• Welcome to this week’s edition of the Cybersecurity Newsletter Weekly, where we dive into the most pressing threats and vulnerabilities shaping the digital landscape.

    As cyber risks continue to evolve at breakneck speed, our October 12, 2025, roundup spotlights a Discord platform breach exposing user data to potential exploitation, the alarming Red Hat data leak that compromised enterprise credentials and source code, critical flaws in 7-Zip software enabling arbitrary code execution, and a sophisticated hack targeting SonicWall firewalls that could bypass network defenses.

    These incidents underscore the urgent need for proactive patching and monitoring. Stay ahead with our detailed breakdowns and mitigation strategies below.

    Threats

    Threat Actors Enhance WARMCOOKIE Backdoor

    The WARMCOOKIE backdoor, first detected in mid-2024 via phishing campaigns, has been updated with new features for better stealth and functionality. Recent variants use dynamic string banks for folder paths and mutexes, enabling execution of executables, DLLs, and PowerShell scripts through temporary directories. These changes allow operators to maintain persistent access in enterprise networks, evading detection while deploying secondary payloads.​

    Read more: https://cybersecuritynews.com/threat-actors-behind-warmcookie-malware/

    Ransomware Groups Abuse Remote Access Tools

    Ransomware operators in 2025 have increasingly targeted legitimate remote access tools like AnyDesk and Splashtop for persistence in enterprise environments. Attackers hijack preinstalled tools or silently install them using command-line flags to blend malicious activity with normal IT operations, often escalating privileges and disabling defenses. This tactic has led to encrypted data, wiped backups, and extended dwell times in campaigns linked to groups like LockBit and Black Basta.​

    Read more: https://cybersecuritynews.com/ransomware-gangs-leverage-remote-access-tools/

    APT Hackers Weaponize ChatGPT for Malware and Phishing

    A China-aligned APT group, tracked as UTA0388, has exploited OpenAI’s ChatGPT since June 2025 to generate sophisticated malware payloads and personalized spear-phishing emails. The AI assists in creating obfuscated code for initial access, C2 modules, and convincing phishing content that bypasses traditional filters by eliminating grammatical errors. This integration accelerates attack development, making campaigns more efficient and harder to detect.​

    Read more: https://cybersecuritynews.com/chatgpt-malware-and-phishing/

    Crimson Collective Targets AWS for Data Exfiltration

    The Crimson Collective, a new threat group, focuses on AWS environments by compromising access keys and escalating privileges to steal sensitive data, as seen in their claimed breach of Red Hat’s GitLab repositories. They use tools like TruffleHog for credential reconnaissance, create new user accounts for persistence, and leverage AWS services for exfiltration to avoid traditional C2 detection. This approach highlights vulnerabilities in cloud misconfigurations and supply chain elements.​

    Read more: https://cybersecuritynews.com/crimson-collective-leverages-aws-services/

    Attackers Exploit Velociraptor DFIR Tool in Ransomware Hits

    Ransomware actors, including Storm-2603, have repurposed the open-source DFIR tool Velociraptor (version 0.73.4.0) via a privilege escalation flaw (CVE-2025-6264) to gain remote access in attacks on VMware ESXi and Windows servers. The tool enables stealthy endpoint monitoring, lateral movement, and deployment of Warlock, LockBit, and Babuk ransomware after initial access through SharePoint vulnerabilities. This abuse underscores the risks of dual-use security tools in unmonitored environments.​

    Read more: https://cybersecuritynews.com/dfir-tool-velociraptor-exploited/

    Hackers Advance ClickFix with Cache Smuggling Technique

    A new ClickFix variant employs cache smuggling to deliver malware without direct downloads, masquerading as a Fortinet VPN checker to trick users into running PowerShell commands via the browser cache. The technique stores obfuscated ZIP payloads as fake JPEG images, extracting them to set up scheduled tasks for C2 connections post-reboot. This evolution evades network-based detections and has been observed in campaigns targeting public Wi-Fi users.​

    Read more: https://cybersecuritynews.com/hackers-upgraded-clickfix-attack/

    SnakeKeylogger Spreads Through Phishing Emails

    SnakeKeylogger, a .NET-based credential stealer, is distributed via weaponized emails posing as CPA payment files with ISO or ZIP attachments containing BAT scripts that invoke PowerShell for payload execution. It captures keystrokes, clipboard data, screenshots, and browser credentials before exfiltrating to C2 servers, often impersonating financial institutions to lure victims. The malware’s modular design and reliance on native Windows tools make it persistent and hard to detect without behavioral analysis.​

    Read more: https://cybersecuritynews.com/snakekeylogger-via-weaponized-e-mails/

    MalTerminal Uses GPT-4 for Dynamic Ransomware Generation

    MalTerminal, an early LLM-embedded malware, leverages OpenAI’s GPT-4 API to generate ransomware encryption code or reverse shells on the fly, adapting payloads during runtime for evasion. Discovered as a potential proof-of-concept, it prompts the AI for malicious scripts based on user input, shifting signatures dynamically and challenging static detection methods. This represents a novel use of LLMs in malware, potentially enabling autonomous attacks.​

    Read more: https://cybersecuritynews.com/llm-enabled-malterminal-malware-gpt-4/

    Cyber Attacks

    Oracle E-Business Suite Zero-Day RCE

    The UK’s National Cyber Security Centre (NCSC) issued an urgent warning about a critical zero-day vulnerability in Oracle E-Business Suite (EBS), tracked as CVE-2025-61882, which enables unauthenticated remote code execution via the BI Publisher Integration component. Organizations using EBS versions 12.2.3 to 12.2.14, particularly those with internet-exposed instances, face high risk from specially crafted HTTP requests that require no authentication or user interaction. Exploitation could lead to data exfiltration or system takeover, with indicators including anomalous servlet URIs and suspicious outbound connections. Mitigation involves applying Oracle’s October 2023 Critical Patch Update and dedicated patch, alongside scanning for IoCs and restricting public access with web application firewalls.​ Read more

    CISA Adds Windows Privilege Escalation to KEV Catalog

    CISA added CVE-2021-43226, a privilege escalation vulnerability in the Microsoft Windows Common Log File System (CLFS) Driver, to its Known Exploited Vulnerabilities catalog on October 6, 2025. This flaw allows local authenticated attackers to elevate privileges to SYSTEM level through buffer overflows triggered by malicious CLFS log files, affecting Windows 10, 11, and various Server editions. Proof-of-concept code is circulating, heightening risks in environments where initial access has been gained via phishing. Federal agencies and critical infrastructure must patch by October 27, 2025, prioritizing domain controllers and using tools like Microsoft Baseline Security Analyzer for assessments. Monitor Event IDs 4656 and 4658 for unauthorized access attempts involving clfs.sys.​ Read more

    Cisco ASA/FTD 0-Day Authentication Bypass

    Cisco disclosed a zero-day vulnerability, CVE-2025-20362, in ASA and FTD software that enables authentication bypass through a path traversal flaw in the VPN web server component. Attackers can exploit this critical issue, rated CVSS 9.1, on devices with remote access VPN enabled to gain unauthorized access without credentials. A proof-of-concept has been released, and active exploitation is underway, potentially leading to remote code execution in chained attacks. Affected versions include those prior to recent patches; users should immediately apply updates from Cisco’s advisory and review configurations for exposed VPN portals. Enhanced logging and intrusion detection rules are recommended to spot traversal attempts in access logs.​ Read more

    Surge in Attacks on Palo Alto GlobalProtect Portals

    Attacks targeting Palo Alto Networks PAN-OS GlobalProtect login portals have escalated dramatically, with over 2,200 unique IP addresses launching probes in recent days. This surge follows patterns seen before vulnerability disclosures, focusing on reconnaissance for weaknesses like the prior CVE-2024-3400 command injection flaw. Malicious actors are scanning for unpatched firewalls to enable remote code execution with root privileges. Organizations should audit March 2025 logs, apply all PAN-OS patches, block suspicious IPs, and implement multi-factor authentication on VPNs. Threat hunting and enhanced monitoring of portal access attempts are critical to detect ongoing campaigns.​ Read more

    Mustang Panda Deploys Novel DLL Side-Loading

    Chinese threat actor Mustang Panda has resurfaced with a new DLL side-loading technique to deliver malware, targeting government and military entities in East Asia. The campaign uses weaponized RAR archives containing legitimate signed executables paired with malicious DLLs, evading detection by leveraging trusted binaries. Once sideloaded, the DLLs deploy variants of ToneShell backdoor, communicating via custom encrypted protocols mimicking TLS traffic. Victims extract and run the files, leading to data exfiltration and persistence through autorun entries. Defenses include scanning archives for mismatched DLLs, restricting executable downloads, and monitoring for anomalous network patterns like FakeTLS headers.​ Read more

    SonicWall Breach Exposes Customer Backups

    SonicWall confirmed a data breach where hackers stole firewall configuration backup files for all customers, potentially exposing sensitive network details. The unauthorized access occurred through a compromised third-party support portal, allowing retrieval of backups without authentication in some cases. This incident heightens risks of targeted attacks using stolen configs to craft exploits or map internal networks. Affected customers should rotate credentials, review access logs, and apply any available patches to SonicWall devices. The company is notifying impacted users and enhancing portal security with stricter controls.​ Read more

    Vulnerabilities

    Google Chrome RCE Vulnerability

    Researchers disclosed a critical remote code execution flaw in Google Chrome’s V8 JavaScript engine, stemming from a WebAssembly type canonicalization bug that fails to distinguish nullability in reference types, enabling hash collisions via birthday attacks. The exploit combines this with a V8 sandbox bypass using JavaScript Promise Integration flaws to achieve full stack control and execute shellcode, such as spawning calc.exe on Windows. Users should update to Chrome version M137.0.7151.57 or later to patch the nullability checks and restore type safety.

    Read more: https://cybersecuritynews.com/google-chrome-rce-vulnerability/

    Redis RCE Vulnerability

    A 13-year-old use-after-free vulnerability in Redis, tracked as CVE-2025-49844 with a CVSS score of 10.0, allows post-authentication attackers to escape the Lua sandbox and execute arbitrary code on the host system via crafted scripts. This flaw affects an estimated 330,000 internet-exposed Redis instances, with 60,000 lacking authentication, enabling data theft, encryption, or lateral movement. Mitigation involves upgrading to patched versions released on October 3, 2025, enabling authentication, disabling Lua if unused, and restricting network access.

    Read more: https://cybersecuritynews.com/redis-rce-vulnerability/

    OpenSSH ProxyCommand Vulnerability

    OpenSSH versions before 10.1 contain a command injection flaw, CVE-2025-61984, that bypasses prior fixes by allowing control characters like newlines in usernames passed via ProxyCommand, leading to remote code execution in shells like Bash. Attackers can exploit this through malicious Git submodules in recursive clones if SSH configs use unquoted %r tokens, injecting payloads after a syntax error. Upgrade to OpenSSH 10.1, which bans control characters, or quote %r in ProxyCommand directives to prevent exploitation.

    Read more: https://cybersecuritynews.com/openssh-vulnerability-proxycommand/

    AWS ClientVPN macOS Vulnerability

    A critical privilege escalation vulnerability, CVE-2025-11462, in AWS Client VPN for macOS versions 1.3.2 to 5.2.0 arises from improper log rotation validation, allowing non-admin users to create symbolic links and overwrite system files for root access. Attackers can exploit this to execute arbitrary code as root by targeting files like crontab during log writes, compromising the entire macOS device. Upgrade to version 5.2.1 immediately, as no other mitigations exist, and restrict local file modifications in log directories. Read more: https://cybersecuritynews.com/aws-clientvpn-for-macos-vulnerability/varutra+3

    CrowdStrike Falcon Sensor Vulnerability

    CrowdStrike disclosed two medium-severity flaws in its Falcon sensor for Windows, CVE-2025-42701 (race condition, CVSS 5.6) and CVE-2025-42706 (logic error, CVSS 6.5), enabling attackers with prior code execution to delete arbitrary files and disrupt system stability. These TOCTOU and origin validation issues affect Windows 7 and later, potentially targeting sensor or OS components. Apply sensor version 7.29 or hotfixes for earlier versions to remediate, as no remote exploitation is possible without initial access. Read more:

    https://cybersecuritynews.com/crowdstrike-falcon-windows-sensor-vulnerability/

    GitLab Security Update

    GitLab released patches in versions 18.4.2, 18.3.4, and 18.2.8 to address multiple DoS vulnerabilities, including high-severity CVE-2025-10004 allowing unauthenticated GraphQL queries to exhaust resources by requesting large blobs. Another high-severity issue, CVE-2025-11340, permits read-only token users to perform unauthorized writes in Enterprise Edition via GraphQL mutations. Self-managed instances should upgrade promptly, while GitLab.com and Dedicated are already protected; monitor advisories for further risks.

    Read more: https://cybersecuritynews.com/gitlab-security-update-vulnerabilities/

    7-Zip Vulnerabilities

    Two high-severity flaws in 7-Zip, CVE-2025-11001 and CVE-2025-11002 (both CVSS 7.0), involve improper symbolic link handling in ZIP files, enabling directory traversal and arbitrary file writes leading to code execution upon extraction. Attackers craft malicious archives to escape extraction paths and overwrite sensitive files, affecting versions before 25.00 released in July 2025. Update to 7-Zip 25.01 manually, as no auto-updates exist, and avoid extracting untrusted archives to prevent compromise.

    Read more: https://cybersecuritynews.com/7-zip-vulnerabilities/

    GitHub Copilot Vulnerability

    A critical flaw in GitHub Copilot Chat (CVSS 9.6) allows remote prompt injection combined with CSP bypass to exfiltrate private repository data, including AWS keys and source code, by encoding content in URLs or images rendered in victim chats. Attackers influence responses across users via hidden Markdown comments in pull requests, injecting malicious code suggestions or prompts to access private repos. GitHub fixed this by disabling image rendering in Copilot Chat; users should avoid clicking suspicious links in AI responses and monitor for anomalous data access.

    Read more: https://cybersecuritynews.com/github-copilot-vulnerability/securityweek+2

    Malicious Code in Antivirus

    The IAmAntimalware technique enables attackers to inject malicious code into antivirus processes, bypassing defenses by hiding malware within security software for persistence and evasion. This requires initial system access for code injection, potentially via privilege escalation, allowing manipulation of alerts and undetected operations. Mitigate by monitoring AV process integrity, enforcing code signing, updating software regularly, and using layered EDR for anomalous behavior detection.

    Read more:https://cybersecuritynews.com/malicious-code-into-antivirus/

    ​Data Breach

    Red Hat Breach

    Crimson Collective compromised Red Hat Consulting’s infrastructure, exfiltrating 32 million files including sensitive data from over 5,000 enterprise customers like Vodafone and HSBC, with ties to LAPSUS$ via attacker “Miku” (Thalha Jubair). Exposed .pfx certificates from financial and airline sectors enable man-in-the-middle attacks and spoofing, affecting critical infrastructure in finance, healthcare, and transport. Experts recommend certificate rotation and credential updates to mitigate secondary risks from leaked network details and API keys.​

    Read more: https://cybersecuritynews.com/red-hat-breach/

    Discord Data Exposure

    A Zendesk breach at Discord’s third-party support exposed 1.5 TB of data for ~70,000 users, including 2.1 million ID photos, names, emails, and partial billing info, claimed by Scattered Lapsus$ Hunters. Access lasted 58 hours via a compromised agent account, targeting support interactions without affecting passwords or full cards. Discord terminated the vendor, notified users via email, and engaged forensics and law enforcement to counter the extortion.​

    Read more: https://cybersecuritynews.com/discord-data-breach-sensitive-data/

    Microsoft Events Flaw

    A vulnerability in Microsoft Events exposed user names and emails from registration/waitlist databases due to access control misconfigurations, discovered by teen hacker Faav. This risks phishing and identity theft for event participants, highlighting needs for better data segregation. Microsoft patched the issue, urging audits and minimized data handling to prevent exploitation.​

    Read more: https://cybersecuritynews.com/microsoft-events-vulnerability/

    Tools

    Forensic-Timeliner v2.2 Update

    Forensic-Timeliner, a Windows forensic tool developed by Acquired Security for DFIR investigators, has released version 2.2 with enhanced automation and improved artifact support. This update consolidates CSV outputs from tools like EZ Tools, KAPE, Axiom, Chainsaw, Hayabusa, and Nirsoft into a unified timeline, enabling rapid reconstruction of event sequences and identification of indicators of compromise. New features include silent mode for headless execution, filter previews via Spectre.Console tables, and keyword tagging for Timeline Explorer integration, alongside date filtering, deduplication, and YAML-configurable parsers for customizable enrichment.​

    Read more: https://cybersecuritynews.com/forensic-timeliner-windows-forensic-tool/

    llm-tools-nmap Kali Linux Tool

    Kali Linux 2025.3 introduces llm-tools-nmap, an experimental plugin that integrates Simon Willison’s LLM tool with Nmap for AI-driven network scanning and security auditing. This bridge allows natural language commands to translate into Nmap actions, supporting network discovery, quick scans of common ports, service detection, OS profiling, and NSE script execution. Installation requires Python 3.7+, the LLM tool, and Nmap, with functions like nmap_quick_scan and nmap_script_scan invoked via the –functions flag, though users must ensure permissions and comply with policies due to experimental risks.​

    Read more: https://cybersecuritynews.com/nmap-tool-for-network-scanning/

    VirusTotal Platform Access Changes

    VirusTotal has updated its platform to simplify access and pricing, introducing streamlined tiers to enhance usability for researchers while rewarding contributors. The free Community Tier remains for individuals with file/URL scanning and public API access, while the Lite Tier at $5,000/year offers advanced search, YARA rules, and private API for small teams. A new Contributor Tier provides free blindspot feeds and discounts for engine partners, and the customizable Duet Tier supports enterprises with high API quotas, emphasizing collaboration under Google Threat Intelligence.​

    Read more: https://cybersecuritynews.com/virustotal-simplifies-user-options/

    Linux and Windows​

    Microsoft Teams Multitasking Update

    Microsoft plans to introduce a multitasking feature in Teams next month, enabling users to open channels in separate windows for better workflow efficiency. This addresses frequent user complaints about switching between conversations in a single interface, which disrupts focus and productivity. The update, tracked as feature ID 509110, extends existing pop-out options for chats and meetings to channels, allowing persistent visibility of important discussions alongside other tasks. For example, developers can monitor technical channels while coding, reducing context switching and mental fatigue. This enhancement signals Microsoft’s commitment to usability improvements in its collaboration platform.​ Read more

    Microsoft 365 Outage Blocks Access

    A major Microsoft 365 outage struck on October 8, 2025, blocking access to Teams, Exchange Online, and the admin center for users worldwide. The issue stemmed from a directory operations problem in backend infrastructure, prompting immediate investigation by Microsoft teams. By late evening, engineers identified the cause and began rebalancing affected services to redirect traffic and restore functionality. Recovery progressed overnight, with services returning online for most users by October 9, though monitoring continued to ensure stability. This incident underscores the risks of authentication dependencies in cloud environments.​ Read more

    Linux Kernel ksmbd Vulnerability Exploited

    Security researcher Norbert Szetei released a proof-of-concept exploit for CVE-2025-37947, a high-severity out-of-bounds write flaw in the Linux kernel’s ksmbd SMB server module on October 9, 2025. This vulnerability allows authenticated local attackers to corrupt kernel memory, potentially enabling privilege escalation to root access. The ksmbd component handles SMB3 file sharing, making it a prime target for network-based attacks in Linux environments. No patches are available yet, but distributions like SUSE are developing fixes amid active exploitation reports. Organizations using ksmbd should disable the module or restrict access until remediation.​ Read more

    Microsoft 365 Outage Disrupts Services

    On October 9, 2025, another Microsoft 365 disruption affected global users, preventing authentication and access to Teams and Exchange Online due to Azure Front Door capacity issues. The outage, linked to Kubernetes instance failures, caused delays and timeouts across regions including Europe and Africa. Microsoft mitigated by restarting affected instances and rerouting traffic, restoring about 98% of services while investigating recent configuration changes. Intermittent problems persisted for some, including cloud PC access via web clients. This event highlights cascading risks in interconnected cloud infrastructure.​ Read more

    Microsoft Azure Global Outage

    Microsoft Azure faced a widespread outage on October 9, 2025, impacting services like the Azure Portal, Entra ID, and tied Microsoft 365 components across multiple regions. The disruption originated from capacity loss in 21 Azure Front Door environments, exacerbated by Kubernetes orchestration failures and potential misconfigurations in North America. Engineers rebalanced infrastructure and initiated failovers, resolving most issues within hours but prompting reviews of traffic management for resilience. This affected business operations globally, emphasizing the need for robust disaster recovery in cloud-dependent setups. Penetration testing could help identify similar vulnerabilities preemptively.​ Read more

    Windows 11 Update and Shutdown Bug Fix

    Microsoft addressed a persistent Windows 11 bug in October 2025 preview builds, where the “Update and shutdown” option would restart the PC instead of powering it off after installing updates. This issue, reported since 2023, often led to unexpected reboots and fan noise during idle periods as failed updates triggered retries. The fix ensures proper shutdown behavior, allowing post-update phases to complete on next boot. It applies to versions like 24H2 and 25H2, with stable rollout expected soon. Users on preview channels can test it now to verify reliability.​ Read more

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Cybersecurity Newsletter Weekly – Discord, Red Hat Data Breach, 7-Zip Vulnerabilities and Sonicwall Firewall Hack appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • VirusTotal (VT) is making important changes to its platform access and pricing. These updates aim to improve accessibility and strengthen its commitment to collaboration.

    The initiative, detailed in a recent company announcement, aims to simplify user options while reinforcing VT’s commitment to the global cybersecurity community as an open, collaborative platform for the common good.

    The changes come in light of community feedback and as part of a broader evolution within Google’s security ecosystem, which now features the unified Google Threat Intelligence (GTI) platform.

    Founded on the principle that collective effort strengthens cyber defense, VirusTotal is refocusing on three primary goals: preserving the platform’s openness, providing a sustainable framework for contributors, and improving access for academics and researchers.

    The company emphasized that while Google Threat Intelligence, which combines the power of VT, Mandiant, and Google, delivers advanced, curated intelligence for enterprises, VirusTotal will remain the community-driven foundation for threat sharing and analysis.

    This dual approach allows VT to serve its core user base while integrating its vast data into Google’s more comprehensive enterprise offerings.

    New Tiers For A Diverse Community

    Key to the announcement is the launch of simplified pricing and new access tiers aimed at serving a diverse user base, from individual researchers to large organizations.

    A key addition is the VT Contributor tier, a dedicated model for technology partners who integrate their detection engines with the platform.

    This tier rewards their crucial role with free access to feeds of their blind spots, priority support, and early access to new features. The other tiers include:

    • VT Community: A robust free tier for individual researchers, academics, and educators, offering file and URL scanning, public API access, and community features.
    • VT Lite: Aimed at small teams, startups, and small MSSPs for non-commercial use, this tier provides advanced search, YARA hunting, and private scanning capabilities, with pricing starting from $5,000 for low API volumes.
    • VT Duet: Designed for large organizations, this option provides the full feature set with a high API quota.

    In a move that reaffirms a long-standing 2016 commitment, VirusTotal stated that security vendors who do not contribute detections are not included in these new tiers.

    This decision underscores the company’s focus on fostering a “healthy community” where participation and contribution are valued.

    The company actively encourages organizations to become contributors and join its mission of protecting the digital commons.

    This evolution ensures that VirusTotal continues to serve as a transparent, collaborative hub for global threat intelligence, strengthening its foundational role in the cybersecurity landscape for years to come.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post VirusTotal Simplifies User Options With Platform Access and New Contributor Model appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new technique enables attackers to exploit antivirus software by injecting harmful code directly into the antivirus processes. This approach makes it easier for them to evade detection and compromise the security that antivirus software is designed to provide.

    This method, detailed by cybersecurity researcher Two Seven One Three on X (@TwoSevenOneT), involves cloning protected services and hijacking cryptographic providers to create a backdoor in the antivirus installation folder, bypassing standard defenses.

    The approach highlights a vulnerability in how antivirus solutions prioritize their own stability. By injecting code into these “unkillable” processes, researchers gain elevated privileges to perform actions like writing files to restricted directories, all while evading detection.

    As antivirus programs evolve to combat sophisticated threats, such techniques underscore the delicate balance between robust security and operational reliability.

    Bypassing Antivirus Defenses

    Antivirus software employs multiple strategies to shield its core processes from interference, ensuring uninterrupted protection for users.

    These programs typically run with SYSTEM-level privileges, granting them broad access to monitor and neutralize threats across the system.

    Process introspection allows the antivirus to vigilantly scan its own threads for anomalies, such as unauthorized code injections from external sources.

    Further safeguards include code integrity checks that verify the authenticity of loaded modules and the use of Windows’ Protected Process Light (PPL) feature.

    This isolates user-mode processes, preventing tampering even by administrators. In the kernel, antivirus drivers deploy sensors to block alterations to detection mechanisms, while self-protection routines automatically restart compromised components or alert on suspicious activity.

    Determining which processes qualify for protection is equally meticulous. Developers avoid simplistic checks like process names, which attackers could spoof by mimicking filenames.

    Instead, solutions like Bitdefender combine verification of the process’s ImagePath, ensuring the executable resides in the correct directory, with restrictions on file writes to installation folders.

    Digital signatures of loaded DLLs add another layer, though attackers can attempt to bypass these through advanced evasion tactics.

    Modifying the Process Environment Block (PEB) or using the CreateProcess API handles proves futile, as kernel drivers monitor initialization from the outset.

    Service Cloning and Injection Methods

    The technique’s ingenuity lies in leveraging the antivirus’s reliance on operating system features while exploiting less-guarded auxiliary components.

    Modern antivirus suites bundle extras like firewalls, VPNs, and user interfaces, each running protected processes with installation folder write access. Since direct termination or suspension of these is blocked short of kernel exploits or tools like EDR-Freeze, researchers turn to cloning.

    By manually exporting and importing registry keys for an antivirus service, such as Bitdefender’s BDProtSrv, a duplicate service can be created with identical configurations.

    A system reboot loads this clone into Services.exe’s cache, spawning a new protected process. Testing with Process Explorer confirms protection via “access denied” errors when attempting termination.

    Injection occurs by hijacking the Windows Cryptography API, which antivirus processes use for encryption and signing. Modifying the registry key HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider to point to a malicious DLL triggers loading during service startup.

    To evade signature checks, the DLL is signed using cloned certificates from legitimate Windows programs, a method detailed in SpecterOps research.

    Steps include creating the cloned service, altering the provider, trusting the signature, launching the service, verifying execution, and restoring the registry to avoid instability.

    IAmAntimalware: A Tool for Testing and Evasion

    To automate this process, Two Seven One Three developed IAmAntimalware, an open-source tool available on GitHub. It clones services, modifies cryptographic providers or COM objects, imports certificates, and starts the duplication all with command-line parameters specifying the original service, clone name, certificate file, and DLL path.

    In tests with Bitdefender, the tool signed a sample DLL using CertClone, another GitHub utility that duplicates signatures. The DLL, which outputs debug strings and writes a “mark.txt” file to the installation folder, was successfully injected after execution.

    Similar results emerged with Trend Micro and Avast, though Avast required tweaks to target its GUI process for reliability. This method’s implications are profound: malware could embed backdoors in antivirus environments, executing undetected.

    Prevention demands vigilant monitoring of module loads from anomalous paths, auditing trusted certificates in the registry, and enforcing PPL alongside behavioral analytics.

    As pentesting evolves, such disclosures push antivirus vendors to fortify against their own strengths turning into liabilities.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Can Inject Malicious Code into Antivirus Processes to Create a Backdoor appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical flaws uncovered in the network communication between Microsoft Defender for Endpoint (DFE) and its cloud services, allowing post-breach attackers to bypass authentication, spoof data, disclose sensitive information, and even upload malicious files to investigation packages.

    These vulnerabilities, detailed in a recent analysis by InfoGuard Labs, highlight ongoing risks in endpoint detection and response (EDR) systems, potentially undermining incident response efforts.

    Reported to Microsoft’s Security Response Center (MSRC) in July 2025, the issues were deemed low severity, with no fixes confirmed as of October 2025.

    The research builds on prior explorations of EDR attack surfaces, focusing on the agent’s interaction with cloud backends. By intercepting traffic using tools like Burp Suite and bypassing certificate pinning through memory patches in WinDbg, the analysis revealed how DFE’s MsSense.exe process handles commands and data uploads.

    Certificate pinning, a common security measure, was circumvented by altering the CRYPT32!CertVerifyCertificateChainPolicy function to always return a valid result, enabling plaintext inspection of HTTPS traffic.

    Similar patches were applied to SenseIR.exe for complete interception, including Azure Blob uploads.

    Azure Upload
    Azure Upload

    Authentication Bypasses and Command Interception

    According to InfoGuard Labs the core issue lies in the agent’s requests to endpoints like https://[location-specific-host]/edr/commands/cnc, where it polls for commands such as isolation, forensics collection, or scans.

    Despite including Authorization tokens and Msadeviceticket headers, the backend ignores them entirely. An attacker with the machine ID and tenant ID easily obtainable by low-privileged users via registry reads can impersonate the agent and intercept responses.

    For instance, an intruder tool like Burp’s Intruder can continuously query the endpoint, snatching available commands before the legitimate agent receives them.

    This allows spoofing responses, such as faking an “Already isolated” status for an isolationcommand, leaving the device unisolated while the Microsoft Defender Portal reports it as secured.

    The serialization format, often in Microsoft Bond, complicates manual crafting, but capturing and modifying legitimate responses suffices for proof-of-concept exploits.

    A parallel vulnerability affects /senseir/v1/actions/ endpoints for Live Response and Automated Investigations. Here, CloudLR tokens are similarly ignored, obtainable without authentication using just the machine ID.

    Attackers can decode action payloads with custom scripts leveraging large language models for Bond deserialization and upload fabricated data to provided Azure Blob URIs via SAS tokens, which remain valid for months.

    Information Disclosure and Malicious File Risks

    Unauthenticated access extends to incident response (IR) exclusions via the registration endpoint, requiring only the organization ID from the registry.

    More alarmingly, polling /edr/commands/cnc without credentials yields an 8MB configuration dump, including RegistryMonitoringConfiguration, DriverReadWriteAccessProcessList, and ASR rules. While not tenant-specific, this data reveals detection logic valuable for evasion.

    Post-breach, attackers can enumerate investigation packages on the filesystem, readable by any user, containing autoruns, installed programs, and network connections.

    For ongoing investigations, spoofed uploads to these packages enable embedding malicious files with innocuous names, tricking analysts into execution during review.

    These flaws underscore the challenges in securing EDR communications, where simple oversights persist despite multiple token types. The analyst urges remediation, arguing that post-breach disruption and analyst-targeted attacks merit a higher priority than MSRC’s assessment.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication and Upload Malicious Files appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity company Huntress on Friday warned of “widespread compromise” of SonicWall SSL VPN devices to access multiple customer environments. “Threat actors are authenticating into multiple accounts rapidly across compromised devices,” it said. “The speed and scale of these attacks imply that the attackers appear to control valid credentials rather than brute-forcing.” A significant chunk of

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors are abusing Velociraptor, an open-source digital forensics and incident response (DFIR) tool, in connection with ransomware attacks likely orchestrated by Storm-2603 (aka CL-CRI-1040 or Gold Salem), which is known for deploying the Warlock and LockBit ransomware. The threat actor’s use of the security utility was documented by Sophos last month. It’s assessed that the attackers

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has rolled out a fix in its latest preview builds to resolve a notorious glitch with the “update and shut down” feature.

    This long-standing issue, which has haunted the operating system for years, tricked users into believing their PCs were powering off when updates were pending, only for the machines to restart unexpectedly and disrupt sleep cycles with noisy fans.

    The bug emerged shortly after Windows 11’s launch in 2021 and quickly became a source of irritation across forums and social media.

    When users selected the “update and shut down” option from the Start menu or Windows Update settings, the system appeared to comply by initiating the shutdown process.

    However, instead of fully powering down, the PC would install the update and reboot, often landing back at the lock screen or desktop. This behavior stemmed from how Windows handles cumulative updates, which bundle security patches, bug fixes, and feature improvements.

    If an update encountered even a minor hiccup during installation, such as a temporary file lock or driver conflict, the system would default to a restart rather than a clean shutdown. Overnight, idle detection kicked in, prompting another installation attempt and creating a cycle of unwanted reboots.

    User complaints painted a vivid picture of the annoyance. Home users described coming downstairs in the middle of the night to find their desktops humming loudly, with fans whirring at full speed to cool spiking CPU and disk activity.

    Office workers reported interrupted workflows, as machines that should have been off instead cycled through updates during off-hours, potentially exposing sensitive data or draining power unnecessarily.

    The issue wasn’t universal but affected a significant portion of Windows 11 devices, especially those on older hardware, where update failures were more common due to compatibility quirks.

    Microsoft’s Patch in Preview Builds

    Microsoft acknowledged the problem in its Windows Insider preview blog on September 29, 2025, detailing Build 26220.6760 for the Dev Channel. The release notes simply state: “Fixed an underlying issue which could lead ‘Update and shutdown’ to not actually shut down your PC after.”

    This fix targets the core mechanics of the shutdown sequence, ensuring that pending updates no longer trigger automatic restarts if a shutdown is explicitly requested.

    Testing in the Insider program has shown promising results, with early feedback indicating that PCs now properly power off as intended, halting the disruptive cycle.

    The company highlighted that this is part of broader efforts to refine Windows Update’s reliability. Preview builds like this one allow Microsoft to iron out issues before they hit the stable release, expected in a future monthly update.

    For now, Insiders in the Dev or Beta channels can access the fix by enabling the toggle in Settings > Windows Update. Microsoft advised non-Insiders to hold off, as preview software carries risks like instability.

    This resolution brings much-needed relief to the Windows 11 community, where the bug had eroded trust in the update process.

    Power users and IT administrators, who rely on scheduled shutdowns for maintenance, stand to benefit most, avoiding the manual interventions that previously mitigated the problem.

    As Windows 11 approaches its fourth year, such fixes underscore Microsoft’s commitment to polishing the user experience amid competition from macOS and Linux distributions.

    Looking ahead, experts predict this could pave the way for smarter update controls, like customizable shutdown behaviors or AI-driven failure predictions.

    For everyday users, the immediate takeaway is simpler: the next time an update prompts “update and shut down,” it should finally mean what it says. With the fix now in testing, a stable rollout could arrive by late 2025, restoring peace to late-night computing.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft Fixes Long-standing Windows 11 ‘Update and Shut down’ Bug appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have identified a new, active campaign of the Stealit malware that uses an experimental Node.js feature to infect Windows systems. According to a report from FortiGuard Labs, threat actors are leveraging Node.js’s Single Executable Application (SEA) functionality to package and distribute their malicious payloads. This updated tactic marks a shift from previous Stealit […]

    The post New Stealit Malware Exploits Node.js Extensions to Target Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Clicking on a malicious link can quickly turn your device into a security risk. Just seconds after clicking, your browser might start downloading malware, taking advantage of weaknesses, or sending you to fake websites that try to steal your personal information.

    The crucial moments following this action determine whether you’ll successfully contain the threat or become another victim of cybercrime.

    This comprehensive guide provides the essential steps every computer and mobile device user must take to protect themselves and their data when they realize they’ve clicked on a suspicious link.​

    Immediate Response Flowchart for Suspicious Link Clicks

    The immediate response to clicking a suspicious link requires swift, strong action across multiple fronts. Modern phishing attacks have evolved far beyond simple email scams, now incorporating sophisticated social engineering techniques, artificial intelligence-powered content generation, and advanced malware delivery systems that can compromise devices within seconds.

    Understanding the proper response protocol can mean the difference between a minor security scare and a devastating data breach that could cost thousands of dollars and months of recovery time.​

    Understanding The Immediate Threats

    Automatic Malware Downloads And Drive-by Attacks

    The moment you click a malicious link, several dangerous processes can begin automatically without any additional user interaction.

    Drive-by downloads represent one of the most insidious threats, as they exploit vulnerabilities in web browsers, plugins, or operating systems to install malware on your device silently.

    These attacks work by scanning your system for unpatched software vulnerabilities and automatically selecting the appropriate exploit to compromise your device.​

    Modern drive-by download attacks operate through multiple vectors, including compromised legitimate websites, malicious advertisements (malvertising), and specially crafted phishing sites.

    The malware payload can range from ransomware and keyloggers to remote access trojans that give cybercriminals complete control over your device.

    What makes these attacks particularly dangerous is their stealth nature – the entire infection process occurs in the background, often without any visible indicators that your system has been compromised.​

    The sophistication of these attacks has increased dramatically in recent years. Attackers now use exploit kits – automated toolkits that identify and exploit system vulnerabilities – to maximize their success rates.

    These kits can detect your browser version, installed plugins, and operating system configuration to deploy the most effective malware variant for your specific setup.

    Some advanced attacks even use fileless techniques, injecting malicious code directly into memory to avoid detection by traditional antivirus software.​

    Browser Exploitation And Session Hijacking

    Beyond automatic downloads, malicious links can exploit browser vulnerabilities to compromise your online sessions and steal authentication credentials.

    Cross-site scripting (XSS) attacks inject malicious JavaScript code into legitimate websites, allowing attackers to steal session cookies, capture keystrokes, or redirect users to phishing sites.

    These attacks are particularly dangerous because they abuse the trust relationship between your browser and legitimate websites.​ Session hijacking attacks specifically target the cookies that maintain your logged-in status on websites.

    Once an attacker steals these session cookies, they can impersonate you on any website where you’re currently authenticated, potentially accessing your email, banking, social media, and other sensitive accounts.

    Modern malware families increasingly include “infostealer” modules specifically designed to extract cookies from browser sessions, with these stolen credentials then sold on dark web marketplaces.​

    The implications of successful session hijacking extend far beyond individual account compromise. Attackers can use hijacked sessions to access corporate networks, steal intellectual property, or launch additional attacks against your contacts and colleagues.

    The average cost of a data breach resulting from compromised credentials exceeds $150 per record, making this a particularly expensive form of cybercrime. Until you’re certain your device is clean, it is essential to protect your entire digital ecosystem.​

    Disconnect From the Internet Immediately

    The first and most critical step is to sever your device’s connection to the internet. Unplug the Ethernet cable for a wired connection or turn off the Wi-Fi on your device.

    This action can prevent malware from fully installing, stop it from spreading to other devices on your network, and cut off any unauthorized transmission of your data to an attacker’s server.​

    Back Up Your Essential Files

    Before attempting to remove any potential malware, back up your important files to an external hard drive or a USB drive. This ensures that your sensitive documents, photos, and other irreplaceable data are safe in case they are corrupted or erased during the cleanup process.

    Be selective and only back up essential files to avoid accidentally saving any malicious programs that may have been downloaded.​

    Run a Full System Scan for Malware

    Use a reputable antivirus or anti-malware program to perform a comprehensive scan of your device. This will help detect and quarantine or remove any malicious software that may have been installed when you clicked the link.

    Ensure your security software is up to date to identify the latest threats effectively. If you do not have security software, you will need to reconnect to the internet to download it briefly.​

    Change Your Passwords

    Immediately change the passwords for any accounts you may have entered credentials for on a suspicious site. It is also a critical security measure to update the passwords for your most important accounts, such as email, banking, and social media.

    Use strong, unique passwords for each account and enable multi-factor authentication (MFA) wherever possible to add a crucial layer of security.​

    Monitor Accounts and Report the Incident

    Keep a close watch on your financial statements and online accounts for any suspicious activity. If you believe sensitive information like your Social Security number was compromised, consider placing a fraud alert with the major credit bureaus.

    Finally, report the phishing attempt to relevant organizations, such as the Federal Trade Commission (FTC), the Internet Crime Complaint Center (IC3), and the company that was being impersonated. If the incident occurred on a work device, notify your IT department immediately.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post 5 Immediate Steps to be Followed After Clicking on a Malicious Link appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A massive, coordinated botnet campaign is actively targeting Remote Desktop Protocol (RDP) services across the United States.

    Security firm GreyNoise reported on October 8, 2025, that it has been tracking a significant wave of attacks originating from over 100,000 unique IP addresses spanning more than 100 countries.

    The operation appears to be centrally controlled, with the primary objective of compromising RDP infrastructure, a critical component for remote work and administration.

    The scale and organized nature of this campaign pose a significant threat to organizations that depend on RDP for their daily operations.

    The investigation into this widespread attack began after GreyNoise analysts detected an anomalous spike in traffic from Brazilian-geolocated IPs.

    This initial finding prompted a broader analysis, which quickly uncovered similar surges in activity from a multitude of countries, including Argentina, Iran, China, Mexico, Russia, and South Africa. Despite the diverse geographic origins, the attacks share a common target: RDP services within the United States.

    Botnet Targeting RDP Infrastructure
    Botnet Targeting RDP Infrastructure

    Analysts are highly confident that this activity is the work of a single, large-scale botnet. This conclusion is supported by the fact that nearly all participating IPs share a similar TCP fingerprint. This technical signature suggests a standard, centralized command-and-control structure orchestrating the attacks.

    The threat actors behind this campaign are employing two specific attack vectors to identify and compromise vulnerable systems.

    The first is an RD Web Access timing attack, a method where attackers measure the server’s response time to login attempts to differentiate between valid and invalid usernames anonymously.

    The second vector is an RDP web client login enumeration, which systematically attempts to guess user credentials. These methods allow the botnet to efficiently scan for and identify exploitable RDP access points without immediately triggering standard security alerts.

    The synchronized use of these specific, non-trivial attack methods across such a vast number of nodes further points to a coordinated operation managed by a single operator or group.

    Mitigations

    In response to this ongoing threat, GreyNoise has released specific recommendations for network defenders. The firm advises organizations to check their security logs for any unusual RDP probing proactively or failed login attempts that match the patterns of this campaign.

    For more direct protection, GreyNoise has created a dynamic blocklist template, named “microsoft-rdp-botnet-oct-25,” available through its platform.

    This allows customers to automatically block all known IP addresses associated with this malicious botnet activity, effectively cutting off the attacks at the network perimeter.

    Organizations that use RDP for remote work should check their RDP security. They need to enforce strong password policies and use multi-factor authentication whenever possible. This will help protect against large-scale hacking attempts, such as brute-force attacks.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Attacking Remote Desktop Protocol Services from 100,000+ IP Addresses appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶