• Cisco has issued a critical security advisory addressing two severe vulnerabilities in its Unified Contact Center Express (CCX) platform that could enable remote attackers to execute arbitrary commands and gain unauthorized system access. The vulnerabilities, published on November 5, 2025, require immediate attention from organizations running Cisco Unified CCX systems. CVE ID Vulnerability Type CVSS […]

    The post Cisco UCCX Vulnerabilities Allow Remote Attackers to Execute Arbitrary Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have identified a sophisticated new malware family, Airstalk, that exploits VMware’s AirWatch API—now known as Workspace ONE Unified Endpoint Management—to establish covert command-and-control channels. The discovery represents a significant threat to evolution, with both PowerShell and .NET variants discovered in what researchers assess with medium confidence was a nation-state-sponsored supply chain attack. The […]

    The post Airstalk Malware Exploits AirWatch MDM for Covert C2 Communication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Introduction Financial institutions are facing a new reality: cyber-resilience has passed from being a best practice, to an operational necessity, to a prescriptive regulatory requirement. Crisis management or Tabletop exercises, for a long time relatively rare in the context of cybersecurity, have become required as a series of regulations has introduced this requirement to FSI organizations in

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has disclosed multiple critical vulnerabilities in Unified Contact Center Express (CCX) that allow unauthenticated remote attackers to execute malicious code and escalate privileges.

    The vulnerabilities affect the Java Remote Method Invocation (RMI) process and authentication mechanisms, potentially compromising entire contact center deployments.

    RCE and Authentication Bypass Vulnerability

    The primary vulnerability, CVE-2025-20354, has a critical CVSS score of 9.8, allowing attackers to upload arbitrary files via the Java RMI process without authentication.

    Successful exploitation allows attackers to execute commands with root privileges on affected systems.

    The vulnerability stems from improper authentication mechanisms in Cisco Unified CCX, leaving organizations’ contact center infrastructure exposed to complete compromise.

    Attackers can leverage this flaw to establish persistent access, steal sensitive customer data, or deploy ransomware across entire contact center networks.

    CVE-2025-20358 presents an equally dangerous authentication bypass affecting the CCX Editor application.

    Rated 9.4 on the CVSS scale, this vulnerability allows attackers to redirect the authentication flow to malicious servers, tricking the CCX Editor into believing legitimate authentication occurred.

    Once bypassed, attackers gain administrative permissions to create and execute arbitrary scripts as internal non-root users.

    This dual-vulnerability combination creates a sophisticated attack chain that allows remote attackers to escalate privileges and maintain control over contact center operations progressively.

    CVE IDVulnerability TypeCVSS Score
    CVE-2025-20354Remote Code Execution9.8
    CVE-2025-20358Authentication Bypass9.4

    Cisco has released software updates addressing both vulnerabilities, with no workarounds available.

    Organizations running Unified CCX version 12.5 SU3 and earlier must upgrade immediately to version 12.5 SU3 ES07, while users on version 15.0 must install version 15.0 ES01.

    The vulnerabilities affect all Unified CCX configurations regardless of deployment settings. Other Cisco products, including Unified Contact Center Enterprise (CCE) and Packaged Contact Center Enterprise, remain unaffected.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Cisco Unified Contact Center Express Vulnerabilities Let Remote Attacker Execute Malicious Code appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercrime has stopped being a problem of just the internet — it’s becoming a problem of the real world. Online scams now fund organized crime, hackers rent violence like a service, and even trusted apps or social platforms are turning into attack vectors. The result is a global system where every digital weakness can be turned into physical harm, economic loss, or political

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Django, one of the most popular Python web development frameworks, has disclosed two critical security vulnerabilities that could allow attackers to execute SQL injection attacks and launch denial-of-service attacks.

    The vulnerabilities, identified as CVE-2025-64458 and CVE-2025-64459, affect core components of the framework and require immediate attention from developers using Django in their applications.

    The more serious of the two vulnerabilities, CVE-2025-64459, carries a high severity rating and involves a potential SQL injection weakness in Django’s QuerySet and Q objects.

    SQL Injection and Windows-Specific DoS Vulnerability

    Security researcher Cyberstan discovered that the QuerySet.The filter(), QuerySet.exclude(), and QuerySet.get() methods, along with the Q() class, are vulnerable when processing specially crafted dictionaries that use the _connector keyword argument with dictionary expansion.

    This flaw could enable malicious actors to inject arbitrary SQL commands into database queries, potentially compromising sensitive data or gaining unauthorized access to backend systems.

    SQL injection remains one of the most dangerous web application vulnerabilities, making this discovery particularly concerning for organizations relying on Django for their web infrastructure.

    The second vulnerability, CVE-2025-64458, affects Django installations running on Windows.

    CVE IDVulnerability TypeAffected VersionsCVSS Score
    CVE-2025-64458Denial-of-Service (DoS)Django 4.2, 5.1, 5.2, 6.0 (beta)5.3
    CVE-2025-64459SQL InjectionDjango 4.2, 5.1, 5.2, 6.0 (beta)9.8

    Seokchan Yoon from ch4n3.KR identified this moderate-severity denial-of-service weakness in the HttpResponseRedirect and HttpResponsePermanentRedirect functions. The issue stems from slow NFKC normalization in Python on Windows.

    Attackers can exploit this performance bottleneck by submitting inputs containing vast numbers of Unicode characters, causing the application to consume excessive resources and potentially become unresponsive.

    Although rated moderate severity, this vulnerability could still disrupt services and affect user experience on Windows-based Django deployments.

    Django developers should update their installations to the latest patched versions as soon as possible.

    Organizations using Django on Windows systems should pay particular attention to the DoS vulnerability. At the same time, all Django users must address the SQL injection flaw regardless of their operating system.

    Regular security updates and following Django’s security best practices remain essential for maintaining secure web applications.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Multiple Django Vulnerabilities Enable SQL injection and DoS Attack appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Bitdefender has once again been recognized as a Representative Vendor in the Gartner® Market Guide for Managed Detection and Response (MDR) — marking the fourth consecutive year of inclusion. According to Gartner, more than 600 providers globally claim to deliver MDR services, yet only a select few meet the criteria to appear in the Market Guide. While inclusion is not a ranking or comparative

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • International law enforcement agencies have taken down three sophisticated fraud and money laundering networks in a coordinated operation that uncovered one of the largest credit card fraud schemes in recent history.

    The operation, codenamed “Chargeback,” revealed criminal activity affecting over 4.3 million cardholders across 193 countries, with total damages exceeding EUR 300 million and attempted fraud exceeding EUR 750 million.

    On November 4, 2025, authorities executed a massive enforcement action involving more than 60 house searches and 18 arrests across multiple countries.

    Coordinated International Action Targets Criminal Networks

    The operation was spearheaded by Germany’s Cybercrime Department at the General Prosecutor’s Office in Koblenz and the Federal Criminal Police Office (Bundeskriminalamt), which had been investigating these networks since December 2020.

    Europol provided critical support throughout the investigation, coordinating efforts to apprehend 44 suspects from Germany and other nations.

    In Germany, over 250 officers from various agencies, including the Federal Criminal Police Office, the Federal Financial Supervisory Authority (BaFin), and tax investigation units, conducted 29 premises searches across multiple states.

    Five arrest warrants were executed, and authorities secured assets worth over EUR 35 million in Luxembourg and Germany.

    The arrested individuals include alleged network operators, executives from German payment service providers, intermediaries, crime-as-a-service providers, and an independent risk manager.

    Between 2016 and 2021, the criminal networks allegedly created approximately 19 million fake online subscriptions using stolen credit card information.

    These fraudulent subscriptions were disguised as legitimate services for pornography, dating, and streaming websites that were professionally designed to avoid detection by search engines.

    The websites could be accessed only via direct URLs or specific links, making them difficult for victims to discover.

    The suspects purposely kept monthly charges around EUR 50 with vague transaction descriptions, making it challenging for cardholders to identify unauthorized charges on their statements.

    This strategy allowed the fraud to continue undetected for extended periods, maximizing the criminals’ profits while minimizing the risk of discovery.

    Six suspects, including executives and compliance officers, allegedly cheated with the fraud networks by providing access to payment infrastructure from four major German payment service providers in exchange for fees.

    To further conceal their activities, the criminals established numerous shell companies, primarily registered in the United Kingdom and Cyprus, obtained through crime-as-a-service providers who supplied complete corporate structures with fake directors and fraudulent Know-Your-Customer documents.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Authorities Dismanteled Major Credit Card Fraud Operation Impacting 4.3 Million Cardholders appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Django development team has released critical security patches addressing two significant vulnerabilities that could expose applications to denial-of-service attacks and SQL injection exploits. The security releases for Django 5.2.8, 5.1.14, and 4.2.26 were published on November 5, 2025, in accordance with Django’s standard security release policy. The two disclosed vulnerabilities pose different levels of […]

    The post Multiple Django Flaws Could Allow SQL Injection and Denial-of-Service Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has confirmed that threat actors are actively exploiting a critical remote code execution (RCE) flaw in its Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software.

    First disclosed on September 25, 2025, the vulnerability tracked as CVE-2025-20333 poses a severe risk to organizations relying on these firewalls for VPN access. With a CVSS score of 9.9, it enables authenticated attackers to run arbitrary code with root privileges, potentially leading to full device compromise.

    The issue stems from inadequate validation of user-supplied input in the VPN web server’s handling of HTTP(S) requests. An attacker armed with valid VPN credentials can craft malicious requests to trigger the flaw, bypassing normal safeguards and executing code that could exfiltrate data, install malware, or pivot deeper into networks.

    Cisco’s advisory, updated November 5, 2025, reveals a new attack variant targeting unpatched systems, causing devices to reload unexpectedly and triggering denial-of-service (DoS) disruptions.

    This escalation underscores the urgency, as real-world exploits have already surfaced in the wild, according to Cisco’s Event Response team.

    Cisco ASA and FTD 0-day RCE Vulnerability

    At its core, CVE-2025-20333 exploits a buffer overflow (CWE-120) in the webvpn component, active when certain remote access features are enabled.

    For ASA software, vulnerable setups include AnyConnect IKEv2 with client services, Mobile User Security (MUS), or basic SSL VPN configurations via commands like “webvpn enable <interface>.”

    FTD devices face similar risks through IKEv2 remote access or SSL VPN enabled in management interfaces like Cisco Secure Firewall Management Center.

    Only devices with enabled SSL listen sockets for these features are exposed; Cisco Secure FMC Software remains unaffected.

    Urgent Recommendations and Response

    No workarounds exist, leaving upgrades as the sole defense. Cisco urges immediate patching to fixed releases listed in the advisory, such as ASA 9.18.4.19 or FTD 7.4.2.

    ProductAffected Versions (Vulnerable)Fixed Versions (Patched)
    Cisco Secure Firewall ASA Software– 9.8.x through 9.16.4.22 – 9.18.1 through 9.18.4.18 – 9.20.1 and earlier– 9.16.4.23 and later – 9.18.4.19 and later – 9.20.2 and later
    Cisco Secure Firewall FTD Software– 6.2.2 through 6.6.7.1 – 6.7.0 through 7.0.5 – 7.2.0 through 7.2.5 – 7.4.0 through 7.4.1.1– 6.6.7.2 and later – 7.0.6 and later – 7.2.6 and later – 7.4.2 and later

    Customers should audit configurations using “show running-config” to identify exposures and monitor for anomalous VPN traffic. The company links this to broader attacks on firewall platforms, advising layered defenses like multi-factor authentication and intrusion detection.

    As cyber threats evolve, this incident highlights the perils of delayed updates in perimeter security. Organizations delaying action risk cascading breaches in an era of persistent exploitation.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Cisco Warns of Hackers Actively Exploiting ASA and FTD 0-day RCE Vulnerability in the Wild appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶