• A critical security flaw has been discovered in the widely used W3 Total Cache WordPress plugin, putting over 1 million websites at serious risk. The vulnerability allows attackers to take complete control of affected websites without needing any login credentials. Field Value CVE ID CVE-2025-9501 Plugin Name W3 Total Cache Affected Versions Before 2.8.13 Fixed […]

    The post W3 Total Cache Security Vulnerability Exposes One Million WordPress Sites to RCE appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has announced the public preview of its Alert Triage and Investigation agent, a significant advancement in artificial intelligence-driven security operations.

    The intelligent agent is now embedded directly within Google Security Operations, helping security teams process alerts faster and more effectively.

    The new agent represents a significant step toward Google’s vision of an “Agentic SOC,” a security operations center powered by intelligent automation.

    Instead of having security analysts check every alert by hand, the agent checks them itself, collects information, and decides whether they are real threats or harmless.

    This capability allows security teams to focus their attention on alerts that genuinely require human expertise.

    During private preview testing, the agent investigated hundreds of thousands of alerts across various organizations and industries.

    Feedback from financial services firms and major retailers revealed substantial time savings. Google analysts reported that the agent’s comprehensive investigation summaries enabled faster decision-making.

    While consolidating complex information that would otherwise require manual queries and analysis.

    The investigation process begins when alerts are generated in Google’s detection engine. The agent reviews each alert and creates a dynamic investigation plan on line with Mandiant experts’ best practices.

    How the Agent Works

    It then executes multiple analytical capabilities, including YARA-L searches, to retrieve relevant events.

    Threat intelligence enrichment using Google Threat Intelligence, command-line analysis for encoded or obfuscated commands, and process tree reconstruction to understand the full scope of potential attacks.

    After completing its investigation, the agent decides whether the alert is real and assigns a confidence score indicating how sure it is.

    Google emphasizes explainability throughout the agent’s process. The system references its sources and outlines investigation steps so analysts understand how recommendations were reached.

    The company uses multiple evaluation techniques, including comparisons with human experts and AI evaluation methods, to ensure accuracy and continuous improvement.

    All eligible Google Security Operations Enterprise and Enterprise Plus users can opt into the public preview immediately by clicking the Gemini icon within Google Security Operations.

    Investigations begin automatically after enrollment, though users can also trigger investigations manually. Google plans to bring the agent to general availability in 2026 with additional enhancements to investigation depth and workflow integration.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Google Reveals Public Preview of Alert Triage and Investigation Agent for Security Operations appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about a severe vulnerability in Lynx+ Gateway devices that could expose sensitive information in clear text during transmission.

    The flaw allows attackers to catch network traffic and obtain plaintext credentials and other confidential data. The vulnerability, tracked as CVE-2025-62765, stems from the product’s failure to encrypt data during transmission.

    This cleartext transmission vulnerability poses a significant security risk for organizations that rely on Lynx+ Gateway technology, particularly those managing critical infrastructure or handling sensitive communications.

    Lynx+ Gateway Vulnerability

    An attacker with network access could exploit this weakness by monitoring traffic flowing through the affected gateway.

    The lack of encryption means that credentials, authentication tokens, and other sensitive information transmitted across the network remain visible to potential threat actors.

    According to CISA, no authentication or user interaction is required to launch an attack, making this vulnerability particularly dangerous.

    The vulnerability has received a CVSS v3 base score of 7.5, indicating a high-severity threat.

    CVE IDProductVulnerability TypeCVSS v3 ScoreCVSS v4 ScoreImpact
    CVE-2025-62765Lynx+ GatewayCleartext Transmission7.5 (High)8.7 (Critical)Plaintext Credentials & Data Exposure

    The CVSS v3 vector string (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A: N) shows the attack can be executed remotely with low complexity and requires no privileges.

    The vulnerability severely impacts confidentiality without affecting integrity or availability. The CVSS v4 score is even more severe at 8.7, reflecting the evolving assessment of this threat.

    The CVSS v4 vector (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA: N) confirms that the attack vector remains network-based, with minimal barriers to exploitation.

    Organizations using Lynx+ Gateway devices should prioritize patching this vulnerability immediately. CISA recommends implementing network segmentation to limit exposure and monitoring for suspicious network activity.

    Additionally, organizations should consider implementing encrypted communication channels and reviewing access logs for signs of unauthorized traffic interception.

    Until patches are available, administrators should restrict network access to affected gateways and implement additional monitoring controls.

    Given the critical nature of this flaw, this update should be treated as a high-priority security incident requiring urgent attention from network and security teams.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated threat actor has orchestrated a multi-stage ransomware attack spanning nine days, leveraging compromised Remote Desktop Protocol (RDP) credentials to infiltrate a corporate network, exfiltrate sensitive data, and deploy Lynx ransomware across critical infrastructure. The attack initiated with a successful RDP login using pre-compromised credentials a critical indicator that the threat actor obtained valid […]

    The post Threat Actors Use Compromised RDP to Deploy Lynx Ransomware After Deleting Backups appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical vulnerability was discovered in the AI-Bolit component of Imunify security products, raising concerns across the web hosting and Linux server communities. This flaw could let attackers execute arbitrary code and escalate their privileges to root, risking the integrity of millions of servers worldwide. Imunify, a security platform widely used on web hosting servers, […]

    The post Imunify AI-Bolit Flaw Allows Arbitrary Code Execution and Root Privilege Escalation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Remcos, a commercial remote access tool distributed by Breaking-Security and marketed as “Remote Administration Software,” continues to pose a significant threat to organizations worldwide. Despite its administrative positioning, the tool’s capabilities are routinely weaponized for unauthorized access and data theft, with recent analysis revealing extensive C2 infrastructure operating across multiple continents. Recent Censys research tracking […]

    The post Mapping Remcos RAT C2 Activity and Associated Communication Ports appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has released an urgent security update for its Chrome browser to address a critical zero-day vulnerability actively exploited by threat actors. The flaw, tracked as CVE-2025-13223, affects the V8 JavaScript engine and poses a significant risk to millions of Chrome users worldwide.​ Critical Zero-Day Under Active Attack The vulnerability was discovered by Clément Lecigne of […]

    The post Chrome Zero-Day Type Confusion Flaw Actively Exploited in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Lynx ransomware has emerged as a significant threat to enterprise environments, with recent intrusions demonstrating sophisticated attack strategies that prioritize data exfiltration and infrastructure destruction.

    The malware campaign combines compromised credentials with careful planning to ensure maximum impact on target networks.

    Security researchers continue to monitor this evolving threat as attackers refine their techniques and expand their targeting scope across various industries.

    The attack chain reveals a methodical approach where threat actors gain initial access through compromised Remote Desktop Protocol credentials, likely sourced from infostealer malware, data breaches, or initial access brokers.

    What distinguishes this campaign is the extended preparation phase before ransomware deployment. Attackers spend days conducting reconnaissance, mapping network infrastructure, and establishing persistent backdoors rather than rushing to encrypt systems immediately.

    This calculated approach significantly increases their chances of success by identifying high-value targets and securing escape routes before triggering detection alarms.

    The DFIR Report security analysts identified that the intrusion began in early March 2025 when an unknown threat actor successfully logged into an internet-facing RDP endpoint using valid credentials.

    Notably, no evidence of credential stuffing or brute force attempts preceded this access, indicating the attackers possessed legitimate account credentials from the start.

    Within minutes of initial access, the threat actor began conducting system reconnaissance using command prompt utilities and deployed SoftPerfect Network Scanner for wider network enumeration.

    The attack evolved rapidly as the threat actor moved laterally to the domain controller within just ten minutes using a separate compromised administrator account.

    Lateral Movement (Source – The DFIR Report)

    Once positioned on the domain controller, the attacker created multiple fake accounts designed to mimic legitimate users, such as administratr, adding them to privileged groups including Domain Administrators.

    The attackers also installed AnyDesk remote access software to establish persistence, ensuring continued access even if their original credentials were discovered.

    Understanding Backup Destruction as an Attack Vector

    A particularly concerning aspect of this Lynx ransomware campaign is the deliberate destruction of backup infrastructure before deploying the malware. After six days of dormancy, the threat actor returned and resumed operations by conducting password spray attacks using NetExec.

    They systematically collected sensitive data from network shares, compressing these files using 7-Zip before exfiltrating the archives via temp.sh, a temporary file-sharing service.

    This data collection phase served as a double extortion preparation method, allowing attackers to threaten victims with data publication if ransoms went unpaid.

    The critical final phase involved connecting directly to backup servers and systematically deleting backup jobs. By removing backup recovery points before deploying Lynx ransomware, the attackers eliminated the victims’ ability to restore encrypted files through alternative means.

    Temporary file sharing site (Source – The DFIR Report)

    This strategy transforms the ransomware into a more effective extortion tool since organizations cannot simply restore from backups.

    The overall time from initial compromise to ransomware deployment reached approximately 178 hours across nine days, allowing the attackers to carefully stage their attack and maximize organizational disruption when Lynx finally encrypted critical systems across multiple backup and file servers.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Threat Actors Leveraging Compromised RDP Logins to Deploy Lynx Ransomware After Deleting Server Backups appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Lazarus APT Group, an advanced persistent threat (APT) attributed to North Korea, has deployed a sophisticated new Remote Access Trojan (RAT) called ScoringMathTea as part of its ongoing Operation DreamJob cyberespionage campaign. ScoringMathTea represents a significant evolution in Lazarus’s malware toolkit, implementing a modular architecture designed specifically to evade detection across both network and […]

    The post Lazarus APT Group’s New ScoringMathTea RAT Enhances Remote Command Execution and More appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Azure successfully defended against a record-breaking distributed denial-of-service (DDoS) attack that peaked at 15.72 terabits per second (Tbps), making it the most significant DDoS attack ever observed in the cloud. On October 24, 2025, Azure’s DDoS Protection system automatically detected and mitigated a massive multi-vector attack targeting a single endpoint in Australia. The assault generated […]

    The post Massive 15 Tbps DDoS Attack From 500K Devices Slams Azure Network appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶