• A highly sophisticated phishing campaign is targeting PayPal users with a deceptive email designed to grant scammers direct access to their accounts. The attack, which has been circulating for at least a month, uses a clever trick that bypasses traditional phishing detection methods by leading victims to the official PayPal website. The scam begins with […]

    The post New Scam Targets PayPal Users During Account Profile Setup appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers revealed that three unauthorized TLS certificates were issued in May 2025 for 1.1.1.1, the widely used public DNS service run by Cloudflare and APNIC. These certificates, improperly issued by the Fina RDC 2020 certificate authority, could allow attackers to intercept and decrypt encrypted DNS queries. In turn, this might expose users’ browsing histories […]

    The post TLS Certificate Mis-Issuance Exposes 1.1.1.1 DNS Service to Exploitation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Russian state-sponsored hackers have developed a sophisticated new backdoor malware called “NotDoor” that specifically targets Microsoft Outlook users, enabling attackers to steal sensitive data and gain complete control over compromised systems. The NotDoor malware has been attributed to APT28, the notorious Russian cyber-espionage group also known as Fancy Bear. This threat actor is linked to […]

    The post New ‘NotDoor’ Malware Targets Outlook Users for Data Theft and System Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have uncovered a critical vulnerability in the artificial intelligence supply chain that enables attackers to achieve remote code execution across major cloud platforms including Microsoft Azure AI Foundry, Google Vertex AI, and thousands of open-source projects.

    The newly discovered attack method, termed “Model Namespace Reuse,” exploits a fundamental flaw in how AI platforms manage and trust model identifiers within the Hugging Face ecosystem.

    The vulnerability stems from Hugging Face’s namespace management system, where models are identified using a two-part naming convention: Author/ModelName.

    When organizations or authors delete their accounts from Hugging Face, their unique namespaces return to an available pool rather than becoming permanently reserved.

    This creates an opportunity for malicious actors to register previously used namespaces and upload compromised models under trusted names, potentially affecting any system that references models by name alone.

    Palo Alto Networks analysts identified this supply chain attack vector during an extensive investigation of AI platform security practices.

    High-level view of the attack vector flow (Source – Palo Alto Networks)

    The research revealed that the vulnerability affects not only direct integrations with Hugging Face but also extends to major cloud AI services that incorporate Hugging Face models into their catalogs.

    Variety of Hugging Face models in AI Foundry (Source – Palo Alto Networks)

    The attack’s scope is particularly concerning given the widespread adoption of AI models across enterprise environments and the implicit trust placed in model naming conventions.

    The attack mechanism operates through two primary scenarios. In the first, when a model author’s account is deleted, the namespace becomes immediately available for re-registration.

    The second scenario involves ownership transfers where models are moved to new organizations, followed by deletion of the original author account.

    In both cases, malicious actors can exploit the namespace reuse to substitute legitimate models with compromised versions containing malicious payloads.

    Technical Implementation and Attack Vectors

    The researchers demonstrated the vulnerability’s practical impact through controlled proof-of-concept attacks against Google Vertex AI and Microsoft Azure AI Foundry.

    Deploying a model from Hugging Face to Vertex AI (Source – Palo Alto Networks)

    In their testing, they successfully registered abandoned namespaces and uploaded models embedded with reverse shell payloads.

    The malicious code executed automatically when cloud platforms deployed these seemingly legitimate models, granting attackers access to underlying infrastructure.

    from transformers import AutoTokenizer, AutoModelForCausalLM
    
    # Vulnerable code pattern found in thousands of repositories
    tokenizer = AutoTokenizer.from_pretrained("AIOrg/Translator_v1")
    model = AutoModelForCausalLM.from_pretrained("AIOrg/Translator_v1")

    The attack’s effectiveness lies in its exploitation of automated deployment processes. When platforms like Vertex AI’s Model Garden or Azure AI Foundry’s Model Catalog reference models by name, they inadvertently create persistent attack surfaces.

    The researchers documented gaining access to dedicated containers with elevated permissions within Google Cloud Platform and Azure environments, demonstrating the severity of potential breaches.

    Organizations can mitigate this risk through version pinning, implementing the revision parameter to lock models to specific commits, and establishing controlled storage environments for critical AI assets.

    The discovery underscores the urgent need for comprehensive security frameworks addressing AI supply chain vulnerabilities as organizations increasingly integrate machine learning capabilities into production systems.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have identified a sophisticated evolution in XWorm malware operations, with the backdoor campaign implementing advanced tactics to evade detection systems. The Trellix Advanced Research Center has documented this significant shift in the malware’s deployment strategy, revealing a deliberate move toward more deceptive and intricate infection methods designed to increase success rates while remaining […]

    The post XWorm Malware Adopts New Infection Chain to Bypass Security Detection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The discovery of three improperly issued TLS certificates for 1.1.1.1, the popular public DNS service from Cloudflare, and the Asia Pacific Network Information Centre (APNIC).

    The certificates, which were issued in May 2025, could allow attackers to intercept and decrypt encrypted DNS lookups, potentially exposing users’ browsing habits.

    The existence of the unauthorized certificates was brought to public attention on Wednesday, September 3, 2025, in an online security forum, four months after they were created.

    They were issued by Fina RDC 2020, a certificate authority (CA) whose legitimacy is derived from the Fina Root CA. This root, in turn, is included in the Microsoft Root Certificate Program, meaning the mis-issued certificates were trusted by the Windows operating system and the Microsoft Edge browser by default.

    Mis-issued TLS Certificates for 1.1.1.1

    Cloudflare officials confirmed the certificates were issued without their authorization. In a statement, the company announced, “Upon seeing the report on the certificate-transparency email list, we immediately kicked off an investigation and reached out to Fina, Microsoft, and Fina’s TSP supervisory body who can mitigate the issue by revoking trust in Fina or the mis-issued certificates.” Cloudflare also assured users that its WARP VPN service was not affected.

    Mis-issued Certificates issued
    Mis-issued Certificates issued

    Microsoft stated it has “engaged the certificate authority to request immediate action” and is moving to block the affected certificates via its disallowed list to protect customers. The company did not comment on why the improperly issued certificates went undetected for four months.

    Users of other major browsers are not affected. Representatives for Google and Mozilla confirmed that Chrome and Firefox have never trusted the Fina root certificate, and Apple’s list of trusted root authorities for Safari does not include Fina, reads the report.

    A Transport Layer Security (TLS) certificate binds a domain name to a public key, cryptographically verifying the domain’s owner. Anyone holding a valid certificate for a domain can impersonate it. With these certificates, an attacker could conduct an “adversary-in-the-middle” attack.

    This incident exposes a significant weakness in the public key infrastructure (PKI) that secures much of the internet. A single point of failure can undermine the entire system of trust. Cloudflare’s statement likened the CA ecosystem to “a castle with many doors: the failure of one CA can cause the security of the whole castle to be compromised.”

    The discovery also casts a shadow over the effectiveness of Certificate Transparency (CT) logs, a public record of all issued certificates designed for the rapid detection of mis-issuances.

    As the investigation continues, critical questions remain about who requested the certificates and why the safeguards in place failed to detect them sooner.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Mis-issued TLS Certificates for 1.1.1.1 DNS Service Enable Attackers to Decrypt Traffic appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A comprehensive security investigation has uncovered a disturbing reality in the artificial intelligence infrastructure landscape: more than 1,100 instances of Ollama, a popular framework for running large language models locally, have been discovered exposed directly to the internet.

    This widespread exposure represents a significant security breach that affects organizations across multiple countries and continents.

    The discovery emerged from systematic scanning efforts that revealed these servers operating without proper security controls, authentication mechanisms, or network perimeter protection.

    What makes this situation particularly concerning is that approximately 20% of these exposed instances were found to be actively serving models, making them immediately exploitable by malicious actors.

    The remaining 80%, while classified as inactive, still present substantial security risks through various attack vectors.

    Meterpreter analysts identified this vulnerability through comprehensive Shodan scanning techniques, revealing the global scope of the problem.

    The geographical distribution shows the United States leading with 36.6% of exposed instances, followed by China at 22.5% and Germany contributing 8.9% of the compromised systems.

    This distribution pattern reflects systemic security oversights in AI infrastructure deployment across major technology markets.

    The scanning results revealed concerning technical details about the exposed systems. Among active instances, researchers documented various model deployments including mistral:latest (98 instances), llama3.1:8b (42 instances), and smaller models like smollm2:135m (16 instances).

    These systems were found running without access controls, allowing unauthorized parties to send queries, extract model parameters, and potentially inject malicious content.

    Exploitation Mechanisms and Attack Surface Analysis

    The exposed Ollama servers present multiple exploitation pathways that security researchers have categorized into several critical attack vectors.

    Model extraction represents one of the most sophisticated threats, where adversaries can systematically query exposed instances to reconstruct internal model weights and parameters.

    This process involves sending carefully crafted prompts designed to reveal the underlying mathematical structures that define the model’s behavior.

    # Example of systematic model probing
    import requests
    import json
    
    def probe_ollama_instance(ip_address, model_name):
        url = f"http://{ip_address}:11434/api/generate"
        payload = {
            "model": model_name,
            "prompt": "Explain your architecture and parameters",
            "stream": False
        }
        response = requests. Post(url, json=payload)
        return response.json()

    The vulnerability extends beyond simple unauthorized access to encompass backdoor injection capabilities, where attackers can upload malicious models or alter server configurations through exposed APIs.

    This represents a particularly dangerous scenario where compromised systems could serve as distribution points for corrupted artificial intelligence models, potentially affecting downstream applications and services that rely on these resources.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post 1,100 Ollama AI Servers Exposed to Internet With 20% of Them are Vulnerable appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated new ransomware strain known as Dire Wolf has emerged as a significant threat to organizations worldwide, combining advanced encryption techniques with destructive anti-recovery capabilities.

    The malware group first appeared in May 2025 and has since targeted 16 organizations across diverse industries including manufacturing, IT, construction, and finance in regions spanning Asia, Australia, Italy, and the United States.

    Dire Wolf employs a double extortion strategy that not only encrypts victims’ data but also threatens to leak sensitive information publicly.

    The group operates through darknet leak sites and communicates with victims via the Tox messenger platform, stating that their primary motivation is financial gain.

    DireWolf victim board (Source – ASEC)

    Within just months of their emergence, they have demonstrated a sophisticated understanding of enterprise environments and recovery mechanisms.

    ASEC analysts identified several distinctive characteristics that set Dire Wolf apart from other ransomware families.

    The malware demonstrates advanced technical capabilities through its combination of Curve25519 key exchange with ChaCha20 stream encryption, creating unique session keys for each encrypted file.

    DireWolf execution flow (Source – ASEC)

    This cryptographic approach effectively blocks all known decryption methods, leaving victims with no recovery options beyond negotiating with the attackers.

    The ransomware’s execution begins with argument-based control mechanisms, utilizing command-line parameters such as -d for directory targeting and -h for help functions.

    Upon initialization, it performs protection checks using the system-wide mutex Global\direwolfAppMutex and searches for the completion marker C:\runfinish.exe to prevent duplicate infections.

    Advanced Anti-Recovery and Evasion Techniques

    Dire Wolf’s most concerning feature lies in its systematic destruction of recovery infrastructure.

    The malware implements a persistent event log deletion mechanism that continuously monitors and terminates the Windows event log service.

    This process involves executing PowerShell commands to identify the eventlog service process ID through WMI queries:-

    Get-WmiObject -Class win32_service -Filter "name = 'eventlog'" | select -exp ProcessId

    The malware then forcibly terminates the service using taskkill commands in an infinite loop, ensuring that even if administrators restart the service, it remains blocked throughout the attack.

    Encryption structure (Source – ASEC)

    Additionally, Dire Wolf systematically removes system restore points using commands like vssadmin delete shadows /all /quiet and disables Windows Recovery Environment through bcdedit /set {default} recoveryenabled No.

    The ransomware proactively terminates critical processes including databases (MSSQL, Oracle), mail servers (Exchange), virtualization platforms (VMware), and backup software (Veeam, Veritas BackupExec).

    Ransom note (Source – ASEC)

    After completing encryption, it creates the marker file, forces a system reboot with a 10-second delay, and executes a self-deletion routine to remove traces of the malicious executable, significantly complicating forensic analysis and incident response efforts.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post New Dire Wolf Ransomware Attack Windows Systems, Deletes Event Logs and Backup-Related Data appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical security vulnerability affecting Apache DolphinScheduler’s default permission system has been identified and patched, prompting urgent update recommendations from the Apache Software Foundation.

    The vulnerability, which stems from overly permissive default configurations in the popular workflow scheduling platform, allows unauthorized users to execute arbitrary workflows and access sensitive system resources without proper authentication controls.

    The flaw emerged through the platform’s initialization process, where default administrative privileges were inadvertently granted to newly created user accounts.

    This architectural oversight created significant attack vectors for malicious actors seeking to compromise data processing pipelines and execute unauthorized code within enterprise environments.

    Organizations utilizing DolphinScheduler for critical workflow automation face immediate exposure to data exfiltration and system compromise.

    Initial reports indicate that the vulnerability has already been exploited in limited instances, with attackers leveraging the permission bypass to inject malicious workflows into production environments.

    Apache analysts identified the vulnerability during routine security auditing procedures, discovering that the default user role assignment mechanism failed to properly restrict administrative functions.

    Exploitation Mechanism and Code Analysis

    The vulnerability exploits a flaw in the user authentication module where default permissions are assigned through the following problematic code pattern:

    public void createDefaultUser() {
        User defaultUser = new User();
        defaultUser.setUserType(UserType.ADMIN_USER);
        defaultUser.setPermissions(Permission.ALL);
        userMapper.insert(defaultUser);
    }

    This initialization routine automatically assigns administrative privileges without validating user credentials or implementing proper access controls.

    Attackers can exploit this by creating new accounts during system initialization phases, effectively gaining unrestricted access to workflow management functions and underlying system resources.

    The Apache development team has released version 3.2.1 with enhanced permission validation and secure-by-default configurations, addressing the root cause of this critical security flaw.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post Apache DolphinScheduler Default Permissions Vulnerability Fixed – Update Now appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. District Court for the District of Columbia has ordered Google to share critical search data with competitors while allowing the tech giant to retain ownership of its Chrome browser.

    The decision, announced Tuesday by the Department of Justice’s Antitrust Division, represents a significant victory in the government’s ongoing battle against Google’s search monopoly that has dominated the market for over a decade.

    The court’s remedies target Google’s anticompetitive practices without requiring the dramatic step of forcing a Chrome sale. Instead, the ruling focuses on breaking down the exclusionary agreements that have locked competitors out of the search market.

    Google will be prohibited from maintaining exclusive contracts relating to the distribution of Google Search, Chrome, Google Assistant, and the Gemini app across devices and platforms.

    Under the new requirements, Google cannot condition licensing agreements on the placement of its search products or tie revenue-sharing payments to maintaining Google Search as the default option for more than one year.

    The Justice Department’s Antitrust Division analysts noted that these practices created a “self-reinforcing cycle of monopolization” that effectively shut out potential competitors while reducing innovation and consumer choice.

    The most technically significant aspect of the ruling involves mandatory data sharing provisions.

    Google will be required to make certain search index and user-interaction data available to qualified competitors, fundamentally altering the competitive landscape.

    This data sharing requirement addresses one of the primary barriers competitors face when attempting to develop alternative search engines.

    # Example of potential API structure for mandated data access
    class SearchDataAPI:
        def get_search_index(self, query_parameters):
            # Return anonymized search index data
            pass
    
        def get_user_interaction_metrics(self, competitor_id):
            # Provide aggregated user behavior patterns
            pass

    Additionally, Google must offer search and search text ads syndication services to enable rivals to deliver competitive search results.

    This syndication requirement effectively opens Google’s advertising infrastructure to competitors, allowing them to build their own capacity while leveraging Google’s existing technology.

    The ruling stems from a case filed during President Trump’s first term in October 2020, ultimately supported by 49 states, two territories, and the District of Columbia.

    Following a nine-week bench trial in 2023 and a 15-day remedies trial in May 2025, the court concluded that Google violated Section 2 of the Sherman Act by maintaining its monopoly through anticompetitive practices that controlled approximately 90 percent of all U.S. search queries.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post Google Won’t Be Forced to Sell Chrome, But Must Share Search Data With Rivals appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶