-
Cybersecurity researchers have disclosed a critical flaw impacting Salesforce Agentforce, a platform for building artificial intelligence (AI) agents, that could allow attackers to potentially exfiltrate sensitive data from its customer relationship management (CRM) tool by means of an indirect prompt injection. The vulnerability has been codenamed ForcedLeak (CVSS score: 9.4) by Noma Security,
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Chinese state-sponsored cyber threat group Salt Typhoon has intensified long-term espionage operations against global telecommunications infrastructure, according to recent legal and intelligence reporting. Aligned with the Ministry of State Security (MSS) and active since at least 2019, Salt Typhoon has systematically exploited network edge devices to establish deep persistence and exfiltrate highly sensitive communications metadata, […]
The post Chinese State-Sponsored Hackers Targeting Telecommunications Infrastructure to Steal Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Federal agencies should implement mass layoffs of their workforces if the government shuts down next week, the White House told agencies on Wednesday, dramatically escalating the stakes of a potential funding lapse.
Agencies should prepare the reduction-in-force notices for all employees whose work is not funded through means other than annual appropriations and does not align with President Trump’s priorities, the Office of Management and Budget said in its memorandum. Agencies will also prepare the standard furlough notices that go out to employees not otherwise exempted to work during a shutdown, OMB said, and those actions will have no bearing on who is subject to layoffs.
While there is no direct connection between RIFs and a shutdown—and agencies generally have the authority to proceed with layoffs regardless of the status of appropriations—OMB directed agencies to drop their plans should a shutdown be avoided. The House has, in a largely party-line vote, passed a stopgap funding bill to keep agencies open through Nov. 21, but Democrats have so far blocked that measure from proceeding in the Senate. Democratic leaders have said they will block the spending bill unless Congress addresses health-care premiums set to increase at the end of the year and meets other demands.
In the memo, which was first reported by Politico, OMB told agencies not to repurpose or transfer funds to minimize the shutdown impact. That marks an about-face from the approach the first Trump administration took during an extended shutdown that began in 2018.
Agencies typically post details of who will get furloughed and who will work without immediate pay during a shutdown, but OMB removed those plans from its website earlier this year. In its new memo, the budget office noted that agencies were supposed to submit their furlough plans by Aug. 1, adding that some had not done so and asking them to send the documents as soon as possible.
A Government Executive analysis of the most recently available data shows that if a shutdown had occurred in 2023, the Biden administration had planned to furlough about 737,000 employees, or about one-third of the workforce.
Earlier this week, OMB held its first shutdown-planning call with agencies. The office noted many programs that received a funding boost in the One Big Beautiful Bill Act would be exempt from the effects of a funding lapse.
While OMB said the RIF plans would “not be necessary” if a shutdown is averted, it suggested agencies should continue to plan for RIFs even after fiscal 2026 appropriations are enacted. Agencies should revise their RIF plans to “retain the minimal number of employees necessary to carry out statutory functions” and send their proposals to OMB. That language mirrors that the Trump administration used earlier this year, when it called for all agencies to deliver layoff plans focused on the “maximum elimination” of functions not required by law.
A federal court previously found that guidance unlawful, with a judge saying OMB and the Office of Personnel Management have no authority to order layoffs at other agencies, but the Supreme Court has since overturned that ruling.
Some agencies have since walked back their plans for mass layoffs, while others, such as the Interior Department, are expected to finalize significant RIFs in the coming weeks.
Senate Minority Leader Chuck Schumer, D-N.Y., said he would not be deterred by the Trump administration’s threats. He predicted the layoffs would be overturned in court or subsequently walked back, as the administration has done in limited circumstances throughout government.
“This is an attempt at intimidation,” Schumer said. “Donald Trump has been firing federal workers since day one—not to govern, but to scare. This is nothing new and has nothing to do with funding the government.”
Sen. Chris Van Hollen, D-Md., likened the layoffs to “mafia-style blackmail,” said they would likely be illegal and vowed that Democrats will be “fighting back with every tool we have.”
“These dedicated workers have nothing to do with the ongoing political and policy disputes that have brought us to the brink of a shutdown,” Van Hollen said.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Department of Government Efficiency personnel have jeopardized the security of Americans’ personal information by uploading sensitive data into cloud environments without the necessary safeguards or oversight, a top Senate Democrat alleges in a report released on Thursday.
The investigation, spearheaded by Sen. Gary Peters, D-Mich. — the ranking member of the Senate Homeland Security and Governmental Affairs Committee — and Democrat staffers on the panel, warned that DOGE “operates outside of, and even counter to, federal law and their purported efficiency and transparency goals.”
President Donald Trump set up the unit on his first day in office and directed it to focus on slashing federal employees and spending, as well as modernizing federal technology. DOGE has come under criticism since then, however, for hoovering up sensitive government data and having its employees handle the collected information without restrictions.
“This environment results in serious cybersecurity vulnerabilities, privacy violations, and risk of corruption that could open Americans’ most sensitive information to targeting by malicious actors or allow it to be used in ways that violate fundamental privacy rights — or serve to benefit DOGE employees and the private companies with which many maintain strong ties,” the report said.
Among the whistleblower complaints detailed in the report were allegations from a former Social Security Administration official that DOGE employees uploaded a live copy of confidential agency data into a vulnerable cloud server.
Chuck Borges, SSA’s former chief data officer, said that DOGE employees at the agency “had access to personal data on all Americans, including Social Security numbers (SSNs), in a cloud environment without any verified security controls and without standard agency visibility into their use of that data” — a level of access that even exceeded Borges’ role. One of these SSA-based DOGE employees, Edward Coristine, had previously been fired from a private sector position for reportedly sharing sensitive data with a competitor.
“Because agency officials allegedly do not have oversight of these DOGE employees’ actions, they cannot know whether these individuals have moved any data out of SSA, granted access to the data to unauthorized users, including to private companies, or whether the data has been accessed illicitly,” the report added.
Thursday’s report comes after Senate Finance Committee Chairman Mike Crapo, R-Idaho, asked SSA earlier this month to provide information to the panel in response to Borges’ claims. An agency spokesperson told Nextgov/FCW at the time that “the data referenced in the complaint is stored in a long-standing environment used by SSA and walled off from the internet” and added that high-level agency officials have administrative access to the system.
Democrat staffers on the Senate Homeland Security and Governmental Affairs Committee also identified “a clear pattern” across agencies, where officials who questioned DOGE’s work were sidelined or let go and DOGE-affiliated personnel were embedded into key positions, such as being named chief information officers. These employees were then able to approve DOGE staffers to work with sensitive data, often without following standard oversight procedures.
DOGE personnel also reportedly directed agencies to assist them in creating databases containing highly sensitive information on most Americans. Thursday’s report said a cyber breach of these cloud environments would be catastrophic.
“An internal SSA risk assessment determined that the likelihood of a data breach with ‘catastrophic adverse effect’ is between 35 and 65 percent,” the report said. “The potential breach of this sensitive data, and its potential misuse, significantly increase the urgency for DOGE to stop any high-risk projects and disclose its work to Congress and the public.”
In a statement, Peters said “DOGE isn’t making government more efficient — it’s putting Americans’ sensitive information in the hands of completely unqualified and untrustworthy individuals.”
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The North Korea-linked threat actors associated with the Contagious Interview campaign have been attributed to a previously undocumented backdoor called AkdoorTea, along with tools like TsunamiKit and Tropidoor. Slovak cybersecurity firm ESET, which is tracking the activity under the name DeceptiveDevelopment, said the campaign targets software developers across all operating systems, Windows,
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Volvo Group has disclosed that a recent ransomware attack on its human resources software provider, Miljödata, may have resulted in unauthorized access to personal information belonging to its North American workforce. The incident underscores growing concerns about third-party risk and the importance of robust vendor security practices. Ransomware Incident and Discovery On August 20, 2025, Miljödata, which […]
The post Volvo Group Reports Data Breach Following Ransomware Attack on HR Vendor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Following a major law enforcement disruption in February 2024, the notorious LockBit ransomware group has resurfaced, marking its sixth anniversary with the release of a new version: LockBit 5.0.
Trend Micro has identified and analyzed binaries for Windows, Linux, and VMware ESXi, confirming the group’s continued focus on cross-platform attacks that can cripple entire enterprise networks.
The discovery of these new variants in early September 2025 signals a significant evolution of the ransomware. This latest version continues the group’s strategy of targeting multiple operating systems simultaneously, a tactic seen since LockBit 2.0 was released in 2021.
Advanced Cross-Platform Attacks
The LockBit 5.0 variants are tailored to their target operating systems, employing sophisticated techniques to evade detection and maximize damage.
- Windows Variant: This version uses heavy obfuscation and packing, loading its malicious payload through DLL reflection to complicate analysis. It also implements anti-analysis measures, such as patching the Event Tracing for Windows (ETW) API and terminating 63 different security-related services. The Windows variant also features a newly formatted and more user-friendly help menu.

Windows variant - Linux Variant: The Linux version mirrors the functionality of its Windows counterpart, providing attackers with a consistent set of command-line options to target specific directories and file types. It can log its activities, showing which files are being encrypted and which folders are excluded.
.webp)
Linux variant - ESXi Variant: A dedicated variant specifically targets VMware’s ESXi virtualization infrastructure. This represents a critical threat, as compromising a single ESXi host can allow attackers to encrypt dozens or even hundreds of virtual machines at once, causing massive disruption. The ESXi variant includes parameters optimized for virtual machine encryption.

ESXi variant Trend Micro analysis shows that LockBit 5.0 is a direct evolution of its predecessor, LockBit 4.0. Both versions share identical hashing algorithms and methods for API resolution, indicating the same developers have built upon their existing codebase.
Key behaviors are consistent across the new variants. Encrypted files are appended with a randomized 16-character extension, making identification and recovery more difficult.
The ransomware also includes checks to avoid executing on systems with Russian language settings or geolocated in Russia. After the encryption process is complete, it clears event logs to cover its tracks.
The technical improvements in LockBit 5.0 make it significantly more dangerous than previous versions. The heavy obfuscation delays the development of detection signatures, while the focus on virtualized environments amplifies its potential impact.
The group’s ability to regroup and release an upgraded ransomware after Operation Cronos demonstrates its resilience.
Organizations are advised to enhance their security posture by proactively hunting for threats and reinforcing endpoint and network protections. Special attention should be given to securing virtualization infrastructure, as it has become a primary target.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post New LockBit 5.0 Ransomware Variant Attacking Windows, Linux, and ESXi Systems appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cisco released an advisory describing a high-severity vulnerability (CVE-2025-20160) in its IOS and IOS XE platforms. The flaw stems from improper validation of the TACACS+ shared secret configuration. When TACACS+ is enabled but no secret is set, remote attackers or machine-in-the-middle adversaries can intercept or manipulate authentication messages. Successful exploitation grants unauthorized access to confidential […]
The post Cisco IOS/XE Vulnerability Allows Unauthorized Access to Confidential Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical path traversal flaw in ZendTo has been assigned CVE-2025-34508 researchers discovered that versions 6.15–7 and prior enable authenticated users to manipulate file paths and retrieve sensitive data from the host system.
This issue underscores the persistent risk in web-based file transfer applications.
Path Traversal Vulnerability (CVE-2025-34508)
ZendTo is a PHP-driven dropoff or pickup service that allows any registered user to upload files for sharing. During the “dropoff” process, two variables chunkName and tmp_name determine how file uploads are staged and moved.
Horizon3.ai reports that the server-side sanitization routine strips non-alphanumeric characters from chunkName, but if an attacker supplies a chunkName comprised entirely of non-alphanumeric characters, the sanitization leaves an empty or dot-only string.
This results in a chunkPath pointing to the root uploads directory rather than a unique temporary file:

Once chunkPath is established, the code concatenates a user-controlled tmp_name to relocate the file into the target dropoff directory:

Because tmp_name is not sanitized, attackers can embed directory traversal sequences.
Downloading this file exposes the application’s log data, including dropoff claim IDs, creating the way to enumerate and exfiltrate any user-uploaded content or critical system files.

Drop-off Summary
Risk Factors Details Affected Products ZendTo versions 6.15–7 and prior Impact Arbitrary file read and information disclosure Exploit Prerequisites Low-privilege authenticated user CVSS 3.1 Score 7.8 (High) Mitigation
In default installations, file access is limited to the www-root user’s permissions, yet this typically encompasses all uploaded content. Beyond user files, adversaries could target the ZendTo database or source code, potentially causing a denial-of-service.
Although CVE-2025-34508 requires authentication, the minimal barrier allows low-privilege users to perform arbitrary file reads.
Administrators are strongly urged to upgrade immediately. The fix implements stricter validation on both chunkName and tmp_name, ensuring only safe, expected filenames are processed.
This disclosure follows high-profile incidents involving MOVEit Transfer (CVE-2023-34362), Accellion FTA (CVE-2021-27104), and GoAnywhere MFT (CVE-2023-0669), highlighting that file-sharing platforms remain prime targets.
Organizations must maintain vigilant patch management and conduct regular security reviews of their file transfer applications.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post ZendTo Vulnerability Let Attackers Bypass Security Controls and Access Sensitive Data appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SetupHijack, an open-source research utility, has emerged as a powerful method for red teaming and security research by targeting race conditions and insecure file handling within Windows installer and update mechanisms.
By polling world-writable directories such as %TEMP%, %APPDATA%, and %USERPROFILE%\Downloads, the tool intercepts installer‐dropped payloads before they execute with elevated privileges, enabling full SYSTEM or Administrator compromise without requiring elevated permissions to run.
SetupHijack continuously scans specified directories for new or modified installer files with extensions .exe, .msi, and .bat. When a target file appears, the tool atomically replaces it with a user-supplied payload, optionally preserving the original file as a .bak backup.
If the privileged process executes the substituted payload before performing integrity checks, the attacker’s code runs under elevated rights.
Unlike file system notification-based methods, SetupHijack relies on high-frequency polling to minimize race-window durations.
SetupHijack Exploits Race Conditions
Hacker House stated that the framework also subverts Authenticode code-signing and installer trust models by integrating a hacked signing process using SignToolEx.exe and SignToolExHook.dll, allowing payloads to bear valid certificates and Authenticode timestamps.
This approach increases the probability of bypassing digital signature verifications employed by many installers and OS protections.
Building the tool is straightforward with Microsoft’s build utilities:

The default execution scans common drop locations, SetupHijack.exe. Flags allow fine-tuning of scan targets:

Additional modes include:
- clean: Restores .bak backups across enabled directories.
- verbose: Logs all actions, including successful payload substitutions.
For remote escalation on multi-user systems, SetupHijack can run alongside tools like shadow.exe under a compromised user account, standing by until an administrative installer process is launched.
In practice, security researchers have observed successful infections of popular applications such as Zoom (version 6.6.1), where the update binary residing in %AppData% was hijacked to inject a custom implant.
During demonstration runs, SetupHijack output logs show detailed infection events:


Deploy an Implant Security Implications
While SetupHijack is intended solely for authorized testing and research, it underscores a critical weakness in many Windows installer processes that trust files in world-writable directories.
Organizations should enforce stricter file-drop locations, implement robust integrity checks, and leverage secure coding practices to prevent time-of-creation/time-of-use (TOCTOU) attacks.
Additionally, signing installers with hardware-protected certificates and performing runtime signature validations can mitigate this class of exploitation.
As supply-chain and installer security become increasingly targeted, tools like SetupHijack serve as both a warning and an opportunity to harden deployment workflows against sophisticated race-condition exploits.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post SetupHijack Tool Exploits Race Conditions and Insecure File Handling in Windows Installer Processes appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


