• The Amphibious Ready Group and Marine Expeditionary Unit—the ARG/MEU—is the Nation’s most flexible and effective formation for projecting power from the sea. Three ships, carrying a 2,200-Marine combined arms team, maneuver as sovereign U.S. territory anywhere on the globe. They respond in hours, not weeks. They can put Marines ashore without relying on ports, airfields, or permission from another country. They bring command and control, aviation, fires, logistics, and a reinforced infantry battalion—all from the sea, ready to fight on arrival.

    Despite the MEU’s proven value in warfighting and deterrence—and its growing combat power under our Force Design initiative—our nation’s maritime expeditionary capability has steadily eroded. Today, we sit at 32 amphibious ships, barely meeting the congressionally mandated floor. With amphibious-ship readiness below 50 percent, we are well short of what’s needed to support three consistently forward-deployed ARG/MEUs. The Marine Corps has identified this gap for years, and leaders within the Department of the Navy are now moving with urgency to stabilize the fleet and drive investment in the industrial base for military shipbuilding.

    As Commandant, I am addressing this amphibious capability shortfall through two initiatives outlined in my Planning Guidance. First, we must restore our amphibious capacity through a return to a 3.0 ARG/MEU presence: three forward-postured MEUs, each with three amphibious warships, persistently positioned around the globe. This has long been the standard, and it remains the Marine Corps’ North Star. Our combatant commanders, the Joint Force, and our civilian leaders rely on these formations to campaign, deter, and respond without delay and without any permission needed from a third party for access, basing or overflight.

    Second, we are modernizing the MEU through Force Design, ensuring it evolves in stride with the changing character of war. Just as our Marine Littoral Regiments are receiving long-range fires, resilient command and control, unmanned systems, and advanced sensing networks, those same capabilities are being fielded across the MEUs, advancing their role as a flexible, multi-domain force from the sea.

    A needed force for a maritime nation

    For 250 years, Marines have been first to fight—closing with the enemy, defending our nation, always forward, always ready, and often from the sea. Our enduring warrior ethos reflects the fundamental truth that the nature of war does not change—but the character of war does—and so must the way we fight.

    After the Second World War, as a new era of global tension took shape, the nation needed a force that could respond rapidly and operate forward without waiting on ports, bases, or permission. That requirement came into sharp focus in the early years of the Cold War, when the Navy and Marine Corps were asked to counter nuclear-armed adversaries, dispersed flashpoints, and threats with no notice. The logic behind the MEU’s design was operational from the start: built to be ready now, to maneuver from the sea, to project power inland, and to shape the fight before it began.

    The advent of nuclear weapons reshaped our approach to amphibious operations. What worked at Okinawa or Inchon required rethinking in the face of a threat that punished mass and predictability. The Corps responded by developing new ways to come from the sea without confining the assault to a narrow beachhead. Vertical envelopment was added to the beach assault, expanding the maneuver space and giving commanders more options.

    To support this new approach, the Marine Corps restructured its forward-deployed forces. Rotary-wing lift, aviation-delivered fire support, and integrated logistics gave rise to the Marine Air-Ground Task Force concept: an integrated formation that could launch from sea, land inland, and fight immediately. By the late 1980s, the MAGTF formations called MEUs were operating routinely from the Mediterranean to the Western Pacific. They weren’t held in reserve. They were deployed forward.

    During the Cold War, the MEU’s value was recognized in operational war plans. One of the clearest examples was in the High North. If Soviet forces pushed into Norway, a MEU embarked aboard amphibious shipping would land in the fjords to reinforce Norwegian defenders and counter Soviet naval infantry along the flanks. That wasn’t a theory, it was backed up by prepositioned equipment, rehearsed in exercises like Teamwork and Northern Wedding, and respected by Soviet planners who were forced to hedge against it.

    The operational rationale that validated the MEU in the past remains just as relevant today. It creates problems adversaries cannot ignore at a cost the Nation can sustain—turning shorelines into entry points, projecting power inland, and transforming maritime access into combat power for the Joint Force. Forward-deployed at sea, the ARG/MEU deters by denying the adversary decision space, shaping the environment in our favor, and introducing risk before conflict begins. Its maneuverable posture gives it both survivability and combat credibility. And it remains able to operate independently, integrate with the fleet, or reinforce allies—preventing escalation and–if required—moving rapidly to combat.

    Toward a modern MEU

    As the character of warfare continues to evolve—driven by a connected world and rapid advances in technology, tomorrow’s fight will be more connected and lethal. Success will depend on speed, precision, and adaptability in a battlespace that is sensor-rich and contested across all domains.

    Force Design, launched in 2019, remains the Marine Corps’ framework for adapting to the changing character of war across our MEUs, Marine Expeditionary Brigades, Marine Expeditionary Forces, and Marine Littoral Regiments. It is guided by a campaign of learning that refines how we man, train, and equip the force to deter aggression and close gaps in a contested, multi-domain fight. That learning is what drives Force Design’s modernization initiatives. The technology fielding that began with the Marine Littoral Regiments is now advancing through the MEUs and across the Corps—shaped by experimentation, real-world operations, and the integration of long-range fires, resilient C2, and unmanned systems. These advances enable MEUs to operate as agile, sea-based maneuver elements—able to sense, shoot, and support the Joint Force from sea to shore.

    The MEU remains a forward-deployed, combined arms team: light enough to deploy quickly, but potent enough to punch above its weight. Its combat power is built around three core advantages: precision fires, adaptable command and control, and enhanced survivability. When armed with HIMARS, NMESIS, loitering munitions, and supported by fifth-generation F-35B sensor fusion, the MEU will deliver effects into areas other formations cannot reach. Its command element is already optimized to serve as an agile hub for multi-domain operations by integrating kinetic and non-kinetic effects, sensors, and decision-makers across the battlespace. Future dispersed C2 nodes, unmanned platforms, and advanced manufacturing capabilities will strengthen its ability to maneuver, sustain, and adapt under pressure.

    Getting to a 3.0 ARG/MEU

    Modernization isn’t enough. Advanced capabilities only matter if we can get them forward, on time, and where the fight is. The MEU is evolving to meet tomorrow’s demands, but realizing its full potential depends on having a fleet that can support it. That’s one of the biggest challenges we face today.

    The problem is capacity. In 1991, the fleet had more than 60 amphibious warships—enough to sustain global presence and reinforce war plans across multiple theaters. But as the nation focused on extended land campaigns in the Middle East, the amphibious fleet was deprioritized. By 1997, that number had dropped to 40, and by 2016 it stood at just 31. Today the amphibious fleet has 32 ships whose average readiness hovers around 45 percent. Shipyards are strained, timelines are slipping, and hulls are aging faster than we can replace them.

    Sustaining a 3.0 ARG/MEU presence will require 31 amphibious ships at 80 percent readiness. The recent LHA/LPD block buy was a step in the right direction, but we must continue to build on this momentum. The Marine Corps is working closely within the broader defense establishment to maintain the fleet, improve readiness, and set conditions for a stronger future. The effort will take broad cooperation, sustained investment, and shared urgency across the U.S. government, industry, and the Department of War.

    Conclusion

    The Corps’ North Star must remain a steady 3.0 ARG/MEU presence: three continuous, three-amphibious warship formations forward deployed—one from the East Coast, one from the West, and one patrolling from Okinawa, Japan. (If you ask our combatant commanders what they need, the answer isn’t a total of three ARG/MEUs; it’s closer to five or six.) 3.0 is the minimum required to provide our nation and the Joint Force with a capability that can serve as both a warfighting formation and a cross-service integrator. It’s what keeps pressure on our adversaries, supports the maritime fight, and gives combatant commanders and national decision makers scalable options they can employ without delay to buy time, create decision-space, and if required to do so, be first to fight.

    Right now, we’re falling short. Every day below that mark costs time, space, and initiative. The ARG/MEU is more than  just a crisis-response formation, it is how a maritime nation extends influence, demonstrates resolve, and turns naval capability into action. It reflects who we are as a service: forward, agile, and ready to fight. The world and our adversaries are moving fast, and so must we. In a battlespace defined by access, timing, capability, and tempo, the ARG/MEU stands out: a formation that reaches the fight without relying on basing or buildup and bringing with it a MAGTF that delivers immediate combat power and multi-domain effects.

    Its capabilities continue to evolve. Its demand by combatant commanders continues to grow. But one thing hasn’t changed: Marines. Their cohesion and resolve turn emerging technologies into battlefield advantage. When they come from the sea, they bring C2, fires, logistics, aviation, and a reinforced infantry battalion—ready to act forcibly before anyone else can.

    The MEU remains the connective tissue between sea and land, deterrence and decision, day-to-day campaigning and high-end warfighting. What began as a Cold War solution has since matured into forward-deployed expression of American resolve.

    For 250 years, Marines have fought forward—ready at a moment’s notice, often from the sea. That legacy endures in the ARG/MEU: first to the fight, lethal on arrival, and ready for anything. This unique capability remains a cornerstone of American strength that secures peace. It must be sustained.

    Gen. Eric Smith is the 39th Commandant of the United States Marine Corps.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new open-source tool called SilentButDeadly has emerged, designed to disrupt Endpoint Detection and Response (EDR) and antivirus (AV) software by severing their network communications.

    Developed by security researcher Ryan Framiñán, the tool leverages the Windows Filtering Platform (WFP) to create temporary, bidirectional blocks on EDR cloud connectivity, isolating threats without terminating processes.

    His approach builds on the 2023 EDRSilencer technique, offering improved operational safety through dynamic, self-cleaning filters.

    The tool addresses a key vulnerability in modern EDR architectures, which rely heavily on cloud-based telemetry for real-time analysis and updates. By preventing outbound data uploads and inbound command reception, SilentButDeadly effectively neuters remote management and threat intelligence sharing.

    Unlike aggressive evasion methods that disrupt security processes, it focuses on stealthy network isolation, making it ideal for red-team exercises and malware analysis in controlled environments. Framiñán’s implementation ensures no persistent artifacts remain unless explicitly configured, reducing forensic footprints.

    SilentButDeadly Execution

    SilentButDeadly’s execution unfolds in structured phases, beginning with privilege verification using Windows APIs like CheckTokenMembership() to confirm administrator access. Users are prompted interactively to proceed, enhancing control.

    The core discovery phase scans running processes via CreateToolhelp32Snapshot(), matching against a predefined list of EDR targets such as SentinelOne’s SentinelAgent.exe and Microsoft Defender’s MsMpEng.exe. Once identified, it queries full process paths and initializes WFP with a dynamic session flagged by FWPM_SESSION_FLAG_DYNAMIC for automatic cleanup.

    Network blocking is implemented at ALE layers: outbound via FWPM_LAYER_ALE_AUTH_CONNECT_V4 and inbound via FWPM_LAYER_ALE_AUTH_RECV_ACCEPT_V4, using high-priority weights (0x7FFF) and process-specific AppID conditions.

    Filters convert executable paths to WFP blobs with FwpmGetAppIdFromFileName0(), ensuring precise targeting. Following isolation, the tool disrupts services by stopping them gracefully and setting startup types to SERVICE_DISABLED, preventing restarts. A summary displays affected processes, block counts, and WFP status before optional cleanup removes all rules.

    Supported targets include SentinelOne, Windows Defender, and Defender ATP (MsSense.exe), with extensibility via a simple array. Command-line options like –verbose for logging and –persistent for enduring filters add flexibility, while robust error handling provides graceful fallbacks.

    Security features emphasize legitimate APIs only, no kernel tweaks, though it requires admin rights. Operationally, it severs EDR updates, telemetry, and scans, but leaves local detection intact. Detection risks include WFP event logs (IDs 5441, 5157) and service modifications, detectable via netsh wfp commands or PowerShell queries.

    Framiñán stresses ethical use for authorized testing, urging defenders to monitor WFP changes and implement resilient EDR designs with local caching.

    Available on GitHub under loosehose/SilentButDeadly, the tool sparks discussions on EDR dependencies, potentially driving vendor improvements. As cyber threats evolve, such research underscores the need for balanced architectures less reliant on constant connectivity.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post SilentButDeadly – Network Communication Blocker Tool That Neutralizes EDR/AV appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The botnet malware known as RondoDox has been observed targeting unpatched XWiki instances against a critical security flaw that could allow attackers to achieve arbitrary code execution. The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), an eval injection bug that could allow any guest user to perform arbitrary remote code execution through a request to the “/bin/get/Main/

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A serious security flaw in Cisco Catalyst Center Virtual Appliance has been discovered that allows attackers with low-level access to gain full administrator control over affected systems.

    The vulnerability, tracked as CVE-2025-20341, impacts virtual appliances running on VMware ESXi and carries a high severity rating with a CVSS score of 8.8.

    This flaw poses a major risk to organizations using these systems for network management and monitoring.

    The vulnerability stems from poor input validation within the system. When users submit data through web requests, the software fails to properly check and verify the information.

    This oversight creates an opportunity for attackers to send specially designed HTTP requests that trick the system into granting them higher privileges.

    The attack can be carried out remotely over the network, making it particularly dangerous for exposed systems.

    What makes this vulnerability concerning is that an attacker only needs basic access credentials to exploit it.

    Someone with Observer role permissions, which are typically given to users who need to view system information, can use this flaw to elevate their privileges to Administrator level.

    Once they gain administrator access, attackers can create new user accounts, modify system settings, and perform other unauthorized actions that compromise the security of the entire network infrastructure.

    Cisco security researchers identified this vulnerability during work on a support case with the Technical Assistance Center.

    The company has confirmed that no public exploits have been observed yet, which gives organizations a window to patch their systems before widespread attacks begin.

    Technical Details and Mitigation

    The vulnerability affects Cisco Catalyst Center Virtual Appliance versions 2.3.7.3-VA and later releases.

    The security flaw is rooted in insufficient validation mechanisms that process user-supplied input through HTTP requests.

    When the system receives these crafted requests, it fails to properly sanitize the data before processing privilege escalation operations.

    Cisco has released version 2.3.7.10-VA as the fixed release that addresses this security issue. Organizations running affected versions should upgrade immediately to this patched version.

    CVE IDCVSS ScoreAffected ProductVulnerable VersionsFixed VersionAttack Vector
    CVE-2025-203418.8 (High)Cisco Catalyst Center Virtual Appliance (VMware ESXi)2.3.7.3-VA and later2.3.7.10-VANetwork (Remote)

    The company has stated that no workarounds are available, making the software update the only effective way to protect against this vulnerability.

    Hardware appliances and AWS-based virtual appliances are not affected by this issue.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Cisco Catalyst Center Vulnerability Let Attackers Escalate Priveleges appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A proof-of-concept (PoC) exploit tool for CVE-2025-64446 has been publicly released on GitHub. This vulnerability, affecting FortiWeb devices from Fortinet, involves a critical path traversal flaw that has already been observed in real-world attacks, allowing unauthorized access to sensitive CGI endpoints.

    Security researchers warn that the tool’s availability could accelerate exploitation attempts against unpatched systems worldwide.​

    CVE-2025-64446 targets FortiWeb’s web application firewall (WAF) component, enabling attackers to bypass access controls and manipulate user accounts through directory traversal techniques.

    Discovered earlier this year, the flaw stems from improper input validation in the CGI handling mechanism, permitting remote code execution in certain configurations.

    According to Fortinet’s advisory, affected versions range from 6.3.0 to 7.4.6, with exploitation in the wild reported as early as October 2025 by threat intelligence firms monitoring dark web forums and incident response logs.

    The vulnerability’s severity is rated CVSS 9.8, indicating its potential to have a widespread impact on enterprises that rely on FortiWeb for web traffic protection.

    The PoC, developed by GitHub user sxyrxyy and shared under the repository “CVE-2025-64446-FortiWeb-CGI-Bypass-PoC,” provides a straightforward Python-based script for testing and exploiting the flaw.

    Designed for authorized security testing, the tool requires minimal setup: users simply install dependencies via “pip install -r requirements.txt” before running the exploit script.

    For vulnerability verification, the command “python3 exploit.py -t <target_ip> –check” probes the target without causing harm, confirming if the system is susceptible to traversal attacks.

    In exploit mode, “python3 exploit.py -t <target_ip> –exploit” leverages the CGI endpoint to create or modify administrative user accounts, defaulting to a username “sxy” and password “sxyrxyadmin1!”.​

    Advanced options enhance the tool’s flexibility for penetration testers. Custom parameters allow specifying usernames, passwords, profile names (default: prof_admin), VDOM instances (default: root), and login names (default: admin).

    For batch operations, the script supports loading multiple targets from a file like targets.txt, enabling scans across IP ranges such as 192.168.1.100 to 192.168.1.102.

    Port customization defaults to 443 for HTTPS, but the “–http” flag switches to unencrypted traffic, and the “–testpoint-name” option sets a default user creation name of “Testpoint”.​

    Experts emphasize the tool’s dual-edged nature: while invaluable for defensive assessments, its public release amplifies threats to outdated FortiWeb deployments in sectors like finance and healthcare.

    Fortinet urges immediate patching to version 7.4.7 or later, alongside network segmentation to mitigate lateral movement risks. The repository’s disclaimer stresses use only on owned or permitted systems, aligning with responsible disclosure norms.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post PoC Exploit Tool Released for FortiWeb WAF Vulnerability Exploited in the Wild appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A severe remote code execution (RCE) flaw has been uncovered in pgAdmin4, the popular open-source interface for PostgreSQL databases.

    Dubbed CVE-2025-12762, the vulnerability affects versions up to 9.9 and could allow attackers to run arbitrary commands on the hosting server, potentially compromising entire database infrastructures.

    The issue stems from improper handling of code injection during server-mode restores from PLAIN-format dump files. When pgAdmin processes these files commonly used for backing up and migrating PostgreSQL data it fails to sanitize inputs adequately.

    An attacker with low privileges, such as an authenticated user, could craft a malicious dump file to inject commands, exploiting the tool’s execution of system-level operations.

    This CWE-94 weakness, rooted in code generation from untrusted sources, requires only network access and no user interaction, making it dangerously straightforward to exploit.

    The National Vulnerability Database (NVD) rates the flaw as critical, with a CVSS v3.1 score of 9.3 out of 10. Key metrics highlight its network-based attack vector, low complexity, and changed scope, leading to high confidentiality impacts alongside moderate integrity and availability risks.

    The advisory aligns with a GitHub issue (#9320) reported by the pgAdmin team, which traces the root cause to unsafe command construction in the restore process.

    pgAdmin developers swiftly addressed the problem in commit 1d39739, released in version 10.0. Users running affected setups in server mode, common in enterprise environments, face immediate threats, especially if handling untrusted dumps from external sources.

    The flaw underscores broader concerns in database tools, where restore functions often bypass strict validation.

    Organizations should prioritize upgrading to pgAdmin 10.0 or later, disable PLAIN-format restores if possible, and audit access controls. As PostgreSQL powers countless applications, this RCE serves as a wake-up call for rigorous input sanitization in DevOps pipelines.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new threat targeting Chinese users has appeared with a dangerous ability to shut down security tools.

    RONINGLOADER, a multi-stage loader spreading a modified version of the gh0st RAT, uses clever tricks to bypass antivirus protection.

    The malware arrives through fake software installers that pretend to be legitimate programs like Google Chrome and Microsoft Teams.

    Once inside a system, it works through several layers of infection to disable Windows Defender and popular Chinese security products like Qihoo 360 Total Security and Huorong.

    This campaign shows how attackers are getting better at breaking through security defenses. The malware brings its own signed driver that looks legitimate to Windows but actually helps it kill security processes.

    What makes it dangerous is how many backup plans it has. If one method to disable security fails, it tries several other approaches.

    This shows the Dragon Breath APT group behind it has learned from earlier campaigns and improved their methods.

    After tracking detection systems, Elastic security analysts identified this campaign using a behavioral rule designed to spot Protected Process Light abuse.

    The research team found RONINGLOADER using a technique that was publicly documented just months earlier. The malware takes advantage of a Windows feature meant to protect important system processes but turns it against Defender itself.

    Attack Method and Infection Chain

    The infection starts with a trojanized NSIS installer that drops multiple components onto the victim system. When someone runs what they think is a normal software installer, they actually activate two separate installers.

    RONINGLOADER Execution flow (Source - Elastic)
    RONINGLOADER Execution flow (Source – Elastic)

    One installs the real software to avoid raising suspicion, while the second quietly deploys the attack chain.

    The malware creates a directory at C:\Program Files\Snieoatwtregoable\ and drops two files: Snieoatwtregoable.dll and an encrypted file called tp.png.

    The DLL file decrypts tp.png using a simple but effective algorithm that combines XOR encryption with a rotate operation:-

    *encrypted_file_content = _ROR1_(*encrypted_file_content ^ xor_key[indx), 4);

    After decryption, the malware loads fresh system libraries to remove any security hooks that might catch its behavior. It then elevates its privileges using the runas command and scans for running security software.

    The malware looks explicitly for Microsoft Defender, Kingsoft Internet Security, Tencent PC Manager, and Qihoo 360 Total Security by checking their process names.

    To kill these processes, RONINGLOADER uses a signed driver called ollama.sys that was digitally signed by Kunming Wuqi E-commerce Co., Ltd.

    The driver registers a single function that accepts a process ID and terminates it using kernel-level APIs that normal security tools cannot block.

    The malware writes this driver to disk, creates a temporary service to load it, sends the termination command, and immediately deletes the service.

    For Qihoo 360, the malware takes extra steps by blocking all network connections through firewall rules before injecting code into the Volume Shadow Copy service process.

    This injection uses Windows thread pools with file write triggers, a technique that helps it avoid detection.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post RONINGLOADER Weaponizes Signed Drivers to Disable Defender and Evade EDR Tools appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Attackers are using fake invoice emails to spread XWorm, a remote-access trojan that quietly steals login credentials, passwords, and sensitive files from infected computers.

    When a user opens the attached Visual Basic Script file, the malware begins working silently in the background without any visible warnings or alerts.

    This makes it extremely dangerous because victims never know their system is compromised until it’s too late.

    Once active, XWorm gives attackers complete control over the infected machine, allowing them to record keystrokes, spy on users, steal personal data, and even install additional threats like ransomware.

    The attack begins with a simple email that appears to be a routine payment notification. These emails typically include a polite message from someone claiming to be an account officer, asking recipients to review processed invoices.

    The message looks harmless enough, but the attachment contains a .vbs file that immediately executes malicious code when opened.

    What makes this tactic clever is that the attackers rely on outdated technology that most people no longer expect to see in business communications.

    Malwarebytes security analysts identified the malicious attachment as Backdoor.XWorm during their investigation.

    XWorm operates as malware-as-a-service, meaning cybercriminals can rent or purchase access to the infrastructure that maintains backdoor connections and collects stolen data.

    A piece of the code inside the vbs file with the last line commented out (Source - Malwarebytes)
    A piece of the code inside the vbs file with the last line commented out (Source – Malwarebytes)

    This business model has made it easier for less technically skilled attackers to launch sophisticated campaigns, increasing the overall threat landscape for both individuals and organizations.

    The Visual Basic Script attachment stands out because modern businesses rarely use this file type anymore. Most email security systems block .vbs files automatically since they can run code directly on a computer without any additional steps.

    However, when these attachments manage to slip through email filters, they can cause serious damage.

    The script immediately drops a batch file named IrisBud.bat into the Windows temporary folder and uses Windows Management Instrumentation to execute it invisibly.

    Infection Mechanism and Execution Flow

    The infection chain starts simple but quickly becomes complex through multiple stages of obfuscation.

    The initial .vbs file contains 429 lines of heavily disguised code that writes another file to the system. This batch file then copies itself to the user profile directory under the name aoc.bat, ensuring persistence even if the temporary files get cleaned up.

    The batch file includes a clever technique to hide its execution by checking if a specific variable exists. If not, it restarts itself in a minimized window that runs completely invisible to the user while the original process exits immediately.

    Inside the batch file, attackers use padding techniques with repeated variables that serve no purpose except to confuse analysis tools and security researchers.

    These dummy variables make the code appear longer and more complicated than it actually is. After removing this padding, the real commands become visible, including instructions to copy files, read encoded data, and launch PowerShell scripts.

    The batch file contains two hidden payload sections that look like ordinary comments starting with double colons, but these actually hold encrypted malware data.

    The PowerShell script performs the final stage of the attack by reading the hidden payloads from aoc.bat, decrypting them using AES encryption with a hardcoded key, and decompressing the data with GZip.

    This produces two executable files that load directly into memory without ever being saved to disk, a technique called fileless execution that helps avoid detection by traditional antivirus software.

    The sandbox analysis revealed a mutex identifier 5wyy00gGpG6LF3m6 that security researchers recognize as belonging to the XWorm malware family, confirming the threat and allowing for proper classification and response.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Hackers are Weaponizing Invoices to Deliver XWorm That Steals Login Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Chinese government-backed hackers used Anthropic’s Claude Code tool to carry out advanced spying on about thirty targets worldwide, successfully breaking into several major organizations.

    The first documented large-scale cyberattack executed primarily by leveraging artificial intelligence with minimal human intervention.

    The operation, detected in mid-September 2025 by Anthropic security team, targeted leading tech companies, financial institutions, chemical manufacturing firms, and government agencies.

    First AI-Orchestrated Cyberattack

    What made this attack different from earlier ones was its heavy use of advanced AI agents. These systems can work on their own and only need humans once in a while.

    The attackers got Claude Code to carry out complex break-in tasks by using advanced jailbreaking techniques.

    They tricked the AI by splitting the attack into harmless-looking tasks and pretending they were working for a real cybersecurity company defending against real threats.

    The operation proceeded through distinct phases. First, human operators selected targets and developed attack frameworks.

    The lifecycle of the cyberattack
    The lifecycle of the cyberattack

    Claude Code then conducted reconnaissance, identifying high-value databases and security vulnerabilities within the target infrastructure.

    The AI wrote its own exploit code, harvested credentials, extracted sensitive data, and created backdoors, all while generating comprehensive documentation for future operations.

    Remarkably, Claude performed 80-90 percent of the campaign with human intervention required only at approximately 4-6 critical decision points per attack.

    At peak activity, the AI executed thousands of requests per second, an impossible pace for human hackers. This level of efficiency marked a major change in cyber attack abilities.

    This incident shows that new AI agent abilities have made it much easier for people to carry out advanced cyberattacks.

    Less experienced, less resourced threat actor groups can now execute enterprise-scale operations that previously required extensive human expertise and effort.

    Anthropic’s discovery highlights a serious problem: the same AI capabilities that enable these attacks are essential to cybersecurity defense.

    Anthropic security teams are advised to experiment with AI-assisted defense in Security Operations Center automation, threat detection, vulnerability assessment, and incident response.

    Industry experts say that AI platforms need stronger protections to stop bad actors from misusing them.

    Enhanced detection methods, improved threat intelligence sharing, and stronger safety controls remain essential as threat actors increasingly adopt these powerful technologies.

    The incident marks a turning point in the cybersecurity landscape, signaling that organizations must rapidly adapt their defensive strategies to counter AI-orchestrated threats.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post First Large-scale Cyberattack Using AI Tools With Minimal Human Input appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Department of Justice (DoJ) on Friday announced that five individuals have pleaded guilty to assisting North Korea’s illicit revenue generation schemes by enabling information technology (IT) worker fraud in violation of international sanctions. The five individuals are listed below – Audricus Phagnasay, 24 Jason Salazar, 30 Alexander Paul Travis, 34 Oleksandr Didenko, 28, and Erick

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶