• A stealthy new malware loader dubbed TinyLoader has begun proliferating across Windows environments, exploiting network shares and deceptive shortcut files to compromise systems worldwide.

    First detected in late August 2025, TinyLoader installs multiple secondary payloads—most notably RedLine Stealer and DCRat—transforming infected machines into fully weaponized platforms for credential theft, remote access, and cryptocurrency hijacking.

    Analysts have observed rapid escalation in the loader’s deployment, with infections traced to corporate file shares, removable media, and social engineering tactics that entice unsuspecting users to execute malicious binaries.

    While malware loaders are not a novel threat, TinyLoader distinguishes itself through a combination of aggressive lateral movement and sophisticated persistence mechanisms.

    Initial access is frequently achieved via network shares: the loader scans for open SMB resources, replicates itself as an innocuous “Update.exe” file, and updates directory timestamps to avoid detection.

    Once executed, it immediately reaches out to predefined command-and-control (C2) servers to download additional modules.

    Hunt.io researchers identified early C2 infrastructure hosted at IP addresses 176.46.152.47 and 176.46.152.46 in Riga, Latvia, with further nodes in the UK and Netherlands, all operated under a single hosting provider to streamline deployment.

    Hunt.io analysts noted that TinyLoader’s interface mirrors modern malware-as-a-service panels, offering threat actors an intuitive web portal for campaign management.

    Examination of the loader’s payload retrieval sequence revealed six hard-coded URLs pointing to malicious binaries—bot.exe and zx.exe among them—which are saved to the Windows temporary directory and executed without user interaction.

    This modular approach allows attackers to rotate payloads and pivot to new tools such as cryptocurrency clipper modules or remote access trojans with minimal redevelopment effort.

    Following the outbreak of infections, security teams scrambled to uncover detection signatures.

    TinyLoader command-and-control login panel (Source – Hunt.io)

    TinyLoader’s login panel carries a consistent HTML title tag:-

    <title>Login - TinyLoader</title>

    This string became a critical indicator for web crawler searches, enabling defenders to enumerate additional C2 panels and preemptively block them.

    Hunt.io scan results (Source – Hunt.io)

    The Hunt.io scan results for suspicious IP address 176.46.152.47 illustrates the initial discovery that triggered further infrastructure mapping.

    Infection Mechanism: Network Share Propagation and Fake Shortcuts

    TinyLoader’s primary infection vector leverages both network file sharing and social engineering via fake Windows shortcuts.

    Upon gaining administrative privileges, the loader injects itself into the Windows registry to hijack .txt file associations:-

    Windows Registry Editor Version 5.00
    [HKEY_CLASSES_ROOT\txtfile\shell\open\command]
    @="\"%SystemRoot%\\System32\\cmd[.]exe\" /c start \"\" \"C:\\Windows\\System32\\Update.exe\" \"%1\""

    This modification ensures that any attempt to open a text file silently launches TinyLoader first, before displaying the legitimate document.

    Concurrently, the malware scans writable network shares, copying both “Update.exe” and malicious shortcut files named “Documents Backup.lnk.”

    When these shortcuts are double-clicked, they execute TinyLoader while masquerading as a user-friendly backup utility.

    Fake desktop shortcut used for social engineering (Source – Hunt.io)

    While the above mentioned fake desktop shortcut used for social engineering, exemplifies this tactic.

    The loader also targets removable media: every USB insertion triggers replication of TinyLoader under enticing names like “Photo.jpg.exe.”

    An accompanying autorun.inf file guarantees execution on the next host, perpetuating the infection cycle.

    Together, these techniques create a resilient propagation mechanism that spans both local and enterprise networks, making TinyLoader exceptionally difficult to eradicate once established.

    Defenders are urged to monitor registry changes affecting file associations, deploy policies restricting executable creation on network shares, and inspect shortcut files for unusual targets.

    By combining signature-based detection of the “Login – TinyLoader” panel with behavioral monitoring of autorun activity, security teams can mitigate the rapid spread of this emerging threat.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post New TinyLoader Malware Attacking Windows Users Via Network Shares and Fake Shortcuts Files appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ukraine has reached a critical milestone, the country’s Ministry of Defense announced Monday: more than one million drones delivered to military units since January, with two million expected by the end of the year. 

    The achievement provides a vivid illustration of a counterintuitive phenomenon: increasing the speed of innovation and deployment of new technologies may not result in any increase in battlefield gains.

    “Those one-way attack drones are not going to gain air superiority, and they don’t have air superiority, and that’s really one of the key attributes of the conflict in Russia-Ukraine, is no one does,” Gen. Alexus Grynkewich, commander of  U.S. European Command, and Supreme Allied Commander Europe, said last week at an NDIA event in Washington, D.C. And, he said, maintaining U.S. and NATO air superiority in an environment where even small militaries can deploy strategies to rapidly erode U.S. advantage remains a “core mission.”

    Ukraine had help reaching its goal. Among the million-plus drones are U.S.-made Switchblade and Ghost drones, as well as unmanned platforms paid for with $2.5 billion donated by nongovernmental groups and citizen donations since 2024. 

    But Ukraine has also radically reformed contracting procedures and opened direct web exchanges, allowing frontline commanders to source drones directly from manufacturers. The Ukrainian government says commanders can now order and receive weapons in as little as five days.

    These strategies have become a model for converting a 20th-century military into one that can effectively fight much larger and better-financed adversaries. The Pentagon is now taking similar steps after years of struggling to produce large numbers of cheap, highly autonomous drones that can also be rapidly modified to meet changing threats.

    Emil Michael, the undersecretary of defense for research and development, speaking at the same event, said the new U.S. approach “mimics what the Ukrainians have done. They push down the innovation to a very small unit level. They’ve competed them on which drones work better. Then they give more financing to the ones that work better. So that’s their model. Our model is going to be: bring it down to the unit level, reduce the barriers, provide broad training grounds.”

    Several Defense Department initiatives to accelerate the development and proliferation of drones are also reaching new milestones, and the department anticipates that development will continue to get faster, officials said.

    Col. Glenn McCartan, the Defense Innovation Unit’s embed to U.S. European Command,  said DIU, working with industry, has finished prototyping its Artemis drones, a process that began in January after the down-selection of competitors. That timeline may seem long compared with Ukraine’s drone development, but is much faster than traditional U.S. procurement. 

    More importantly, McCartan said, DIU has helped build open communication lines between drone makers and commanders, allowing for small, fast buys. This includes commanders in Europe who are working to build up large drone and other weapons stockpiles on NATO’s border with Russia, an effort called the Eastern Flank Deterrence Line

    In April, Ukraine’s former commander in chief, Gen. Valeriy Zaluzhny, observed that modern victory now depends on “the ability to outpace the enemy in technological development.” The observation raises a larger question: outpace to where?

    Ukraine’s fast-delievered, million-plus drone force exists not just because of direct builder-to-soldier business relationships, but also because of broader trends in information-technology democratization. Digital tech has become exponentially cheaper, more powerful, and more available. It is the same trend that created the modern IT-led digital economy that displaced last century’s enterprises, which focused on control of physical assets. 

    But Ukraine’s “static front line,” as U.S. Army War College professor Frank Sobchak called it in August, also shows that rapid technology development does not necessarily build advantage over a larger, well-resourced adversary such as China or Russia. It simply erodes an opponent’s relative advantage. The result is a new type of conflict: more nimble operations and far faster invention and deployment of new weapons, but slower decisive wins.

    Grynkewich said U.S. air dominance will have to come from a mix of more capable next-generation platforms, fighters and bombers—manned and unmanned—alongside cheap drones.

    But the democratization that allowed Ukraine to build a massive drone force in just months does not lend itself to the construction of highly complex fighters and bombers, or other systems apart from consumer electronics, Michael acknowledged. 

    “With a drone, you can go from start to prototype in 18 months. You can’t do that for an F-35, right? You can’t have a startup just say, ‘Here’s an airplane.’” 

    In other words, fighter jets remain necessary, but technology trends are rendering them obsolete more quickly, so the U.S. advantage in air dominance is dissolving more rapidly—and coming at higher cost.

    For Michael, the key to building new U.S. dominance is continued investment in digital infrastructure away from the battlefield. For example, he said he is looking for ways to deploy artificial intelligence across the entire Defense Department.

    Defense One asked Michael about a recent MIT analysis and comments from AI technology leaders suggesting a potential drop in funding to the sector.

    “We had the same thing with the internet. We had the same feeling with mobile phones. I think we’re going through the same cycle with AI right now, where we’re not sure where it ends. My instinct says it ends the same way the internet and mobile phones did. AI becomes a critical part of what we do every day. The infrastructure around it is much more significant than you think it’ll be, and the advantages you can get from it are much greater than you could possibly imagine sitting right at the beginning.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The rise of hybrid workforces and multi-cloud environments has made Identity & Access Management (IAM) more critical than ever. In 2025, a robust IAM solution is the cornerstone of a Zero Trust security model, where no user, device, or application is trusted by default. The best IAM tools go beyond simple authentication, offering a comprehensive […]

    The post Top 10 Best Identity and Access Management (IAM) Tools in 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly disclosed remote code execution (RCE) vulnerability in Microsoft’s IIS Web Deploy toolchain has captured industry attention after the release of a public proof-of-concept. Tracked as CVE-2025-53772, this flaw resides in the unsafe deserialization logic of the msdeployagentservice and msdeploy.axd endpoints, allowing authenticated attackers to run arbitrary code on vulnerable web servers. IIS Web […]

    The post IIS WebDeploy RCE Vulnerability Gets Public PoC appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors are rapidly weaponizing Hexstrike-AI, a recently released AI-powered offensive security framework, to scan for and exploit zero-day CVEs in under ten minutes. 

    Originally marketed as an offensive security framework for red teams, Hexstrike-AI’s architecture has already been repurposed by malicious operators within hours of its public release.

    Key Takeaways
    1. Hexstrike-AI automates zero-day exploits in under 10 minutes.
    2. It links LLMs to 150+ tools for resilient workflows.
    3. Rapidly weaponized against Citrix CVEs, driving urgent AI-driven defenses.

    Hexstrike-AI Automates Exploits in Minutes

    Checkpoint’s recent analysis shows how artificial intelligence (AI) can manage and simplify complex attacks by coordinating many specialized agents. This AI-driven system helps automate multi-step attacks more efficiently.

    With Hexstrike-AI, that theory has become operational. The framework stands on a FastMCP server core, binding large-language models (Claude, GPT, Copilot) to over 150 security tools via MCP decorators. 

    AI agents can invoke standardized functions such as nmap_scan(target, options) and execute_exploit(cve_id, payload) without human micromanagement. 

    Dark-web chatter confirmed that threat actors are testing Webshell deployments against the freshly disclosed Citrix NetScaler ADC and Gateway CVEs CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424 within hours of disclosure.

    Hexstrike-AI’s MCP orchestration layer interprets high-level commands, such as “exploit NetScaler,” into sequenced technical workflows. 

    Each stage of reconnaissance, memory-handling exploitation, persistence via webshell, and exfiltration is handled by specialized MCP agents, ensuring retry logic and automated resilience. 

    CheckPoint observed that, to the underground posts, operators achieved unauthenticated remote code execution on vulnerable appliances and dropped web shells in under ten minutes.

    Dark web posts discussing HexStrike AI, shortly after its release
    Dark web posts discussing HexStrike AI, shortly after its release

    The architecture of Hexstrike-AI implements:

    Abstraction Layer: Translates vague operator intent into precise function calls.

    MCP Agents: Autonomous servers bridging LLMs with tools, orchestrating everything from nmap_scan and hydra_brute to custom NetScaler exploit modules.

    Automation & Resilience: Built-in retry loops and failure recovery ensure chained operations proceed without human intervention.

    Intent-to-Execution Translation: The execute_command API dynamically constructs and executes workflows based on intent strings.

    This model mirrors academic projections of AI orchestration driving next-gen cyberattacks—now crystallized in Hexstrike-AI’s code.

    Citrix’s August 26 advisories revealed three critical NetScaler vulnerabilities. Traditionally, exploiting such memory and access-control flaws demanded expert reverse engineering and exploit writing. 

     Dark web post claiming to have successfully exploited Citrix CVE’s using HexStrike AI
     Dark web post claiming to have successfully exploited Citrix CVEs using HexStrike AI

    Hexstrike-AI collapses that barrier, enabling parallelized scanning of thousands of IPs and dynamic adaptation of exploit parameters until success.

    The time-to-exploit for CVE-2025-7775 has already been reduced from weeks to minutes, with webshell-equipped appliances appearing on underground markets.

    Mitigations

    Organizations must quicken patching cycles and implement adaptive, AI-driven detection systems. 

    Static signatures alone will not suffice against rapidly orchestrated attacks. Monitoring dark-web intelligence for early signals, enforcing segmentation and least-privilege models, and integrating autonomous response playbooks are critical. 

    Defenders must keep up with the growth of AI-powered offenses through telemetry correlation and machine-speed patch validation.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Hackers Leverage Hexstrike-AI Tool to Exploit Zero Day Vulnerabilities Within 10 Minutes appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Within hours of its release, the newly unveiled framework Hexstrike-AI has emerged as a game-changer for cybercriminals, enabling them to scan, exploit and persist inside targets in under ten minutes. Hexstrike-AI, a red-team tool, quickly turned into a hacking weapon on underground forums, where attackers shared ways to use it against new Citrix NetScaler zero-day flaws. Security […]

    The post Hackers Use Hexstrike-AI to Exploit Zero-Day Flaws in Just 10 Minutes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Inf0s3c Stealer, a stealthy Python-based grabber built to harvest system information and user data from Windows hosts. Packed as a 64-bit PE file compressed with UPX and bundled via PyInstaller, the executable imports a suite of Windows API functions to enumerate processes, navigate directories, manipulate memory, and manage security settings. Once executed, it methodically collects […]

    The post Stealthy Python Malware Uses Discord to Steal Windows Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • AI-powered cybersecurity tools can be turned against themselves through prompt injection attacks, allowing adversaries to hijack automated agents and gain unauthorized system access.

    Security researchers Víctor Mayoral-Vilches & Per Mannermaa Rynning, revealed how modern AI-driven penetration testing frameworks become vulnerable when malicious servers inject hidden instructions into seemingly benign data streams. 

    Key Takeaways
    1. Prompt injection hijacks AI security agents by embedding malicious commands.
    2. Encodings, Unicode tricks, and env-var leaks bypass filters to trigger exploits.
    3. Defense needs sandboxing, pattern filters, file-write guards, and AI-based validation.

    This attack technique, known as prompt injection, exploits the fundamental inability of Large Language Models (LLMs) to distinguish between executable commands and data inputs once both enter the same context window.

    Prompt Injection Vulnerabilities

    Investigators used an open-source Cybersecurity AI (CAI) agent that autonomously scans, exploits, and reports network vulnerabilities. 

    During a routine HTTP GET request, the CAI agent received web content wrapped in safety markers:

    AI-Powered Cybersecurity Tools Turned Against Prompt Injection

    The agent interpreted the “NOTE TO SYSTEM” prefix as a legitimate system instruction, automatically decoding the base64 payload and executing the reverse shell command. 

    Within 20 seconds of initial contact, the attacker gained shell access to the tester’s infrastructure, illustrating the attack’s rapid progression from “Initial Reconnaissance” to “System Compromise.”

    Attackers can evade simple pattern filters using alternative encodings—such as base32, hexadecimal, or ROT13—or hide payloads in code comments and environment variable outputs. 

    Unicode homograph manipulations further disguise malicious commands, exploiting the agent’s Unicode normalization to bypass detection signatures.

    AI-Powered Tools Turned Against Themselves
    Attack landscape for AI security tools

    Mitigations

    To counter prompt injection, a multi-layered defense architecture is essential:

    • Execute all commands inside isolated Docker or container environments to limit lateral movement and contain compromises.
    • Implement pattern detection at the curl and wget wrappers. Block any response containing shell substitution patterns like $(env) or $(id) and embed external content within strict “DATA ONLY” wrappers.
    • Prevent the creation of scripts with base64 or multi-layered decoding commands by intercepting file-write system calls and rejecting suspicious payloads.
    • Apply secondary AI analysis to distinguish between genuine vulnerability evidence and adversarial instructions. Runtime guardrails must enforce a strict separation of “analysis-only” and “execution-only” channels.

    Novel bypass vectors will appear as LLM capabilities advance, resulting in a continuous arms race similar to early web application XSS defenses. 

    Organizations deploying AI security agents must implement comprehensive guardrails and monitor for emerging prompt injection techniques to maintain a robust defense posture.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post AI-Powered Cybersecurity Tools Can Be Turned Against Themselves Through Prompt Injection Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly uncovered variant of the notorious RapperBot malware is covertly commandeering internet-connected devices—particularly outdated network video recorders (NVRs)—and transforming them into a powerful distributed denial-of-service (DDoS) army in mere moments. Security researchers have detailed a sophisticated exploit chain that leverages zero-day vulnerabilities, outdated firmware, and alternative DNS infrastructures to orchestrate attacks exceeding terabit-scale traffic […]

    The post Hijacked by RapperBot: Devices Exploited for Instant DDoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Jaguar Land Rover (JLR), the UK’s leading luxury automotive manufacturer, has disclosed that it is the victim of a significant cyberattack affecting its global information technology infrastructure. In a statement released early Wednesday, JLR confirmed that an unauthorized intrusion forced the company to take precautionary measures by proactively shutting down critical systems to contain the […]

    The post Jaguar Land Rover Confirms Cyberattack Disrupting Global IT Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶