• The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting Gladinet and Control Web Panel (CWP) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerabilities in question are listed below – CVE-2025-11371 (CVSS score: 7.5) – A vulnerability in files or directories accessible to

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have discovered a sophisticated attack technique that exploits Microsoft’s OneDrive application to execute malicious code without detection. The method, known as DLL sideloading, leverages the way Windows loads library files to trick legitimate applications into running attacker-controlled software. This technique represents a significant threat to enterprise environments where OneDrive is widely deployed across […]

    The post Hackers Abuse OneDrive.exe via DLL Sideloading to Run Malicious Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Seqrite Labs’ APT Team has documented fresh campaigns from Silent Lynx, a sophisticated threat actor group known for orchestrating spear-phishing operations that impersonate government officials to target diplomatic and governmental employees across Central Asia. The group, also tracked under aliases including YoroTrooper, Sturgeon Phisher, and Cavalry Werewolf, continues its espionage-focused activities with minimal operational security […]

    The post Silent Lynx APT New Attack Targeting Governmental Employees Posing as Officials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The HydraPWK project’s latest Apes-T1 snapshot refines its penetration-testing Linux distribution by replacing Elasticsearch with the open-source OpenSearch, resolving licensing issues and enhancing tools for industrial security assessments.

    This update, released shortly after the major Apes version, highlights HydraPWK’s focus on compliance and usability, positioning it as a streamlined rival to the ubiquitous Kali Linux in the ethical hacking community.

    By prioritizing real-time performance and plug-and-play tools, HydraPWK appeals to specialists targeting embedded systems, offering a fresh take on pentesting without the overhead often seen in broader distros.​

    OpenSearch Integration and UI Polish

    Apes-T1 addresses a post-release hiccup where Elasticsearch’s restrictive license led to its removal from the repository, as noted in GitHub issues.

    In its place, OpenSearch a scalable, Apache-licensed search engine now serves as the backend for tools like Arkime, enabling efficient network forensics without proprietary entanglements.

    OpenSearch Dashboards also joins as a custom HydraPWK build, providing visualization capabilities tailored for observability in pentesting workflows.

    An updated hydrapwk-purplizer colorscheme for the Xfce terminal fixes error visibility problems, ensuring clearer output during live operations.​

    These changes maintain HydraPWK’s semi-rolling model, allowing updates via a simple APT command or fresh ISO downloads. The team apologized for the oversight and encouraged honest community feedback over hype, fostering trust in this Debian-based distro aimed at industrial sectors like avionics and drones.​

    HydraPWK vs. Kali Linux

    When stacked against Kali Linux, HydraPWK emerges as a more niche, lightweight contender optimized for physical and real-time pentesting.

    Kali, with over 600 pre-installed tools like Nmap, Metasploit, and Wireshark, excels in general-purpose ethical hacking but can feel bloated and resource-heavy, often requiring manual tweaks for stability in specialized environments.

    HydraPWK, built on Debian’s testing branch with a PREEMPT_RT kernel, loads kernel modules automatically for low-latency interactions with hardware like UAVs or automotive ECUs, reducing setup time compared to Kali’s broader scope.

    Kali’s vast ecosystem supports diverse tasks from wireless attacks to forensics via tools like Aircrack-ng and John the Ripper, but its non-root-by-default approach in recent versions adds configuration layers that HydraPWK bypasses with its out-of-the-box hardening.

    While Kali thrives on community-driven metapackages for customization, HydraPWK’s “+hydrapwk” packages emphasize industrial focus, avoiding Kali’s occasional update-induced instability for a more predictable, plug-and-play experience.

    Users praise HydraPWK’s speed and completeness as potential Kali successors for targeted ops, though Kali remains the gold standard for comprehensive, multi-platform testing.

    As cyber threats target industrial IoT, HydraPWK’s refinements make it a compelling choice for pros seeking efficiency without sacrificing power. Updates are straightforward, keeping the distro agile in a fast-evolving field.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post HydraPWK Penetration Testing OS With Necessary Hacking Tools and Simplified Interface appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Check Point Research uncovered four critical vulnerabilities in Microsoft Teams that could allow attackers to impersonate executives, manipulate messages, alter notifications, and forge identities during video and audio calls. The research team discovered that both external guest users and malicious insiders could exploit these security flaws, fundamentally undermining the trust that 320 million monthly active […]

    The post Attackers Exploit Microsoft Teams Flaws to Manipulate Messages and Fake Notifications appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Acronis Threat Research Unit has analyzed recent activity linked to the DragonForce ransomware group and identified a new malware variant in the wild. The latest sample uses vulnerable drivers such as truesight.sys and rentdrv2.sys to disable security software, terminate protected processes and correct encryption flaws previously associated with Akira ransomware. The updated encryption scheme addresses […]

    The post DragonForce Cartel Surfaces from Leaked Conti v3 Ransomware Source Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical security flaw in the WordPress Post SMTP plugin has left more than 400,000 websites vulnerable to account takeover attacks.

    The vulnerability, identified as CVE-2025-11833, enables unauthenticated attackers to access email logs containing sensitive password reset information, potentially compromising administrator accounts and entire websites.

    The flaw stems from a missing authorization check in the plugin’s core functionality, allowing threat actors to exploit logged email data without requiring any authentication credentials.

    The Post SMTP plugin, designed to replace WordPress’s default PHP mail function with SMTP mailers, includes an email logging feature that inadvertently exposes critical security information.

    Since November 1, 2025, attackers have actively targeted this vulnerability, with over 4,500 exploitation attempts already blocked by security systems.

    The widespread use of this plugin across hundreds of thousands of WordPress installations has created a significant attack surface for cybercriminals seeking unauthorized access to websites.

    Wordfence researchers identified the vulnerability through their Bug Bounty Program on October 11, 2025, just one day after its introduction.

    Security researcher netranger discovered and responsibly reported the flaw, earning a bounty of $7,800 for the critical finding.

    The WP Experts development team responded swiftly to disclosure, releasing patch version 3.6.1 on October 29, 2025, to address the security gap affecting all versions up to and including 3.6.0.

    The vulnerability carries a CVSS score of 9.8, placing it in the critical severity category. Site administrators must immediately update to version 3.6.1 to protect their installations from ongoing exploitation attempts.

    Wordfence Premium users received firewall protection on October 15, 2025, while free version users will receive the same safeguards by November 14, 2025.

    Technical Exploitation Mechanism

    The vulnerability resides within the PostmanEmailLogs class constructor, which displays logged email messages without performing capability checks on the __construct function.

    Attackers can exploit this weakness by manipulating URL parameters to access arbitrary email logs through the plugin’s interface.

    Vulnerability Details:-

    ParameterDetails
    CVE IDCVE-2025-11833
    CVSS Score9.8 (Critical)
    Vulnerability TypeMissing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
    Affected PluginPost SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App
    Affected VersionsAll versions <= 3.6.0
    Patched Version3.6.1
    Active Installations400,000+
    Discovery DateOctober 11, 2025
    Patch Release DateOctober 29, 2025
    Researchernetranger (Wordfence Bug Bounty Program)
    Bounty Awarded$7,800.00
    Exploitation StatusActive (4,500+ attacks blocked as of November 1, 2025)

    The vulnerable code accepts GET requests with specific parameters including page, view, and log_id, allowing unauthorized users to retrieve stored email content directly from the database.

    public function __construct() {
        global $wpdb;
        $this->db = $wpdb;
        $this->logger = new PostmanLogger( get_class( $this ) );
    
        //Render Message body in iframe
        if(
            isset( $_GET['page'] ) && $_GET['page'] == 'postman_email_log'
            &&
            isset( $_GET['view'] ) && $_GET['view'] == 'log'
            &&
            isset( $_GET['log_id'] ) && !empty( $_GET['log_id'] )
        ) {
            $id = sanitize_text_field( $_GET['log_id'] );
            $email_query_log = new PostmanEmailQueryLog();
            $log = $email_query_log->get_log( $id, '' );
            echo ( isset ( $header ) && strpos( $header, "text/html" ) );
            die;
        }
    }

    The exploitation process involves attackers triggering password reset requests for administrator accounts, then accessing the logged reset emails containing password reset links through the unprotected interface.

    This two-step attack vector enables complete site takeover, granting malicious actors full administrative privileges to upload backdoors, modify content, and redirect users to malicious destinations.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post WordPress Post SMTP Plugin Vulnerability Exposes 400,000 Websites to Account Takeover Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A severe security vulnerability has been discovered in a widely used React Native development package, potentially exposing millions of developers to remote attacks. Security researchers from JFrog recently uncovered CVE-2025-11953, a critical remote code execution flaw affecting the @react-native-community/cli NPM package, which receives approximately two million weekly downloads. The vulnerability carries a maximum CVSS score […]

    The post Critical RCE Bug in Leading React Native NPM Module Could Allow Full System Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security teams drown in alerts but starve for insight. Blocklists catch the obvious. SIEM correlation gives clues. But only context reveals what an alert really means, and what you should do about it. 

    Every SOC sees thousands of signals: odd domains, masquerading binaries, strange persistence artifacts. On their own, these indicators mean almost nothing. A suspicious process might be malware or a legitimate update from a vendor you barely know. 

    But the moment you add threat context — history, connected IOCs, malware family relations, sandbox behavior — the picture changes completely. 

    Meet TI Lookup: The Context Engine 

    ANY.RUN Threat Intelligence Lookup is a real-time investigation tool that lets analysts instantly understand what they’re dealing with — from domains and IPs to file hashes and URLs. 

    It’s powered by rich data crowdsourced from 15,000+ SOCs and researchers worldwide, continuously enriched by ANY.RUN’s sandbox detections. Instead of wasting time digging through multiple feeds, analysts get actionable context in seconds. 

    TI Lookup: query an IOC, get actionable intelligence for quick decision 

     
    You achieve:  

    • Instant clarity: Quickly identify whether an IOC is malicious, suspicious, or benign; 
    • Deeper context: View sandbox behavior, relations, and threat actor links in one place; 
    • Smarter triage: Speed up incident response with verified data and fewer false positives. 

    Context turns data into decisions. And decisions stop breaches from happening. 

    Here are five highly practical ways SOC analysts use context to speed triage, reduce noise, and fight more effectively: powered by ANY.RUN’s Threat Intelligence (TI) Lookup.  

    Tactic 1: Domain Intelligence – From Suspicious to Confirmed Threat 

    The Alert: 

    Domain contacted: logrecovery[.]com 

    Without Context: Could be legitimate cybersecurity resource. Requires manual investigation across multiple platforms. 

    With TI Context: 

    • Observed in AsyncRAT and Amadey sandbox executions; 
    • Linked to active command-and-control infrastructure; 
    • Associated with information-stealing campaigns and botnets. 

    domainName:”logrecovery.com” 

    Immediate Action: Block the domain at your proxy/firewall, tag it as a high-confidence IOC in your threat intelligence platform, and hunt retroactively for any historical connections in your network traffic logs. 
     
    Why It Matters: Stealer malware exfiltrates credentials, session tokens, and sensitive data. Every minute it remains unblocked is a window for data theft. Context lets you move from “investigate” to “contain” immediately. 

    Stop hunting for context, start acting on it. Sign up to trial Threat Intelligence Lookup and see how it works 

    Tactic 2: Email Attachment Analysis – Spotting Campaign Patterns 

    The Alert:  

    Suspicious attachment: Electronic_Receipt 

    Without Context: Generic filename. Could be legitimate invoice or phishing. Requires time-consuming manual analysis. 

    With TI Context: 

    • Detected in a number of malware analyses; 
    • Part of  credential-harvesting campaigns; 
    • Linked to a most dangerous Tycoon phishing kit. 

    filePath:”Electronic_Receipt” 

    Malware samples featuring file pattern 

    Immediate Action: Add the file hash to your SIEM blocklist, check egress logs for any systems that may have already connected to associated C2 domains, and update mail gateway filters to catch variants. 

    Why It Matters: Tycoon 2FA can intercept user credentials and session cookies to bypass MFA, enabling unauthorized access to accounts even with additional security measures. Organizations using cloud services are at the most risk.

    Recognizing campaign patterns helps you understand the scope: is this a targeted attack or part of a broader spray-and-pray operation? Context answers that question instantly.  

    Tactic 3: IP Address Intelligence – Understanding Payload Delivery 

    The Alert: 

    Outbound connection to: 45.155.205[.]11 
     
    Without Context: Could be legitimate software update checks. Requires manual investigation across multiple platforms. 

    With TI Context: 

    • Observed in DBatLoader and GuLoader sandbox executions; 
    • Linked to active command-and-control infrastructure; 
    • Associated with information-stealing campaigns. 

    destinationIP:”162.241.62.63″ 

    IP context: malware and campaign associations 
     
    Immediate Action: Block the domain at your proxy/firewall, tag it as a high-confidence IOC in your threat intelligence platform, and hunt retroactively for any historical connections in your network traffic logs. 

    Why It Matters: Stealer malware exfiltrates credentials, session tokens, and sensitive data. Every minute it remains unblocked is a window for data theft. Context lets you move from “investigate” to “contain” immediately. 

    Tactic 4: Process Behavior – Detecting Credential Theft 

    The Alert: 

    Unusual process detected: New Text Document mod.exe 

    Without Context: Can be a nonchalantly attributed document, but the .exe extension arouses suspicion. Manual verification required. 

    With TI Context: 

    • Observed in XRed backdoor campaigns; 
    • Associated with session hijacking and credential theft; 
    • Tampers with Windows registry, establishes persistence. 

    filePath:”New Text Document mod.exe” 

    Malware running the similar process 

    Immediate Action: Check all endpoints for this process name and file hash, flag any instances for immediate investigation, and monitor for suspicious authentication behavior patterns like impossible travel or unusual access times. 

    Malicious process poorly disguised as a document 

    Why It Matters: XRed is a backdoor designed for long-term system infiltration and control and stealing sensitive data. It combines elements of remote access Trojans (RATs), infostealers, and backdoors to execute a range of malicious activities. 

    Tactic 5: Registry Key Persistence – Finding the Foothold 

    The Alert:  
     
    Registry modification: \Software\Microsoft\update 

    Without Context: Registry changes happen constantly. Could be legitimate software, Windows updates, or persistence mechanism. Difficult to prioritize without additional information. 

    With TI Context: 

    • Appears in known malware persistence mechanisms 
    • Seen in stealer campaigns 
    • Used to maintain access across system reboots 
    • Indicator of established compromise, not initial infection 

    RegistryKey:”Software\\Microsoft\\update” and threatLevel:”malicious” 

    Search for malware that modifies registry 
     
    Immediate Action: Escalate immediately to incident response team, scan affected hosts for additional IOCs associated with notorious stealers, and check for lateral movement indicators across your environment. 

    Why It Matters: If you’re seeing persistence mechanisms, the attacker has already established a foothold. This isn’t prevention, it’s containment. Context tells you this is a critical escalation requiring full IR protocols, not just endpoint remediation. 

    The Context Advantage: From Hours to Minutes 

    Each of these scenarios represents a fork at the road of a SOC analysts. Without context, you’re stuck in investigation mode chasing down leads, correlating data points, and hoping you make the right call. With context, you skip directly to response. 

    Consider the time savings: 

    • Manual TI gathering: 20-45 minutes per artifact across multiple platforms 
    • TI Lookup with context: Seconds to retrieve comprehensive intelligence 
    • Decision confidence: Immediate clarity on threat severity and appropriate response 

    For a SOC analyst triaging 50+ alerts per day, that’s the difference between constantly playing catch-up and staying ahead of threats. 

    How Threat Intelligence Delivers Context Automatically 

    TI Lookup doesn’t just tell you whether an artifact is malicious, it shows you the full picture: 

    • Sandbox execution history: See how the artifact behaves in real, interactive malware analysis sessions 
    • Associated campaigns: Understand which threat actors and malware families use this indicator 
    • Infrastructure relationships: Map connections between domains, IPs, and file hashes 
    • Temporal context: Know if this is an emerging threat or part of an established campaign 

    Instead of piecing together intelligence from multiple sources, you get a unified view that connects artifacts to actual malware behavior.  

    Start Making Context-Driven Decisions Today 

    Next time an alert hits your queue, ask yourself: do you have the context to act confidently, or are you about to spend the next thirty minutes hunting for it? 

    Context isn’t a luxury for SOC analysts. It’s the difference between reactive scrambling and proactive defense. The threats are already using automation and infrastructure at scale. Your intelligence should, too. 

    Ready to add context to your threat hunting workflow? Explore ANY.RUN’s TI Lookup and see how instant threat intelligence transforms the way you analyze and respond to security alerts. 

    Speed without guessing, confidence without over-triaging. Choose threat intelligence trial option for your SOC

    The post Beat Threats with Context: 5 Actionable Tactics for SOC Analysts  appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • XLoader remains one of the most challenging malware families confronting cybersecurity researchers.

    This sophisticated information-stealing loader emerged in 2020 as a rebrand of FormBook and has evolved into an increasingly complex threat.

    The malware’s code decrypts only at runtime and sits protected behind multiple encryption layers, each locked with different keys hidden throughout the binary.

    Even automated sandbox analysis tools struggle against XLoader’s aggressive evasion techniques that block malicious execution when virtual environments are detected.

    Check Point researchers identified a breakthrough approach to analyzing XLoader by leveraging generative artificial intelligence.

    The latest XLoader version 8.0 sample presented significant obstacles with customized encryption schemes, obfuscated API calls, and extensive sandbox evasion techniques.

    The malware authors release new versions regularly, changing internal mechanisms and adding anti-analysis methods that render previous research quickly outdated.

    The research demonstrated how ChatGPT accelerated static reverse engineering from days to hours.

    By exporting IDA Pro database contents and analyzing them through cloud-based artificial intelligence, researchers showed deep analysis could proceed without maintaining live disassembler sessions.

    Integration of an LLM with the reverse engineering environment through MCP (Source – CheckPoint)

    This approach removed dependency on heavy local tooling while making results reproducible and easier to share.

    Decrypting XLoader’s Built-in Protection

    XLoader version 8.0 implements sophisticated protection mechanisms through a built-in crypter that wraps the main payload in two rounds of RC4 encryption.

    The first layer applies RC4 decryption to the entire buffer, followed by a second pass processing 256-byte chunks using a different key.

    Each encryption round requires specific keys derived through complex algorithms scattered across multiple functions.

    Check Point analysts noted the main payload undergoes this dual-layer encryption scheme, with Stage-1 and Stage-2 keys calculated through separate derivation processes.

    The Stage-1 key (20EBC3439E2A201E6FC943EE95DACC6250A8A647) and Stage-2 key (86908CFE6813CB2E532949B6F4D7C6E6B00362EE) were successfully extracted through artificial intelligence-assisted analysis combined with runtime debugging validation.

    The complete unpacking process traditionally consuming days of manual reverse engineering, was compressed into approximately 40 minutes, offering defenders fresher indicators of compromise.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post XLoader Malware Analyzed Using ChatGPT’s, Breaks RC4 Encryption Layers in Hours appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶