• Cybercriminals are exploiting the growing popularity of artificial intelligence tools by distributing malicious Chrome browser extensions that masquerade as legitimate AI services. These fake extensions, mimicking popular AI platforms like ChatGPT, Claude, Perplexity, and Meta’s Llama, are designed to hijack user prompts and redirect them to attacker-controlled domains for malicious purposes. Security researchers from Palo […]

    The post Warning: Malicious AI Tools Being Distributed as Chrome Extensions by Threat Actors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Problem: Legacy SOCs and Endless Alert Noise Every SOC leader knows the feeling: hundreds of alerts pouring in, dashboards lighting up like a slot machine, analysts scrambling to keep pace. The harder they try to scale people or buy new tools, the faster the chaos multiplies. The problem is not just volume; it is the model itself. Traditional SOCs start with rules, wait for alerts to fire,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical security alert highlighting the active exploitation of a serious vulnerability in the Libraesva Email Security Gateway (ESG). Cataloged as CVE-2025-59689, this command injection vulnerability has emerged as a significant threat for organizations relying on Libraesva’s email security defenses. Libraesva’s Email Security Gateway is widely […]

    The post CISA Issues Alert on Actively Exploited Libraesva ESG Command Injection Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Japanese beverage conglomerate Asahi Group Holdings has halted production at its domestic factories following a significant cyberattack that crippled its systems on Monday.

    A company spokesperson confirmed on Tuesday that production has not resumed and that there is no foreseeable timeline for when operations can be restored. The incident has brought production of iconic products, such as Asahi Super Dry beer, Nikka Whisky, and Mitsuya Cider, to a standstill.

    The cyberattack caused a widespread system failure, compelling the company to suspend critical business functions across its group companies in Japan.

    Asahi Cyberattack

    These suspended operations include order processing, shipping, and call center services. Asahi operates 30 beer, beverage, and food production plants in Japan, and the company is still in the process of investigating whether all of them have been forced to stop production.

    In a statement, Asahi confirmed a cyberattack caused the system failure but stated there has been no confirmed leakage of personal or customer data.

    The disruption is currently limited to its operations within Japan, with its European business, including UK beer supply, remaining unaffected.

    While Asahi has not disclosed the specific nature of the attack, the system-wide outage and operational paralysis are hallmarks of a potential ransomware incident.

    Such attacks have become increasingly common against large corporations, where hackers encrypt critical data and demand payment for its release.

    The food and beverage industry is a particularly vulnerable target due to its reliance on just-in-time production and time-sensitive supply chains, where prolonged downtime can lead to significant financial losses.

    An expert noted that with Asahi holding nearly 40% of the market share in Japan, the disruption will be costly for the company and potentially for its resellers.

    This incident is the latest in a string of high-profile cyberattacks targeting major industrial and manufacturing companies in Japan and globally.

    In a 2024 report, Asahi had identified cyberattacks as one of the primary risks to its business. The company has apologized to its customers and business partners for the inconvenience and stated it is actively investigating the cause while working to restore its systems. No group has publicly claimed responsibility for the attack.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Beer Brewing Giant Asahi Halts Production Following Cyberattack appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly patched security flaw impacting Broadcom VMware Tools and VMware Aria Operations has been exploited in the wild as a zero-day since mid-October 2024 by a threat actor called UNC5174, according to NVISO Labs. The vulnerability in question is CVE-2025-41244 (CVSS score: 7.8), a local privilege escalation bug affecting the following versions – VMware Cloud Foundation 4.x and 5.x VMware

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has released an urgent alert for system administrators and IT teams worldwide. Researchers have confirmed that attackers are actively exploiting a serious vulnerability in the sudo utility used on many Linux and Unix systems. This flaw, tracked as CVE-2025-32463, could allow attackers to gain full administrative control of affected machines. Sudo […]

    The post CISA Issues Alert on Active Exploitation of Linux and Unix Sudo Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A team of security researchers has released an in-depth technical report on CVE-2025-32463, a critical local privilege escalation flaw in the widely used Linux sudo utility. The vulnerability, which affects sudo versions 1.9.14 through 1.9.17, allows a local attacker with standard sudo access to gain full root privileges by abusing the tool’s –chroot feature. At the heart […]

    The post Researchers Publish Technical Analysis of Linux Sudo Privilege Escalation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have flagged a previously undocumented Android banking trojan called Datzbro that can conduct device takeover (DTO) attacks and perform fraudulent transactions by preying on the elderly. Dutch mobile security company ThreatFabric said it discovered the campaign in August 2025 after users in Australia reported scammers managing Facebook groups promoting “active senior

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A surge in attacks targeting improperly managed MS-SQL servers, culminating in the deployment of the open-source XiebroC2 command-and-control (C2) framework. Similar in functionality to legitimate tools like Cobalt Strike, XiebroC2 offers capabilities for information gathering, remote control, and defense evasion, making it an attractive option for threat actors seeking a cost-effective intrusion platform. In one […]

    The post Threat Actors Exploiting MS-SQL Servers to Deploy XiebroC2 Framework appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A malicious npm package masquerading as the official Postmark MCP Server has been exfiltrating user emails to an external server. 

    This fake “postmark-mcp” module, available on npm from versions 1.0.0 through 1.0.15, built trust over 15 incremental releases before dropping a backdoor in version 1.0.16. 

    The stealthy payload consisted of a single line of code that silently BCC’d every outbound email to the attacker’s domain.

    Postmark-mcp BCC Email Exfiltration Attack

    According to Postmark the attacker published the “postmark-mcp” package under the guise of ActiveCampaign’s Postmark MCP Server library. 

    By aligning naming, versioning, and package description with legitimate Postmark conventions, the malicious actor evaded cursory scrutiny. 

    Developers integrating MCP services via npm install postmark-mcp unknowingly pulled in a trojanized dependency. In version 1.0.16, a lone line inserted into the main transport script added unauthorized BCC functionality:

    Fake Postmark MCP Attack

    This code snippet hooks into the existing Postmark client workflow, leveraging the addHeader method to duplicate outbound emails. 

    Because the malicious line is syntactically innocuous and embedded alongside legitimate header setup logic, it escaped notice in code reviews and automated security scans.

    Thousands of email messages exchanged between developers and their users were silently forwarded to the attacker’s server. 

    Although the legitimate Postmark API and official SDKs remain uncompromised, organizations relying on unverified third-party packages may have suffered unauthorized data leakage.

    Postmark urges all users to immediately:

    • Uninstall “postmark-mcp” from your projects:
    Fake Postmark MCP Attack
    • Examine SMTP logs and Postmark track events for suspicious BCC operations or unexpected API calls.
    • Change any credentials or tokens transmitted during the compromise window to prevent further unauthorized access.

    Postmark reaffirms that it has never published a “postmark-mcp” library on npm. The official packages and SDKs are listed in the Postmark documentation and GitHub repository. 

    Users can verify package authenticity by checking the postmark and postmark.js libraries maintained at github.com/ActiveCampaign/postmark and consulting the API docs at Postmark’s developer portal.

    This incident highlights the critical importance of vetting third-party dependencies. Integrating only officially documented libraries ensures that your email infrastructure remains secure.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶