• The Cybersecurity and Infrastructure Security Agency has issued a critical warning regarding a newly identified vulnerability affecting Gladinet CentreStack and Triofox platforms.

    The flaw, tracked as CVE-2025-11371, exposes sensitive system files and directories to unauthorized external access, potentially compromising organizations relying on these file-sharing solutions for business operations.

    These files or directories accessible to external parties allow attackers to discover and retrieve confidential system information without proper authentication.

    The vulnerability stems from improper access controls within the affected applications, classified under CWE-552, which specifically addresses issues where sensitive resources remain accessible to unintended actors.

    Security researchers have confirmed active exploitation attempts targeting vulnerable deployments, prompting immediate federal agency intervention.

    Understanding the Exposure and Risk

    The vulnerability CVE-2025-11371 creates a significant exposure window for attackers attempting to gather reconnaissance data or launch follow-up attacks.

    By accessing exposed directories, threat actors can identify system configurations, user information, and potentially hardcoded credentials information commonly leveraged in multi-stage attack chains.

    While the vulnerability has not yet been publicly linked to ransomware campaigns, cybersecurity experts warn that the accessible information could enable devastating ransomware deployments.

    CVE IDVulnerability TypeAffected Products
    CVE-2025-11371Files or Directories Accessible to External PartiesGladinet CentreStack, Triofox

    CISA has assigned this vulnerability a remediation deadline of November 25, 2025, providing organizations approximately three weeks to implement protective measures.

    The agency recommends three primary mitigation strategies depending on organizational capability and risk tolerance. First, organizations should immediately apply all vendor-supplied patches and security updates.

     Second, federal agencies managing cloud services should implement controls aligned with Binding Operational Directive 22-01, which mandates specific security baselines for government cloud infrastructure.

    Third, organizations unable to patch or implement equivalent protections are advised to discontinue using the product entirely.

    Organizations currently deploying Gladinet CentreStack or Triofox should prioritize verification of their current software versions and check vendor advisories for available patches.

    Network administrators should review access logs to identify any suspicious file access attempts or unusual data queries.

    Implementing network segmentation, restricting external access to administrative interfaces, and deploying enhanced monitoring solutions can provide interim protection while patches are applied.

    The vulnerability underscores ongoing challenges with cloud-based file-sharing platforms and the critical importance of maintaining updated security postures.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CISA Warns of Gladinet CentreStack and Triofox Files Vulnerability Exploited in Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hyundai AutoEver America, LLC has formally confirmed a significant data breach that compromised sensitive customer information. The automotive software provider disclosed the incident through official breach notification letters sent to affected individuals, revealing that attackers gained unauthorized access to names, Social Security numbers, and driver’s license information during a coordinated cyber attack.​ The unauthorized activity […]

    The post Hyundai AutoEver Confirms Data Breach Exposing Personal Data, Including SSNs and License Info appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has released an emergency security update for Chrome across all platforms, rolling out version 142.0.7444.134 and 142.0.7444.135 to address five critical and medium-severity vulnerabilities. The update addresses urgent security concerns identified in the browser’s WebGPU implementation and other core components that could expose users to remote code execution attacks. The emergency release came on […]

    The post Google Issues Emergency Chrome Update to Fix Critical RCE Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google Threat Intelligence Group (GTIG) has unveiled details of an experimental malware family called PROMPTFLUX, which leverages the company’s Gemini AI API to dynamically rewrite its own code, marking a chilling evolution in AI-assisted cyber threats.

    This development, detailed in GTIG’s latest AI Threat Tracker report released on November 4, 2025, highlights how adversaries are shifting from mere productivity tools to embedding large language models (LLMs) directly into malware for real-time adaptation and evasion.

    While still in testing phases and not yet capable of widespread compromise, PROMPTFLUX represents the first observed instance of “just-in-time” AI integration in malicious software, potentially paving the way for more autonomous attacks.​

    PROMPTFLUX operates as a VBScript-based dropper, initially masquerading as innocuous installers like “crypted_ScreenRec_webinstall” to trick users across various industries and regions.

    Its core innovation lies in the “Thinking Robot” module, which uses a hard-coded Gemini API key to query the “gemini-1.5-flash-latest” model for obfuscated VBScript code designed to bypass antivirus detection.

    PROMPTFLUX Malware Using Gemini API

    The malware prompts the LLM to generate self-contained evasion scripts, outputting only the code without extraneous text, and logs responses in a temporary file for refinement.

    In advanced variants, it rewrites its entire source code hourly, embedding the original payload, API key, and regeneration logic to create a recursive mutation cycle that ensures persistence via the Windows Startup folder.

    GTIG notes that while features like the self-update function remain commented out, indicating early development, the malware also attempts lateral spread to removable drives and network shares.

    This approach exploits AI’s generative power not just for creation, but for ongoing survival, differing from static malware that relies on fixed signatures easily detected by defenders.​

    The emergence of PROMPTFLUX aligns with a maturing cybercrime marketplace where AI tools flood underground forums, offering capabilities from deepfake generation to vulnerability exploitation at subscription prices.

    GTIG’s analysis reveals state-sponsored actors from North Korea, Iran, and China, alongside financially motivated criminals, increasingly abusing Gemini across the attack lifecycle from phishing lures to command-and-control setups.

    PROMPTFLUX Malware Using Gemini API
    PROMPTFLUX Malware Using Gemini API

    For instance, related malware like PROMPTSTEAL, linked to Russia’s APT28, queries Hugging Face’s Qwen2.5 LLM to generate reconnaissance commands disguised as image tools.

    Attackers are also employing social engineering in prompts, posing as CTF participants or students to circumvent AI safeguards and extract exploit code.

    As these tools lower barriers for novice actors, GTIG warns of heightened risks, including adaptive ransomware like PROMPTLOCK that dynamically crafts Lua scripts for encryption.

    In response, Google has swiftly disabled associated API keys and projects, while DeepMind enhances Gemini’s classifiers and model safeguards to block misuse prompts.

    The company emphasizes its commitment to responsible AI via principles that prioritize robust guardrails, sharing insights through frameworks like Secure AI (SAIF) and tools for red-teaming vulnerabilities.

    Innovations such as Big Sleep for vulnerability hunting and CodeMender for automated patching underscore efforts to counter AI threats proactively.

    Though PROMPTFLUX poses no immediate compromise risk, GTIG predicts rapid proliferation, urging organizations to monitor API abuses and adopt behavioral detection over signatures.

    As AI integrates deeper into operations, this report signals an urgent need for ecosystem-wide defenses to stay ahead of evolving adversaries.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Google Warns of New PROMPTFLUX Malware Using Gemini API to Rewrite its Own Source Code appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered a resurgent Gootloader malware campaign employing sophisticated new evasion techniques that exploit ZIP archive manipulation to evade detection and analysis. Credit for uncovering this latest threat goes to security researcher RussianPanda and the team at Huntress, identified the campaign actively targeting victims through compromised websites. Despite previous disruption efforts earlier this […]

    The post Gootloader Returns with a New ZIP File Tactic to Conceal Malicious Payloads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers at Tenable have uncovered a series of critical vulnerabilities in OpenAI’s ChatGPT that could allow malicious actors to steal private user data and launch attacks without any user interaction. The security flaws affect hundreds of millions of users who interact with large language models daily, raising significant concerns about the safety of AI. […]

    The post HackedGPT: New Vulnerabilities in GPT Models Allow Attackers to Launch 0-Click Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SonicWall has formally implicated state-sponsored threat actors as behind the September security breach that led to the unauthorized exposure of firewall configuration backup files. “The malicious activity – carried out by a state-sponsored threat actor – was isolated to the unauthorized access of cloud backup files from a specific cloud environment using an API call,” the company said in a

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated espionage campaign targeting recruitment professionals has emerged, with the APT-C-60 threat group weaponizing VHDX files to compromise organizations.

    The threat actors impersonate job seekers in spear-phishing emails sent to recruitment staff, exploiting trust relationships to deliver malicious payloads.

    While earlier campaigns directed victims to download VHDX files from Google Drive, recent attacks have evolved to attach the malicious VHDX file directly to emails.

    Once a victim opens the weaponized VHDX file and clicks the embedded LNK file, a malicious script executes via Git, a legitimate application, initiating a multi-stage infection process that deploys sophisticated data-stealing malware.

    JPCERT analysts identified this campaign targeting East Asian regions, particularly Japan, between June and August 2025.

    The threat group demonstrates advanced operational security by leveraging legitimate services like GitHub and statcounter to maintain command-and-control infrastructure.

    The attacks showcase technical sophistication through multi-layered obfuscation techniques, including XOR encoding with the key “sgznqhtgnghvmzxponum” for initial payloads and AES-128-CBC encryption for secondary stage downloads.

    The malware identifies compromised machines using volume serial numbers and computer names, enabling precise victim tracking.

    The infection chain begins when the LNK file executes gcmd.exe, a legitimate Git component, which runs the script glog.txt stored within the VHDX file.

    This script displays a fabricated resume as a decoy while simultaneously creating WebClassUser.dat (Downloader1) and registering it in the system registry at HKCU\Software\Classes\CLSID\{566296fe-e0e8-475f-ba9c-a31ad31620b1}\InProcServer32.

    Persistence is established through COM hijacking, ensuring the malware executes automatically during system operations.

    Downloader1 communicates with statcounter using specially crafted referrer headers in the format ONLINE=>[Number1],[Number2] >> [%userprofile%] / [VolumeSerialNumber + ComputerName].

    The threat actors monitor these referrer values and upload corresponding files to GitHub repositories. Downloader1 retrieves files from URLs like https://raw.githubusercontent.com/carolab989/class2025/refs/heads/main/[VolumeSerialNumber+ComputerName].txt, which contain instructions for downloading Downloader2.

    Infection Mechanism and Payload Deployment

    The infection mechanism employs a cascading deployment strategy with multiple encoded layers.

    Downloader2 downloads and deploys SpyGlace malware, utilizing dynamic API resolution with an encoding scheme combining ADD and XOR operations.

    Flow of malware infection (Source - JPCert)
    Flow of malware infection (Source – JPCert)

    The current version applies XOR 0x05 after ADD 0x04, representing an evolution from earlier variants. Files retrieved by Downloader2 are XOR-decoded using the key “AadDDRTaSPtyAG57er#$ad!lDKTOPLTEL78pE” before execution through COM hijacking.

    SpyGlace versions 3.1.12 through 3.1.14 have been observed implementing comprehensive data exfiltration capabilities through 17 distinct commands.

    The malware communicates with command-and-control servers at IP address 185.181.230.71 using modified RC4 encryption combined with BASE64 encoding.

    The modified RC4 implementation increases Key Scheduling Algorithm cycles and performs additional XOR operations.

    SpyGlace employs a characteristic encoding scheme combining single-byte XOR with SUB instructions for string obfuscation and API resolution.

    The download command retrieves encrypted files and decrypts them using AES-128-CBC with the hardcoded key B0747C82C23359D1342B47A669796989 and IV 21A44712685A8BA42985783B67883999, creating files at %temp%\wcts66889.tmp.

    The malware establishes persistence by changing its automatic execution path from %public%\AccountPictures\Default\ in version 3.1.13 to %appdata%\Microsoft\SystemCertificates\My\CPLs in version 3.1.14.

    SpyGlace implements comprehensive surveillance capabilities, including remote shell access, file manipulation, process control, disk enumeration, and automated screenshot capture through the screenupload command, which calls the Clouds.db module at %LocalAppData%\Microsoft\Windows\Clouds\Clouds.db with the export function mssc1.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post APT-C-60 Attacking Job Seekers to Download Weaponized VHDX File from Google Drive to Steal Sensitive Data appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has rolled out an urgent security patch for its Chrome browser, addressing five vulnerabilities that could enable attackers to execute malicious code remotely.

    The update, version 142.0.7444.134/.135 for Windows, 142.0.7444.135 for macOS, and 142.0.7444.134 for Linux, targets critical flaws in core components like WebGPU and the V8 JavaScript engine.

    The patch arrives amid heightened scrutiny of browser security, as WebGPU, a modern API for GPU-accelerated web applications, has become a prime target for sophisticated exploits.

    Remote code execution vulnerabilities in such components could allow malicious websites to hijack user systems without any interaction beyond visiting a compromised page.

    Google emphasized that the fixes were developed in collaboration with external researchers, preventing these issues from reaching a wider audience. The update will propagate gradually over the coming days and weeks to ensure stability across millions of devices worldwide.

    Key Vulnerabilities Patched in Chrome 142

    Among the five security fixes, three stand out for their high severity, including the out-of-bounds write in WebGPU and inappropriate implementations in V8 and Views.

    These flaws, if unpatched, could lead to memory corruption, enabling attackers to run arbitrary code, steal sensitive data, or install malware. The remaining two medium-severity issues affect the Omnibox address bar, potentially exposing users to phishing or injection risks.

    For a detailed breakdown, the following table summarizes the CVEs, their severity, affected components, and technical details based on Google’s disclosures:

    CVE IDSeverityAffected ComponentDescription and ImpactCVSS v3.1 Score (Estimated)Reported ByDate Reported
    CVE-2025-12725HighWebGPUOut-of-bounds write flaw allowing memory corruption and remote code execution via malicious web content. Affects rendering of GPU-accelerated graphics in web apps.8.8 (High)Anonymous2025-09-09
    CVE-2025-12726HighViewsInappropriate implementation leading to UI manipulation and potential remote code execution through crafted web pages. Impacts browser’s visual rendering engine.8.1 (High)Alesandro Ortiz2025-09-25
    CVE-2025-12727HighV8Inappropriate implementation in JavaScript engine enabling heap corruption and remote code execution. Exploitable via specially crafted scripts on websites.8.8 (High)303f06e32025-10-23
    CVE-2025-12728MediumOmniboxInappropriate implementation allowing address bar spoofing, which could facilitate phishing attacks. No direct code execution but aids social engineering.6.5 (Medium)Hafiizh2025-10-16
    CVE-2025-12729MediumOmniboxSimilar implementation flaw in address bar, enabling URL manipulation for deceptive user interfaces.6.1 (Medium)Khalil Zhani2025-10-23

    These estimates for CVSS scores align with typical ratings for similar browser flaws, emphasizing the urgency of the high-severity issues. Google has restricted full bug details until most users update, a standard practice to limit exploit development.

    This update highlights the vulnerabilities inherent in modern web standards like WebGPU, which promise enhanced performance for gaming and AI applications but introduce new attack surfaces.

    V8, powering Chrome’s JavaScript execution, remains a frequent target due to its ubiquity across web ecosystems. Security tools such as AddressSanitizer and libFuzzer played a crucial role in detecting these bugs during development, showcasing proactive measures in Chromium’s pipeline.

    Users should immediately check for updates via Chrome’s settings menu under “About Chrome” to apply the patch. Enterprises relying on Chrome for corporate environments are advised to enforce auto-updates and monitor for signs of exploitation, such as unusual browser crashes or network anomalies.

    As cyber threats evolve, this incident serves as a reminder of the importance of timely patching in safeguarding digital lives.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Chrome Emergency Update to Patch Multiple Vulnerabilities that Enable Remote Code Execution appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HONOLULU—Pacific Air Forces’s massive REFORPAC exercise in the Pacific this summer “identified the capabilities that we need to win in this theater,” the command’s deputy leader said last week: namely, artificial intelligence, autonomy, machine learning; improved command and control capabilities; and resilient cyber networks “that can communicate securely in expeditionary environments and survive relentless attacks.”

    Speaking at the AFCEA TechNet Indo-Pacific conference, Lt. Gen. Laura Lenderman said that while “revisionist autocracies” want to “upend the security, freedom, and prosperity” of the Indo-Pacific, there is “another chapter we’re writing…filled with optimism and clarity, that strengthens deterrence, inspires progress and reinforces our shared vision of the future.” 

    That vision was “on full display” during Exercise Resolute Pacific, Lenderman said.

    The exercise included 4,000 sorties at 50 locations that spanned 6,000 miles. Shortly after it kicked off in July, Pacific Air Forces Commander Gen. Kevin Schneider said in an interview that this region “is critically important, not only to the nations in the region that touch the Pacific Ocean, but to the world.”

    However, Schneider said, “from an operational perspective, the geography of this theater is incredibly challenging…so, our ability to command and control, to operate, to move with speed, scale, and agility across the vastness of this area is probably the most challenging thing that we do in not only the United States Air Force, but across all branches of the United States military.”

    Maj. Gen. Anthony Mastalir, who was then commander of U.S. Space Forces Indo-Pacific, noted in the same July interview that space capabilities are also critical in the theater.

    “If you’re going to project power, you have to have space. Space is the force multiplier that will allow us to project power great distances. So being able to close those gaps over the vast Pacific Ocean…in this theater, space superiority over the INDOPACOM AOR is a precondition for Joint Force success, period.”

    In REFORPAC and Resolute Space, an exercise that ran concurrently, tested the ability of airmen and guardians “to conduct sustained, complex military operations involving large numbers of forces in situations where we contested air and space superiority, power projection, and global mobility, Lenderman said.

    It was also critical training, Command Sgt. Major Katie McCool, command chief for Pacific Air Forces, said in July. “We want our airmen to be prepared on Day One to go into any type of contingency and be able to execute,” she said. And while those airmen and guardians are learn concepts and tactics in their initial training, “you cannot recreate the conditions there that we have here, from small islands to Alaska.”

    Command Sgt. Maj. Jason Childers, the senior enlisted leader for U.S. Space Forces Indo-Pacific, had a similar take.

    “You have Guardians that usually sit inside of ops centers located and distributed around the world, often not even seeing the light of day, working 24/7, operating systems that are in the space domain, so they can’t really see, taste, touch, hear, or smell the environment that they’re operating in. So, to be able to conduct exercises like this… certainly helps to robust and enhance our readiness.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶