-
The Russia-linked state-sponsored threat actor known as APT28 (aka UAC-0001) has been attributed to attacks exploiting a newly disclosed security flaw in Microsoft Office as part of a campaign codenamed Operation Neusploit. Zscaler ThreatLabz said it observed the hacking group weaponizing the shortcoming on January 29, 2026, in attacks targeting users in Ukraine, Slovakia, and Romania, three
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The HoneyMyte APT group, also known as Mustang Panda and Bronze President, continues expanding its cyber-espionage operations across Asia and Europe, with Southeast Asia being the most heavily targeted region. Recent investigations reveal that the group has significantly enhanced its malware arsenal during 2025, introducing new capabilities to the CoolClient backdoor and deploying multiple browser […]
The post HoneyMyte Hacker Group Expands CoolClient Malware With New Advanced Toolset appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical XML External Entity (XXE) vulnerability has been disclosed in the Syncope identity management console.
The flaw could allow administrators to expose sensitive user data and compromise session security inadvertently.
The vulnerability, tracked as CVE-2026-23795, affects multiple versions of the platform and requires immediate patching.
The improper restriction of XML External Entity references in Apache Syncope Console creates a pathway for XXE attacks when administrators create or edit Keymaster parameters.
An attacker with sufficient administrative entitlements can craft malicious XML payloads to trigger unintended data exposure.
CVE ID Vulnerability CVSS Score Affected Component Affected Versions Attack Vector Impact CVE-2026-23795 XML External Entity (XXE) Injection 6.5 Apache Syncope Console 3.0-3.0.15, 4.0-4.0.3 Network Data Exposure, Session Hijacking This attack vector bypasses normal security restrictions by exploiting the way the application processes XML input without proper validation and sanitization.
XXE vulnerabilities are among the most dangerous attack vectors in identity management systems because they operate at the application layer and can provide direct access to sensitive configuration data, user credentials, and authentication tokens.
In the context of Syncope’s role as a user identity and access management platform, the implications extend beyond individual sessions to potentially compromise the entire authentication infrastructure.
The vulnerability impacts Apache Syncope versions spanning two major release branches:
Component Affected Versions Fixed Version Syncope Client IdRepo Console (3.x) 3.0 through 3.0.15 3.0.16 Syncope Client IdRepo Console (4.x) 4.0 through 4.0.3 4.0.4 Organizations running these versions should prioritize upgrading immediately.
The vulnerability requires administrator-level access to exploit, limiting direct external attack surface but creating significant insider threat risks.
Attack Methodology
The attack requires an administrator account with permissions to modify Keymaster parameters through the Syncope Console interface.
Once authenticated, the attacker constructs specially formatted XML containing external entity declarations pointing to sensitive system files or internal network resources.
When the application processes this malicious XML, it resolves the external entities and exposes their contents to the attacker.
This technique enables attackers to read arbitrary files from the server, access internal network resources, and potentially extract user session tokens or authentication credentials.
The issue is rated moderate because an attacker needs admin access first, but the possible impact is still large.
Apache recommends immediate upgrades to version 3.0.16 for users on the 3.x branch and version 4.0.4 for those on the 4.x branch.
Organizations unable to patch immediately should restrict administrative console access to trusted personnel and implement additional network monitoring to detect suspicious XML parsing activity.
Organizations managing identity infrastructure should review their deployment status and prioritize this patch in their security update schedule to prevent potential session hijacking and data exposure incidents.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Apache Syncope Vulnerability Let Attackers Hijack User Sessions appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
APT28, the Russia-linked advanced persistent threat group, has launched a sophisticated campaign targeting Central and Eastern Europe using a zero-day vulnerability in Microsoft Office.
The threat actors leveraged specially crafted Microsoft Rich Text Format (RTF) files to exploit the vulnerability and deliver malicious backdoors through a multi-stage infection chain.
The campaign, tracked as Operation Neusploit, represents a significant escalation in APT28’s capabilities and demonstrates their continued focus on high-value targets across Ukraine, Slovakia, and Romania.
The attack begins when users receive socially engineered emails containing weaponized RTF documents.
These messages are customized in English and local languages including Romanian, Slovak, and Ukrainian to increase the likelihood of successful infection.
Once victims open these files, the vulnerability is silently triggered, allowing the threat actors to execute arbitrary code on the compromised system without any visible warning to the user.
Zscaler analysts identified this campaign in January 2026 and attributed it to APT28 based on significant overlaps in tools, techniques, and procedures with the group’s known operations.
The researchers observed active exploitation occurring in the wild on January 29, 2026, just three days after Microsoft released an emergency security update to address the vulnerability.
Infection Mechanism and Persistence Strategy
The infection chain involves two distinct variants of dropper malware designed to deploy different payloads to compromised systems.
The first variant deploys MiniDoor, a lightweight email-stealing tool built using Microsoft Outlook Visual Basic for Applications (VBA).
MiniDoor operates by monitoring Outlook login events and systematically harvesting emails from the infected mailbox. The malware forwards stolen communications to hardcoded email addresses controlled by the attackers.
To maintain persistence, the dropper modifies Windows registry settings to disable Outlook security protections and automatically load the malicious macro each time the application launches.
- CVE ID: CVE-2026-21509
- Vulnerability Type: Remote Code Execution
- Affected Component: Microsoft Office RTF Handler
- Severity: Critical
- Patch Date: January 26, 2026
The second dropper variant deploys PixyNetLoader, which establishes a foothold for deploying the Covenant Grunt implant, providing the attackers with command-and-control capabilities.
Both variants employ server-side evasion techniques, delivering payloads only to requests originating from targeted geographic regions with correct HTTP headers. This selective delivery makes detection and analysis significantly more challenging for security researchers worldwide.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.
The post APT28 Hackers Exploiting Microsoft Office 0-Day in the Wild to Deploy Malware appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
In March 2025, the Ricochet Chollima APT group, widely recognized as APT37 and linked to North Korean state-sponsored operations, launched a targeted spear-phishing campaign against activists focused on North Korean affairs. The threat actors initiated the attack chain via spear-phishing emails impersonating a North Korea-focused security expert based in South Korea. The emails referenced legitimate […]
The post Chollima APT Hackers Weaponize LNK Files to Deploy Sophisticated Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Mozilla has rolled out comprehensive AI controls in Firefox 148, launching February 24, 2026, allowing users to globally disable all generative AI features across the browser. The update addresses growing user concerns about AI integration while maintaining optional AI functionality for those who want it. Firefox 148 AI Control Features The new AI controls section […]
The post Mozilla Introduces Global Kill Switch for Firefox AI Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new Android spyware campaign that uses romance scams and fake chat profiles to spy on users in Pakistan. The malicious app, named GhostChat and detected as Android/Spy.GhostChat.A, disguises itself as a dating chat platform but is actually built for data theft and surveillance. Instead of being listed on Google Play, it is distributed as […]
The post GhostChat Malware Locks Victims’ Devices, Demands Passcodes for Restoration appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hundreds of malicious skills are distributed through OpenClaw’s marketplace, transforming the popular AI agent ecosystem into a new supply chain attack vector. Threat actors are weaponizing the platform’s extensibility features to deliver droppers, backdoors, and infostealers disguised as legitimate automation tools. OpenClaw Skills Become Malware Distribution Channel OpenClaw is a self-hosted AI agent that executes […]
The post Abuse of OpenClaw AI Capabilities Enables Stealthy Malware Campaigns appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A dangerous banking malware called Anatsa has been discovered spreading through the Google Play Store, reaching more than fifty thousand downloads before detection.
The malicious application was cleverly hidden as a document reader, making it appear harmless to unsuspecting users searching for legitimate file management tools.
This discovery highlights how cybercriminals continue to exploit official app stores as distribution channels for sophisticated financial threats targeting Android users worldwide.
The Anatsa banking trojan is particularly concerning because it specifically targets banking credentials and sensitive financial information from infected devices.
The malware operates as an installer that downloads and deploys the full Anatsa banking trojan payload once the initial application gains access to a device.
Users who downloaded and installed this fake document reader application unknowingly gave the malware permission to operate with elevated access, creating a gateway for financial theft and personal data extraction.
The distribution method through Google’s official marketplace made this attack particularly effective, as users typically trust applications found on authorized platforms.
This represents a significant breach in app store security screening processes, demonstrating how malicious developers continue to evade detection systems.
Zscaler ThreatLabz analysts identified this malicious application and immediately began tracking its distribution network and associated command-and-control infrastructure.
The security researchers confirmed the malware’s connection to banking theft operations and provided detailed technical indicators to help other security teams detect infected devices.
Their investigation revealed the attack chain and documented how the malware communicates with external servers to receive commands and exfiltrate stolen banking information.
Analyzing the Malware’s Infection and Communication Mechanism
Understanding how Anatsa establishes persistence on infected Android devices is crucial for users and security professionals seeking to prevent compromise.
Once installed, the banking trojan integrates itself into the operating system and actively monitors user activity, particularly focusing on banking application interactions.
When users open their banking applications or enter financial credentials, the malware captures this sensitive information through overlay attacks and credential logging techniques.
The malware then communicates with command-and-control servers located at specific IP addresses, transmitting stolen banking details directly to threat actors.
This direct connection to attacker-controlled infrastructure means compromised devices remain under active threat actor control, continuously feeding banking information and session tokens to criminal operations.
Security researchers recommend users immediately remove any suspicious document reader applications, verify app authenticity through official channels, and enable multi-factor authentication on all banking accounts to mitigate potential compromise risks.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.
The post Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical authenticated command execution vulnerability has been disclosed affecting multiple Hikvision Wireless Access Point (WAP) models.
The flaw, tracked as CVE-2026-0709, stems from insufficient input validation in device firmware, potentially allowing attackers with valid credentials to execute arbitrary commands on affected systems.
The vulnerability carries a CVSS v3.1 base score of 7.2, indicating a high-severity threat.
According to the advisory, attackers who can authenticate to the device can send specially crafted packets containing malicious commands directly to the WAP, bypassing critical security controls.
This attack vector bypasses network perimeter defenses since it requires valid credentials, making it particularly dangerous in environments where user authentication has been compromised or where insider threats exist.
Affected Models and Timeline
Affected Model Vulnerable Firmware Version DS-3WAP521-SI V1.1.6303 build250812 and earlier DS-3WAP522-SI V1.1.6303 build250812 and earlier DS-3WAP621E-SI V1.1.6303 build250812 and earlier DS-3WAP622E-SI V1.1.6303 build250812 and earlier DS-3WAP623E-SI V1.1.6303 build250812 and earlier DS-3WAP622G-SI V1.1.6303 build250812 and earlier Hikvision has released patched firmware versions (V1.1.6601 build 251223) that address the flaw across all affected devices.
The vulnerability was initially reported on January 30, 2026, by an independent security researcher, exzettabyte.
Organizations deploying these WAP models should immediately prioritize updating to the resolved firmware version to mitigate exploitation risks.
Vulnerability Details and Impact
The authenticated nature of this vulnerability makes it particularly concerning for enterprise environments.
While attackers must possess valid device credentials, compromised user accounts, stolen credentials, or insider threats can serve as entry points.
Once authenticated, the insufficient input validation allows threat actors to inject and execute arbitrary commands with device privileges, potentially leading to complete system compromise.
Organizations operating affected Hikvision WAP models should take immediate action. Patches are available for download on the official Hikvision support portal.
Administrators should deploy firmware version V1.1.6601 build 251223 across all vulnerable devices in their infrastructure.
Simultaneously, organizations should review access controls and enforce strong authentication mechanisms to limit device access to authorized personnel only.
For organizations unable to patch immediately, implementing network segmentation to restrict device access and monitoring authentication logs for suspicious activity can provide interim protection.
Additionally, credential rotation for affected devices is recommended to prevent exploitation through compromised accounts. Hikvision’s HSRC continues monitoring security threats and welcomes vulnerability disclosures at hsrc@hikvision.com.
Organizations with questions regarding this vulnerability should contact Hikvision support through official channels.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Hikvision Wireless Access Points Vulnerability Enables Malicious Command Execution appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶



ThreatLabz has identified another malicious app on the Google Play Store disguised as a document reader. The app currently has over 50K downloads and serves as an installer for the Anatsa banking trojan.