• The English-speaking cybercriminal ecosystem, commonly known as “The COM,” has transformed from a niche community of social media account traders into a sophisticated, organized operation fueling some of the world’s most damaging cyberattacks.

    What started as simple forums for trading rare social media handles has evolved into a professional, service-driven criminal marketplace targeting multinational corporations, government agencies, and critical infrastructure across the globe.

    The COM’s growth accelerated during the cryptocurrency boom between 2020 and 2021, when cybercriminals shifted their focus from stealing social media accounts to draining digital wallets containing millions of dollars.

    This shift introduced new attack methods and monetization strategies that fundamentally changed the landscape of cybercrime.

    The ecosystem now operates as a comprehensive supply chain where specialized roles work together seamlessly to execute coordinated attacks.

    CloudSEK security analysts identified that The COM’s operational structure mirrors legitimate business models.

    Different threat actors specialize in specific roles—some handle social engineering through vishing calls, others manage credential theft, and specialized teams handle data exfiltration and money laundering.

    This specialization allows criminal operations to scale rapidly while distributing risk across multiple independent actors.

    The emergence of groups like Lapsus$ and ShinyHunters demonstrated The COM’s evolution into theatrical, publicity-driven operations.

    Lapsus$ became infamous for breaching major tech companies, including NVIDIA, Samsung, and Microsoft, by manipulating customer support staff through social engineering.

    The group pioneered a “leak-and-brag” approach, publicly taunting victims and law enforcement while threatening data releases to accelerate ransom payments.

    The Attack Mechanism: Targeting the Human Perimeter

    CloudSEK security researchers noted that The COM’s most effective weapon is social engineering rather than technical exploits.

    The primary infection vector involves human manipulation through vishing crews who impersonate IT support staff, telecom providers, or corporate help desk personnel.

    These operators deceive employees into revealing credentials, approving remote access, or executing system commands that grant attackers entry to corporate networks.

    The technique operates through a simple principle: compromising a person is easier than compromising a device. Attackers use detailed victim profiling gathered through open-source intelligence and breached data, enabling highly targeted campaigns.

    Once inside networks, attackers leverage legitimate tools like Remote Desktop Protocol and cloud services to move laterally, avoiding detection by blending with regular administrative traffic.

    This approach has proven devastatingly effective against even organizations with advanced security infrastructure, making human-focused security measures increasingly critical for enterprise defense strategies moving forward.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post English-Speaking Cybercriminal Ecosystem ‘The COM’ Drives a Wide Spectrum of Cyberattacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Law enforcement agencies disrupted a vast network of cybercrime tools between November 10 and 14, 2025, coordinated from Europol’s headquarters in The Hague, Netherlands.

    Dubbed the latest phase of Operation Endgame, the effort targeted three notorious malware families: the infostealer Rhadamanthys, the Remote Access Trojan (RAT) VenomRAT, and the Elysium botnet.

    These stealers and botnets have contributed to ransomware attacks and data theft globally, impacting hundreds of thousands of victims and stealing millions in credentials and cryptocurrency.

    Rhadamanthys stealer
    Rhadamanthys stealer

    The operation, led by Europol and Eurojust, united authorities from 11 countries, including Australia, Belgium, Canada, Denmark, France, Germany, Greece, Lithuania, the Netherlands, the United Kingdom, and the United States.

    Private sector partners played a pivotal role, with contributions from cybersecurity firms like Cryptolaemus, Shadowserver, SpyCloud, Proofpoint, CrowdStrike, Lumen, Abuse.ch, Have I Been Pwned, Spamhaus, DIVD, and Bitdefender. Their expertise in threat intelligence, sinkholing, and malware analysis helped identify and neutralize the infrastructure.

    The dismantled network comprised hundreds of thousands of compromised computers holding millions of stolen credentials.

    Rhadamanthys alone granted its operators access to over 100,000 cryptocurrency wallets, potentially valued at millions of euros.

    Many victims remain unaware of infections, underscoring the stealthy nature of these threats. Infostealers quietly harvest login details, while RATs like VenomRAT enable remote control for espionage or ransomware deployment, and botnets like Elysium amplify distributed denial-of-service (DDoS) attacks and spam campaigns.

    Web page seized
    Web page seized

    Europol’s command post in The Hague buzzed with over 100 officers from participating nations, facilitating real-time intelligence sharing on seized servers, suspects, and data transfers. Eurojust supported legal tools like European Arrest Warrants and Investigation Orders.

    Operation Endgame, focused on ransomware enablers since its inception, signals no end to the fight. Authorities urge individuals to check for infections using resources like politie.nl/checkyourhack and haveibeenpwned.com.

    As cybercriminals adapt, this phase highlights the power of global collaboration in disrupting underground economies. Victims and researchers alike should monitor for residual threats, as the next move in this cyber chess game looms.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Operation Endgame – 1,000+ Servers Used by Rhadamanthys, VenomRAT, and Elysium Dismantled appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Between November 10 and 14, 2025, law enforcement agencies executed one of the most significant coordinated operations against cybercriminals in recent history. Operation Endgame, coordinated from Europol’s headquarters in The Hague, successfully dismantled three major threats to global cybersecurity: the infamous Rhadamanthys infostealer, the VenomRAT remote access trojan, and the Elysium botnet. This remarkable international […]

    The post Operation Endgame: Authorities Takedown 1,025 Servers Linked to Rhadamanthys, VenomRAT, and Elysium appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Behind every click, there’s a risk waiting to be tested. A simple ad, email, or link can now hide something dangerous. Hackers are getting smarter, using new tools to sneak past filters and turn trusted systems against us. But security teams are fighting back. They’re building faster defenses, better ways to spot attacks, and stronger systems to keep people safe. It’s a constant race — every

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Elastic has released a security advisory addressing an origin validation error in Kibana that could expose systems to Server-Side Request Forgery (SSRF) attacks. The vulnerability, tracked as CVE-2025-37734, affects multiple versions of the popular data visualization and exploration platform and has prompted immediate patching across all affected deployments. CVE ID Vulnerability Affected Versions CVSS Score Fixed Versions […]

    The post Kibana Vulnerabilities Expose Systems to SSRF and XSS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new ClickFix campaign is tricking users with a fake Windows update that runs in their browser. Called “Fake OS Update,” this scam takes advantage of people’s trust in the familiar blue screen of death (BSOD) from Microsoft.

    It delivers malware and shows how social engineering can be more effective than technical tricks.

    Cybersecurity researcher Daniel B., who works at the UK’s National Health Service, first spotted the attack last month while probing malicious online threats.

    As detailed in his LinkedIn post, the scam operates primarily on the domain groupewadesecurity[.]com. Simply visiting the site often via malvertising or spam links triggers a full-screen overlay mimicking a Windows OS crash or update prompt.

    The fake BSOD, complete with error codes and progress bars, appears on both PCs and smartphones, creating panic and urgency.

    What sets this apart from earlier ClickFix variants is its multi-step deception. After the initial screen, victims are instructed to perform three “manual fixes” using keyboard shortcuts: pressing Ctrl+Alt+Del to “restart services,” entering a bogus command in a simulated command prompt, and finally downloading a “recovery tool” from a linked malicious site.

    In reality, these actions grant attackers remote access or install infostealers and ransomware loaders. The campaign’s sophistication lies in its cross-device compatibility and avoidance of immediate redirects, making it harder for browser protections to flag.

    ClickFix attacks, which trick users into “fixing” non-existent issues via clicks, have plagued browsers since 2020. But as attackers refine their tactics employing hyper-realistic graphics, localized languages, and timely lures tied to real events like Patch Tuesday, this variant proves especially insidious.

    Indicators of compromise, including URLs and payloads, are cataloged on platforms such as ThreatFox and urlscan.io under the “Fake OS Update” tag, aiding threat hunters in tracking the spread.

    Experts warn that such campaigns highlight a critical gap: while endpoint detection tools catch many automated threats, human error remains the weakest link.

    “User vigilance and regular cybersecurity training are as vital as firewalls,” notes a spokesperson for the UK’s National Cyber Security Centre (NCSC).

    Organizations should prioritize awareness programs that simulate these scenarios, alongside browser extensions such as uBlock Origin to block suspicious domains.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post New ClickFix Attack Tricks Users with ‘Fake OS Update’ to Execute Malicious Commands appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have uncovered a sophisticated supply chain attack disguised as a legitimate cryptocurrency wallet. Socket’s Threat Research Team discovered a malicious Chrome extension called “Safery: Ethereum Wallet,” published on the Chrome Web Store on November 12, 2024, that employs an ingenious technique to steal user seed phrases through hidden blockchain transactions. The extension, identified […]

    The post Malicious Chrome Extension Grants Full Control Over Ethereum Wallet appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Dell Technologies has disclosed a critical security vulnerability in its Data Lakehouse platform that could allow remote attackers to escalate privileges and compromise system integrity.

    The flaw, tracked as CVE-2025-46608, affects all versions before 1.6.0.0 and has been assigned a CVSS score of 9.1, placing it in the critical severity category.

    The security flaw stems from an improper access control vulnerability in Dell Data Lakehouse. A highly privileged attacker with remote access could exploit this weakness to elevate their privileges beyond their authorized level.

    Dell Data Lakehouse Vulnerability

    The vulnerability is particularly concerning because it requires low attack complexity and no user interaction. Making exploitation relatively straightforward for attackers who have already gained high-level access to the system.

    The vulnerability can be exploited over the network, with a broader scope, potentially affecting resources beyond the vulnerable component.

    CVE IDAffected productCVSS ScoreAffected VersionsPatched Version
    CVE-2025-46608Dell Data Lakehouse9.1 (Critical)Prior to 1.6.0.01.6.0.0 or later

    Successful exploitation could result in high impact on the security, integrity, and availability of the system.

    Dell Technologies has classified this vulnerability as critical due to its potential to grant unauthorized access with elevated privileges, leading to complete compromise of system integrity and customer data.

    Attackers exploiting this flaw could access sensitive information, modify critical data, or interrupt system operations.

    Dell has released version 1.6.0.0 of Data Lakehouse to address this vulnerability. The company strongly recommends that all customers upgrade to the latest version immediately to mitigate the risk.

    Users running affected versions should contact Dell Technical Support and reference advisory DSA-2025-375 for assistance with the upgrade process.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Critical Dell Data Lakehouse Vulnerability Let Remote Attacker Escalate Privileges appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitLab has released critical security patches addressing nine vulnerabilities across Community Edition (CE) and Enterprise Edition (EE), including a concerning prompt injection flaw in GitLab Duo that could expose sensitive information from confidential issues. The company is urging all self-managed installations to upgrade immediately to versions 18.5.2, 18.4.4, or 18.3.6. The most alarming vulnerability is CVE-2025-6945, a prompt […]

    The post GitLab Vulnerabilities Expose Users to Prompt Injection Attacks and Data Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Businesses today are dealing with faster, stealthier email threats that look routine yet unleash aggressively malicious scripts the moment a user engages. This is especially true when the lure arrives as an attachment that resembles a harmless image file. 

    The perception gap is exactly what attackers exploit with SVG phishing, whereby what appears to be an SVG file is actually XML text that can carry links, redirects, and scripted behaviors.

    These can masquerade as a logo, button, or invoice graphic and then hand the victim off to a credential harvester or session hijacking flow, which is exactly the pattern that researchers from ANY.RUN reported recently.

    Industry benchmarks indicate this is not a theoretical edge case. SVG phishing attacks were virtually unknown in 2024 but rose from 0.1% of attacks that year to 4.9% of phishing by the first half of 2025, according to Hoxhunt.

    The tide seems to have peaked in March this year at 15%, underscoring the growing risk of these lures as adversaries look for formats that slip past legacy attachment filtering policies.

    In short, the combination of trusted visual design, attachment-first delivery, and code-capable image files explains why SVG phishing has moved from curiosity to commonplace.

    This is why security teams and decision-makers should tune policy, inspection, and response with this specific vector in mind.

    Why SVG Phishing Is a Problem Now

    An SVG is a vector graphic made of text and XML, which means it can carry links, scripts, and redirects. It behaves more like a tiny web page than a static image.

    Attackers can weaponize this by sending small SVG attachments that render a convincing image yet redirect to a credential harvester or MFA-bypass flow. 

    Phishing campaigns increasingly attach compact SVG files that render brand-faithful prompts such as “view invoice,” “confirm account,” “open statement,” and then hand off to credential theft or session hijacking flows once a user clicks.

    Mail gateways and client apps have historically treated such “images” as low risk, even though the SVG format’s text-based content supports heavy obfuscation.

    SVG phishing is gaining ground not necessarily because users are careless, but because the file type invites misplaced trust, and the tooling around it hasn’t fully caught up.

    Combined with trusted-brand styling and short-lived infrastructure, SVG phishing lures can evade both signature-based inspection and hurried human judgment.

    The first evasion is psychological. Receivers treat “images” as safe and click readily, while brand-faithful visuals lower suspicion. The second is technical.

    Text-based SVGs pack base64 blobs, JavaScript, external references, or data URIs that some tools don’t fully sanitize at the attachment layer.

    The third is operational. Adversaries rotate domains and CDN links inside SVG code, so even when defenders block one path, the lure quickly reroutes.

    These traits help SVG phishing outperform older “macro doc” tactics that have been blunted by hardened defaults in Office and mail clients.

    For instance, like other email providers, Microsoft has responded by retiring SVG rendering in Outlook for Web and Windows, leaving placeholders instead.

    Hardening Your Defenses Against SVG Threats

    Start with policy. If your business does not rely on SVG attachments, block them at the secure email gateway and collaboration perimeter, allowing only PNG/JPG for images. 

    If you must allow SVGs, enforce server-side sanitization and content disarm and reconstruction (CDR) so that any scripts, external references, and event handlers are stripped before delivery.

    Render SVGs in a sandboxed viewer that forbids external calls and JavaScript, and log any attempted outbound requests for threat hunting.

    Tune your mail gateway to parse inside the SVG, not just the wrapper. This enables you to flag data URIs, onload/onmouseover handlers, and suspicious chains. 

    Finally, align clients with updated or more secure defaults on inline SVG behavior to eliminate opportunistic render-path attacks.

    Fighting Back with People and Processes

    Security awareness should treat “SVG” as an active file type, not a safe picture. Thus, coach employees to report unexpected graphics-only attachments from vendors or SaaS brands.

    Since the median time-to-fall is under a minute, auto-quarantine workflows and one-click reporting buttons are essential to pull copies from other inboxes before widespread clicks. 

    Simulated exercises should include SVG phishing scenarios that mimic real-world brand design, short subjects, and call-to-action buttons.

    Pair this with tabletop drills where incident response teams practice extracting malicious SVGs, enumerating external references, and tracing credential theft across CASB and IdP logs. 

    In terms of incident response and metrics, track hit rates for attachment-only campaigns separately from link-only phishes to surface gaps hidden by blended reporting.

    Review supplier communications that commonly include imagery, such as marketing assets, invoices, and shipping labels. These can be ready-made covers for SVG phishing lures if your allow-list is loose. 

    Isolate the mailbox and capture the original attachment, then use a safe text viewer to inspect for external href values, base64 blobs, and event handlers.

    Block-listed domains should be added to mail and web filters immediately, and identity teams should search IDP logs for fresh sessions and 2FA prompts around the lure’s delivery window. 

    If credentials were entered, force resets and revoke refresh tokens, then monitor for token replay and OAuth consent grants abused during the phish.

    Close the loop by updating SEG rules for the exact obfuscation method so that the next variant is caught sooner.

    The Bottom Line

    SVG phishing is not a fad. It is part of a wider pivot to file-centric social engineering that exploits speed and ambiguity.

    As platforms remove easy render paths, like Outlook dropping inline SVGs, the advantage tilts back to defenders who combine policy, inspection, and user education. 

    But attackers will continue evolving, so any improvements to the process should be treated as ongoing capacity building, not a one-off block-list tweak.

    Keep SVG phishing on your radar during quarterly control reviews, and validate with live exercises so that your technology and human defenses can neutralize the lure before it can do any damage.

    Again, if you do not need SVG attachments, block them. If you do, sanitize and sandbox them. Don’t treat images as safe.

    SVG phishing thrives on speed and misplaced trust, but you can flip the script with simple policy, deeper inspection, and practiced response.

    The post How Attackers Turn SVG Files Into Phishing Lures appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶