• Ukraine

    Trump backs out of peace talks with Putin. The much-anticipated Budapest meeting between President Donald Trump and Russian President Vladimir Putin was put on hold, the New York Times reported Tuesday, after Russian officials said they don’t intend to make a deal to end their war in Ukraine. Trump had been touting the Budapest summit, but canceled it after learning Putin had no interest in his proposal to end the fighting along the current front lines. 

    Russian Foreign Minister Sergei Lavrov’s lie: “A ceasefire now would mean only one thing: A large part of Ukraine would remain under Nazi rule,” Lavrov said after a preliminary phone call with Secretary of State Marco Rubio, repeating Russia’s false assertion that they invaded Ukraine to free it from fascism.

    Still a chance? Hungarian Prime Minister Viktor Orban is still making plans to hold the summit in Budapest eventually, Reuters reported Tuesday.

    “Weasel out”: Ukrainian President Volodymyr Zelenskyy took to X to call out Russia for dipping out of negotiations as soon as Trump made clear he wouldn’t be sending long-range Tomahawk missiles to Ukraine. “This signals that deep-strike capabilities may hold the key to peace,” Zelenskyy said. 

    Though Tomahawks may not be in Ukraine’s near future, Bell Textron on Monday announced that the company had signed letters of intent to explore sales of its helicopters to the country. That could include the AH-1Z Viper attack helicopter.


    Welcome to this Wednesday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Meghann Myers and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1962, President John F. Kennedy ordered a naval quarantine of Cuba after American reconnaissance planes discovered Soviet weapons on the island.


    Around the Defense Department

    Trump pushes out Army’s No. 2 general in favor of Hegseth aide. The White House on Monday sent in a nomination to make Lt. Gen. Christopher LaNeve the next Army vice chief of staff, though the current one has been in the four-year role for under two years, Breaking Defense reported. Gen. James Mingus assumed he would retire after this job ended, an Army official told Breaking Defense, adding that “it is a little early but not significant.”

    Why now? LaNeve, a former commander of 8th Army in Korea and the 82nd Airborne Division, has all the bona fides you’d expect from a vice chief of staff. What’s not clear is why he’s being pushed into that role just six months into his job as Defense Secretary Pete Hegseth’s senior military aide, while the vice chief of staff position is usually held for three or so years. Trump could be teeing LaNeve up to be the next chief, as the vice chief is usually a top contender for the role. Current Army Chief of Staff Gen. Randy George just passed two years in the job.

    The move came just days after Hegseth announced the admiral overseeing military strikes on alleged drug-trafficking boats off Venezuela would retire early. Adm. Alvin Holsey has been leading U.S. Southern Command for less than a year.

    Speaking of the boat strikes, a group of independent U.N. experts say they amount to “extrajudicial executions.” In a Tuesday statement, experts appointed by the U.N. Human Rights Council said that even if the Trump administration’s allegations against the boaters “were substantiated, the use of lethal force in international waters without proper legal basis violates the international law of the sea and amounts to extrajudicial executions.” Reuters reports.

    The Pentagon is clamping down on communication with Congress, according to another Breaking Defense exclusive. An Oct. 15 memo signed by Hegseth and his deputy, Steve Feinberg, requires all correspondence with Capitol Hill to be coordinated through the office of the assistant defense secretary for legislative affairs. 

    While there is an exception for the independent inspector general’s office, the memo requires “coordination and alignment of Department messaging when engaging with Congress to ensure consistency and support for the Department’s priorities.” 

    Pentagon spokesman Sean Parnell, in a statement to CNN, said the move is intended to “improve accuracy and responsiveness in communicating with the Congress to facilitate increased transparency.”

    More transparency would be a welcome change to lawmakers who have chided the Defense Department for its lack of response to official requests for information. 

    “‘He lost us’: Generals, senior officers say trust in Hegseth has evaporated,” reports the Washington Times’ Ben Wolfgang, citing “current senior military officers and current and former Defense Department officials.” Leaders he spoke to pointed to Hegseth’s “public ‘grandstanding’ widely seen as unprofessional and the personnel moves made by the former cable TV host leading to an unprecedented and dangerous exodus of talent from the Pentagon…”

    Turning point? “Numerous high-ranking officers painted Mr. Hegseth’s Sept. 30 speech to hundreds of generals and admirals gathered at Marine Corps Base Quantico in Virginia as a turning point in how his leadership style, attitude and overall competency are viewed in the upper echelons of the U.S. armed forces,” the Times writes. Read on, here

    The Army wants drones that understand “commander’s intent.” That’s part of a draft UAS strategy that calls for a new career field, new advanced training, and soldier-built drones, reports Defense One’s Meghann Myers. The forthcoming strategy will focus on “universal interoperability and autonomy,” Maj. Gen. Clair Gill said at last week’s AUSA annual meeting in Washington, D.C.

    Right now, the service is looking for software that will enable drones to take orders rather than be flown. “You know, gone are the days where a drone operator is actually being a pilot, where they have to be hands on the sticks all the time,” Gill said. Read on, here

    Shutdown pauses talks on accelerating B-21 production.  Northrop Grumman CEO Kathy Warden, whose company sank half a billion dollars into speeding up production of its new strategic bomber, said Tuesday that talks with the Air Force are on hold during the federal shutdown, which is about to enter its fourth week. Warden spoke during the company’s third-quarter earnings call; Defense One’s Thomas Novelly has more, here.

    Middle East

    A civil-military coordination center in Israel will become the main hub for Gaza assistance, U.S. Central Command announced Tuesday. About 200 U.S. military personnel will help coordinate “humanitarian, logistical, and security assistance,” into Gaza, but will remain in Israel. The center will also “monitor” the implementation of the Israel-Hamas ceasefire, according to CENTCOM.

    Analysis: Turkey’s help in securing the ceasefire is already paying off, Reuters reports, in “diplomatic leverage in Washington, with officials expected to use the goodwill to push for progress on F-35 fighter jet sales, relief from U.S. sanctions, and support for its security goals in Syria. The effort also reestablished Turkey’s influence in Middle East diplomacy—unsettling Israel and Arab rivals such as Egypt, Saudi Arabia, and the UAE—and capped a reset in U.S.-Turkey relations following Erdoğan’s September visit to the White House.” More, here.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated phishing kit dubbed Tykit, which impersonates Microsoft 365 login pages to harvest corporate credentials.

    First detected in May 2025, the kit has surged in activity during September and October, exploiting SVG files as a stealthy delivery mechanism.

    Unlike basic phishing lures, Tykit demonstrates maturity through consistent obfuscation techniques and multi-stage command-and-control (C2) interactions, making it a potent tool for credential theft across global organizations.

    The kit’s rise aligns with a broader spike in SVG-based attacks, where seemingly innocuous image files embed JavaScript payloads. These scripts use XOR encoding to rebuild malicious code, which executes via the dangerous eval() function to redirect victims to fake login sites.

    Cybersecurity firm ANY.RUN has identified Tykit, a mature phishing-as-a-service (PhaaS) kit that impersonates Microsoft 365 login pages to capture corporate credentials through adversary-in-the-middle (AitM) techniques.

    Tykit Phishing Kit Mimics Microsoft 365 Login

    Tykit emerged in sandbox environments in early May 2025, with researchers pivoting from a single suspicious SVG (SHA256: a7184bef39523bef32683ef7af440a5b2235e83e7fb83c6b7ee5f08286731892) to over 189 related sessions.

    Domains like loginmicr0sft0nlineeckaf[.]52632651246148569845521065[.]cc host the phishing pages, often appending Base64-encoded victim emails via the “?s=” parameter. Exfiltration targets servers on segy[.]cc variants, sending staged POST requests to /api/validate and /api/login.

    This infrastructure spans templated domains resembling domain-generation algorithms, with patterns like ^loginmicr(o|0)s.?.([a-z]+)?\d+.cc$ for phishing hosts and ^segy?. for C2.

    The kit’s consistency, unchanged client-side logic, and obfuscation suggest organized operators distributing it widely, evading detection through basic anti-debugging like blocking developer tools and context menus.

    Tykit’s flow begins with an SVG prompting a fake “phone number check,” which accepts any input to proceed.

    The process starts by sending you to a CAPTCHA page that uses Cloudflare Turnstile to block bots. After that, it loads a page that looks like Microsoft 365. In the background, it checks emails using JSON data, which includes session keys and redirects.

    Upon credential entry, obfuscated JavaScript exfiltrates data to /api/login, including expired JWT tokens for authenticity.

    Server responses dictate outcomes: success renders benign HTML to mask theft, errors show “incorrect password” prompts, and “info” status triggers logging to /x.php. This adversary-in-the-middle (AitM) setup bypasses basic MFA, stealing emails, passwords, and tokens in JSON format.

    Cyber threats hit diverse sectors, including construction, IT, finance, government, telecom, real estate, and education, primarily in the US, Canada, LATAM, EMEA, Southeast Asia, and the Middle East.

    Compromises enable account takeovers, data exfiltration from SaaS apps, and lateral movement, posing risks of regulatory fines and trust erosion.

    To counter it, organizations should inspect SVG content with sandboxing and content disarmament, adopt phishing-resistant MFA like FIDO2, and monitor IOCs such as eval() calls, Base64 parameters, and suspicious domains.

    SIEM rules for /api/validate patterns, combined with user training on anomalous “images,” can disrupt campaigns early. As phishing evolves, Tykit underscores the need for proactive threat hunting to stay ahead of these “typical” yet effective kits.

    Expand Your Threat Coverage with Fresh IOCs from real-time Cyberthreats => Try Now

    The post New Tykit Phishing Kit Mimics Microsoft 365 Login Pages to Steal Corporate Account Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Since its emergence in August 2022, Lumma Infostealer has rapidly become a cornerstone of malware-as-a-service platforms, enabling even unskilled threat actors to harvest high-value credentials.

    Delivered primarily via phishing sites masquerading as cracked software installers, the malicious payload is encapsulated within a Nullsoft Scriptable Install System (NSIS) package designed to evade signature-based detection.

    Upon execution, fragmented AutoIt modules are reassembled in memory, with obfuscated shellcode loaded through process hollowing.

    This technique replaces a legitimate process with the stealer, camouflaging its activity under the guise of a benign executable.

    Genians analysts identified Lumma Infostealer following a surge in reports of credential theft in September 2025. Victims across both consumer and enterprise environments reported unauthorized access to web sessions, remote desktop services, and digital asset wallets.

    The stolen browser cookies and account tokens facilitate seamless session hijacking, bypassing multi-factor authentication measures in many cases.

    Cryptocurrency wallets saved in local databases, as well as VPN and RDP credentials stored in configuration files, are exfiltrated via encrypted channels to command-and-control (C2) domains hosted on compromised cloud infrastructure.

    The multifaceted nature of these thefts amplifies the potential for identity fraud, financial loss, and deeper network intrusions.

    Although Lumma Infostealer often serves as an initial foothold for ransomware and other follow-on attacks, its standalone impact is far-reaching.

    Victims may remain unaware of the breach until secondary actions—such as unauthorized wire transfers or illicit account listings on underground forums—bring the compromise to light.

    The modular design of the malware facilitates continuous updates, with developers pushing regular patches to evade new detection signatures.

    Strengthening endpoint detection and response (EDR) systems with behavior-based analytics and threat intelligence integration is critical to intercept the attack chain before data reaches the attacker’s C2 infrastructure.

    Infection Mechanism and Evasion Tactics

    At the heart of Lumma’s infection strategy is a layered installer that bypasses conventional scanners. When a user executes the downloaded NSIS installer, it drops a ZIP archive into the Temp directory.

    A command-line script (Contribute.docx) then invokes extrac32.exe to unpack a disguised Cabinet file.

    The extracted components—fragments of an AutoIt script and the AutoIt interpreter—are programmatically merged into a single executable stub.

    The following snippet illustrates the process hollowing routine used to inject the final payload:-

    ; Fragment of AutoIt loader
    Run("cmd.exe /c Contribute.docx")
    _ConsoleWrite("Launching AutoIt mode...")  
    _ProcessCreate("Riding.pif", "", @SystemDir, 0, $pi)  
    _WinAPI_WriteProcessMemory($pi.hProcess, $remoteAddr, $shellcode, BinaryLen($shellcode))  
    _WinAPI_SetThreadContext($pi.hThread, $context)  
    _WinAPI_ResumeThread($pi.hThread)
    Lumma Infostealer Attack Flow (Source – Genians)

    By verifying the absence of security processes (like SophosHealth, ekrn, AvastUI) with tasklist and findstr, the installer adjusts execution timing and payload placement, slipping past heuristic defenses.

    Once injected, the malicious process decrypts its C2 domains—rhussois.su, diadtuky.su, and todoexy.su—and establishes encrypted channels for data exfiltration.

    Stolen artifacts include web browser cookies, Telegram session data, cryptocurrency wallet files, and configuration files for VPN and RDP services.

    These credentials enable lateral movement and persistent access within victim networks, often without raising immediate alarms.

    The sophistication of Lumma Infostealer’s infection mechanism underscores the necessity for continuous monitoring of process injection events, routine auditing of installer behaviors, and enforcement of application allowlisting policies.

    Implementing network-level blocks for known C2 domains and employing sandbox detonation for suspicious NSIS packages can further mitigate the threat posed by this stealthy and adaptable infostealer.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Lumma Infostealer Malware Attacks Users to Steal Browser Cookies, Cryptocurrency Wallets and VPN/RDP Accounts appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals continue to evolve their email phishing arsenals, reviving legacy tactics while layering on advanced evasions to slip past automated filters and human scrutiny. In 2025, attackers are noted tried-and-true approaches—like password-protected attachments and calendar invites—with new twists such as QR codes, multi-stage verification chains, and live API integrations. These refinements not only prolong the […]

    The post Threat Actors Advancing Email Phishing Attacks to Bypass Security Filters appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitLab has urgently released patch versions 18.5.1, 18.4.3, and 18.3.5 for its Community Edition (CE) and Enterprise Edition (EE) to address multiple critical security flaws, including several high-severity denial-of-service (DoS) vulnerabilities.

    These updates fix issues allowing specially crafted payloads to overwhelm systems, alongside access control and authorization bugs affecting authenticated users.

    The company emphasizes immediate upgrades for all self-managed installations, noting that GitLab[.]com is already protected, and Dedicated customers require no action.​

    Among the most pressing fixes are three DoS vulnerabilities rated high or medium severity, enabling remote attackers to crash GitLab instances without authentication.

    The first, CVE-2025-10497, targets event collection, where unauthenticated users send crafted payloads to trigger resource exhaustion and service denial.

    Impacting CE/EE versions from 17.10 prior to the patches, it carries a CVSS score of 7.5, highlighting low complexity and high availability impact.

    Similarly, CVE-2025-11447 exploits JSON validation in GraphQL requests, allowing unauthenticated actors to flood the system with malicious payloads starting from version 11.0.

    This flaw also scores 7.5 on CVSS, affecting a broad range of installations and potentially halting API responses.​ A medium-severity DoS issue, CVE-2025-11974, arises during file uploads to specific API endpoints, where large files from unauthenticated sources consume excessive resources.

    Versions from 11.7 are vulnerable, with a CVSS of 6.5, though it requires low-privilege access in some scenarios.

    These vulnerabilities were reported via GitLab’s HackerOne program or discovered internally, underscoring the platform’s exposure to event processing, data validation, and upload mechanisms.​

    CVE IDDescriptionSeverityCVSS ScoreImpacted Versions (CE/EE unless noted)
    CVE-2025-10497DoS in event collectionHigh7.517.10 before 18.3.5, 18.4 before 18.4.3, 18.5 before 18.5.1​
    CVE-2025-11447DoS in JSON validationHigh7.511.0 before 18.3.5, 18.4 before 18.4.3, 18.5 before 18.5.1​
    CVE-2025-11974DoS in uploadMedium6.511.7 before 18.3.5, 18.4 before 18.4.3, 18.5 before 18.5.1​

    Beyond DoS threats, the patches remediate higher-impact issues like CVE-2025-11702, a high-severity improper access control in the runner API for EE, allowing authenticated users to hijack runners across projects with a CVSS of 8.5.

    CVE-2025-11971 fixes incorrect authorization in CE pipeline builds, enabling unauthorized executions via commit manipulation (CVSS 6.5).

    Lower-severity flaws include business logic errors in EE group memberships (CVE-2025-6601, CVSS 3.8) and missing authorizations in quick actions (CVE-2025-11989, CVSS 3.7), which could lead to unintended access or command execution.​

    These fixes align with GitLab’s biannual patch schedule, with full details public 30 days post-release on their issue tracker. Bug fixes in the updates address Redis gem downgrades, connection pool errors, and Geo routing leaks across versions.​

    Mitigations

    GitLab strongly urges upgrading all affected self-managed instances immediately to mitigate these risks, applicable to Omnibus, source, and Helm deployments.

    Following best practices like regular patching enhances security hygiene, as outlined in their handbook. With no reported exploits yet, proactive updates prevent potential disruptions in development workflows.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • When users authenticate to Microsoft cloud services, their activities generate authentication events recorded across multiple logging systems.

    Microsoft Entra sign-in logs and Microsoft 365 audit logs capture identical authentication events but represent this critical security data using different formats.

    Security analysts investigating incidents frequently encounter the UserAuthenticationMethod field in Microsoft 365 sign-in events, which displays cryptic numeric values such as 16, 272, or 33554432 without official documentation from Microsoft explaining their meaning.

    This undocumented field has posed challenges for security teams attempting to analyze authentication patterns, identify suspicious login activities, or assess phishing-resistant authentication adoption.

    The lack of documentation meant incident responders working in environments where only Microsoft 365 audit logs were available struggled to understand what authentication methods users employed during sign-in events.

    Through systematic correlation analysis between Microsoft Entra sign-in logs and Microsoft 365 audit logs, Sekoia analysts discovered that the UserAuthenticationMethod field operates as a bitfield where each bit position represents a distinct authentication method.

    This breakthrough enables security professionals to decode these numeric values into human-readable authentication method descriptions.

    The research team mapped each bit position to specific authentication methods by leveraging shared correlation identifiers between the logging systems.

    Microsoft 365 audit logs contain an InterSystemsId field while Entra ID logs include a correlationId field, both referencing identical authentication events.

    By matching events across sources, researchers correlated numeric UserAuthenticationMethod values with detailed authentication method descriptions found in Entra ID’s authenticationMethodDetail fields.

    Decoding the Bitfield Mapping Technique

    The bitfield structure allows multiple authentication methods to appear simultaneously in one numeric value.

    For instance, value 272 converts to binary as 100010000, activating bit 4 representing Password Hash Sync (decimal value 16) and bit 8 representing via Staged Rollout (decimal value 256), indicating “Password Hash Sync via Staged Rollout” as the authentication mechanism.

    The mapping encompasses 28 documented bit positions, including Password in the cloud at bit 0 (decimal 1), Temporary Access Pass at bit 1, Seamless SSO at bit 2, Windows Hello for Business at bit 18 (decimal 262144), and Passkey at bit 25 (decimal 33554432).

    However, several bits remain unmapped including positions 5, 7, 9-17, 22, and 26.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Decoding Microsoft 365 Audit Log Events Using Bitfield Mapping Technique – Investigation Report appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CyberProof researchers detected a significant surge in Remcos (Remote Control & Surveillance Software) campaigns throughout September and October 2025, exploiting sophisticated fileless techniques to evade endpoint detection and response (EDR) solutions. By leveraging highly obfuscated PowerShell scripts and process hollowing into Microsoft’s RMClient.exe, attackers are gaining stealthy persistence and targeting browser credentials. Although Remcos is […]

    The post Fileless Remcos Attacks: Injecting Malicious Code into RMClient to Evade EDR appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • China-based threat actors have exploited the critical ToolShell vulnerability in Microsoft SharePoint servers to infiltrate networks across multiple continents, targeting government agencies and critical infrastructure in a suspected espionage campaign.

    This vulnerability, identified as CVE-2025-53770, enables unauthenticated remote code execution and has been actively used since its disclosure in July 2025, despite Microsoft’s rapid patching efforts.

    Security researchers from Symantec report that the attacks began shortly after patches were released, affecting organizations in the Middle East, Africa, South America, and beyond.

    ToolShell stems from a deserialization of untrusted data issue in on-premises SharePoint servers, allowing attackers to execute arbitrary code without authentication.

    It builds on earlier flaws like CVE-2025-49704 and CVE-2025-49706, which were demonstrated at the Pwn2Own Berlin event in May 2025.

    The exploit chain typically involves an authentication bypass (CVE-2025-53771), where a crafted POST request to the ToolPane.aspx endpoint tricks the server into granting access, followed by injecting malicious payloads for code execution.

    Microsoft confirmed exploitation by at least three Chinese-linked groups Budworm (Linen Typhoon), Sheathminer (Violet Typhoon), and Storm-2603 shortly after patching on July 21, 2025.

    These actors have leveraged ToolShell for zero-day attacks, compromising file systems and enabling persistent access.

    Targets And Attack Patterns

    The campaign’s scope is broad, with confirmed breaches in a Middle Eastern telecom firm, two African government departments, South American agencies, a U.S. university, an African state technology entity, a Middle Eastern government department, and a European finance company.

    Initial access in the Middle East occurred on July 21, 2025, via a webshell deployment, followed by DLL sideloading of malware using legitimate binaries from Trend Micro and BitDefender.

    In South American cases, attackers exploited SQL and Apache HTTP servers with Adobe ColdFusion, using a renamed “mantec.exe” to mimic Symantec tools and sideload malicious DLLs.

    Evidence points to mass scanning for vulnerable servers, with selective follow-up on high-value targets for credential theft and lateral movement.

    The attackers deployed Zingdoor, a Go-based HTTP backdoor linked to the Glowworm group (aka Earth Estries or FamousSparrow), first documented in 2023 for espionage against government and tech sectors.

    ShadowPad, a modular RAT associated with APT41-nexus groups like Blackfly, was also used via DLL sideloading for command execution and updates.

    KrustyLoader, a Rust-written loader tied to UNC5221 (a China-nexus actor), delivered second-stage payloads like Sliver, an open-source C2 framework abused for red-team emulation.

    Living-off-the-land tools included Certutil for downloads, Procdump and LsassDumper for credential dumping, GoGo Scanner for reconnaissance, Revsocks for proxying, and the PetitPotam exploit (CVE-2021-36942) for privilege escalation.

    IoCs

    This activity highlights ToolShell’s widespread abuse beyond initial reports, underscoring the need for urgent patching of on-premises SharePoint instances.

    With over 400 compromises detected and links to Salt Typhoon tactics, the operations suggest state-sponsored espionage focused on persistent, stealthy network access.

    TypeIndicatorDescription
    SHA256 Hash6240e39475f04bfe55ab7cba8746bd08901d7678b1c7742334d56f2bc8620a35LsassDumper
    SHA256 Hash929e3fdd3068057632b52ecdfd575ab389390c852b2f4e65dc32f20c87521600KrustyLoader
    SHA256 Hashdb15923c814a4b00ddb79f9c72f8546a44302ac2c66c7cc89a144cb2c2bb40faLikely ShadowPad
    SHA256 Hashe6c216cec379f418179a3f6a79df54dcf6e6e269a3ce3479fd7e6d4a15ac066eShadowPad Loader
    SHA256 Hash071e662fc5bc0e54bcfd49493467062570d0307dc46f0fb51a68239d281427c6Zingdoor
    SHA256 Hash1f94ea00be79b1e4e8e0b7bbf2212f2373da1e13f92b4ca2e9e0ffc5f93e452bPetitPotam/CVE-2021-36942 exploit
    SHA256 Hashdbdc1beeb5c72d7b505a9a6c31263fc900ea3330a59f08e574fd172f3596c1b8RevSocks
    SHA256 Hash6aecf805f72c9f35dadda98177f11ca6a36e8e7e4348d72eaf1a80a899aa6566LsassDumper
    SHA256 Hash568561d224ef29e5051233ab12d568242e95d911b08ce7f2c9bf2604255611a9Socks Proxy
    SHA256 Hash28a859046a43fc8a7a7453075130dd649eb2d1dd0ebf0abae5d575438a25ece9GoGo Scanner
    SHA256 Hash7be8e37bc61005599e4e6817eb2a3a4a5519fded76cb8bf11d7296787c754d40Sliver
    SHA256 Hash5b165b01f9a1395cae79e0f85b7a1c10dc089340cf4e7be48813ac2f8686ed61ProcDump
    SHA256 Hashe4ea34a7c2b51982a6c42c6367119f34bec9aeb9a60937836540035583a5b3bcProcDump
    SHA256 Hash7803ae7ba5d4e7d38e73745b3f321c2ca714f3141699d984322fa92e0ff037a1Minidump
    SHA256 Hash7acf21677322ef2aa835b5836d3e4b8a6b78ae10aa29d6640885e933f83a4b01mantec.exe (Benign executable)
    SHA256 Hash6c48a510642a1ba516dbc5effe3671524566b146e04d99ab7f4832f66b3f95aabugsplatrc.dll
    URLhttp://kia-almotores.s3.amazonaws[.]com/sy1cyjtKrustyLoader C&C server
    URLhttp://omnileadzdev.s3.amazonaws[.]com/PBfbN58lXKrustyLoader C&C server

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Chinese Hackers Using ToolShell Vulnerability To Compromise Networks Of Government Agencies appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors with ties to China exploited the ToolShell security vulnerability in Microsoft SharePoint to breach a telecommunications company in the Middle East after it was publicly disclosed and patched in July 2025. Also targeted were government departments in an African country, as well as government agencies in South America, a university in the U.S., as well as likely a state technology

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Oracle has disclosed two critical vulnerabilities in its E-Business Suite’s Marketing product that could hand full control to remote attackers.

    Dubbed CVE-2025-53072 and CVE-2025-62481, these flaws affect the Marketing Administration component and carry a perfect storm CVSS score of 9.8, marking them as among the most severe threats disclosed this year.

    Organizations relying on Oracle’s suite for customer relationship management and marketing automation now face urgent patching needs to avert potential data breaches and system takeovers.

    The vulnerabilities stem from weaknesses in how the Marketing Administration handles HTTP requests. An unauthenticated attacker needs only network access, no special privileges, or user interaction to exploit them.

    Once triggered, the flaws enable full compromise of the Oracle Marketing module, granting attackers high-level access to confidentiality, integrity, and availability.

    This could mean stealing sensitive customer data, altering marketing campaigns, or disrupting operations entirely.

    In today’s threat landscape, where ransomware groups and nation-state actors hunt for easy entry points, such exposures in widely used ERP systems like Oracle E-Business Suite amplify the danger.

    Details Of The Flaws

    Both CVEs target versions 12.2.3 through 12.2.14 of Oracle Marketing, with no mitigations in place beyond applying the latest security patches.

    Oracle’s advisory highlights that the issues remain unchanged from initial assessments, underscoring their straightforward exploitability.

    The CVSS 3.1 vector for each (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) breaks down to network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, and high impacts across all categories.

    CVE IDComponentAttack VectorRequires Auth?CVSS 3.1 ScoreAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability ImpactAffected Versions
    CVE-2025-53072Marketing AdministrationHTTP (Network)No9.8LowNoneNoneUnchangedHighHighHigh12.2.3-12.2.14
    CVE-2025-62481Marketing AdministrationHTTP (Network)No9.8LowNoneNoneUnchangedHighHighHigh12.2.3-12.2.14

    These entries reveal a pattern: identical scoring and vectors suggest related coding errors, possibly in input validation or session handling, though Oracle has not released specifics to avoid aiding attackers.

    Mitigations

    The disclosure arrives amid a surge in supply chain attacks targeting enterprise tools, echoing recent breaches at companies like Cisco and Microsoft.

    For businesses in retail, finance, or e-commerce where Oracle E-Business Suite powers core marketing functions, these vulnerabilities could expose terabytes of customer profiles to theft or manipulation, leading to regulatory fines under GDPR or CCPA.

    Oracle urges immediate patching via its Critical Patch Update for October 2025, available on My Oracle Support.

    In the interim, experts recommend network segmentation, web application firewalls tuned for HTTP anomalies, and monitoring for unusual Marketing Administration traffic.

    Cybersecurity firms like Mandiant warn that exploit code may surface soon on dark web forums, given the high incentive.

    As enterprises scramble, this incident highlights the need for proactive vulnerability management in legacy systems. With no evidence of active exploitation yet, the window for defense remains open but it’s narrowing fast.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Critical Vulnerability In Oracle E-Business Suite’s Marketing Product Allows Full Access To Attackers appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶