• Oracle has issued a critical security alert for a severe vulnerability in its E-Business Suite platform that could allow attackers to execute remote code and steal sensitive data without requiring authentication. The flaw, identified as CVE-2025-61884, affects multiple versions of the widely used enterprise software and has been assigned a CVSS score of 7.5, indicating high […]

    The post Oracle E-Business Suite Flaw Enables Remote Code Execution and Data Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • McAfee’s Threat Research team recently uncovered a sophisticated new Astaroth campaign that represents a significant evolution in malware infrastructure tactics. This latest variant has abandoned traditional command-and-control (C2) server dependencies in favor of leveraging GitHub repositories to host critical malware configurations. The Astaroth banking malware has evolved beyond conventional C2 server architectures by exploiting GitHub’s […]

    The post Astaroth Banking Malware Exploits GitHub for Hosting Configuration Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have disclosed details of a new Rust-based backdoor called ChaosBot that can allow operators to conduct reconnaissance and execute arbitrary commands on compromised hosts. “Threat actors leveraged compromised credentials that mapped to both Cisco VPN and an over-privileged Active Directory account named, ‘serviceaccount,'” eSentire said in a technical report published

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Defender for Endpoint’s cloud communication can be abused to bypass authentication, intercept commands, and spoof results, allowing attackers to derail incident response and mislead analysts. Recent research shows that multiple backend endpoints accept requests without effectively validating tokens, enabling unauthenticated manipulation if a machine ID and tenant ID are known. Microsoft reportedly classified the […]

    The post Attackers Exploit Defender for Endpoint Cloud API to Bypass Authentication and Disrupt Incident Response appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • An open-source tool called RealBlindingEDR enables attackers to blind, permanently disable, or terminate antivirus (AV) and endpoint detection and response (EDR) software by clearing critical kernel callbacks on Windows systems.

    Released on GitHub in late 2023, the utility leverages signed drivers for arbitrary memory read and write operations, bypassing protections like PatchGuard to target six major kernel callback types. This development raises alarms for cybersecurity professionals, as the tool has been adopted by ransomware groups such as Crypto24 in recent attacks.​

    The tool’s creator emphasizes research purposes only, disclaiming any malicious use, while providing detailed implementation insights in a Chinese-language analysis article.

    By exploiting vulnerable drivers like echo_driver.sys or dbutil_2_3.sys, RealBlindingEDR gains kernel-level access without triggering immediate detection.

    Users download the executable from releases, pair it with a compatible driver, and execute commands like “RealBlindingEDR.exe c:\echo_driver.sys 1” for blinding mode or variants for shutdowns.

    Screenshots attached to the repository demonstrate real-time removal of callbacks, allowing file deletions and process terminations that AV tools typically block.​

    RealBlindingEDR systematically erases callbacks registered via functions such as CmRegisterCallback(Ex), ObRegisterCallbacks, PsSetCreateProcessNotifyRoutine(Ex), PsSetCreateThreadNotifyRoutine(Ex), PsSetLoadImageNotifyRoutine(Ex), and MiniFilter drivers.

    RealBlindingEDR Tool – Clearing Kernel Callbacks

    These mechanisms allow AV/EDR solutions to monitor process creation, thread activity, image loading, registry changes, file operations, and object handles. For instance, removing ObRegisterCallbacks eliminates handle protection, enabling ordinary admin users to kill EDR processes that would otherwise resist termination.​

    The process involves locating global kernel structures like PsProcessType or FltGlobals through exported functions in ntoskrnl.exe and fltmgr.sys.

    It then traverses linked lists of callback entries, nullifying function pointers or rerouting list heads to evade PatchGuard-induced blue screens. Adaptation for Windows 7 to 11 and various servers ensures broad compatibility, with ongoing issues tracked via GitHub.​

    Tested against products including 360 Security Guard, Tencent Computer Manager, Kaspersky Endpoint Security, Windows Defender, and AsiaInfo EDR, the tool achieves three key outcomes without halting the target’s main process, preserving communication with central management to avoid alerts.

    Blinding mode prevents monitoring of sensitive behaviors like malware drops or privilege escalations. Permanent disablement follows by deleting protected files or registry entries post-callback removal, surviving reboots. Killing is straightforward once object protections vanish.​

    Demos show, for example, terminating AV processes via Task Manager and erasing self-protected files, as depicted in repository images of command outputs and before-and-after states.​

    While intended for ethical research, RealBlindingEDR’s simplicity, requiring only a signed driver and admin rights, poses risks for red teaming and real-world threats.

    Ransomware operators like Crypto24 have integrated it into multi-stage attacks, impairing defenses before encryption. Organizations should monitor for vulnerable driver loads and kernel anomalies using advanced EDR with behavioral analytics.​

    Microsoft and AV vendors urge driver signature enforcement and tools like Driver Signature Enforcement Overrider mitigations. Future updates may target ETW providers and WFP callbacks, escalating kernel-level evasion tactics.

    Security teams are advised to review endpoint logs for unusual sys file accesses and prioritize least-privilege driver usage.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post RealBlindingEDR Tool That kills or Permanently Turn off AV/EDR Using Kernel Callbacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A surge in attacks targeting SonicWall SSLVPN devices, affecting numerous customer networks, just weeks after a major breach exposed sensitive firewall data.

    Starting October 4, 2025, threat actors have rapidly authenticated into over 100 accounts across 16 environments, using what appear to be stolen valid credentials rather than brute-force methods.

    This coordinated attack highlights the growing risks to remote access tools in enterprise settings, potentially stemming from a recent cloud storage incident at SonicWall.

    The compromises unfolded quickly, with clustered login attempts peaking over the next two days. In many cases, attackers connected briefly from the IP address 202.155.8[.]73 before disconnecting without further action.

    However, in more severe instances, they performed network scans and tried to access local Windows accounts, indicating deeper reconnaissance or lateral movement efforts.

    Huntress noted the scale and speed suggest attackers possess insider knowledge of credentials, raising alarms for organizations relying on SonicWall for secure remote access.

    SonicWall SSLVPN Under Attack

    SonicWall’s recent security advisory has escalated concerns by confirming that hackers accessed encrypted configuration backups for every customer using its MySonicWall cloud service.

    These files contain critical data like credentials and settings, which, even encrypted, could enable targeted exploits if decrypted. The company initially reported in mid-September that fewer than 5% of firewalls were impacted, but the update on October 10 revealed the breach affected all users of the backup feature.

    While Huntress has not confirmed a direct connection between the breach and the SSLVPN attacks, the timing and nature of the incidents align suspiciously.

    The firm is sharing indicators of compromise, including the suspicious IP, to help defenders identify similar activity. SonicWall urges customers to log into MySonicWall.com immediately to check for affected devices and follow detailed remediation steps, such as resetting all exposed credentials.

    Mitigations

    To mitigate risks, businesses should act swiftly by restricting wide-area network management and remote access where feasible. Temporarily disable HTTP, HTTPS, SSH, SSL VPN, and inbound management interfaces until credentials are fully reset.

    This includes revoking local admin passwords, VPN pre-shared keys, LDAP or RADIUS bind credentials, wireless passphrases, and SNMP settings on impacted firewalls.

    Further, organizations must roll over external API keys, dynamic DNS configurations, SMTP or FTP accounts, and any automation secrets linked to management systems.

    Enhanced logging is crucial for reviewing recent logins and changes for anomalies, retaining records for forensic analysis. Once resets are complete, re-enable services gradually while monitoring for unauthorized re-entry.

    Enforcing multi-factor authentication on all admin and remote accounts, alongside applying least-privilege principles, will bolster defenses long-term.

    Huntress continues tracking these threats and offers guidance through its support resources, emphasizing proactive vigilance in an era of credential-based attacks.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Oracle has disclosed a critical vulnerability in its E-Business Suite that enables unauthenticated attackers to remotely access sensitive data, raising alarms for enterprises relying on the platform for core operations.

    Tracked as CVE-2025-61884, the flaw affects the Oracle Configurator component and was detailed in a security alert released on October 11, 2025.

    This comes just days after another exploited E-Business Suite vulnerability, CVE-2025-61882, highlighting ongoing security challenges in Oracle’s enterprise resource planning software.

    The issue allows hackers to bypass authentication over HTTP, potentially exposing configuration data critical to business processes like finance and supply chain management.​

    Oracle E-Business Suite RCE Vulnerability

    CVE-2025-61884 resides in the Runtime UI of Oracle Configurator, a module used for managing product and service configurations within E-Business Suite.

    Attackers with network access can exploit this flaw without credentials, leading to unauthorized data retrieval or enumeration. The vulnerability stems from an authentication bypass mechanism, though specific technical details like affected endpoints remain undisclosed to prevent widespread abuse.

    Oracle rates it with a CVSS 3.1 base score of 7.5, classifying it as high severity due to its ease of exploitation. No credits are given to external researchers, suggesting internal discovery by Oracle’s security team.​

    The following table summarizes key aspects of the vulnerability:

    CVE IDAffected ComponentProtocolCVSS Base ScoreAttack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability ImpactSupported Versions
    CVE-2025-61884Oracle Configurator (Runtime UI)HTTP7.5NetworkLowNoneNoneUnchangedHighNoneNone12.2.3-12.2.14 ​

    This structured breakdown underscores the remote, unauthenticated nature of the threat, making it accessible to any internet-facing deployment.​

    Successful exploitation could grant hackers complete access to all Oracle Configurator data, including sensitive business configurations that drive operational decisions.

    For organizations in sectors like manufacturing or retail, this means exposure of proprietary models, pricing strategies, and customer details, potentially leading to competitive disadvantages or regulatory violations.

    The high confidentiality impact without affecting integrity or availability positions it as a data exfiltration vector rather than a disruptive attack.

    Given the recent exploitation of CVE-2025-61882 by ransomware groups like Cl0p, security experts warn that CVE-2025-61884 could follow suit, especially as proof-of-concepts for similar flaws circulate. Enterprises with unpatched E-Business Suite instances face elevated risks, particularly if exposed to the public internet.​

    Mitigations

    Oracle urges immediate application of the released patches for versions 12.2.3 through 12.2.14, available via the Security Alert program for supported releases under Premier or Extended Support.

    Customers on older versions should upgrade to maintained branches, as earlier releases like 12.1.3 may also be vulnerable despite lacking testing.

    Additional defenses include network segmentation to limit HTTP access to the Configurator UI and monitoring for anomalous requests.

    Oracle’s advisory provides detailed patch instructions through support documents, emphasizing the Lifetime Support Policy for ongoing protection.

    While no active exploitation has been confirmed for this CVE, the pattern of rapid E-Business Suite attacks demands swift action to safeguard sensitive resources.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A startup called Valinor has just unveiled what is essentially a field hospital in a box—one with integrated software and data connectivity missing from today’s battlefield medicine. 

    Harbor is a 20-foot shipping container that can be modified for different types of battlefield care, such as immediate damage control or prolonged casualty care. The exterior can be hardened against ballistics and it can be modified to power anti-drone defensive systems. Anduril is partnering with Valinor to allow telehealth over Anduril’s Lattice mesh network, in order to better manage the electro-magnetic signatures coming to and from the unit, to make it more difficult to target by enemy drones, etc. 

    Luke Sciulli, head of medical innovation at Valinor, spoke with Defense One about the idea. He’s a former Army medic who has made more than 10 visits to Ukraine since the start of Russia’s 2022 expanded invasion, embedding with different humanitarian organizations there. “These trips have provided visceral proof of just how quickly the nature of warfare is changing, even versus my time in Special Forces less than a decade ago,” he told Defense One over email.

    One key change he’s seen emerge from the war zone in Eastern Europe: the deliberate targeting of frontline medical workers is increasingly common practice. The fight also shows that drone warfare makes air superiority elusive, which complicates getting helicopters into combat zones to pull the wounded from the field. Evacuations that should take minutes in Ukraine now take between 72 and 96 hours, he said. That’s key, the United States relied heavily on medical evacuations to reduce battlefield casualties in its Middle East operations. Those two factors create a need for much more advanced battlefield medical care, because medical evacutions will be much more difficult and the need for frontline care would be much higher.

    While it’s tempting to think the better-resourced U.S. military wouldn’t face the same challenges, high-intensity warfare is likely to produce far more casualties—and far more quickly—than the engagements the U.S. has fought so far this century.

    Today, the U.S. can set up an Army field hospital in about 72 hours, according to 2018 studies but they are expensive to run—upwards of $3 million a month, according to a separate 2015 study based U.S. field-hospital deployments in Afghanistan, the most recent academic data available. And field hospitals don’t compare to regular hospitals in terms of modern health monitoring or other capabilities.

    This year, the company developed and delivered prototypes to the Marine Corps and special operations forces. The units can be modified depending on the deployment context. “Looking forward, we have secured the team and resources to produce [approximately] 300 units in 2026, if contracted to do so. We designed Harbor from first principles to support mass manufacturing, including edge manufacturing or production overseas,” he said.

    Harbor can be set up in minutes and units start around $300,000, which puts them “several orders of magnitude less [in cost] than other traditional medical solutions,” he said. Each unit includes a hardened exterior for force protection, providing more protection than a tent.

    But the most important upgrade is the integration of modern information technology into battlefield medicine—sensors, connectivity, and other features–that have been shown to improve medical outcomes in emergency triage situations. In essence, each unit is both a sickbay but also a computer platform with an operating system capable of running apps.

    Sciulli told Defense One: “A big emphasis for us in building Harbor [operating system] was the ability to do a lot of treatment remotely, including embedded telehealth, remote monitoring of various vitals, offline clinical resources—think video-assisted guides for different procedures and emergency medicine—and even remote control of certain devices, including ventilators, IV fluid pumps, and IV syringe pumps. It’s both about making it easier for clinicians and medics on the ground to do more with less, and for remote caregivers to be more connected and able to help actively on the front lines.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Oracle on Saturday issued a security alert warning of a fresh security flaw impacting its E-Business Suite that it said could allow unauthorized access to sensitive data. The vulnerability, tracked as CVE-2025-61884, carries a CVSS score of 7.5, indicating high severity. It affects versions from 12.2.3 through 12.2.14. “Easily exploitable vulnerability allows an unauthenticated attacker with

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors are increasingly abusing Discord webhooks as covert command-and-control (C2) channels inside open-source packages, enabling stealthy exfiltration of secrets, host telemetry, and developer environment data without standing up bespoke infrastructure. Socket’s Threat Research Team has documented active abuse across npm, PyPI, and RubyGems, where hard-coded Discord webhook URLs act as write-only sinks to siphon […]

    The post Threat Actors Exploit Discord Webhooks for C2 via npm, PyPI, and Ruby Packages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶