• Zscaler, a leading cloud security company, has acquired SPLX, an innovative AI security pioneer, to enhance its Zero Trust Exchange platform with advanced AI protection capabilities. The acquisition will integrate shift-left AI asset discovery, automated red teaming, and governance features that enable organizations to secure their AI investments throughout the entire lifecycle from development to […]

    The post Zscaler Acquires SPLX to Strengthen AI-Powered Zero Trust Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Zscaler, a leading cloud security company, has announced the acquisition of SPLX, an innovative AI security firm, to enhance its Zero Trust Exchange platform with advanced artificial intelligence protection capabilities.

    The acquisition aims to help organizations secure their AI investments throughout the entire development and deployment lifecycle.

    The integration of SPLX’s technology into Zscaler’s platform will enable organizations to shift left with AI asset discovery, automate red teaming, and implement robust governance tools.

    Zscaler emphasized that while AI creates tremendous value, its potential can only be fully realized when properly secured.

    Comprehensive AI Security Development

    By combining SPLX’s advanced technology with Zscaler’s Zero Trust Exchange intelligence and native data protection, the company will secure the complete AI lifecycle on a single unified platform.

    With AI infrastructure investments projected to exceed $250 billion by the end of 2025, companies are confronting a rapidly expanding attack surface and increasing shadow AI sprawl.

    Continuously evolving models, agents, and large language models require ongoing discovery, risk assessment, and remediation to maintain security.

    SPLX brings specialized expertise in AI red teaming, asset management, threat inspection, prompt hardening, and governance to Zscaler’s existing capabilities.

    The enhanced platform will feature AI asset discovery that extends beyond public generative AI applications to include models, workflows, code repositories, and Model Context Protocol servers in both public and private deployments.

    The solution includes automated AI red teaming with over 5,000 purpose-built attack simulations designed to identify risks and vulnerabilities from development through production, offering real-time remediation.

    Additionally, the platform expands Zscaler’s current AI Runtime Guardrails to protect sensitive data and block malicious attacks between AI applications and large language models, including agentic workflows.

    SPLX expressed excitement about joining forces with Zscaler to address the vast attack surface created by rapidly expanding AI infrastructure investments.

    The partnership will deliver SPLX’s innovation through one of the world’s most trusted security platforms, securing AI innovation at the pace organizations are adopting it.

    The acquisition strengthens Zscaler’s position as a trusted partner for organizations seeking to securely adopt AI technologies.

    With comprehensive AI governance and compliance support, the enhanced platform enables organizations to shift from reactive defense to proactive protection of their valuable AI investments while meeting regulatory requirements and governance frameworks.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Zscaler Acquires Enterprise AI Security Firm SPLX to Boost Zero Trust Exchange appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have successfully demonstrated how artificial intelligence can dramatically accelerate malware analysis, decrypting complex XLoader samples in a fraction of the time previously required. XLoader, a sophisticated malware loader with information-stealing capabilities dating back to 2020, has long been considered one of the most challenging malware families to analyze. The malware combines multiple layers […]

    The post XLoader Malware Analyzed Using ChatGPT’s AI, Breaks RC4 Encryption Layers in Hours appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has released an urgent security alert addressing a critical remote code execution vulnerability affecting Android devices worldwide. The vulnerability, tracked as CVE-2025-48593, exists in Android’s System component and requires no user interaction for exploitation, making it an exceptionally dangerous threat. The flaw affects Android versions 13 through 16 and demands immediate attention from device […]

    The post Android Hit by 0-Click RCE Vulnerability in Core System Component appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals have shifted their focus to a highly profitable target: the trucking and logistics industry.

    Over the past several months, a coordinated threat cluster has been actively compromising freight companies through deliberate attack chains designed to facilitate multi-million-dollar cargo theft operations.

    The emergence of this campaign represents a disturbing intersection of physical crime and digital exploitation, where cyber capabilities enable the theft of real goods ranging from electronics to energy beverages.

    The targeting strategy employed by these threat actors demonstrates sophisticated understanding of supply chain operations.

    Rather than attacking specific companies, the criminals operate opportunistically, intercepting communications and compromising accounts across the transportation sector.

    Their primary objective involves gaining unauthorized access to carrier systems, which enables them to bid on legitimate shipments and orchestrate their interception and resale on underground markets or through international channels.

    Proofpoint researchers identified this threat cluster after detecting a significant uptick in campaigns beginning as early as January 2025, with intensified activity accelerating through mid-2025.

    The threat actors deploy multiple remote monitoring and management tools including ScreenConnect, SimpleHelp, PDQ Connect, and N-able, frequently using multiple RMM solutions in combination to establish persistent access and conduct thorough system reconnaissance.

    Infection mechanism

    The infection mechanism primarily relies on social engineering tactics that exploit the inherent trust and urgency present in freight industry communications.

    Attackers compromise load board accounts—online marketplaces facilitating cargo shipment bookings—then post fraudulent listings and deploy malicious URLs when carriers express interest.

    Attack flow (Source – Proofpoint)

    Upon execution, the embedded executables grant adversaries complete system control, allowing them to harvest credentials through tools like WebBrowserPassView and deepen their foothold within target networks.

    What distinguishes this campaign is the seamless integration of legitimate RMM tools into criminal infrastructure.

    Unlike traditional remote access trojans, these commonly used software packages often bypass security detection mechanisms due to signed installer packages and legitimate reputation.

    Threat actors subsequently leverage compromised access to delete existing freight bookings, manipulate dispatcher notifications, and coordinate the theft directly using the victim’s own infrastructure.

    According to the National Insurance Crime Bureau, cargo theft causes approximately $34 billion in annual losses, with projections indicating a 22 percent increase in 2025.

    Proofpoint has documented nearly two dozen campaigns within just two months, suggesting this exploitation trend will continue accelerating as criminals recognize the effectiveness and profitability of cyber-enabled cargo theft operations.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Threat Actors Leverage RMM Tools to Hack Trucking Companies and Steal Cargo Freight appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ransomware is malicious software designed to block access to a computer system or encrypt data until a ransom is paid. This cyberattack is one of the most prevalent and damaging threats in the digital landscape, affecting individuals, businesses, and critical infrastructure worldwide. A ransomware attack typically begins when the malware infiltrates a system through various vectors such as

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors are leveraging weaponized attachments distributed via phishing emails to deliver malware likely targeting the defense sector in Russia and Belarus. According to multiple reports from Cyble and Seqrite Labs, the campaign is designed to deploy a persistent backdoor on compromised hosts that uses OpenSSH in conjunction with a customized Tor hidden service that employs obfs4 for

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Tycoon 2FA phishing kit represents one of the most sophisticated threats targeting enterprise environments today. This Phishing-as-a-Service (PhaaS) platform, which emerged in August 2023, has become a formidable adversary against organizational security, employing advanced evasion techniques and adversary-in-the-middle (AiTM) strategies to bypass multi-factor authentication protections. According to the Any.run malware trends tracker, Tycoon 2FA […]

    The post Anatomy of Tycoon 2FA Phishing: Tactics Targeting M365 and Gmail appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical remote code execution vulnerability affecting XWiki’s SolrSearch component has become the target of widespread exploitation attempts, prompting cybersecurity authorities to add it to their watchlist.

    The flaw allows attackers with minimal guest privileges to execute arbitrary commands on vulnerable systems, posing a significant security risk to organizations using this open-source enterprise wiki platform.

    XWiki, which positions itself as an advanced open-source enterprise wiki and alternative to platforms like Confluence and MediaWiki, released a security advisory and patch in February addressing this severe vulnerability.

    The flaw resides in the SolrSearch component and remarkably requires only guest-level privileges for exploitation, making it accessible to virtually any user with basic system access.

    Vulnerability Discovery and Delayed Exploitation

    The early release of proof-of-concept code alongside the advisory meant that the vulnerability experienced an unusually delayed exploitation timeline. Initial reconnaissance scans appeared in July, but actual exploitation attempts did not surge until recently.

    The exploitation method demonstrates relatively straightforward execution patterns. Attackers send specially crafted GET requests to the vulnerable XWiki endpoint, specifically targeting the SolrSearch RSS media function.

    SANS observed that the malicious requests embed Groovy script commands within asynchronous execution blocks, allowing remote code execution through shell commands.

    Captured exploit attempts reveal attackers attempting to download and execute shell scripts from external servers, specifically from the IP address 74.194.191.52.

    The User-Agent string in these requests contains the email address bang2013@atomicmail.io, potentially belonging to the threat actor.

    Investigation of the hosting server uncovered an unexpected connection to Chicago rap culture, with references to captivity rapper King Lil Jay and rival RondoNumbaNine, both previously associated with opposing gang affiliations.

    The vulnerability presents critical risks because it enables complete system compromise through remote code execution capabilities. Organizations running XWiki installations must prioritize immediate patching to prevent potential breaches.

    The attack requires no user interaction and minimal complexity, making it particularly attractive to opportunistic threat actors conducting mass internet scanning campaigns.

    Security teams should verify their XWiki installations are updated with the February security patch, monitor for suspicious SolrSearch requests, and implement network-level protections to detect exploitation attempts.

    The combination of low attack complexity and widespread scanning activity indicates this vulnerability will remain a high-priority target for malicious actors.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Actively Scanning Internet to Exploit XWiki Remote Code Execution Vulnerability appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has issued a critical security alert for Android devices, highlighting a severe zero-click vulnerability in the system’s core components that could allow attackers to execute malicious code remotely without any user interaction.

    Disclosed in the November 2025 Android Security Bulletin, this flaw affects multiple versions of the Android Open Source Project (AOSP) and underscores the ongoing risks in mobile operating systems.

    As smartphones handle sensitive data like banking credentials and personal communications, such vulnerabilities pose significant threats to millions of users worldwide.

    The primary concern revolves around CVE-2025-48593, a remote code execution (RCE) bug discovered in the System component. This vulnerability requires no additional privileges or user engagement, making it particularly dangerous.

    Attackers could potentially exploit it via crafted network packets or malicious apps distributed through sideloads or third-party stores.

    Google classified it as critical due to its potential for full device compromise, including data theft, ransomware deployment, or even turning the phone into a botnet node. The issue was reported internally via Android bug ID A-374746961 and patched in AOSP versions 13 through 16.

    Vulnerability Breakdown and Affected Systems

    This zero-click exploit stems from improper handling of system-level processes, allowing arbitrary code injection during routine operations like app launches or background syncing.

    Security researchers note that while the exact root cause remains under wraps to prevent widespread abuse, it aligns with past Android flaws where memory corruption enabled privilege escalation.

    Devices running Android 10 and later are eligible for updates, but older versions may remain exposed if manufacturers lag in deployment.

    In addition to the critical RCE, the bulletin addresses CVE-2025-48581, a high-severity elevation of privilege (EoP) vulnerability in the same System component. This could let malicious apps gain unauthorized access to sensitive features, though it requires some initial foothold.

    CVE IDReferencesTypeSeverityUpdated AOSP Versions
    CVE-2025-48593A-374746961RCECritical13, 14, 15, 16
    CVE-2025-48581A-428945391EoPHigh16

    To protect against these threats, users should immediately check for system updates via Settings > System > System Update. Google recommends applying the 2025-11-01 security patch level, which fully resolves these issues for supported devices.

    Manufacturers like Samsung, Pixel, and others must roll out patches promptly, as delays could leave billions vulnerable.

    This bulletin arrives amid rising mobile threats, including state-sponsored spyware targeting activists. No active exploits have been reported yet, but the zero-click nature amplifies risks for high-profile targets.

    Android’s modular update system via Google Play helps, but fragmentation remains a challenge. Experts urge enabling auto-updates and avoiding untrusted apps to stay secure in an increasingly hostile digital landscape.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Critical Android 0-Click Vulnerability in System Component Allows Remote Code Eexecution Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶