• A newly discovered ransomware group called Yurei has emerged with sophisticated encryption capabilities, targeting organizations through double-extortion tactics while leveraging open-source code to rapidly scale operations. First observed on September 5, 2025, this Go-based ransomware employs the ChaCha20 encryption algorithm and PowerShell commands to compromise victim systems, marking another evolution in the ransomware-as-a-service ecosystem. Flow […]

    The post Yurei Ransomware Uses PowerShell to Deploy ChaCha20 File Encryption appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Two critical vulnerabilities have been discovered in the Linux Common Unix Printing System (CUPS), exposing millions of systems to remote denial-of-service attacks and authentication bypass exploits. 

    The vulnerabilities, tracked as CVE-2025-58364 and CVE-2025-58060, affect the core printing infrastructure used across virtually all Linux distributions and pose significant risks to network security.

    Key Takeaways
    1. Two Critical CUPS vulnerabilities impact all Linux systems.
    2. Attackers can crash printing services and gain admin access.
    3. Immediate fix required until patches arrive.

    Remote DoS Vulnerability

    The first vulnerability, CVE-2025-58364, stems from unsafe deserialization and validation of printer attributes within the libcups library. 

    This moderate-severity flaw allows attackers to trigger a null dereference through crafted printer attribute responses, causing system crashes across local networks.

    The vulnerability manifests in the ipp_read_io() function when processing IPP_OP_GET_PRINTER_ATTRIBUTES requests. 

    Security researchers demonstrated that the combination of ippNewRequest(), cupsDoRequest(), and ippValidateAttributes() functions creates a dangerous code path where malformed responses can cause null pointer dereferences in the loop for (ptr = attr->values[i].string.text; *ptr; ptr ++).

    The attack vector requires adjacent network access, making it exploitable within local subnets where CUPS services automatically discover printers. 

    Systems running cups-browsed service are particularly vulnerable, as the service actively listens for printer announcements on the network. 

    The vulnerability affects all CUPS versions below 2.4.12, with no patches currently available. The vulnerability was discovered and reported by security researcher SilverPlate3.

    Authentication Bypass Vulnerability

    CVE-2025-58060 represents a high-severity authentication bypass vulnerability affecting CUPS configurations using AuthType Negotiate or any non-Basic authentication method. 

    The flaw allows attackers to bypass password verification by sending Authorization: Basic headers when the system expects different authentication types.

    The vulnerability exists in the scheduler/auth.c file within the cupsdAuthorize() function. When administrators configure DefaultAuthType to anything other than Basic authentication, the system incorrectly skips password validation if an incoming request contains a Basic authentication header. 

    Attackers can exploit this by sending requests with Authorization: Basic $(echo -n admin:x | base64), where the password can be any arbitrary string.

    This bypass grants unauthorized access to CUPS administrative functions, potentially allowing attackers to modify printer configurations, access print queues, or execute administrative commands. 

    The vulnerability affects systems where administrators have implemented Kerberos, LDAP, or other enterprise authentication mechanisms to secure their printing infrastructure.

    The vulnerability was identified and reported by researcher hvenev-insait.

    CVE IDTitleCVSS 3.1 ScoreSeverity
    CVE-2025-58364Remote DoS via null dereference6.5Moderate
    CVE-2025-58060Authentication bypass with AuthType Negotiate7.8High

    Mitigations

    Both vulnerabilities expose critical weaknesses in CUPS deployments across enterprise and home networks. 

    The DoS vulnerability can disrupt printing services network-wide, while the authentication bypass compromises administrative access controls. 

    Organizations using CUPS in production environments should immediately assess their exposure and implement network-level protections.

    Network administrators should restrict IPP port 631 access through firewalls and disable the cups-browsed service on systems that don’t require automatic printer discovery. 

    For the authentication bypass vulnerability, temporarily reverting to AuthType Basic with strong passwords provides immediate protection until patches become available. 

    Organizations should monitor the OpenPrinting project repository for security updates and apply patches immediately upon release.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Linux CUPS Vulnerability Let Attackers Remote DoS and Bypass Authentication appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical vulnerability in FlowiseAI has been discovered that allows attackers to take over user accounts with minimal effort. The flaw, tracked as CVE-2025-58434, affects both cloud-hosted and self-hosted FlowiseAI deployments, posing significant risks to organizations using this AI workflow automation platform. CVE Number Affected Product Vulnerability Type CVSS 3.1 Score CVE-2025-58434 FlowiseAI (npm package flowise) Unauthenticated Password […]

    The post FlowiseAI Password Reset Token Vulnerability Enables Account Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In 2025, web applications are no longer just static websites; they are dynamic, complex ecosystems that serve as the primary interface between businesses and their customers. This makes them a prime target for cybercriminals. Traditional network firewalls and intrusion prevention systems (IPS) are often blind to application-layer attacks, leaving web applications vulnerable to exploits like […]

    The post Top 10 Best Web Application Firewall (WAF) Solutions In 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Phishing-as-a-Service operation called VoidProxy that uses advanced adversary-in-the-middle techniques to bypass traditional multi-factor authentication and steal session tokens from Microsoft 365 and Google accounts. The five steps of a SIM-swap attack illustrating how fraudsters bypass multi-factor authentication to compromise accounts  Okta has uncovered a sophisticated new emergence of VoidProxy, a highly evasive Phishing-as-a-Service platform that […]

    The post VoidProxy PhaaS Targets Microsoft 365 and Google Accounts in New Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Two critical security vulnerabilities have been discovered in the Common Unix Printing System (CUPS), a widely used printing subsystem for Unix-like operating systems. The flaws, designated as CVE-2025-58364 and CVE-2025-58060, expose Linux systems to remote denial-of-service attacks and authentication bypass, potentially affecting millions of Linux machines worldwide. CVE Severity CVSS Score Impact Affected Versions CVE-2025-58364 […]

    The post Linux CUPS Flaw Allows Remote Denial of Service and Authentication Bypass appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new proof-of-concept (PoC) tool named BitlockMove demonstrates a novel lateral movement technique that leverages BitLocker’s Distributed Component Object Model (DCOM) interfaces and COM hijacking.

    Released by security researcher Fabian Mosch of r-tec Cyber Security, the tool enables attackers to execute code on remote systems within the session of an already logged-on user, bypassing the need to steal credentials or impersonate accounts.

    BitlockMove Tool

    The BitlockMove tool exploits how certain COM classes, when configured as “INTERACTIVE USER,” can spawn a process in the context of the current user’s session.

    Suppose these processes are also susceptible to COM hijacking. In that case, an attacker can remotely modify the registry, deliver a malicious DLL via Server Message Block (SMB), and trigger its execution through DCOM.

    This technique is particularly stealthy because the malicious code runs directly within the target user’s context, generating fewer indicators of compromise compared to traditional methods like credential theft from LSASS.

    The PoC specifically targets the BDEUILauncher Class (CLSID ab93b6f1-be76-4185-a488-a9001b105b94), which can launch several processes. One of these, BaaUpdate.exe, is vulnerable to COM hijacking when started with specific parameters.

    The tool hijacks a related BitLocker CLSID (A7A63E5C-3877-4840-8727-C1EA9D7A4D50) from the remote system. Since BitLocker is most commonly enabled on Windows client operating systems, this lateral movement technique is primarily effective against workstations rather than servers.

    BitlockMove’s Modes of Operation

    The tool, written in C#, operates in two distinct modes: enumeration and attack.

    • Enum Mode: An attacker can use this mode to identify active user sessions on a target host. This allows the threat actor to select a high-privilege user, such as a domain administrator, for the attack.
    Enumeration mode
    Enumeration mode
    • Attack Mode: In this mode, the tool executes the attack. The attacker specifies the target host, the username of the active session, a path to drop the malicious DLL, and the command to be executed. The tool then performs the remote COM hijack, triggers the payload, and cleans up by removing the hijack from the registry and deleting the DLL.
    Attack Mode
    Attack Mode

    Defenders can detect this technique by monitoring for specific behaviors. Key indicators include the remote COM hijacking of the targeted BitLocker-related CLSID, followed by the BaaUpdate.exe process loading a newly dropped DLL from the hijack location.

    Suspicious subprocesses spawning from BaaUpdate.exe or BdeUISrv.exe are also strong signs of compromise. Security teams can build threat hunting queries to look for the presence of the BdeUISrv.exe process, as its legitimate use is rare.

    The PoC uses a hardcoded DLL, making signature-based detection straightforward; however, attackers can easily create custom DLLs to evade such defenses.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post BitlockMove Tool Enables Lateral Movement via Bitlocker DCOM & COM Hijacking appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity serves as a critical reminder of the pervasive risks within the digital supply chain, as several industry-leading companies disclosed significant data breaches.

    The incidents, affecting vulnerability management giants Tenable and Qualys, as well as enterprise software provider Workday, all stemmed from a security flaw in a common third-party service.

    This chain of disclosures highlights the cascading impact a single vulnerability can have on multiple, otherwise secure, organizations, raising serious questions about vendor risk management and trust in the ecosystem.

    The breaches at Tenable and Qualys are particularly concerning, as they involved unauthorized access to systems containing sensitive customer data. Both companies have confirmed that the intrusion was linked to a third-party vendor, forcing them to launch comprehensive investigations and notify affected clients.

    Similarly, Workday’s announcement of a breach traced back to the same external service provider underscores the widespread nature of the threat. These events have put a spotlight on the security posture of vendors and the due diligence required to protect against supply chain attacks.

    In addition to these high-profile incidents, our weekly recap delves into other essential security updates, newly discovered vulnerabilities, and patches released by major software developers.

    We will analyze the technical details behind the breaches at Tenable, Qualys, and Workday, examine the broader implications for enterprise security, and provide insights into the latest threat intelligence to help you stay ahead of emerging risks.

    Threats

    Lazarus APT Employs “ClickFix” Social Engineering in Espionage Campaigns

    The North Korean-linked Lazarus APT group is now using the “ClickFix” social engineering technique to deploy malware and steal sensitive intelligence. This method involves tricking victims with fake technical problems and guiding them through malicious “fixes”. In a recent campaign, the group used this technique within fake job recruitment scenarios. Victims were lured to fraudulent interview websites and told they had camera configuration issues. The provided “fix” was a malicious batch script that downloaded the BeaverTail information-stealing malware, disguised as an NVIDIA driver update.

    The attack is designed for both Windows and macOS, demonstrating the group’s cross-platform capabilities. The malware establishes persistence through registry modifications and communicates with multiple command-and-control servers to ensure long-term access to compromised systems. Read More

    US-China Trade Talks Targeted by APT41 Malware Campaign

    U.S. federal authorities are investigating a sophisticated malware campaign attributed to the China-linked APT41 hacking group, which targeted sensitive trade negotiations between Washington and Beijing in July 2025. The attackers sent fraudulent emails impersonating U.S. Representative John Moolenaar, chairman of a House committee on China. The emails were sent to U.S. trade groups, law firms, and government agencies with the goal of harvesting intelligence on America’s trade strategies.

    The emails used subject lines like “Your insights are essential” and contained malicious attachments disguised as draft legislation. Opening the attachment would deploy malware, giving attackers access to the target’s network. The attack’s timing was strategic, occurring just before key trade talks. The FBI and U.S. Capitol Police are investigating the incident. Read More

    LunaLock Ransomware Gang Threatens to Train AI with Stolen Art

    A new ransomware group known as LunaLock is targeting independent artists with a novel extortion tactic: threatening to use their stolen artwork to train AI models. The group recently breached “Artists & Clients,” a digital marketplace for illustrators, stealing and encrypting creative works and personal data. The attackers demanded a ransom of up to $80,000, warning that if it wasn’t paid, all stolen artwork would be submitted to AI training datasets sold to major tech companies.

    This is considered the first known instance of a ransomware group using the threat of AI training as leverage. The attack has left freelance artists vulnerable, with stolen data including portfolios, commission archives, and private chats. Read More

    MostereRAT Malware Targets Windows Systems with Advanced Evasion Tactics

    A new Remote Access Trojan (RAT) named MostereRAT is targeting Microsoft Windows systems through a phishing campaign. Written in Easy Programming Language (EPL), a language rarely seen in cyberattacks, the malware uses multiple layers of advanced evasion techniques to gain complete control over compromised machines. The campaign primarily targets Japanese users with phishing emails disguised as business inquiries.

    MostereRAT can disable security tools, block antivirus traffic, escalate privileges by mimicking the powerful TrustedInstaller account, and install remote access tools like AnyDesk and TightVNC. Its ability to interfere with security protections makes it a significant threat.Read More

    Salat Stealer Malware Offered as a Service for Data Exfiltration

    A sophisticated Go-based information stealer called Salat Stealer is actively targeting Windows systems to exfiltrate browser credentials, cryptocurrency wallet data, and session information. Operating under a Malware-as-a-Service (MaaS) model, it is likely run by Russian-speaking actors and provides a turnkey solution for cybercriminals.

    The malware uses advanced techniques to achieve persistence and evade detection, including UPX packing, process masquerading, registry run keys, and scheduled tasks. It encrypts stolen data before sending it to its command-and-control server, making it a stealthy and persistent threat capable of causing financial loss and identity theft. Read More

    Scattered LAPSUS$ Hunters Hacking Group Announces Permanent Shutdown

    The notorious cybercrime collective known as “Scattered LAPSUS$ Hunters 4.0” has announced it is permanently ceasing public operations. The declaration was made on their Telegram channel on September 8, 2025, marking an abrupt end for a group known for high-profile attacks against major corporations using sophisticated social engineering and identity-centric tactics.

    The group’s strategy was often described as “log in, not hack in,” focusing on compromising legitimate user accounts to bypass traditional security defenses. Their methods included voice phishing (vishing), SIM swapping, and MFA fatigue attacks. The reasons for their sudden departure remain unclear, with speculation pointing to internal pressures or law enforcement intervention. Read More

    Cyber Attacks

    Massive Supply Chain Attack Hits 18 Popular NPM Packages

    A major supply chain attack compromised 18 popular npm packages, including chalk, debug, and supports-color, which collectively have over two billion weekly downloads. The attack, which started around September 8, 2025, involved injecting malicious code designed to steal cryptocurrency from users. The malware intercepts and manipulates in-browser cryptocurrency transactions, rewriting wallet addresses to redirect funds to attacker-controlled accounts. The maintainer of the packages fell victim to a phishing attack after receiving a fraudulent email from a domain masquerading as npm support. Read More

    Jaguar Land Rover Halts Production Following Cyberattack

    Jaguar Land Rover (JLR) was forced to shut down production at its UK manufacturing plants and has suspended its global operations following a significant cyberattack. The company is currently investigating the incident and is working to restore its systems. The full extent of the attack and the financial impact have not yet been disclosed. This incident highlights the increasing trend of cyberattacks targeting the automotive industry, causing major disruptions to supply chains and production lines. Read More

    New Cyberattack Weaponizes DeskSoft’s App Builder

    A new cyberattack campaign is exploiting a legitimate application from DeskSoft, a German software company, to deploy malware. Attackers are using DeskSoft’s application builder to create malicious installers that appear to be genuine software. When executed, these installers deploy malware onto the victim’s system. This technique allows attackers to bypass some security measures that might otherwise flag a standalone malicious file. Read More

    DarkSamurai APT Group Uses Malicious LNK Files in New Campaign

    The DarkSamurai APT group has been identified in a new campaign that uses malicious LNK files to compromise targets. The group, known for its targeted attacks, hides malicious payloads within these shortcut files. Once a user clicks the LNK file, it executes a script that downloads and runs malware on the system. This method is part of a larger trend of threat actors using non-executable file types to initiate infections and evade detection. Read More

    Novel Phishing Attack Mimics Google AppSheet to Bypass Security

    A new and sophisticated phishing campaign is using Google AppSheet to create convincing phishing pages that bypass traditional email security filters. Attackers are leveraging the legitimate Google service to host malicious forms and pages, making them appear trustworthy to victims. The phishing emails often impersonate well-known services and prompt users to enter their credentials on the fraudulent AppSheet page. This technique abuses the trust associated with Google’s domains to increase the success rate of the phishing attacks. Read More

    Vulnerabilities

    Salesloft-Drift Cyberattack Linked to GitHub Compromise

    A major supply-chain attack that affected over 700 organizations, including Cloudflare, Zscaler, and Palo Alto Networks, has been traced back to a compromise of Salesloft’s GitHub account starting as early as March 2025. Threat actors leveraged this access to steal OAuth authentication tokens from Salesloft’s Drift chat platform. The attackers, identified by Google as UNC6395, used the stolen tokens between August 8 and August 18 to exfiltrate data, primarily business contact information, from customers’ integrated applications like Salesforce. In response, Salesloft engaged Mandiant for an investigation, took the Drift platform offline, and has since contained the incident. Read More

    Windows Defender Vulnerable to Service Hijacking

    A severe vulnerability in Windows Defender’s update process allows an attacker with administrator privileges to disable the security service by leveraging a symbolic link attack. The flaw lies in how the WinDefend service selects its execution folder during an update. An attacker can create a symbolic link with a higher version number in the ProgramData\Microsoft\Windows Defender\Platform\ directory, redirecting the service to an attacker-controlled folder. This allows them to manipulate Defender’s core files, perform DLL side-loading attacks, or simply delete the executables to disable the service, leaving the system unprotected. Read More

    SAP Releases September 2025 Security Patch Day Updates

    SAP has released its September 2025 Security Patch Day, addressing 17 new security notes and updating 3 previous ones. The updates include two “Hot News” vulnerabilities with a CVSS score of 10.0, which affect SAP NetWeaver AS for Java. These critical flaws, tracked as CVE-2025-41235 and CVE-2025-41236, could allow an unauthenticated attacker with network access to gain full control of the system. Another high-severity vulnerability (CVSS 8.1) in SAP CRM WebClient UI was also patched. Read More

    Zoom Patches High-Severity Flaw in Meeting SDK

    Zoom has issued a security update for its Meeting SDK for Windows, addressing a high-severity improper input validation vulnerability (CVE-2025-42993). This flaw, which has a CVSS score of 7.5, could allow an authenticated user to cause a denial of service via network access. The vulnerability affects Zoom Meeting SDK for Windows versions before 5.17.10. Users and administrators are advised to update to the patched version to mitigate the risk. Read More

    Ivanti Patches Critical RCE Flaws in Endpoint Manager (EPM)

    Ivanti has addressed several critical remote code execution (RCE) vulnerabilities in its Endpoint Manager (EPM) software. The most severe of these, with a CVSS score of 9.8, could allow an unauthenticated attacker to execute arbitrary code on the core server. These vulnerabilities affect all supported versions of Ivanti EPM. The company has released patches and strongly recommends that all customers apply them immediately to prevent potential exploitation. Read More

    Fortinet Fixes Critical FortiDDoS OS Command Injection Flaw

    Fortinet has patched a critical OS command injection vulnerability in FortiDDoS, its distributed denial-of-service mitigation appliance. Tracked as CVE-2025-44365, the flaw has a CVSS score of 9.8 and allows an authenticated attacker to execute arbitrary commands on the system via specially crafted HTTP requests. The vulnerability impacts multiple versions of FortiDDoS. Fortinet has released updated firmware versions to address the issue and urges customers to upgrade their appliances as soon as possible. Read More

    Microsoft’s September 2025 Patch Tuesday Fixes 62 Flaws

    Microsoft’s September 2025 Patch Tuesday release includes fixes for 62 vulnerabilities, with five classified as critical. Key patches address remote code execution flaws in Microsoft Exchange Server, Windows DHCP Server, and Visual Studio. One of the Exchange vulnerabilities (CVE-2025-23875) is noted as “Exploitation More Likely.” Additionally, a zero-day elevation of privilege vulnerability in the Windows Kernel (CVE-2025-23974), which was publicly disclosed, has also been patched. Read More

    Data Breaches

    Widespread Supply Chain Attack Hits Major Tech Firms via Salesloft Drift

    A sophisticated and widespread supply chain attack targeting the Salesloft Drift marketing application has resulted in data breaches at numerous major technology companies. The campaign allowed threat actors to gain unauthorized access to data stored within the companies’ Salesforce CRM environments by exploiting a vulnerability in the third-party integration. The incident highlights the significant risks associated with third-party applications integrated into core business platforms.

    Tenable Confirms Customer Data Exposure

    Tenable confirmed it was impacted by the breach, which exposed customer contact information and details from support cases. The compromised data, stored in Tenable’s Salesforce instance, included names, business email addresses, phone numbers, and the subject lines of support inquiries. The company emphasized that its core products were not affected and has since revoked compromised credentials and disabled the vulnerable application to mitigate the threat. Read More

    Qualys’s Salesforce Data Accessed in Attack

    Cloud security provider Qualys announced it also fell victim to the supply chain attack, leading to unauthorized access to some of its Salesforce data. Qualys clarified that the incident did not affect its production environments or the Qualys Cloud Platform. The breach was limited to information accessible through the compromised Salesloft Drift integration. Read More

    Dynatrace Breach Exposes Customer Contact Info

    Observability platform Dynatrace reported that the breach exposed customer business contact information stored within its Salesforce environment. The company reassured its customers that the incident was contained to its CRM platform and did not compromise any of its core products, services, or sensitive customer telemetry data. Dynatrace promptly disabled the Drift application upon learning of the third-party compromise. Read More

    Elastic Discloses Email Account Compromise

    In a related incident stemming from the Salesloft Drift compromise, Elastic disclosed that an unauthorized actor gained read-only access to a single email account via the “Drift Email” integration. The company’s investigation confirmed that its Salesforce environment was not impacted. Elastic scanned the exposed inbox for sensitive information and notified the small number of customers whose credentials may have been compromised. Read More

    Workday Targeted in Coordinated Campaign

    Workday, a leading provider of enterprise cloud applications, confirmed it suffered a data breach as part of the same attack campaign. The incident, which Workday became aware of on August 23, 2025, involved unauthorized access to its third-party CRM platform through the Salesloft Drift application. The company responded by disconnecting the app and launching a full investigation. Read More

    Tools

    SpamGPT: AI-Powered Phishing-as-a-Service

    A new cybercrime toolkit named SpamGPT is being sold on the dark web, allowing attackers to launch large-scale, effective phishing campaigns. The “spam-as-a-service” platform uses an AI assistant, “KaliGPT,” to automate the creation of convincing phishing emails, lowering the technical skill required to conduct such attacks. SpamGPT is marketed as an all-in-one solution that mimics legitimate email marketing services but is designed for illegal activities. It abuses trusted cloud services like Amazon AWS and SendGrid to ensure inbox delivery and bypass security filters. For $5,000, the toolkit also includes a training program for compromising SMTP servers, enabling even low-skilled actors to execute widespread attacks. This development underscores the need for organizations to implement strong email authentication protocols like DMARC, SPF, and DKIM, and to deploy AI-powered security solutions to detect AI-generated phishing content. Read more

    Forensic Analysis of Microsoft Azure Storage

    Security researchers have detailed a forensic methodology for investigating security incidents within Microsoft Azure Storage services. The process involves collecting and analyzing logs from various sources, including Azure Monitor Logs, Storage Analytics Logs, and Microsoft Defender for Cloud. Key artifacts in an investigation include access patterns, IP addresses, user agents, and API call authentications, which help in reconstructing the attacker’s activities. Understanding shared access signature (SAS) token abuse and identifying anomalous data access or exfiltration are critical components of the analysis. The research provides a structured approach for security teams to effectively respond to and investigate threats in cloud storage environments, which are increasingly targeted by attackers. Read more

    Hackers Exploit Microsoft Teams for Malicious Link Delivery

    Cybercriminals are increasingly exploiting Microsoft Teams to deliver malicious links, bypassing traditional email security gateways. A new attack campaign uses compromised accounts to send messages containing seemingly legitimate links, such as for shared documents or meeting invitations. When a user clicks the link, they are redirected through a series of servers to a phishing page designed to steal credentials or a landing page that delivers malware. Because the links are shared within the trusted environment of Teams, users are more likely to click on them. The technique highlights a shift in attack vectors as threat actors adapt to target collaboration platforms that have become central to modern business operations. Read more

    The Rise of “Evil AI”: AI-Enhanced Hacking Tools

    A new category of AI-enhanced tools, dubbed “Evil AI,” is emerging, designed specifically for malicious purposes like spreading disinformation, creating deepfakes, and launching sophisticated cyberattacks. Unlike general-purpose AI models that may have safeguards, these tools are built without ethical constraints to aid cybercriminals. They can be used to generate highly convincing phishing emails, create malware that can alter its code to evade detection (polymorphic malware), and automate vulnerability discovery. The development of such tools represents a significant threat, as it can accelerate the pace and scale of cybercrime. Read more

    Villager: An AI-Powered Penetration Testing Tool

    A new open-source tool called Villager leverages AI to enhance penetration testing and red team operations. Villager acts as an AI-powered agent that can assist with various stages of an attack, from reconnaissance and vulnerability scanning to privilege escalation and lateral movement. The tool can interpret natural language commands, allowing security professionals to direct the AI to perform complex tasks, such as “find all web servers vulnerable to SQL injection on this network.” By integrating with existing penetration testing frameworks and tools, Villager aims to augment the capabilities of security testers, allowing them to operate more efficiently and effectively. Read more

    Analysis

    Salesloft Breach Traced to GitHub Compromise, Affecting 700+ Companies

    A massive supply-chain attack that targeted customers of Salesloft’s Drift integration has been traced back to a compromised GitHub account. The incident, which unfolded in August 2025, impacted over 700 organizations, including high-profile tech companies like Cloudflare, Zscaler, and Palo Alto Networks.

    Investigators from Google’s Mandiant unit revealed that an unauthorized actor had access to Salesloft’s GitHub account from March to June 2025. During this time, the threat actor, tracked as UNC6395, stole OAuth authentication tokens for the Drift platform. These tokens were then used between August 8 and August 18 to gain unauthorized access to customers’ connected applications, most notably Salesforce instances. The attackers exfiltrated sensitive data, including customer relationship management (CRM) records, support cases, and embedded secrets like API keys. The breach extended beyond Salesforce to other integrations like Google Workspace and Slack. In response, Salesloft and Salesforce globally disabled all Drift integrations on August 20, and the Drift application was taken offline on September 5, 2025. Read more

    New ClickFix Attack Lures Victims with “Free WiFi” Offer

    A new social engineering campaign is using the promise of “Free WiFi” to trick users into executing malicious PowerShell malware. This attack is a variant of the ClickFix technique, a method that has seen a 517% surge in the first half of 2025.

    The ClickFix tactic deceives users by presenting a fake error message, CAPTCHA, or other lure that instructs them to copy and paste a script into a command-line interface to “fix” a non-existent problem. Because the victim runs the malicious code themselves, this technique effectively bypasses many browser and endpoint security protections. This attack vector is used to deliver a wide range of malware, including information stealers, ransomware, and remote access trojans (RATs). First observed in early 2024, the ClickFix method has become a popular and effective tool for threat actors. Read more

    Nmap vs. Wireshark: Understanding Two Essential Network Tools

    Nmap and Wireshark are fundamental tools in network analysis and security, but they serve distinct purposes. Nmap is an active scanner, while Wireshark is a passive analyzer.

    • Nmap (Network Mapper) is used for network discovery and security auditing. It actively sends packets to a network to discover hosts, identify open ports, detect running services, and fingerprint operating systems. It gives a high-level map of the network and its potential vulnerabilities.
    • Wireshark is a network protocol analyzer that captures and provides a detailed, low-level view of traffic on a network in real-time. It doesn’t send packets itself but listens to data traveling across the network. It’s used for troubleshooting network problems, examining security issues, and deep-diving into specific communication protocols by inspecting the contents of individual packets.

    In practice, the tools are complementary. An administrator might use Nmap to identify an unusual open port and then use Wireshark to capture and analyze the traffic going to and from that port to understand what is happening. Read more

    The post Weekly Cybersecurity News Recap : Tenable, Qualys, Workday Data Breaches and Security Updates appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Federal Bureau of Investigation (FBI) has released a flash alert detailing the activities of two cybercriminal groups, UNC6040 and UNC6395, that are actively compromising Salesforce environments to steal data for extortion purposes.

    The advisory, published by the FBI on September 12, 2025, provides indicators of compromise (IOCs) and defensive measures to help organizations protect against these ongoing campaigns that leverage distinct tactics to achieve their objectives.

    Here is the detailed coverage of Lessons from Salesforce/Salesloft Drift Data Breaches – Detailed Case Study.

    UNC6040’s Social Engineering Campaign

    Since at least October 2024, the group tracked as UNC6040 has been using social engineering, particularly voice phishing (vishing), to gain initial access.

    The threat actors call an organization’s help desk, posing as IT support staff, attempting to resolve a fake technical issue. During these calls, they persuade employees to either share their credentials or grant the attackers access to the company’s Salesforce instance.

    A key tactic involves tricking employees into authorizing a malicious “connected app” within the Salesforce portal. This app is often a modified version of the legitimate Salesforce Data Loader tool.

    By convincing a user with sufficient privileges to approve the application, UNC6040 gains persistent access via OAuth tokens issued by Salesforce.

    This method can bypass security controls like multi-factor authentication (MFA) and password resets, as the activity appears to originate from a trusted, integrated application.

    The attackers then use API queries to exfiltrate large volumes of data. Following the data theft, some victims have received extortion emails from the notorious “ShinyHunters” group, demanding payment to prevent the public release of the stolen information.

    UNC6395 Exploits Third-Party Integration

    The second group, UNC6395, employed a different method to breach Salesforce instances. In August 2025, these actors exploited compromised OAuth tokens associated with the Salesloft Drift application, an AI-powered chatbot that integrates with Salesforce.

    By using these compromised third-party tokens, the group was able to access and exfiltrate data from the victim’s Salesforce environment, highlighting the security risks posed by third-party application integrations.

    In response to this campaign, Salesloft and Salesforce collaborated to revoke all active access and refresh tokens for the Drift application on August 20, 2025. This action successfully terminated the threat actors’ access to the compromised Salesforce platforms through this specific vector.250912.pdf

    The FBI has released an extensive list of IOCs, including IP addresses, malicious URLs, and user-agent strings associated with both UNC6040 and UNC6395, to help network defenders detect and block related activity. The agency strongly recommends that organizations take several steps to mitigate the risk of compromise.

    Of course, here is the table with the Indicators of Compromise, with the IP addresses formatted as requested.

    UNC6040 Indicators of Compromise

    IoC TypeIndicator
    IP Address13.67.175[.]79
    IP Address20.190.130[.]40
    IP Address20.190.151[.]38
    IP Address20.190.157[.]160
    IP Address20.190.157[.]98
    IP Address23.145.40[.]165
    IP Address23.145.40[.]167
    IP Address23.145.40[.]99
    IP Address23.162.8[.]66
    IP Address23.234.69[.]167
    IP Address23.94.126[.]63
    IP Address31.58.169[.]85
    IP Address31.58.169[.]92
    IP Address31.58.169[.]96
    IP Address34.86.51[.]128
    IP Address35.186.181[.]1
    IP Address37.19.200[.]132
    IP Address37.19.200[.]141
    IP Address37.19.200[.]154
    IP Address37.19.200[.]167
    IP Address37.19.221[.]179
    IP Address38.22.104[.]226
    IP Address45.83.220[.]206
    IP Address51.89.240[.]10
    IP Address64.95.11[.]225
    IP Address64.95.84[.]159
    IP Address66.63.167[.]122
    IP Address67.217.228[.]216
    IP Address68.235.43[.]202
    IP Address68.235.46[.]22
    IP Address68.235.46[.]202
    IP Address68.235.46[.]151
    IP Address68.235.46[.]208
    IP Address68.63.167[.]122
    IP Address69.246.124[.]204
    IP Address72.5.42[.]72
    IP Address79.127.217[.]44
    IP Address83.147.52[.]41
    IP Address87.120.112[.]134
    IP Address94.156.167[.]237
    IP Address96.44.189[.]109
    IP Address96.44.191[.]141
    IP Address96.44.191[.]157
    IP Address104.223.118[.]62
    IP Address104.193.135[.]221
    IP Address141.98.252[.]189
    IP Address146.70.165[.]47
    IP Address146.70.168[.]239
    IP Address146.70.173[.]60
    IP Address146.70.185[.]47
    IP Address146.70.189[.]47
    IP Address146.70.189[.]111
    IP Address146.70.198[.]112
    IP Address146.70.211[.]55
    IP Address146.70.211[.]119
    IP Address146.70.211[.]183
    IP Address147.161.173[.]90
    IP Address149.22.81[.]201
    IP Address151.242.41[.]182
    IP Address151.242.58[.]76
    IP Address163.5.149[.]152
    IP Address185.141.119[.]136
    IP Address185.141.119[.]138
    IP Address185.141.119[.]151
    IP Address185.141.119[.]166
    IP Address185.141.119[.]168
    IP Address185.141.119[.]181
    IP Address185.141.119[.]184
    IP Address185.141.119[.]185
    IP Address185.209.199[.]56
    IP Address191.96.207[.]201
    IP Address192.198.82[.]235
    IP Address195.54.130[.]100
    IP Address196.251.83[.]162
    IP Address198.44.129[.]56
    IP Address198.44.129[.]88
    IP Address198.244.224[.]200
    IP Address198.54.130[.]100
    IP Address198.54.130[.]108
    IP Address198.54.133[.]123
    IP Address205.234.181[.]14
    IP Address206.217.206[.]14
    IP Address206.217.206[.]25
    IP Address206.217.206[.]26
    IP Address206.217.206[.]64
    IP Address206.217.206[.]84
    IP Address206.217.206[.]104
    IP Address206.217.206[.]124
    IP Address208.131.130[.]53
    IP Address208.131.130[.]71
    IP Address208.131.130[.]91
    URLLogin[.]salesforce[.]com/setup/connect?user_code=aKYF7V5N
    URLLogin.salesforce.com/setup/connect?user_code=8KCQGTVU
    URLhttps://help[victim][.]com
    URLhttps://login[.]salesforce[.]com/setup/connect
    URLhttp://64.95.11[.]112/hello.php
    URL91.199.42.164/login

    UNC6395 Indicators of Compromise

    IoC TypeIndicator
    IP Address208.68.36[.]90
    IP Address44.215.108[.]109
    IP Address154.41.95[.]2
    IP Address176.65.149[.]100
    IP Address179.43.159[.]198
    IP Address185.130.47[.]58
    IP Address185.207.107[.]130
    IP Address185.220.101[.]33
    IP Address185.220.101[.]133
    IP Address185.220.101[.]143
    IP Address185.220.101[.]164
    IP Address185.220.101[.]167
    IP Address185.220.101[.]169
    IP Address185.220.101[.]180
    IP Address185.220.101[.]185
    IP Address192.42.116[.]20
    IP Address192.42.116[.]179
    IP Address194.15.36[.]117
    IP Address195.47.238[.]83
    IP Address195.47.238[.]178
    User-AgentSalesforce-Multi-Org-Fetcher/1.0
    User-AgentSalesforce-CLI/1.0
    User-Agentpython-requests/2.32.4
    User-AgentPython/3.11 aiohttp/3.12.15

      Key recommendations include training employees, especially call center staff, to recognize and report phishing and vishing attempts.

      The FBI also advises enforcing phishing-resistant MFA across all possible services, applying the principle of least privilege to user accounts, and implementing strict IP-based access restrictions.

      Furthermore, organizations should continuously monitor network logs and API usage for anomalous behavior indicative of data exfiltration and regularly review all third-party application integrations connected to their software platforms, rotating API keys and credentials frequently.

      Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

      The post FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration appeared first on Cyber Security News.

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

    1. IBM X-Force researchers have uncovered sophisticated new malware campaigns orchestrated by the China-aligned threat actor Hive0154, also known as Mustang Panda. The discovery includes an advanced Toneshell backdoor variant that evades detection systems and a novel USB worm called SnakeDisk specifically targeting Thailand-based devices. Enhanced Toneshell Backdoor Evades Detection The latest iteration of Toneshell, dubbed […]

      The post Mustang Panda Uses SnakeDisk USB Worm and Toneshell Backdoor to Target Air-Gap Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶