Hackers have launched a sophisticated phishing campaign impersonating both OpenAI and the recently released Sora 2 AI service. By cloning legitimate-looking landing pages, these actors are duping users into submitting their login credentials, participating in faux “gift” surveys, and even falling victim to cryptocurrency scams. Security researchers note that these deceptive domains are already ensnaring […]
Luxembourg, October 14th, 2025, CyberNewsWire Surge in scale and sophistication highlights rising threats to tech and digital infrastructure Gcore, the global edge AI, cloud, network, and security solutions provider, has successfully mitigated one of the largest DDoS attacks recorded to date. The large-scale, multi-regional DDoS attack reached a peak bandwidth of 6 Tbps (terabits per […]
Luxembourg, Luxembourg, October 14th, 2025, CyberNewsWire
Surge in scale and sophistication highlights rising threats to tech and digital infrastructure
Gcore, the global edge AI, cloud, network, and security solutions provider, has successfully mitigated one of the largest DDoS attacks recorded to date.
The large-scale, multi-regional DDoS attack reached a peak bandwidth of 6 Tbps (terabits per second) and a packet rate of 5.3 Bpps (billion packets per second).
The attack targeted a hosting provider operating in the gaming sector, but the methodology and scale confirm a broader trend of intensifying DDoS campaigns aimed at a wide range of digital infrastructure.
The attack was consistent with the AISURU botnet, which has been associated with several high-impact incidents in recent months worldwide.
“This incident underscores an ongoing escalation in both the scale and sophistication of DDoS attacks,” said Andrey Slastenov, Head of Security at Gcore.“While this event was a short-burst volumetric flood, across the industry we increasingly see campaigns used to probe resilience or coincide with other vectors. Without robust, adaptive protection, organizations across tech, hosting, and enterprise sectors remain at risk.”
Attack Highlights:
Peak traffic: 6 Tbps
Packet rate: 5.3 Bpps
Main protocol: UDP, typical of volumetric floods
Duration: 30-45 seconds
Geographic concentration: 51% of sources originated in Brazil and 23.7% in the US, together accounting for nearly 75% of all traffic
This event mirrors insights from the recently published Gcore Radar report Q1-Q2 2025, which revealed that not only did the number of DDoS attacks increase by 41% in just one quarter, but attacks targeting tech companies also rose significantly, accounting for 30% of all recorded incidents.
In the context of this attack, the multi-regional origin and volumetric scale signal a concerning evolution of botnet capabilities, exploiting unsecured infrastructure in regions with high device density and weaker security controls. AISURU’s concentration in Brazil and the US reflects this dynamic.
Strategic Implications for Hosting and Enterprise Infrastructure
The attack’s characteristics align with a growing tactic observed in modern DDoS campaigns: short-burst, high-intensity attacks designed not only to cause downtime but to probe infrastructure resilience.
“For hosting providers, uptime is currency,” added Slastenov. “When a botnet can generate 6 Tbps of traffic, even a few seconds of disruption can translate to financial and reputational damage. This is why adaptive mitigation, edge-layer filtering, and Layer 7 behavioral analysis are no longer optional, they’re mission-critical.”
Gcore’s Response and Defense Capabilities
Gcore’s global DDoS Protection solution absorbed and neutralized the attack without service interruption, leveraging its globally distributed infrastructure across 210+ Points of Presence and a filtering capacity exceeding 200 Tbps.
The incident highlights the need for integrated, AI-driven DDoS defense strategies capable of real-time response and deep traffic inspection—especially as attacks continue to combine volumetric and application-layer exploits.
About Gcore
Gcore is a global infrastructure and software provider for AI, cloud, network, and security solutions. Headquartered in Luxembourg, Gcore operates its own sovereign infrastructure across six continents, delivering ultra-low latency and compliance-ready performance for mission-critical workloads.
Its AI-native cloud stack combines software innovation with hyperscaler-grade functionality, enabling enterprises and service providers to build, train, and scale AI everywhere, across public, private, and hybrid environments.
By integrating AI, compute, networking, and security into a single platform, Gcore accelerates digital transformation and empowers organizations to unlock the full potential of AI-driven services. Users can learn more at gcore.com.
SimonMed Imaging has confirmed that an external hacking incident compromised the personal data of 1,275,669 patients, making it one of the largest healthcare breaches of the year. The breach, which occurred on January 21, 2025, but was not discovered until January 28, exposed names and other personal identifiers. Written notifications were sent to affected individuals […]
In a sprawling network of covert remote labor, more than 10,000 North Korean IT professionals have infiltrated global technology and freelance marketplaces by exploiting VPNs, virtual private servers (VPS), and so-called “laptop farms” to conceal their true origins. State-backed cyber units employ these operatives to generate revenue for sanctioned weapons programs and gather intelligence across […]
Ivanti has disclosed 13 vulnerabilities in its Endpoint Manager (EPM) software, including two high-severity flaws that could enable remote code execution and privilege escalation, urging customers to apply mitigations while patches remain in development.
The announcement comes amid growing scrutiny of enterprise management tools, as attackers increasingly target them for supply chain compromises.
Although no exploitation in the wild has been reported, the issues highlight the risks of outdated deployments in endpoint security environments.
Critical Vulnerabilities Exposed In Endpoint Manager
Among the vulnerabilities, CVE-2025-9713 stands out as a high-severity path traversal issue with a CVSS score of 8.8, allowing unauthenticated remote attackers to execute arbitrary code if users interact with malicious files.
This flaw, rooted in CWE-22, exploits weak input validation during configuration imports, potentially letting adversaries upload and run malicious payloads on the EPM Core server.
Complementing it is CVE-2025-11622, an insecure deserialization vulnerability (CVSS 7.8, CWE-502) that permits local authenticated users to escalate privileges, granting unauthorized access to sensitive system resources.
The remaining 11 vulnerabilities are medium-severity SQL injection flaws (each CVSS 6.5, CWE-89), such as CVE-2025-11623 and CVE-2025-62392 through CVE-2025-62384.
CVE ID
Description
CVSS Score
Severity
CVSS Vector
CWE
CVE-2025-11622
Insecure deserialization allowing local authenticated privilege escalation.
7.8
High
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
502
CVE-2025-9713
Path traversal allowing remote unauthenticated RCE with user interaction.
8.8
High
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
22
CVE-2025-11623
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
CVE-2025-62392
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
CVE-2025-62390
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
CVE-2025-62389
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
CVE-2025-62388
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
CVE-2025-62387
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
CVE-2025-62385
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
CVE-2025-62391
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
CVE-2025-62383
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
CVE-2025-62386
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
CVE-2025-62384
SQL injection allowing remote authenticated arbitrary data read.
6.5
Medium
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
89
These allow remote authenticated attackers to extract arbitrary data from the database, including credentials or configuration details, without needing user interaction beyond initial authentication.
Ivanti noted that all issues were responsibly reported by researcher 06fe5fd2bc53027c4a3b7e395af0b850e7b8a044 via Trend Micro’s Zero Day Initiative, underscoring the value of coordinated disclosure in bolstering defenses.
No proof-of-concept exploits or indicators of compromise (IoCs) have been publicly released, as Ivanti confirmed no active attacks at disclosure time.
However, the potential for data exfiltration via SQL injections could aid broader campaigns, similar to past incidents targeting management consoles like those from SolarWinds or Log4j.
Ivanti EPM versions 2024 SU3 SR1 and earlier are affected, with the 2022 branch now end-of-life as of October 2025, leaving users without official support.
For the high-severity CVEs, fixes are slated for EPM 2024 SU4, expected November 12, 2025. The SQL injections will follow in SU5 during Q1 2026, delayed due to the complexity of resolving them without disrupting reporting features.
Ivanti emphasized that upgrading to the latest 2024 release already mitigates much of the risk through enhanced security controls. Customers on EOL versions face heightened exposure and should migrate promptly to avoid unpatched vulnerabilities.
The company’s FAQ addresses concerns, noting that while patches are forthcoming, immediate mitigations can secure environments in the interim.
Mitigations
To counter CVE-2025-11622, Ivanti recommends firewall whitelisting to block high-range TCP ports and restricting Core server access to local EPM administrators only, aligning with established best practices.
For the path traversal in CVE-2025-9713, users must avoid importing untrusted configuration files and thoroughly vet any necessary ones, as such actions inherently carry risks.
The SQL injection cluster can be addressed by removing the Reporting database user, though this disables analytics features, a trade-off detailed in Ivanti’s documentation. Overall, staying on EPM 2024 SU3 SR1 or later provides layered protections, reducing exploit viability.
Ivanti’s disclosure, despite pending patches, prioritizes transparency, allowing proactive defenses in a landscape where endpoint managers are prime targets for ransomware and APT groups. Organizations should audit their EPM setups and consult Ivanti’s Success Portal for tailored support.
A new proof-of-concept (PoC) exploit has been published for a critical flaw in the widely used sudo utility. This vulnerability enables any local user to escape a chroot jail and execute commands with root privileges. Organizations relying on sudo are urged to audit and update their installations immediately. Chroot Escape Enables Root Access The flaw resides in sudo’s handling of […]
A recent surge in threat actors leveraging remote management and monitoring (RMM) tools for initial access has intensified scrutiny of platforms once reserved for legitimate IT administration. While AnyDesk has waned in popularity among adversaries due to improved detection, ConnectWise ScreenConnect has emerged as a preferred option for stealthy intrusion, persistence, and lateral movement. This […]
A critical vulnerability in the widely used Sudo utility has come under scrutiny following the public release of a proof-of-concept exploit, raising alarms for Linux system administrators worldwide.
CVE-2025-32463 targets the chroot feature in Sudo versions 1.9.14 through 1.9.17, enabling local attackers to escalate privileges to root level with minimal effort.
Discovered by security researcher Rich Mirch, this flaw exploits how Sudo handles user-specified root directories, potentially allowing unauthorized command execution as the superuser.
The issue, rated at a CVSS score of 9.3, critical, underscores ongoing risks in privilege management tools essential to Unix-like operating systems.
Reports indicate active exploitation in the wild, prompting urgent calls for patching from organizations like CISA.
This development arrives amid a surge in Sudo-related vulnerabilities, highlighting the tool’s persistent role as a prime target for attackers seeking deeper system access.
The vulnerability stems from Sudo’s improper resolution of paths when using the –chroot option, introduced in version 1.9.14 to support user-defined root environments.
In affected versions, an attacker can craft a malicious /etc/nsswitch.conf file within a controlled directory, tricking Sudo into loading an arbitrary shared library during command evaluation.
This bypasses sudoers file restrictions, granting root privileges even to users not explicitly authorized for escalation.
Rich Mirch identified the issue through analysis of Sudo’s path resolution logic, noting that the chroot feature’s implementation creates an error-prone vector for local privilege escalation.
The flaw does not require network access or high privileges, making it particularly dangerous in multi-user environments like servers and development machines.
Stratascale’s advisory details how this could lead to full system compromise, including data exfiltration or malware deployment.
Ubuntu and Red Hat have confirmed the vulnerability affects their distributions, with patches rolled out in recent updates.
Proof Of Concept Demonstration
The GitHub repository by researcher kh4sh3i provides a straightforward PoC exploit, demonstrating the escalation in a controlled setting.
Users clone the repository, navigate to the directory, and make the exploit.sh script executable, and run it after checking their initial user ID.
The script leverages the chroot option to manipulate Sudo’s environment, resulting in a successful privilege gain as evidenced by the post-execution ID output showing root access.
Terminal screenshots in the repo illustrate the process: starting as a low-privilege user in the lowuser group, the exploit executes via sudo, flipping the context to root@test with full administrative capabilities.
PoC Exploit
This visual proof, mirroring the attached demonstration image, confirms the vulnerability’s reliability on unpatched systems.
While intended for educational use, the PoC emphasizes the need for caution, as unauthorized deployment constitutes illegal activity. Exploit-DB hosts a similar script, underscoring the ease of adaptation for malicious purposes.
Systems running vulnerable Sudo versions face severe risks, including complete takeover by local threat actors, which could facilitate lateral movement in breached networks.
Affected products span major Linux distributions: Ubuntu 24.04 LTS, 24.10, and 25.04; Red Hat Enterprise Linux variants; and Debian-based setups with Sudo 1.9.14-1.9.17.
Legacy versions before 1.9.14 remain unaffected due to the absence of chroot support. Immediate mitigation involves updating to Sudo 1.9.17p1 or later, where the feature is deprecated and the path resolution flaw is reverted.
Administrators should enable AppArmor or SELinux profiles to constrain Sudo operations and monitor logs for suspicious chroot invocations.
CISA has added this CVE to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply patches by October 2025.
Aspect
Details
CVE ID
CVE-2025-32463
CVSS v3.1 Score
9.3 (Critical)
Attack Vector
Local
Impact
High Confidentiality, Integrity, Availability
Affected Versions
Sudo 1.9.14 – 1.9.17
Patched Versions
1.9.17p1+
Organizations delaying updates risk heightened exposure, especially in cloud and containerized environments reliant on Sudo for automation.
Cybersecurity researchers have identified several malicious packages across npm, Python, and Ruby ecosystems that leverage Discord as a command-and-control (C2) channel to transmit stolen data to actor-controlled webhooks.
Webhooks on Discord are a way to post messages to channels in the platform without requiring a bot user or authentication, making them an attractive mechanism for attackers to