Skip to content

ADMIN.FOUNDATION

  • Vulnerability in Perplexity’s Comet Browser Screenshot Feature Allows Malicious Prompt Injection

    ·

    AI, cyber security, Cyber Security News

    Researchers have discovered a critical security vulnerability in Perplexity’s Comet AI browser that allows attackers to inject malicious commands through hidden text in screenshots. The vulnerability, disclosed on October 21, 2025, demonstrates how AI-powered browsers can become dangerous gateways for attackers to access users’ sensitive accounts like banking and email services. How Attackers Hide Dangerous […]

    The post Vulnerability in Perplexity’s Comet Browser Screenshot Feature Allows Malicious Prompt Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Global SMS Phishing Campaign Traced to China Targets Users Worldwide

    ·

    cyber security, Cyber Security News, Phishing, SMS Phishing

    A sophisticated and widespread smishing campaign originating from China has emerged as a significant threat to users worldwide. Researchers have attributed the ongoing attack to a group known as the Smishing Triad, which has demonstrated unprecedented scale and complexity through a decentralized infrastructure capable of registering and churning thousands of malicious domains daily. Since January […]

    The post Global SMS Phishing Campaign Traced to China Targets Users Worldwide appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Exploiting Adobe Magento RCE Vulnerability Exploited in the Wild – 3 in 5 Stores Vulnerable

    ·

    cyber security, Cyber Security News, vulnerability, Vulnerability News

    Hackers have begun actively targeting a critical remote code execution flaw in Adobe’s Magento e-commerce platform, putting thousands of online stores at immediate risk just six weeks after Adobe issued an emergency patch.

    Known as SessionReaper and tracked as CVE-2025-54236, the vulnerability allows unauthenticated attackers to hijack customer sessions and potentially execute arbitrary code, leading to data breaches and store compromises.

    Security firm Sansec reported blocking over 250 exploitation attempts on October 22, 2025, with attacks originating from multiple IP addresses worldwide.​

    Adobe Magento RCE Vulnerability Exploited

    SessionReaper stems from an improper input validation issue in Adobe Commerce and Magento Open Source versions, including 2.4.9-alpha2 and earlier, affecting the Commerce REST API.

    Discovered by independent researcher Blaklis and patched by Adobe on September 9, 2025, the flaw enables attackers to upload malicious files disguised as session data via the /customer/address_file/upload endpoint, bypassing authentication.

    This nested deserialization bug can lead to full remote code execution, especially on systems using file-based session storage, though Redis or database-backed setups may also be vulnerable.​

    A detailed technical breakdown released by Assetnote researchers on October 21, 2025, included proof-of-concept code demonstrating the exploit, effectively closing the window for undetected patching.

    Sansec’s forensics team likened SessionReaper’s severity rating of 9.1 on the CVSS scale to past Magento threats like CosmicSting (CVE-2024-34102) in 2024, TrojanOrder (CVE-2022-24086) in 2022, and the infamous Shoplift vulnerability in 2015, each resulting in thousands of hacked stores shortly after disclosure.

    With exploit details now public, experts predict widespread automated attacks within 48 hours, fueled by scanning tools that thrive on such high-impact flaws, Sansec said.

    Despite Adobe’s urgent advisory and hotfix availability, adoption remains alarmingly low. Sansec’s monitoring shows only 38% of Magento stores have applied protections six weeks post-patch, leaving 62% or three in five exposed to this critical threat.

    Initial reports from September indicated even fewer than one in three stores were secured, highlighting persistent delays in e-commerce security updates that expose sensitive customer data like payment details to theft.

    This vulnerability’s broad impact on global online retailers underscores the urgency, as unpatched sites become prime targets for credential stuffing, malware injection, and supply chain disruptions.​

    Mitigations

    Store owners must act swiftly to mitigate risks. Adobe recommends deploying the official patch from their repository or upgrading to the latest secure release, with detailed instructions in their developer guide.

    For immediate defense without patching, activating a web application firewall (WAF) is crucial; Sansec Shield, for instance, has blocked SessionReaper since discovery and offers a free month via coupon code SESSIONREAPER.

    Observed exploits trace back to IPs such as 34.227.25.4, 44.212.43.34, 54.205.171.35, 155.117.84.134, and 159.89.12.166, delivering payloads that probe server configurations or install backdoors.

    Sansec continues real-time tracking, urging merchants to monitor for similar activity and follow their live attack dashboard for updates.

    As exploitation ramps up, the e-commerce sector faces a potential wave of breaches reminiscent of historical Magento incidents.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Exploiting Adobe Magento RCE Vulnerability Exploited in the Wild – 3 in 5 Stores Vulnerable appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals Impersonate Aid Agencies to Lure Victims with Fake Financial Offers

    ·

    cyber security, Cyber Security News

    Scammers have intensified their efforts to defraud vulnerable populations through sophisticated impersonation schemes and fraudulent financial aid offers, according to recent intelligence monitoring and law enforcement findings. The threat landscape reveals a coordinated, international ecosystem of fraud operations targeting individuals across multiple social media platforms, with particular focus on older adults who represent a significant […]

    The post Cybercriminals Impersonate Aid Agencies to Lure Victims with Fake Financial Offers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Stealthy Malware Leveraging Variable Functions and Cookies for Evasion

    ·

    cyber security, Cyber Security News, Malware

    Cybersecurity researchers at Wordfence Threat Intelligence and their Care and Response teams have observed a persistent trend in new malware that leverages heavy obfuscation techniques to evade detection. While some malware attempts to blend in as legitimate files, the more common strategy involves sophisticated obfuscation through variable functions and cookie manipulation. This article explores this […]

    The post Stealthy Malware Leveraging Variable Functions and Cookies for Evasion appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Active Exploits Target Magento and Adobe Commerce RCE, Attackers Inject Webshells

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Unauthenticated attackers are actively exploiting a critical vulnerability affecting Adobe Commerce and Magento platforms worldwide. The flaw, tracked as CVE-2025-54236 and dubbed SessionReaper, enables remote code execution and customer account takeover on thousands of online stores. CVE ID Vulnerability Name Affected Products Type CVSS 3.1 CVE-2025-54236 SessionReaper Adobe Commerce & Magento (all versions) Unauthenticated RCE, Account […]

    The post Active Exploits Target Magento and Adobe Commerce RCE, Attackers Inject Webshells appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Secure AI at Scale and Speed — Learn the Framework in this Free Webinar

    ·

    AI is everywhere—and your company wants in. Faster products, smarter systems, fewer bottlenecks. But if you’re in security, that excitement often comes with a sinking feeling. Because while everyone else is racing ahead, you’re left trying to manage a growing web of AI agents you didn’t create, can’t fully see, and weren’t designed to control. Join our upcoming webinar and learn how to make AI

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Jira Vulnerability Lets Attackers Alter Files Accessible to the Jira JVM Process

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Atlassian has disclosed a critical path traversal vulnerability affecting Jira Software Data Center and Server that could allow authenticated attackers to modify files accessible to the Jira Java Virtual Machine (JVM) process. The vulnerability, tracked as CVE-2025-22167, carries a high severity rating with a CVSS score of 8.7 and affects multiple product versions dating back […]

    The post Jira Vulnerability Lets Attackers Alter Files Accessible to the Jira JVM Process appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • TransparentTribe Targets Linux Systems in Indian Military to Deploy DeskRAT

    ·

    cyber security, Cyber Security News, Linux

    In July 2025, cybersecurity firm CYFIRMA uncovered an active phishing campaign targeting Linux-based operating systems used by Indian government and military organisations. This operation, attributed to TransparentTribe (also known as APT36 or Operation C-Major), is the latest in a series of ongoing cyber espionage campaigns supporting Pakistan’s strategic interests. TransparentTribe, a Pakistani-nexus threat group active […]

    The post TransparentTribe Targets Linux Systems in Indian Military to Deploy DeskRAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CISA Warns of Motex LANSCOPE Endpoint Manager Vulnerability Exploited in Attacks

    ·

    cyber security, Cyber Security News, vulnerability, Vulnerability News

    CISA has issued a critical alert regarding a severe vulnerability in Motex LANSCOPE Endpoint Manager, a popular tool for managing IT assets across networks.

    Dubbed an improper verification of the source of a communication channel flaw, this issue allows attackers to execute arbitrary code simply by sending specially crafted packets.

    The vulnerability, tracked under CVE-2025-61932, has already been exploited in the wild, prompting CISA to add it to its Known Exploited Vulnerabilities (KEV) catalog.

    Organizations using the software are urged to act immediately to prevent potential breaches that could lead to data theft, ransomware deployment, or full system compromise.

    This warning comes amid a surge in endpoint management exploits, as cybercriminals increasingly target administrative tools to gain deeper network access.

    Motex LANSCOPE, developed by Japanese firm Motex, helps IT teams monitor and control devices remotely, making it a prime target for attackers seeking to pivot from individual endpoints to entire infrastructures.

    While specific details on the exploitation campaigns remain limited, security researchers note that the flaw’s remote code execution (RCE) capability makes it particularly dangerous, especially in unpatched environments.

    At its core, the vulnerability stems from inadequate checks on incoming communication packets, allowing malicious actors to impersonate legitimate sources.

    According to the CWE-940 definition, this improper verification can bypass authentication mechanisms, enabling unauthenticated remote access.

    Attackers need only craft packets that mimic trusted traffic, potentially leading to the deployment of malware or backdoors without user interaction.

    CISA’s alert highlights that while the vulnerability’s use in ransomware campaigns is currently unknown, its RCE nature aligns with tactics seen in recent high-profile attacks, such as those targeting supply chain weaknesses.

    Endpoint managers like LANSCOPE are often deployed in enterprise settings, including sectors like finance and healthcare, where downtime or data exposure could have cascading effects.

    Early indicators suggest exploitation may involve phishing-laced packets or direct network probes, underscoring the need for robust network segmentation.

    Mitigations

    To counter the threat, CISA recommends applying vendor-provided patches or mitigations without delay. Motex has reportedly released updates addressing the issue, but organizations should verify compatibility before deployment.

    For cloud-integrated instances, adherence to Binding Operational Directive (BOD) 22-01 is essential, emphasizing vulnerability management in federal systems guidance that extends valuably to private entities.

    If patches prove unavailable or ineffective, discontinuing use of the product is advised as a last resort. This incident reflects ongoing challenges in endpoint security, where legacy tools often lag behind evolving threats.

    As CISA continues to monitor developments, experts call for proactive measures like regular vulnerability scanning and zero-trust architectures.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CISA Warns of Motex LANSCOPE Endpoint Manager Vulnerability Exploited in Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 792 793 794 795 796 … 1,055
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence