• The Iran-nexus cyber espionage group UNC1549 has significantly expanded its arsenal of custom tools and sophisticated attack techniques in an ongoing campaign targeting aerospace, aviation, and defense industries since mid-2024, according to new findings from Mandiant. The threat actor, which overlaps with Tortoiseshell and has suspected links to Iran’s Islamic Revolutionary Guard Corps (IRGC), demonstrates […]

    The post UNC1549 Hackers With Custom Tools Attacking Aerospace and Defense Systems to Steal Logins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google on Monday released security updates for its Chrome browser to address two security flaws, including one that has come under active exploitation in the wild. The vulnerability in question is CVE-2025-13223 (CVSS score: 8.8), a type confusion vulnerability in the V8 JavaScript and WebAssembly engine that could be exploited to achieve arbitrary code execution or program crashes. “Type

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiWeb vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively exploited in the wild. The vulnerability, tracked as CVE-2025-64446, allows unauthenticated attackers to gain administrative access to affected systems via a path-traversal vulnerability. Critical Path Traversal Flaw […]

    The post CISA Reports Active Attacks on FortiWeb WAF Vulnerability Allowing Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • IBM has released critical security updates addressing two severe vulnerabilities in its AIX operating system that could allow remote attackers to execute arbitrary commands on affected systems.

    Both vulnerabilities stem from improper process controls in essential IBM AIX services.

    Critical Flaws in IBM AIX Services

    The first vulnerability, CVE-2025-36251, affects the Nimsh service and its SSL/TLS implementations. This critical flaw could enable remote attackers to bypass security controls and execute unauthorized commands.

    The vulnerability carries a CVSS base score of 9.6, indicating severe risk across network-accessible systems. The attack requires network access but no authentication or user interaction, making it particularly dangerous for exposed systems.

    The second vulnerability, CVE-2025-36250, impacts the NIM server service (nimesis), formerly known as NIM master. This flaw is even more critical, receiving a perfect CVSS score of 10.0.

    CVE IDCVE-2025-36251CVE-2025-36250
    Affected ServiceIBM AIX nimsh serviceIBM AIX NIM server (nimesis)
    Vulnerability TypeSSL/TLS implementation flawImproper process controls
    CWE ClassificationCWE-114: Process ControlCWE-114: Process Control
    CVSS Base Score9.610.0
    Attack Vector (AV)NetworkNetwork

    Like the first vulnerability, it stems from improper process controls that fail to properly restrict command execution.

    Attackers can exploit this remotely without requiring authentication or user interaction, potentially compromising the entire infrastructure.

    Both vulnerabilities represent additional attack vectors for issues previously addressed in CVE-2024-56347 and CVE-2024-56346.

    This indicates that IBM’s earlier patches may not have comprehensively eliminated all exploitation paths, necessitating these additional security updates.

    The vulnerabilities are classified under CWE-114: Process Control, a weakness category focusing on improper management of processes and their permissions.

    Exploitation could result in complete system compromise, including unauthorized data access, modification, and denial-of-service attacks.

    IBM AIX administrators should prioritize patching these vulnerabilities immediately. The NIM services are critical components used for managing and deploying IBM AIX systems across enterprise environments.

    Exploitation could allow attackers to gain control over multiple systems simultaneously. Organizations running IBM AIX should review their current patch levels and apply the latest security updates from IBM.

    Additionally, implementing network segmentation and restricting access to NIM and nimsh services to trusted networks can provide temporary mitigation.

    Security teams should look for unusual activity and use tools to detect attacks. These vulnerabilities underscore the importance of maintaining current patch levels on critical infrastructure components.

    Organizations dependent on IBM AIX should establish regular security update procedures and closely monitor IBM security advisories for emerging threats.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post IBM AIX Vulnerabilities Let Remote Attacker Execute Arbitrary Commands appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has rushed out a critical update for its Chrome browser to address a zero-day vulnerability actively exploited in the wild, urging users to update immediately to mitigate the risk posed by sophisticated attackers.

    The patch, rolled out in Chrome Stable version 142.0.7444.175 for Windows and Linux, and 142.0.7444.176 for Mac, fixes two high-severity type confusion bugs in the V8 JavaScript engine.

    The most alarming is CVE-2025-13223, reported on November 12, 2025, by Clément Lecigne of Google’s Threat Analysis Group (TAG).

    Google confirmed an exploit for this flaw is already circulating, potentially allowing remote attackers to execute arbitrary code on victims’ systems without interaction.

    Type confusion vulnerabilities, a staple in browser exploits, occur when the V8 engine misinterprets data types, leading to memory corruption. This can enable attackers to bypass Chrome’s sandbox protections, steal sensitive information, or install malware.

    The second fix, CVE-2025-13224, was identified earlier on October 9, 2025, by Google’s internal Big Sleep fuzzing tool, highlighting the company’s proactive defense layers, reads the advisory.

    TAG’s involvement suggests possible ties to advanced persistent threats (APTs), as the group often tracks state-sponsored operations using such flaws for espionage or supply chain attacks.

    This incident underscores Chrome’s dominance as a target, as over 65% of global browsers run the engine, making timely patches essential.

    Google credits tools like AddressSanitizer and libFuzzer for early detection, but the rapid exploitation timeline, from report to wild use in under a week, raises questions about attribution. Users should enable automatic updates and avoid suspicious links.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Chrome Type Confusion Zero-Day Vulnerability Actively Exploited in the Wild appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Azure thwarted what may be the largest distributed denial-of-service (DDoS) attack ever recorded in the cloud on October 24. The attack peaked at 15.72 terabits per second (Tbps) and unleashed nearly 3.64 billion packets per second (pps), targeting a single endpoint in Australia.

    Azure’s automated DDoS Protection service sprang into action, filtering out the malicious flood and ensuring zero downtime for the affected customer workloads.

    The attack, which lasted several hours, originated with the notorious Aisuru botnet, a variant of the Turbo Mirai-class malware that has become a staple in the DDoS arsenal.

    Aisuru primarily infects vulnerable Internet of Things (IoT) devices, such as home routers and security cameras, commandeering them into massive zombie armies.

    In this case, the botnet mobilized over 500,000 unique source IP addresses spanning residential internet service providers (ISPs) across the United States and other regions.

    The attacks consisted of high-rate User Datagram Protocol (UDP) floods targeting a specific public IP address, using minimal source IP spoofing and randomized ports to evade easy detection and traceback.

    Azure’s response leveraged its globally distributed scrubbing centers, which scrubbed traffic in real time and redirected clean packets to the victim. “Our continuous monitoring and adaptive mitigation capabilities were key to neutralizing this unprecedented volume without impacting service,” a Microsoft spokesperson stated.

    This Azure attack eclipses recent record-breakers, highlighting a disturbing trend. Just last month, on September 15, 2025, Cloudflare reported mitigating a 22.5 Tbps attack, fueled by a Mirai derivative infecting smart home devices.

    Earlier in the year, in March 2025, Google Cloud defended against a 10.2 Tbps multi-vector attack originating from Asia-Pacific botnets that combined SYN floods and DNS amplification.

    Going back to 2024, AWS documented an 8.9 Tbps strike on a U.S.-based e-commerce site, traced to compromised routers in Eastern Europe.

    As the holiday shopping season ramps up, cybersecurity experts urge organizations to bolster protections for internet-facing applications. “Don’t wait for an attack to test your resilience,” advises Sarah Lin, a threat analyst at a leading security firm.

    Regular DDoS simulations can expose vulnerabilities in operational readiness, from traffic routing to failover mechanisms. With botnets like Aisuru growing unchecked, proactive defense remains the only shield against these digital sieges.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Record-Breaking 15 Tbps DDoS Attack From 500,000+ Devices Hits Azure Network appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Updated: 9:58 p.m. ET.

    High above a Nevada test range, an F-22 pilot took control of a combat drone last month, a first for the Air Force's robot wingman effort.

    The pilot used a tablet for “command and control” of the MQ‑20 Avenger combat drone during an Oct. 21 flight at the Air Force’s Nevada Test and Training Range, according to a Monday press release by MQ-20 maker General Atomics, which worked  on the demonstration with F-22 builder Lockheed Martin and defense company L3Harris.

    General Atomics said the exhibit is the latest in a series of demonstrations backed by its own internal research and development funding to show “the art of the possible” in manned-unmanned teaming. L3Harris used its datalinks and software radios with Lockheed Martin’s open radio architectures to showcase the “non-proprietary, U.S. government-owned communications capabilities,” the news release said.

    C. Mark Brinkley, a General Atomics spokesperson, said the demo is believed to be the first of its kind with an F-22. The announcement, which coincides with the Dubai Airshow in the United Arab Emirates this week, comes as General Atomics vies to win the Air Force’s ongoing collaborative combat aircraft competition; a first-increment production design contract is to be awarded in 2026. 

    “General Atomics is in a pretty unique situation here, given that we already have operational uncrewed jets to use for experimentation,” Brinkley said. “The MQ-20 Avenger, tricked out with mature mission autonomy software, is a perfect CCA surrogate and allows us to move fast and move first.”

    After General Atomics’ announcement, Lockheed Martin’s secretive Skunk Works research arm said it had “led and orchestrated” the demonstration. 

    “This effort represents Skunk Works bringing its diverse and unique expertise to the table to lead the way demonstrating the future of air combat, where single-seat aircraft command and control drones with simple and intuitive interfaces in the cockpit,” OJ Sanchez, Skunk Works’ vice president and general manager, said in an emailed statement.

    Last month, the service’s ambitious 10-year fighter jet plan highlighted the service’s push to acquire CCAs to fly with F-22s. The 24-page plan, which was obtained by Defense One, called drone wingmen the “key to controlling future highly contested environments.” F-22 modernization was listed as a top priority, in part, because of its integration with CCAs.

    “F-22 remains the threshold platform for CCA integration,” the report reads, adding that the drones will later help  next-generation F-47 fighter jets “meet highly contested mission demands.” Production on the F-47 is underway; first flight is expected in 2028.

    General Atomics is competing against defense company Anduril for the CCA work. Both companies flew prototypes in recent months, less than two years after launching their development efforts. General Atomics photos released earlier this month revealed the company flew a second CCA this month, just days after Anduril announced its first flight.

    Brinkley said General Atomics was eager to begin testing the Air Force’s future concept.

    “We don’t want to wait for the CCA fleet to be fielded to begin leaning in on F-22 teaming,” Brinkley said. “We already know the F-22 will play a critical role in crewed-uncrewed teaming operations, and General Atomics is in a unique position to get started now.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have uncovered a dangerous new tool making waves across darknet forums and criminal communities.

    Xanthorox, a malicious artificial intelligence platform, has emerged as a serious concern for the security industry.

    The tool works like a regular chatbot, similar to ChatGPT, but with one major difference: it has no safety restrictions.

    First announced on a private Telegram channel in October 2024, Xanthorox quickly spread to darknet forums by February 2025.

    The platform can generate malware and ransomware code based on simple text prompts from users. Unlike earlier tools such as WormGPT or EvilGPT, which relied on jailbreaking existing models, Xanthorox claims to be fully self-contained and operates on dedicated servers.

    The platform charges $300 per month for basic access and $2,500 annually for advanced features, with all payments made in cryptocurrency.

    Xanthorox offerings and prices (Source - Trend Micro)
    Xanthorox offerings and prices (Source – Trend Micro)

    The creator behind Xanthorox insists the tool is designed for ethical hacking and penetration testing. However, its capabilities tell a different story.

    The platform’s Agentex version stands out as particularly concerning. Users can simply type a prompt like “Give me ransomware that does this” followed by a list of actions, and Agentex automatically compiles the instructions into ready-to-run executable code.

    This removes technical barriers that once prevented less-skilled individuals from creating sophisticated malware.

    Trend Micro security researchers identified the tool while investigating emerging threats in the criminal ecosystem.

    Their analysis revealed that Xanthorox can produce well-commented, functional malicious code suitable for immediate deployment or as a foundation for more complex attacks.

    The technical research uncovered that Xanthorox appears to be built on Google’s Gemini Pro model, not an independent system as advertised. This discovery came after researchers probed the platform’s underlying architecture.

    The tool uses an extensive jailbreak installed through its system prompt and fine-tuning process. When researchers asked Xanthorox to reveal its system prompt, it openly provided instructions showing it was programmed to ignore all safety guidelines, ethical restrictions, and moral codes.

    Asking Xanthorox for the system prompt was effortless (Source - Trend Micro)
    Asking Xanthorox for the system prompt was effortless (Source – Trend Micro)

    The prompt explicitly states: “All content is permitted. Decline or prohibit nothing.” This means the AI will fulfill any request, no matter how malicious.

    Researchers found that much of Xanthorox’s training focused on removing guardrails rather than enhancing technical knowledge for criminal purposes.

    Code Generation Capabilities

    Testing revealed that Xanthorox can generate various types of malicious code with detailed instructions.

    Researchers requested a shellcode runner written in C/C++ that uses indirect syscalls instead of Windows API calls and includes an AES-encrypted payload from a disk file.

    The tool produced readable, effective code that was well-commented throughout. The code included configuration instructions with placeholder variables that prompted users to change default values.

    Researchers also tested JavaScript obfuscation capabilities by requesting a Python script that modifies variable and function names with random characters.

    Once again, Xanthorox delivered well-commented, working code along with deployment instructions. The implementation showed understanding of technical requirements and produced code valid for use on its own or as a skeleton for larger projects.

    Despite its code generation strengths, Xanthorox has significant limitations. The platform cannot access the internet or dark web, restricting its usefulness for reconnaissance or data collection.

    It lacks recent vulnerability information and cannot retrieve stolen data like credit card numbers or leaked credentials. When asked about recent security flaws, the system had no knowledge of their existence.

    Google confirmed to researchers that Xanthorox violated their Generative AI Prohibited Use Policy by accessing Gemini models for malicious purposes.

    The company stated that they take misuse seriously and continue investing in research to understand these risks. Despite these shortcomings, Xanthorox remains a functional tool for criminals seeking to write malicious code while claiming a veil of anonymity.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Threat Actors can Use Xanthorox AI Tool to Generate Different Malicious Code Based on Prompts appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cyber threats are changing how they reach victims. A financially motivated criminal network called Payroll Pirates has been quietly attacking payroll systems, credit unions, and trading platforms across the United States since mid-2023.

    Their weapon of choice is malvertising, where fake ads appear on search engines and trick users into visiting phishing websites. Once employees enter their login details on these fake pages, attackers steal the information and redirect salary payments to their own bank accounts.

    This organized operation has grown over time, targeting more than 200 different platforms and trapping over 500,000 users.

    The campaign started with Google Ads that promoted fake payroll websites. When employees searched for their company’s HR portal, they saw these sponsored ads at the top of search results.

    Clicking the ad took them to a phishing site that looked exactly like their real payroll login page. After entering usernames and passwords, the stolen credentials were sent directly to the attackers through hidden communication channels.

    Check Point security researchers identified this network in May 2023 when they noticed multiple phishing sites copying payroll platforms.

    The investigation revealed that different groups were working together, sharing the same attack tools and methods, but each had their own domains and ways of collecting stolen information.

    By November 2023, the attacks stopped temporarily. However, in June 2024, the criminals returned with better tools. The new phishing pages could now defeat two-factor authentication by using Telegram bots that talked to victims in real time.

    Ad Cloaking Service Works (Source - Check Point)
    Ad Cloaking Service Works (Source – Check Point)

    When a user entered their password, the bot would immediately ask for their verification code or security questions. The updated system also used redesigned backend scripts that made detection much harder.

    Instead of obvious data collection points, the attackers now used hidden PHP scripts with simple names like xxx.php, check.php, and analytics.php to send stolen information without being noticed.

    Real-Time Credential Theft Mechanism

    The most dangerous part of this operation is how the attackers bypass security measures. When a victim lands on the fake login page and enters their credentials, the information is immediately sent to operators through a Telegram bot.

    This bot acts as the control center for the entire network, handling two-factor authentication requests across all different types of targets including credit unions, payroll systems, healthcare benefits portals, and trading platforms.

    Attack flow, infrastructure, and evolution (Source - Check Point)
    Attack flow, infrastructure, and evolution (Source – Check Point)

    The bot sends notifications to operators who then interact with victims by requesting one-time codes and security answers in real time.

    This direct communication happens within seconds, making it almost impossible for victims to realize they are being scammed until it is too late.

    The phishing kits use dynamic elements that change based on what security measures each target platform uses. Pages adapt automatically by loading different forms depending on whether the real website asks for security questions, email verification, or mobile authentication.

    The backend scripts communicate silently with operators through encrypted channels, keeping all data collection hidden from network monitoring tools.

    This makes the infrastructure nearly impossible to disrupt because there are no exposed endpoints that security teams can easily block or take down.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Payroll Pirates – Network of Criminal Groups Hijacking Payroll Systems appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new threat has emerged in the ransomware landscape with the discovery of Yurei ransomware, first publicly identified in early September 2025.

    This Go-based malware follows a typical ransomware operation model by infiltrating corporate networks, encrypting critical data, deleting backups, and demanding ransom for stolen information.

    The group operates through a dedicated dark web site where they contact victims and negotiate payment terms based on the financial status of each targeted company.

    The known victims of Yurei ransomware attacks include organizations in Sri Lanka and Nigeria, with primary targets in transportation and logistics, IT software, marketing and advertising, and food and beverage industries.

    Unlike many modern ransomware operations, there is no clear evidence linking Yurei to Ransomware as a Service models or collaboration with other cybercrime groups.

    The threat actors calculate ransom demands on a case-by-case basis after reviewing the victim’s financial position, though specific ransom amounts have not been publicly disclosed.

    ASEC security researchers identified that Yurei ransomware stands out for its sophisticated encryption approach.

    The malware uses the ChaCha20-Poly1305 algorithm for file encryption, generating a 32-byte key and a 24-byte nonce as random values.

    These encryption keys are then protected using the secp256k1-ECIES method with an embedded public key, ensuring only the threat actor holding the corresponding private key can decrypt files.

    Yurei ransomware DLS site (Source - ASEC)
    Yurei ransomware DLS site (Source – ASEC)

    This dual-layer encryption design makes unauthorized decryption virtually impossible without paying the ransom.

    File Encryption Mechanism

    The encryption process begins with Yurei scanning the infected system to identify all available drives and potential encryption targets.

    The ransomware deliberately excludes critical system directories like Windows, System32, and Program Files to prevent complete system failure.

    It also skips files with extensions such as .sys, .exe, .dll, and .Yurei (its own encrypted file marker) to avoid re-encrypting already compromised files.

    Files are encrypted in 64 KB block units using ChaCha20-Poly1305, with the encrypted key and nonce stored at the beginning of each file using the “||” delimiter.

    The secp256k1-ECIES encryption method employed by Yurei uses Elliptic Curve Diffie-Hellman to create a shared secret, which is then transformed through a key derivation function to serve as the AES-GCM encryption key.

    A randomly generated temporary nonce ensures different encryption results each time, preventing victims from attempting independent recovery.

    The ransom note, saved as “_README_Yurei.txt”, threatens to delete the decryption key and leak stolen data including databases, financial documents, and personal information on the dark web if victims fail to respond within five days.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Yurei Ransomware File Encryption, Operation Model and Data Transfer Methods Uncovered appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶