• A sandbox escape vulnerability affecting iPhones and iPads running iOS 16.2 beta 1 or earlier versions. The proof-of-concept (POC) exploits weaknesses in the itunesstored and bookassetd daemons, enabling attackers to modify sensitive files on the device’s Data partition areas typically protected from unauthorized access.

    Researcher Kim shared the details in a blog post on October 20, 2025, emphasizing that the findings stem from her reverse engineering efforts and urging readers to verify independently.

    The vulnerability hinges on a maliciously crafted “downloads.28.sqlitedb” database, which tricks the itunesstored daemon into downloading and placing a secondary database, “BLDatabaseManager.sqlite,” into a shared system group container.

    While itunesstored operates under strict sandbox limits, the subsequent stage leverages bookassetd a daemon handling iBooks downloads with broader permissions.

    MobileGestalt Exploit

    This allows writes to mobile-owned paths like /private/var/mobile/Library/FairPlay/, /private/var/mobile/Media/, and even system caches such as /private/var/containers/Shared/SystemGroup/systemgroup.com.apple.mobilegestaltcache/Library/Caches/com.apple.MobileGestalt.plist.

    In a demo on an iPhone 12 running iOS 16.0.1, Kim modified the MobileGestalt cache to spoof the device as an iPod touch (model iPod9,1), proving the exploit’s reach.

    The process requires preparing the target file in a modified EPUB format, zipped without compressing the mimetype file, and hosting supporting assets like iTunesMetadata.plist on a server.

    Attackers must then use tools like 3uTools or afcclient to inject the databases into /var/mobile/Media/Downloads/, followed by targeted reboots to trigger the downloads.

    Expected behavior halts writes to unauthorized paths, but the flaw permits modifications unless the destination is root-controlled.

    Kim lists numerous writable locations, including caches and media directories, potentially enabling persistence, configuration tampering, or data exfiltration.

    The exploit requires physical or tethered access to place the database, but once set up, it could facilitate more sophisticated attacks on jailbroken or compromised devices.

    Apple has not yet commented, and Kim notes the issue may be patched imminently. She provides basic files on GitHub for educational use, stressing that the research is for learning only and not for illegal activities.

    As iOS evolves with tighter sandboxing, this POC underscores ongoing challenges in daemon isolation. Security teams should monitor for related indicators, like anomalous database entries in download logs.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post New MobileGestalt Exploit for iOS 26.0.1 Enables Unauthorized Writes to Protected Data appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has taken a significant step toward its vision of an Agentic SOC by announcing the public preview of the Alert Triage and Investigation agent, a purpose-built AI agent natively embedded into Google Security Operations. This advancement brings the promise of intelligent agents assisting human analysts with routine tasks, decision-making, and workflow automation closer to […]

    The post Google Launches Public Preview of Its Alert Triage and Investigation Agent for Security Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Outlook NotDoor backdoor malware first appeared in threat campaigns identified by Lab52, the intelligence arm of Spanish firm S2 Grupo.

    Linked to APT28/Fancy Bear, NotDoor leverages malicious Outlook macros for persistent access and data theft. Attackers embed these macro payloads within Outlook’s data files to monitor incoming emails and trigger hidden code on infected systems.

    This has enabled advanced persistent threat groups to quietly exfiltrate files, execute commands, and maintain stealthy control by abusing a trusted application.

    Initial compromise often begins with DLL sideloading. Threat actors place a maliciously crafted SSPICLI.dll next to the legitimate OneDrive.exe, exploiting how Windows prioritizes loading DLLs.

    The fake DLL allows the actor to execute commands and stage malware components without raising alarms.

    Infection artifacts include multiple files: a real OneDrive.exe, SSPICLI.dll (malicious), tmp7E9C.dll (renamed legitimate DLL), and testtemp.ini containing the VBA macro. These details are crucial for defenders tracking suspicious file events and Registry modifications.

    Splunk security researchers were among the first to thoroughly analyze NotDoor. Their deep dive revealed encoded PowerShell commands launched by OneDrive.exe and how the malware quietly creates TEMP directories for dropped artifacts.

    The detection guide by Splunk helps defenders recognize rogue processes spawning PowerShell, network calls, and registry changes that activate macro auto-loading, disable security prompts, or allow all macros without warning.

    This research provides valuable blueprints for building reliable detection.

    Outlook Macro Persistence and Obfuscation

    A key NotDoor technique involves copying the macro-laden testtemp.ini file to Outlook’s VBAProject.OTM location within the user’s Roaming directory.

    This file holds all custom automation and email-handling macros for Outlook. Under normal circumstances, only Outlook should write here, so any outside process (such as malware) is highly suspicious.

    The macro backdoor sets up C2 communications: it can receive and execute attacker instructions via email triggers, and quietly send data back out.

    It relies on obfuscation, randomized variable names, and custom encoding to slip past simple scans. Splunk researchers pinpointed registry modifications as pivotal for persistence.

    The malware changes settings to automatically load the malicious macro at startup (LoadMacroProviderOnBoot) and lowers Outlook’s macro security level to let all macros execute, suppressing security dialogs.

    The following code snippet shows a common Splunk detection search for registry changes:-

     tstats security_contents_summaries_only count FROM datamodelEndpoint.Registry WHERE Registry.registrypath=HKCU\\Software\\Microsoft\\Office\\Outlook\\Security\\LoadMacroProviderOnBoot Registry.registryvaluedata=0x00000001
    Outlook Security Registry Changes (Source – Splunk)

    Defenders can follow these Splunk detection models to catch NotDoor malware, watching for macro file events and registry modifications that signal infection and persistence.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Researchers Detailed Techniques to Detect Outlook NotDoor Backdoor Malware appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Justice Department announced major actions against North Korean cybercrime, including five people admitting guilt and the government taking more than $15 million in property linked to the crimes.

    These operations reveal how the Democratic People’s Republic of Korea (DPRK) uses fraudulent IT workers and cryptocurrency heists to fund its weapons programs while evading international sanctions.

    Facilitators in the United States and Ukraine helped North Korean actors secure remote IT jobs with American companies.

    North Korean State-Sponsored Cybercrime

    The scheme involved using stolen or false identities and hosting company-provided laptops at U.S. residences to create the false appearancethat workers were based in the U.S.

    This elaborate fraud impacted more than 136 U.S. companies, generating over $2.2 million in revenue for the North Korean regime and compromising the identities of over 18 American citizens.

    According to the Justice Department, five individuals have admitted they are guilty of their roles in these schemes.

    Three U.S. nationals, Audricus Phagnasay, Jason Salazar, and Alexander Paul Travis, admitted to providing their identities to overseas IT workers and hosting laptops at their homes.

    Travis, an active-duty U.S. Army member at the time, received at least $51,397 for his participation. Their scheme alone earned approximately $1.28 million from victim companies.

    Ukrainian national Oleksandr Didenko pleaded guilty to stealing U.S. citizen identities and selling them to overseas IT workers, enabling fraudulent employment at 40 U.S. companies.

    Didenko agreed to forfeit more than $1.4 million. Additionally, Erick Ntekereze Prince admitted to supplying falsely certified IT workers through his company, earning over $89,000.

    Separately, the Justice Department went to court to get back over $15 million in cryptocurrency stolen by APT38, a North Korean military hacking group.

    The group executed four major heists in 2023, stealing virtual currency from platforms in Estonia, Panama, and Seychelles, totaling approximately $382 million.

    These enforcement actions demonstrate the government’s comprehensive approach to disrupting North Korean revenue generation schemes that fund weapons development and threaten national security.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post North Korean Hackers Infiltrated 136 U.S. Companies to Generate $2.2 Million in Revenue appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sharp increase in attacks targeting a critical vulnerability in XWiki servers. Multiple threat actors are actively exploiting CVE-2025-24893 to deploy botnets and coin miners, and to establish unauthorized server access across the internet.

    Since the initial discovery on October 28, 2025, exploitation has expanded dramatically. VulnCheck reported that multiple independent attackers are now actively targeting the vulnerability.

    Ranging from automated botnets to sophisticated actors using custom tooling and specialized scanners. Within just two days of the first report, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-24893 to its Known Exploited Vulnerabilities catalog on October 30, 2025.

    Since then, canary security systems have seen a big increase in scanning and attack attempts. The group of attackers is wide and includes many different types of hackers.

    Rapid Exploitation Expansion

    On November 3, 2025, the RondoDox botnet began incorporating this vulnerability into its attack arsenal, leading to a sharp increase in exploitation attempts.

    These attacks are identifiable by their distinctive HTTP User-Agent signatures and payload naming conventions.

    CVE IDVulnerability TypeAffected Software
    CVE-2025-24893Remote Code Execution (RCE)XWiki

    Cryptocurrency mining operations have also joined the wave of exploitation. Multiple coin miner campaigns have been detected fetching secondary payloads from compromised servers.

    VulnCheck researchers observed attackers downloading hidden scripts that ultimately deploy cryptocurrency mining software on vulnerable XWiki installations.

    More concerning are the reverse shell attempts, indicating potential hands-on-keyboard activity. VulnCheck researchers identified several attempts to establish direct command-and-control connections.

    Including one attack from an AWS-associated IP address with no prior abuse history, suggesting more targeted operations beyond automated scanning.

    The vulnerability allows attackers to execute arbitrary code on internet-exposed XWiki servers through specially crafted requests to the SolrSearch endpoint.

    Attackers exploit the Groovy scripting functionality to download and execute malicious payloads, ranging from botnet recruitment scripts to cryptocurrency miners.

    VulnCheck analysts have documented attacks originating from numerous IP addresses across different countries, with payload hosting servers frequently changing locations.

    The exploitation techniques include direct payload execution, multi-stage infection chains, and hidden shell scripts designed to evade detection.

    By the time CISA added the vulnerability to its catalog, attackers were already days ahead of defenders. This highlights a critical gap between initial exploitation and widespread visibility.

    Organizations using Canary Intelligence and early warning systems gained crucial time to patch and defend before attacks became widespread.

    VulnCheck Security teams should monitor for unusual requests to XWiki’s SolrSearch functionality, unexpected outbound connections from XWiki servers, and any signs of cryptocurrency mining or botnet activity.

    Organizations running XWiki installations should immediately apply available security patches and review server logs for indicators of compromise.

    Network segmentation and restricting internet exposure of XWiki servers can significantly reduce the attack surface. It is also recommended to add security rules that can spot attacks using the CVE-2025-24893 bug.

    The rapid adoption of this vulnerability by multiple threat actor groups underscores the importance of early detection and immediate patching.

    Defenders who wait for official advisories are already behind the curve of exploitation, making proactive security monitoring essential in today’s threat landscape.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Exploiting XWiki Vulnerability in the Wild to Hire the Servers for Botnet appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Pig-butchering scams, the sophisticated long-con investment fraud schemes that have plagued millions globally, have reached unprecedented scale through the strategic deployment of artificial intelligence technologies. Once reliant on labor-intensive social engineering, these cybercriminal enterprises now leverage AI-generated identities, automated messaging systems, and deepfake video synthesis to orchestrate operations at an industrial scale, generating estimated annual […]

    The post AI-Powered Expansion of Pig Butchering Scam Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Samsung users across West Asia and North Africa are raising serious privacy concerns over AppCloud. This pre-installed bloatware application collects sensitive personal data without consent. It cannot be easily removed from Galaxy A and M series smartphones. AppCloud, developed by ironSource, an Israeli-founded company now owned by American tech firm Unity, has been embedded into […]

    The post Pre-Installed Spyware Found on Samsung Galaxy Devices and Cannot Be Removed appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly identified phishing campaign is exploiting Microsoft Entra tenant invitation functionality to orchestrate TOAD (Telephone-Oriented Attack Delivery) attacks against unsuspecting users. Security researchers have uncovered how threat actors are weaponizing legitimate Microsoft Entra features to bypass email filtering and establish initial contact with victims through a deceptive social engineering vector. The campaign operates by […]

    The post Microsoft Entra Invitations Hijacked in Surge of TOAD Phishing Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Samsung has been accused of shipping budget Galaxy A and M series smartphones with pre-installed spyware that users can’t easily remove.

    The software in question, AppCloud, developed by the mobile analytics firm IronSource, has been embedded in devices sold primarily in the Middle East and North Africa (MENA) region.

    Security researchers and privacy advocates warn that it quietly collects sensitive user data, fueling fears of surveillance in politically volatile areas.

    AppCloud tracks users’ locations, app usage patterns, and device information without seeking ongoing consent after initial setup. Even more concerning, attempts to uninstall it often fail due to its deep integration into Samsung’s One UI operating system.

    Reports indicate the app reactivates automatically following software updates or factory resets, making it virtually unremovable for average users. This has sparked outrage among consumers in countries such as Egypt, Saudi Arabia, and the UAE, where affordable Galaxy models are popular entry points into Android.

    The issue came to light through investigations by SMEX, a Lebanon-based digital rights group focused on MENA privacy. In a recent report, SMEX highlighted how AppCloud’s persistence could enable third-party unauthorized data harvesting, posing significant risks in regions with histories of government overreach.

    “This isn’t just bloatware, it’s a surveillance enabler baked into the hardware,” said a SMEX spokesperson. The group called on Samsung to issue a global patch and disclose the full scope of data shared with ironSource.

    Social media platforms have amplified the controversy, with viral posts claiming international bans on affected devices. However, official statements from Samsung and regulatory bodies like the FCC deny any such prohibitions, labeling the rumors as misinformation.

    Samsung has yet to respond directly to SMEX’s allegations, but a company spokesperson reiterated their commitment to user privacy standards.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Unremovable Spyware on Samsung Devices Comes Pre-installed on Galaxy Series Devices appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A threat actor known as “888” has purportedly dumped sensitive data stolen from electronics giant LG Electronics, raising alarms in the cybersecurity community.

    The breach, first spotlighted on November 16, 2025, allegedly includes source code repositories, configuration files, SQL databases, and, critically, hardcoded credentials and SMTP server details potentially exposing LG’s internal communications and development pipelines to widespread exploitation.​

    The leak surfaced via a post on ThreatMon, a platform that tracks dark web activity, where “888” shared samples to prove authenticity. Described as originating from a contractor access point, the dataset reportedly spans multiple LG systems, hinting at a supply chain vulnerability rather than a direct corporate hack.

    LG Data Leak Claim

    Cybersecurity analysts note that hardcoded credentials embedded directly in code for convenience pose severe risks, as they could enable attackers to impersonate LG personnel or pivot to connected services.

    SMTP credentials, which manage email routing, might further allow phishing campaigns or spam operations disguised as legitimate LG correspondence.​

    Threat actor “888” is no stranger to high-profile claims. Active since at least 2024, this individual has targeted entities like Microsoft, BMW Hong Kong, Decathlon, and Shell, often extorting ransoms or selling data on breach forums.

    Their tactics typically involve initial access brokers and infostealer malware, and they monetize leaks through cryptocurrency payments. In this LG incident, no ransom demand has been publicly confirmed.

    Still, samples shared include file structures suggesting the presence of gigabytes of proprietary code, which could undermine LG’s intellectual property in consumer electronics and smart appliances.​

    LG Electronics has yet to issue an official statement, but the timing aligns with a turbulent year for the company. Earlier in October 2025, LG’s telecom arm, LG Uplus, confirmed a separate breach affecting customer data, amid a wave of South Korean telecom hacks.

    Experts speculate these incidents may share common vectors, such as unpatched vulnerabilities in cloud integrations or third-party tools. The exposure of source code could reveal flaws in LG’s IoT devices, amplifying risks for millions of users worldwide.​

    As investigations unfold, security firms urge organizations to scan for leaked credentials using tools like Have I Been Pwned and to rotate all suspected keys immediately.

    This alleged breach underscores the fragility of global supply chains, where a single contractor’s lapse can cascade into corporate espionage. For LG, swift disclosure and remediation will be key to mitigating fallout amid relentless cyber threats.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Allegedly Claim Leak of LG Source Code, SMTP, and Hardcoded Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶