• Suspected espionage-driven threat actors from Iran have been observed deploying backdoors like TWOSTROKE and DEEPROOT as part of continued attacks aimed at aerospace, aviation, and defense industries in the Middle East. The activity has been attributed by Google-owned Mandiant to a threat cluster tracked as UNC1549 (aka Nimbus Manticore or Subtle Snail), which was first documented by the threat

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A dangerous scam targeting WhatsApp users has emerged as one of the fastest-growing threats across messaging platforms worldwide.

    The scheme exploits WhatsApp’s screen-sharing feature, introduced in 2023, to manipulate users into exposing their most sensitive financial and personal information.

    Reports from the United Kingdom, India, Hong Kong, and Brazil highlight the scam’s global reach, with one documented case in Hong Kong resulting in a loss of HK$5.5 million, equivalent to US$700,000.

    This social engineering attack demonstrates how even trusted communication platforms can become weapons when criminals combine psychological manipulation with technical access to a user’s device.

    The scam operates on a foundation of deception rather than sophisticated malware, relying entirely on human psychology to achieve its goals.

    Attackers place unsolicited WhatsApp video calls, impersonating bank representatives, Meta support agents, or even family members in distress.

    Screen sharing scam report from Brazil (Source - Welivesecurity)
    Screen sharing scam report from Brazil (Source – Welivesecurity)

    To appear legitimate, they spoof local phone numbers and deliberately disable or blur their video feed to conceal their identity.

    The attacker then creates a false sense of urgency by claiming unauthorized charges on credit cards, suspicious account activity, or pending verification issues that require immediate action.

    ESET security researchers have identified this scam as a particularly effective variant of remote access fraud that exploits three critical elements: trust established through an impersonated authority figure, urgency created through fabricated threats, and control granted by the screen-sharing feature or remote access applications.

    The combination of these factors provides criminals with near-complete visibility into a user’s smartphone.

    Once the victim agrees to share their screen, the attacker’s access becomes comprehensive. Criminals can observe passwords, two-factor authentication codes, one-time passwords, and banking applications in real time.

    They can capture screenshots, request the user to open financial apps, and manipulate them into authorizing unauthorized bank transfers under the pretense of resolving technical issues.

    More alarmingly, attackers often trick users into installing remote access tools like AnyDesk or TeamViewer, which grant them full control of the device.

    Some victims have unknowingly installed malware such as keyloggers that silently record sensitive information for later exploitation.

    Technical Mechanism

    The Technical Mechanism Behind Account Takeover demonstrates why this attack remains so dangerous. When an attacker gains access to incoming text messages and WhatsApp verification codes through screen sharing, they can immediately hijack the victim’s WhatsApp account.

    With control of the account, criminals access stored conversations, financial data, and personal contacts.

    They proceed to drain banking accounts, hijack social media profiles, and impersonate victims to target their relatives and friends with the same scam, creating cascading waves of fraud.

    Defense against this threat depends primarily on awareness and discipline rather than technical solutions.

    Users should never share their screen with unknown callers and must independently verify any alarming information through official channels before taking action.

    Enabling two-step verification in WhatsApp by navigating to Settings → Account → Two-step verification provides crucial protection by requiring a second authentication factor even if credentials are compromised.

    Organizations and individuals must recognize that social engineering remains the most powerful weapon in a cybercriminal’s arsenal, making skepticism and careful judgment the strongest defenses against such attacks.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post WhatsApp Screen-Sharing Scam Let Attackers Trick Users into Revealing Sensitive Data appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Princeton University confirmed on November 15 that an Advancement database containing sensitive personal information about alums, donors, faculty members, students, parents, and other community members was compromised by outside actors on November 10. The unauthorized access lasted less than 24 hours before the institution’s security teams discovered and responded to the incident. The compromised database […]

    The post Princeton University Data Breach: Donor Information Exposed in Compromised Database appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • DoorDash has publicly disclosed a cybersecurity incident in which an unauthorized third party gained access to specific user information through a targeted social engineering attack against one of the company’s employees. The company confirmed that while personal data was compromised, no sensitive financial information or identification documents were accessed during the breach. The incident represents […]

    The post DoorDash Confirms Data Breach Compromised User Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • You’ve probably already moved some of your business to the cloud—or you’re planning to. That’s a smart move. It helps you work faster, serve your customers better, and stay ahead. But as your cloud setup grows, it gets harder to control who can access what. Even one small mistake—like the wrong person getting access—can lead to big problems. We’re talking data leaks, legal trouble, and serious

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In a major law enforcement operation conducted on November 12, 2025, the East Netherlands cybercrime team successfully dismantled a significant criminal infrastructure.

    Authorities seized approximately 250 physical servers located in data centers across The Hague and Zoetermeer, which collectively powered thousands of virtual servers used for illegal activities.

    This operation represents one of the largest infrastructure takedowns targeting bulletproof hosting services that have been instrumental in facilitating cybercrimes across multiple jurisdictions.

    The seized hosting company operated under the guise of legitimacy while providing complete anonymity to its users.

    Police analysts identified that the provider marketed itself as bulletproof hosting, explicitly claiming not to cooperate with law enforcement agencies and guaranteeing protection for its criminal clientele.

    Despite these promises, the company’s infrastructure ultimately became the centerpiece of a comprehensive investigation that has exposed its true nature as a criminal enterprise serving exclusively illegal purposes.

    Police.nl security analysts noted that the hosting company had appeared in more than 80 criminal investigations both domestically and internationally since 2022.

    The company continued facilitating illegal operations until the moment of seizure, demonstrating its persistent role in supporting various cybercriminal activities across different threat landscapes and attack vectors.

    The Criminal Infrastructure’s Role in Cyberattacks

    The rogue hosting provider functioned as a critical enabler for multiple types of cybercriminal activities.

    Criminals rented digital space from this company to launch ransomware attacks, deploy botnets designed to compromise thousands of systems, execute sophisticated phishing campaigns targeting organizations and individuals, and distribute child exploitation material.

    This hosting service essentially provided the digital foundation that allowed threat actors to conduct their operations with perceived impunity.

    The operational scope of this infrastructure was substantial, with the platform housing criminal websites, malware command-and-control servers, phishing infrastructure, and various other illegal services.

    The seizure of both physical and virtual servers immediately disrupted these criminal operations and prevented new attacks from being launched through this particular infrastructure.

    Following the seizure, authorities prioritized analyzing the vast amount of data recovered from the servers to identify additional criminal networks, individual threat actors, and victims requiring notification.

    The investigation continues with law enforcement agencies focusing on identifying all users of the hosting service and tracing the full extent of criminal activities conducted through this infrastructure.

    This operation demonstrates the critical importance of targeting the underlying infrastructure that enables cybercriminal operations at scale.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Authorities Seized Thousands of Servers from Rogue Hosting Company Used to Fuel Cyberattacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Scams and threats circulating on messaging apps like WhatsApp demonstrate how easily trusted platforms can be weaponized against users. One deceptive tactic gaining traction involves tricking people into sharing their phone screens during WhatsApp video calls. The screen-sharing feature, available since 2023, is increasingly being turned against users to steal data, identities, and money. Cases […]

    The post WhatsApp Screen-Sharing Scam: How Attackers Are Deceiving Users to Expose Sensitive Information appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Remcos, a commercial remote access tool distributed by Breaking-Security and marketed as administrative software, has become a serious threat in the cybersecurity landscape.

    Developed in the mid-2010s, this malware enables attackers to execute remote commands, steal files, capture screens, log keystrokes, and collect user credentials through command-and-control servers using HTTP or HTTPS channels.

    Despite being positioned as legitimate software with both free and paid versions, unauthorized copies are actively used in the wild for data theft and unauthorized system access.

    The malware spreads through email campaigns containing malicious attachments and files hosted on compromised websites.

    Attackers also use specialized loaders such as GuLoader and Reverse Loader to deliver Remcos as a second-stage payload, allowing them to bypass initial detection systems.

    Once installed, the malware establishes persistence and maintains continuous communication with its control infrastructure, creating a reliable backdoor for ongoing attacks.

    Censys security analysts noted that between October 14 and November 14, 2025, they consistently tracked over 150 active Remcos command-and-control servers worldwide.

    Infrastructure

    This substantial infrastructure demonstrates the tool’s widespread adoption among threat actors.

    The servers typically operated on port 2404, the default choice for Remcos, with additional activity observed on ports 5000, 5060, 5061, 8268, and 8808, showing operators’ flexibility in deployment strategies.

    Remcos persistence configuration (Source - Censys)
    Remcos persistence configuration (Source – Censys)

    Understanding C2 Communication Networks reveals how Remcos maintains control. The malware communicates through HTTP and HTTPS protocols on predictable ports, with network traffic frequently containing encoded POST requests and unusual TLS configurations that create distinctive patterns.

    Operators typically reuse certificates across multiple servers, employ template-based setups, and leverage inexpensive hosting providers like COLOCROSSING, RAILNET, and CONTABO across the United States, Netherlands, Germany, and other countries.

    This infrastructure pattern enables network defenders to identify and block communications at detection points.

    The detected persistence mechanisms include Scheduled Tasks and Registry Run-key entries, allowing attackers to maintain access even after system restarts.

    This combination of command execution, file transfer capabilities, and resilient persistence makes Remcos particularly dangerous for organizations with weak security controls, requiring immediate network monitoring and endpoint detection measures.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Remcos RAT C2 Activity Mapped Along with The Ports Used for Communications appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Quantum devices that measure Earth's magnetic fields could help replace GPS—if researchers can figure out how to tell when such devices are working well, or even at all. A Pentagon contract suggests one company is solving that key problem.

    On Tuesday, SandboxAQ announced an agreement with the Defense Innovation Unit to join the Transition of Quantum Sensing program, or TQS, which allows the military to test the company’s AQNav software aboard a range of aircraft under a variety of conditions, according to a release viewed exclusively by Defense One. The deal builds on the company’s previous agreement with the Air Force, which tested the company’s software on C-17 Globemaster IIIs during exercises in May and July 2023.

    Luca Ferrara, general manager of AQNav at SandboxAQ, said the agreement, coupled with recent research breakthroughs, has set the stage for rapid development in magnetic navigation. It will still take years before small, cheap, self-piloting one-way attack drones are able to find their way to targets, he said, but the DIU contract shows confidence that researchers are now asking the right questions.

    Magnetic sensing is not exactly new. A patchwork of magnetic fields across the Earth’s crust is what makes a compass point north. But “north” doesn’t offer the level of precision a commander would want to chart a course for a plane or a drone. 

    High-tech and expensive quantum sensors can pick up information about magnetic fields far more accurately than old compasses. But the variation in those magnetic fields across the Earth’s crust, the very feature that makes them useful as a location tool, also means that quantum sensors will work well in some places and not in others. Maps that show different magnetic fields are limited, and the testing of magnetic sensors is similarly constrained.

    “The way those maps get made at scale is, you have a plane that's specially outfitted with a lot of sensors. You can get down to like tens of meters of accuracy … That’s what we would call a very well-sampled map, and you have a very clean signal, meaning your magnetometer is in a clean part of the plane,” Ferrara said. In other words, it works well under scripted conditions.

    To make magnetic navigation useful where GPS is under attack, researchi is building out an understanding of how it will or will not work under a much wider set of conditions. 

    But that is a huge challenge, since the standard metrics that researchers use to certify navigation performance, like Required Navigation Performance or the U.S. military’s Circular Error Probable, can be misleading when dealing with magnetic navigation. A lot of what the company does is employ AI to figure out how to fill in those gaps.

    A paper by SandboxAQ’s chief navigation engineer, Prasenjit Sengupta, in the December 2025 scientific journal Navigation, discusses a new method to compute the degree to which the error rate stays within certain knowable bounds. It’s a bit like a weather report to tell you how clear or cloudy it is outside, but instead it offers a reliable statistic to indicate how “cloudy” your magnetically sensed position is.

    Magnetic navigation isn’t going to be a perfect replacement for GPS, Ferrara said. But if you can understand the conditions under which it will perform better or worse and to what degree—or, as he described it, “Knowing what the limitations are and working around them with the user”—then you have at least some of the essential building blocks to decide what other positioning systems to include in a GPS-backup scheme. 

    “Just to be clear, it’s also about having the sensors on board that platform be able to reliably, scalably create clean measurements so that it can know where it is in the moment reliably and well, to the best of our ability, every time,” he said, underscoring that even a GPS alternative has to know its own limits.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Identity security fabric (ISF) is a unified architectural framework that brings together disparate identity capabilities. Through ISF, identity governance and administration (IGA), access management (AM), privileged access management (PAM), and identity threat detection and response (ITDR) are all integrated into a single, cohesive control plane. Building on Gartner’s definition of “identity

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶