• The notorious cybercrime forum BreachForums has resurfaced online, this time on a clearnet domain accessible without specialized tools like Tor.

    The platform, long a hub for data leaks, hacking tools, and illicit trades, went dark earlier this year following a series of law enforcement takedowns and internal disruptions.

    Now, just months later, it’s operational again, drawing both excitement from underground actors and suspicion from security experts.

    The forum’s return was announced by its administrator, known only as “koko,” who claimed in a pinned post that core functionality has been fully restored from a recent backup.

    Users can once again browse sections dedicated to stolen credentials, ransomware discussions, and zero-day exploits. Koko emphasized that the site is “stronger than ever,” with enhanced anonymity features to evade detection.

    However, the revival comes amid whispers of compromise, specifically, the old escrow system, which handled cryptocurrency transactions for illicit deals, was hacked, leading to significant losses for vendors and buyers alike.

    BreachForums Is Back Again?

    BreachForums isn’t starting over entirely; koko detailed that the team is rebuilding the escrow service from scratch to address the vulnerabilities exposed in the breach.

    “We’ve learned from the mistakes,” Koko wrote, promising improved encryption and multi-signature wallets to prevent future thefts.

    This follows a pattern for the forum, which has bounced back multiple times since its inception in 2022 as a successor to the shuttered RaidForums.

    Past iterations have been hit by FBI seizures and arrests, including the 2023 takedown of its founder, Conor Fitzpatrick, aka “Pompompurin.”

    Yet, the clearnet pivot marks a bold shift. By ditching the dark web, BreachForums aims to attract a broader audience, including less tech-savvy criminals who avoid Tor’s complexities.

    Despite the optimism from koko, skepticism abounds in the cyber underground. Many forum veterans suspect this iteration could be a honeypot operated by law enforcement.

    “It’s too clean, too quick,” one anonymous poster commented, echoing concerns that U.S. agencies like the FBI or Secret Service might be monitoring activity to build cases.

    Cybersecurity firms such as Recorded Future have issued warnings, noting that clearnet domains are easier for authorities to track via IP logs and hosting providers.

    Experts urge caution for anyone encountering the site. “BreachForums has always been a double-edged sword, valuable intel for researchers, but a magnet for real threats,” said John Doe, a threat analyst at a leading security firm.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Infamous Cybercriminal Forum BreachForums Is Back Again With a New Clear Net Domain appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Dell Technologies has disclosed three critical vulnerabilities in its Storage Manager software that could allow attackers to bypass authentication, disclose sensitive information, and gain unauthorized access to systems.

    Announced on October 24, 2025, these flaws affect versions of Dell Storage Manager up to 20.1.21 and pose significant risks to organizations relying on the tool for managing storage arrays.

    With CVSS scores ranging from 6.5 to 9.8, the vulnerabilities highlight ongoing challenges in securing management interfaces, potentially enabling remote exploitation without user interaction.

    The most severe issue, CVE-2025-43995, carries a CVSS base score of 9.8, classifying it as critical. This improper authentication flaw resides in the DSM Data Collector component.

    An unauthenticated attacker with remote access can exploit exposed APIs in the ApiProxy.war file within DataCollectorEar.ear by crafting a special SessionKey and UserId.

    These credentials leverage special users created in the Compellent Services API for internal purposes, allowing attackers to sidestep protection mechanisms entirely.

    Exploitation could lead to full system compromise, including high confidentiality, integrity, and availability impacts, as detailed in its vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

    High-Risk Authentication Gaps Exposed

    Complementing this is CVE-2025-43994, scored at 8.6, which involves a missing authentication check for a critical function.

    Again targeting DSM 20.1.21, this vulnerability enables unauthenticated remote attackers to trigger information disclosure while also disrupting service availability.

    The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H indicates low complexity and no privileges needed, making it a prime target for opportunistic hackers.

    Attackers could extract configuration data or operational details, paving the way for broader network intrusions.

    A third vulnerability, CVE-2025-46425, affects version 20.1.20 and introduces an improper restriction of XML external entity references, earning a 6.5 score.

    While requiring low privileges, a remote attacker could exploit this to read sensitive files, leading to unauthorized access without impacting integrity or availability directly (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). This XXE flaw underscores the dangers of parsing untrusted XML inputs in storage management tools.

    CVE IDDescriptionCVSS Base ScoreVector String
    CVE-2025-43995Improper Authentication (Bypass)9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    CVE-2025-43994Missing Authentication (Disclosure)8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
    CVE-2025-46425XXE Reference Vulnerability6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

    Dell Storage Manager Vulnerabilities

    Dell urges customers to evaluate risks using both base and environmental CVSS scores, emphasizing immediate updates.

    Affected products include Dell Storage Manager versions prior to 2020 R1.21; remediation is available in version 2020 R1.22 or later, downloadable from Dell’s support site for Storage SC2000 drivers.

    The advisory saw a quick revision on the same day to refine remediation guidance. Credit goes to Tenable for discovering CVE-2025-43994 and CVE-2025-43995, and to independent researcher Ahmed Y.

    Elmogy for CVE-2025-46425. As enterprises increasingly depend on storage solutions for data centers, these disclosures serve as a reminder to prioritize authentication hardening and regular vulnerability scanning.

    No active exploitation has been reported yet, but the ease of remote access makes swift action essential to prevent potential breaches.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Critical Dell Storage Manager Vulnerabilities Let Attackers Compromise System appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers at Datadog have uncovered a sophisticated phishing technique that weaponizes Microsoft Copilot Studio to conduct OAuth token theft attacks. Dubbed “CoPhish,” this attack method leverages the legitimate appearance of Microsoft domains to trick users into consenting to malicious applications. The attack exploits a fundamental trust issue: users naturally trust URLs hosted on official […]

    The post Critical CoPhish Exploit Uses Copilot Studio to Hijack OAuth Tokens appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers are actively exploiting a critical flaw in Microsoft’s Windows Server Update Services (WSUS), with security researchers reporting widespread attempts in the wild.

    The vulnerability, tracked as CVE-2025-59287, allows remote code execution on unpatched WSUS servers, potentially granting attackers full control over enterprise networks.

    As of October 27, 2025, firms monitoring global scan data have identified at least 2,800 exposed WSUS instances online, scanned via ports 8530 and 8531, though not all may be vulnerable.

    The issue stems from a deserialization flaw in WSUS’s update approval process, first disclosed earlier this month. Microsoft rated it as critical with a CVSS 3.1 score of 9.8, highlighting its ease of exploitation without authentication.

    A proof-of-concept (POC) exploit surfaced on underground forums shortly after patching guidance was released on October 15, fueling rapid attacks.

    “We’re seeing exploitation attempts spike since the POC dropped,” said a spokesperson for cybersecurity firm ShadowPeak, which began fingerprinting WSUS deployments last week.

    Their scans on October 25 revealed the 2,800 instances, primarily in North America and Europe, underscoring the vulnerability’s reach in corporate environments.

    Exploitation Tactics And Real-World Impact

    Attackers are leveraging the POC to chain the flaw with lateral movement techniques, targeting WSUS servers that manage patch deployments across Windows fleets.

    Once compromised, hackers can deploy malicious updates, exfiltrate sensitive data, or install persistent backdoors.

    Early indicators include anomalous traffic to WSUS endpoints and unusual update approvals logged in the event viewer IDs 10016 and 20005.

    A notable incident involved a mid-sized U.S. financial firm, where intruders used the vulnerability to access internal Active Directory, leading to a brief outage on October 23.

    While Microsoft has urged immediate patching via its October 2025 security bulletin, adoption lags, with only 40% of scanned instances showing signs of mitigation, per ShadowPeak’s telemetry.

    This delay amplifies risks for organizations relying on WSUS for automated updates, especially in hybrid cloud setups where servers expose HTTP/HTTPS ports to the internet.

    CVE IDAffected ProductCVSS 3.1 ScoreDescriptionImpact
    CVE-2025-59287Microsoft WSUS (versions < 10.0.20348.2000)9.8 (Critical)Deserialization vulnerability in update handlingRemote code execution; network compromise

    Experts warn that unmonitored WSUS setups, often overlooked in legacy infrastructure, are prime targets for ransomware groups like LockBit 3.0, which have referenced the POC in their leak sites.

    Mitigations

    To counter the threat, Microsoft recommends applying the latest cumulative updates and restricting WSUS port access via firewalls, ideally, limiting it to internal VPNs.

    Tools like Nessus or custom scripts can fingerprint exposures, while endpoint detection platforms should flag deserialization anomalies.

    “This isn’t just a patch issue; it’s a reminder to audit update servers regularly,” advised cybersecurity analyst Elena Vasquez.

    As exploitation evolves, the 2,800 exposed instances signal a ticking clock for IT teams. With no end to the scans in sight, the vulnerability could drive a wave of breaches if patching doesn’t accelerate.

    Organizations should prioritize WSUS hardening to safeguard their update ecosystems against this pervasive peril.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Exploiting Microsoft WSUS Vulnerability In The Wild – 2800 Instances Exposed Online appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Law enforcement agencies from the United States and France have seized the onion leak website operated by the notorious Scattered LAPSUS$ Hunters collective, displaying a prominent seizure notice featuring logos from the FBI, Department of Justice, and international partners.

    This coordinated action, executed around October 9, 2025, targeted the BreachForums infrastructure, which the group had repurposed as a data extortion portal following a massive breach of Salesforce customer databases.

    The takedown disrupts the group’s ability to threaten and leak stolen data publicly, though experts warn that such actors often pivot to alternative channels like Telegram.

    Scattered LAPSUS$ Hunters

    Scattered LAPSUS$ Hunters emerged in August 2025 as an alliance of infamous hacking groups, including Scattered Spider, LAPSUS$, and ShinyHunters, often referred to as the “Trinity of Chaos” within the cybercrime underworld known as The Com.

    This supergroup quickly escalated its activities by launching social engineering attacks on Salesforce tenants, claiming to have stolen over one billion records from high-profile organizations such as Adidas, Cisco, McDonald’s, and Qantas Airways.

    Their campaign blended data theft with extortion demands, using BreachForums, previously a hacking bazaar shut down in 2023, as a clearnet and Tor-based leak site to pressure victims into paying ransoms.

    By early October, the group had listed dozens of compromised entities, setting a deadline of October 10, 2025, for payments to avoid data dumps.

    The seizure involved the U.S. Department of Justice, FBI, France’s Central Brigade of Cybercrime (BL2C), and the Paris Prosecutor’s Office, who took control of BreachForums’ domains and backend servers, including database backups dating back to 2023.

    Visitors to the site, both on the clearnet (breachforums.hn) and onion versions, encountered an animated banner confirming the infrastructure’s transfer to federal hands, mirroring past takedowns like RaidForums in 2022.

    Although the Tor site was briefly restored, the operation prevented immediate large-scale leaks, with the group defiantly posting on Telegram that “seizing a domain does not really affect our operations.”

    In response, Scattered LAPSUS$ Hunters leaked data from six companies across aviation, energy, and retail sectors on October 10, including personal details like names, emails, and phone numbers, before declaring no further releases.

    Despite the disruption, the collective announced a temporary dissolution on October 11, 2025, halting activities until 2026 to evade heightened law enforcement scrutiny while teasing an Extortion-as-a-Service (EaaS) model and potential targets like the FBI and NSA.

    Cybersecurity firms note that domain seizures rarely end such groups’ operations entirely, as they maintain Telegram channels and could relaunch mirror sites swiftly.

    Organizations are urged to monitor for renewed activity, enhance Salesforce security, and review for indicators of compromise from social engineering tactics.

    This event underscores the persistent challenge of combating loosely organized cybercrime syndicates, with experts predicting the group’s return in a more covert form.

    As the dust settles, the incident highlights international cooperation’s role in curbing digital extortion, though vigilance remains essential in the evolving threat landscape.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Scattered LAPSUS$ Hunters Onion Leak Website Taken Down By Law-enforcement Agencies appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The newly released OpenAI Atlas web browser has been found to be susceptible to a prompt injection attack where its omnibox can be jailbroken by disguising a malicious prompt as a seemingly harmless URL to visit. “The omnibox (combined address/search bar) interprets input either as a URL to navigate to, or as a natural-language command to the agent,” NeuralTrust said in a report published Friday

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft is preparing to introduce a groundbreaking feature in Teams that will revolutionise how hybrid workers manage their presence information. The new capability will automatically identify and update users’ work locations by detecting their connection to organisational Wi-Fi networks, eliminating the need for manual status updates. Scheduled for deployment in December 2025, this opt-in functionality […]

    The post Microsoft Adds Wi-Fi-Based Work Location Auto-Detection to Teams appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Famous Chollima, a DPRK-aligned threat group, has evolved its arsenal, with BeaverTail and OtterCookie increasingly merging functionalities to steal credentials and cryptocurrency via deceptive job offers. A recent campaign involved a trojanized Node.js application distributed through a malicious NPM package, highlighting the group’s adaptation in delivery methods. In the campaign, Famous Chollima notes merged BeaverTail […]

    The post North Korean Chollima Actors Added BeaverTail and OtterCookie to its Arsenal appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical vulnerability affecting more than 706,000 BIND 9 DNS resolvers worldwide has been disclosed with proof-of-concept exploit code now publicly available. The security flaw enables attackers to perform cache poisoning attacks by injecting malicious DNS records into vulnerable resolver caches, potentially redirecting users to attacker-controlled infrastructure. The vulnerability, tracked as CVE-2025-40778, was disclosed by […]

    The post 706,000+ BIND 9 DNS Resolvers Exposed to Cache Poisoning – PoC Released appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers from Team Z3 have withdrawn their planned demonstration of a zero-click remote code execution vulnerability in WhatsApp at the Pwn2Own Ireland 2025 hacking competition, opting instead for private coordinated disclosure to Meta. The high-stakes exploit, which stood to earn a record-breaking $1 million bounty, was one of the most anticipated demonstrations at the […]

    The post WhatsApp 0-Click Exploit Disclosed to Meta at Pwn2Own Security Event appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶