the threat group known as “Scattered Lapsus$ Hunters“. Insider Threat Detected Through Screen Sharing The leaked images displayed internal dashboards, […]

    The post CrowdStrike Fires Employee for Leaking Internal System Info to Hackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated supply chain attack has reportedly compromised data across hundreds of organizations, linking the breach to a critical integration between customer success platform Gainsight and CRM giant Salesforce.

    The notorious hacking collective ShinyHunters is claiming responsibility for the intrusion, which allegedly affects over 200 companies. The attack vector did not rely on breaking into Salesforce directly but instead on exploiting the trusted connection established through third-party applications.

    On November 20, 2025, Salesforce took emergency action to contain the threat. The company officially disabled the connection between Gainsight-published applications and the Salesforce ecosystem after detecting “unusual activity.”

    According to a statement from Salesforce, their investigation suggests that the activity facilitated unauthorized access to customer data, specifically through the app’s external connection.

    Exploiting Trusted OAuth Tokens

    The mechanics of this campaign highlight a growing trend in modern cyber warfare: targeting the “keys” rather than the “locks.”

    The Google Threat Intelligence Group (GTIG), including researchers from Mandiant, identified the threat actors as affiliates of ShinyHunters. These adversaries compromised third-party OAuth tokens.

    In the SaaS environment, OAuth tokens function like digital permissions slips, allowing apps like Gainsight to talk to Salesforce without requiring a user to log in every time.

    By stealing these tokens, the attackers could potentially bypass multi-factor authentication and standard login defenses, masquerading as the trusted application to exfiltrate sensitive corporate data. This method allows threat actors to move laterally within cloud environments while remaining undetected by traditional perimeter security.

    While the scope of the data loss is potentially massive, Salesforce has been clear in its distinction regarding where the fault lies. The company emphasized that there is “no indication that this issue resulted from any vulnerability in the Salesforce platform.” Instead, the breach is strictly related to the external connection and the management of credentials for the Gainsight integration.

    Currently, customers are unable to connect their Gainsight-published applications to Salesforce until further notice. Both Salesforce and Mandiant are actively notifying organizations that show signs of compromise.

    This incident mirrors similar campaigns observed recently, such as attacks targeting Salesloft Drift, suggesting a concerted effort by threat groups to audit and exploit SaaS ecosystems where third-party permissions are often granted and forgotten.

    Urgent Actions for SaaS Administrators

    This incident serves as a critical wake-up call for organizations relying on interconnected SaaS platforms. Security teams are urged to immediately treat this as a signal to audit their entire cloud environment.

    The primary recommendation is to review all connected apps within Salesforce instances and revoke OAuth tokens for any integration that is unused, suspicious, or related to the affected Gainsight applications.

    Organizations using Gainsight integrations should monitor for official communications from both vendors, Salesforce and Gainsight.

    However, proactive defense is required. If any anomalous activity is detected from an integration, administrators should rotate credentials immediately and assume a potential compromise.

    As threat actors increasingly pivot toward identity-based attacks and token theft, the maintenance of third-party permissions has become just as vital as patching software vulnerabilities.

    Here is the table of Indicators of Compromise (IoCs) associated with the ShinyHunters campaign targeting Salesforce and Gainsight integrations.

    IOC TypeValueFirst Seen (UTC)Last Seen (UTC)Observed Activity
    IP Address104.3.11[.]12025-11-08 13:11:292025-11-08 13:15:23AT&T IP; reconnaissance and unauthorized access. ​
    IP Address198.54.135[.]1482025-11-16 21:48:032025-11-16 21:48:03Mullvad VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address198.54.135[.]1972025-11-16 22:00:562025-11-16 22:06:57Mullvad VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address198.54.135[.]2052025-11-18 10:43:552025-11-18 12:09:35Mullvad VPN proxy IP; reconnaissance and unauthorized access. obsi
    IP Address146.70.171[.]2162025-11-18 20:21:482025-11-18 20:50:13Mullvad VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address169.150.203[.]2452025-11-18 20:54:022025-11-18 23:04:12Surfshark VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address172.113.237[.]482025-11-18 21:23:292025-11-18 21:51:32NSocks VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address45.149.173[.]2272025-11-18 22:05:152025-11-18 22:05:18Surfshark VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address135.134.96[.]762025-11-19 08:26:182025-11-19 10:30:37IProxyShop VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address65.195.111[.]212025-11-19 10:57:372025-11-19 10:59:19IProxyShop VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address65.195.105[.]812025-11-19 11:17:512025-11-19 11:48:07Nexx VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address65.195.105[.]1532025-11-19 12:23:172025-11-19 12:23:35ProxySeller VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address45.66.35[.]352025-11-19 12:47:432025-11-19 12:47:45Tor VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address146.70.174[.]692025-11-19 12:47:492025-11-19 12:47:49Proton VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address82.163.174[.]832025-11-19 14:30:362025-11-19 22:26:46ProxySeller VPN proxy IP; reconnaissance and unauthorized access. ​
    IP Address3.239.45[.]432025-10-23 00:17:222025-10-23 00:45:36AWS IP; reconnaissance against customers with compromised Gainsight access token. ​
    User Agentpython-requests/2.28[.]12025-11-08 13:11:192025-11-08 13:15:01Not an expected user agent string used by Gainsight connected app; use in conjunction with other IOCs shared. ​
    User Agentpython-requests/2.32[.]32025-11-16 21:48:032025-11-16 21:48:03Not an expected user agent string used by Gainsight connected app; use in conjunction with other IOCs shared. ​
    User Agentpython/3.11 aiohttp/3.13[.]12025-10-23 00:00:002025-10-23 00:01:00Not an expected user agent string used by Gainsight connected app; use in conjunction with other IOCs shared. ​
    User AgentSalesforce-Multi-Org-Fetcher/1.02025-11-18 22:05:132025-11-19 22:24:01Leveraged by threat actor for unauthorized access; also observed in Salesloft Drift activity. ​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post ShinyHunters Claims Data Theft from 200+ Companies via Salesforce Gainsight Breach appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Bad actors are leveraging browser notifications as a vector for phishing attacks to distribute malicious links by means of a new command-and-control (C2) platform called Matrix Push C2. “This browser-native, fileless framework leverages push notifications, fake alerts, and link redirects to target victims across operating systems,” Blackfog researcher Brenda Robb said in a Thursday report. In

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting Oracle Identity Manager to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is CVE-2025-61757 (CVSS score: 9.8), a case of missing authentication for a critical function that can result in pre-authenticated

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF).

    This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code Execution (RCE) with root privileges.

    The release follows reports of active exploitation in the wild, including “silent patches” and subsequent bypasses that have left many appliances exposed.

    The Exploitation Chain

    The new module, identified as exploit/linux/http/fortinet_fortiweb_rce, automates a sophisticated attack chain that bypasses authentication mechanisms before executing arbitrary operating system commands.

    The attack begins with CVE-2025-64446, a critical authentication bypass vulnerability with a CVSS score of 9.1. As analyzed by researchers at watchTowr, this flaw involves a path traversal issue combined with improper handling of the CGIINFO header.

    By manipulating this header and traversing to the fwbcgi executable, an unauthenticated attacker can impersonate the built-in admin user and create a new administrative account without valid credentials.

    Once administrative access is established, the module leverages CVE-2025-58034 to compromise the underlying system. This second vulnerability is an authenticated command injection flaw found in the FortiWeb API and CLI, where special elements in OS commands are not properly neutralized.

    Rapid7 analysis confirms that this flaw allows an authenticated user to escape the intended shell restrictions and execute commands as the root user. By chaining these two issues, the Metasploit module allows an external attacker to go from zero access to full system control in seconds.

    Metasploit Module

    The Metasploit module is designed to be flexible across different attack scenarios. In its default mode, it automatically exploits the authentication bypass (CVE-2025-64446) to provision a random administrator account.

    It then authenticates with these new credentials to trigger the command injection. Alternatively, if an attacker already possesses valid credentials, the module can be configured to skip the bypass phase and directly exploit CVE-2025-58034.

    Technically, the exploit utilizes a chunked upload mechanism to deliver its payload. As seen in the pull request documentation, the module uploads a “bootstrap payload” in multiple parts (e.g., 4 chunks) before amalgamating and executing them.

    This method ensures reliable execution even within the constrained environment of the appliance. Successful exploitation grants a shell with uid=0(root), giving the attacker complete control over the WAF device.

    Fortinet has released patches to address these vulnerabilities, and users are strongly advised to upgrade to FortiWeb version 8.0.2 or later immediately.

    Because CVE-2025-64446 allows for the silent creation of rogue administrators, simply patching is insufficient for potentially compromised devices. Security teams should audit their user lists for unknown accounts and review logs for requests to /api/v2.0/cmdb/system/admin originating from untrusted IP addresses.

    CVE IDVulnerability TypeCVSSAffected Products (Partial List)
    CVE-2025-64446Auth Bypass / Path Traversal9.1FortiWeb 7.4.0-7.4.4, 7.6.0-7.6.4, 8.0.0-8.0.1
    CVE-2025-58034OS Command Injection7.2FortiWeb 8.0.0-8.0.1

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A former IT contractor from Ohio has admitted to launching a cyberattack against his employer’s network in retaliation for being terminated, federal prosecutors announced this week.

    Maxwell Schultz, 35, of Columbus, Ohio, pleaded guilty to computer fraud charges after leading a technical attack that locked thousands of employees out of their systems nationwide.

    On May 14, 2021, Schultz was fired from his contract position in the company’s IT department. Rather than accepting the termination, he chose to strike back digitally.

    Shortly after his dismissal, Schultz impersonated another contractor to fraudulently obtain valid login credentials, gaining unauthorized access to the company’s network.

    Once inside the system, Schultz executed a PowerShell script designed to cause maximum disruption.

    The malicious code reset approximately 2,500 employee passwords simultaneously, effectively locking thousands of workers and contractors out of their computers across multiple locations.

    Schultz didn’t stop at password resets. He actively sought methods to delete digital evidence of his unauthorized access, including PowerShell event logs and system logs.

    Despite clearing multiple logs, investigators eventually traced the attack back to him. The company suffered significant financial losses exceeding $862,000.

    These damages included widespread employee downtime, disrupted customer service operations, and extensive labor costs required to restore standard network functionality.

    The ripple effects impacted both internal operations and customer relationships. As part of his guilty plea, Schultz acknowledged that anger over his termination motivated the attack. He now faces serious federal consequences.

    U.S. District Judge Lee Rosenthal will sentence Schultz on January 30, 2026. He faces up to 10 years in federal prison and a maximum fine of $250,000.

    The FBI led the investigation, with Assistant U.S. Attorneys Rodolfo Ramirez and Michael Chu prosecuting the case.

    This case highlights the critical importance of immediately revoking system access for terminated employees, particularly those with administrative privileges.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Fired Techie Admits Hacking Employer’s Network in Retaliation for Termination appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Rapid7’s Metasploit team has released a new exploit module targeting critical zero-day vulnerabilities in Fortinet’s FortiWeb web application firewall, chaining two security flaws to achieve unauthenticated remote code execution with root privileges.​ CVE ID Vulnerability Type Affected Product Impact CVE-2025-64446 Authentication Bypass Fortinet FortiWeb Administrative account creation, privilege escalation CVE-2025-58034 Command Injection Fortinet FortiWeb Remote […]

    The post Metasploit Releases New Exploit for Fresh FortiWeb 0-Day Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity giant CrowdStrike has confirmed the termination of an insider who allegedly provided sensitive internal system details to a notorious hacking collective.

    The incident, which came to light late Thursday and Friday morning, involved the leak of internal screenshots on a public Telegram channel operated by the threat group known as “Scattered Lapsus$ Hunters.”

    The leaks surfaced when Scattered Lapsus$ Hunters, a self-proclaimed “supergroup” comprising members from Scattered Spider, LAPSUS$, and ShinyHunters, posted images purportedly showing access to CrowdStrike’s internal environment.

    The screenshots, which TechCrunch reviewed, displayed internal dashboards, including an Okta Single Sign-On (SSO) panel used by employees to access corporate applications.

    The hackers claimed these images were proof of a broader compromise achieved through a third-party breach at Gainsight, a customer success platform used by Salesforce clients.​

    However, the reality appears to be less about a technical breach and more about human vulnerability. Reports indicate that the threat actors allegedly offered the insider $25,000 to facilitate access to the network.

    While the hackers claimed to have received authentication cookies, CrowdStrike maintains that its security operations center detected the activity before any malicious access could be fully established.​

    CrowdStrike swiftly addressed the claims, clarifying that the leaked images were the result of an employee sharing pictures of their screen rather than a systemic network intrusion.

    CrowdStrike spokesperson said to Cybersecurity News, “We identified and terminated a suspicious insider last month following an internal investigation that determined he shared pictures of his computer screen externally. Our systems were never compromised, and customers remained protected throughout. We have turned the case over to the relevant law enforcement agencies.”

    This incident is part of a larger, aggressive campaign by Scattered Lapsus$ Hunters, who have recently targeted major corporations by exploiting third-party vendors like Gainsight and Salesloft.

    In October 2025, the group claimed to have exfiltrated nearly 1 billion records from Salesforce customers, listing high-profile victims such as Allianz Life, Qantas, and Stellantis on their data leak site.

    The group’s modus operandi often involves high-pressure social engineering and recruiting insiders to bypass perimeter defenses, a tactic that has become increasingly common in 2025.​

    While CrowdStrike successfully contained this specific insider threat without customer impact, the event highlights the persistent danger posed by recruited employees in high-stakes cybersecurity environments.

    The convergence of sophisticated social engineering with the pooled resources of three major cybercrime gangs represents a significant evolution in the threat landscape facing tech enterprises today.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CrowdStrike Fires Insider for Sharing Internal System Details with Hackers appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶