• Google on Wednesday released security updates for the Chrome web browser to address four vulnerabilities, including one that it said has been exploited in the wild. The zero-day vulnerability in question is CVE-2025-10585, which has been described as a type confusion issue in the V8 JavaScript and WebAssembly engine. Type confusion vulnerabilities can have severe consequences as they can be

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Raven Stealer, a sophisticated information-stealing malware that has been wreaking havoc on users’ sensitive data. This contemporary malware represents a concerning evolution in credential theft technology, combining advanced evasion techniques with streamlined data exfiltration capabilities. Raven Stealer stands out as a lightweight yet highly effective information-stealing malware developed primarily in Delphi and C++. Cybersecurity researchers […]

    The post Raven Stealer Targets Google Chrome Users to Exfiltrate Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers at Varonis Threat Labs have uncovered a persistent vulnerability that has remained unaddressed for over a decade, allowing attackers to exploit browser handling of Right-to-Left (RTL) and Left-to-Right (LTR) text scripts to create deceptive URLs. This technique, known as BiDi Swap, enables threat actors to craft malicious links that appear legitimate to unsuspecting […]

    The post Hackers Abuse RTL/LTR Text Tricks and Browser Flaws to Mask Malicious Links appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Protecting digital infrastructure is critical in 2025, as cyber threats escalate in complexity and diversity.

    Next‑Generation Firewalls (NGFWs) have become the cornerstone for enterprise security, offering not just robust traffic filtering, but also deep packet inspection, advanced threat intelligence, and seamless cloud integration for defense against today’s persistent and evolving threats.

    Why Top 10 Best Next‑Generation Firewall (NGFW) Providers Of 2025

    Enterprise, SMB, and cloud operators all need NGFWs to safeguard assets against ransomware, malware, phishing, and insider risks.

    These top providers offer AI-powered threat detection, modular scalability, centralized management, and connectivity to hybrid architectures ensuring future-proof security that adapts to both regulatory demands and business growth.

    Comparison Table: Top 10 Best Next‑Generation Firewall (NGFW) Providers Of 2025

    ToolsApplication ControlAdvanced Threat ProtectionCloud IntegrationCentralized ManagementSD-WAN Capabilities
    Palo Alto Networks✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Fortinet✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Check Point✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Cisco Systems✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Juniper Networks✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Sophos✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Barracuda Networks✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Forcepoint✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Huawei✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    WatchGuard✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes

    1. Palo Alto Networks

    Best Next‑Generation Firewall
    Palo Alto Networks

    Why We Picked It

    Palo Alto Networks leads NGFW innovation with AI-driven threat detection and unified security architecture, protecting enterprises across cloud, data center, and remote office environments.

    Its deep visibility and simplified zero trust controls allow organizations flexible yet powerful defenses. With industry-best support for hybrid and SASE deployments, it scales from branch offices to hyperscale data centers.

    The platform delivers consistent, real-time prevention against known and zero-day attacks, even in encrypted traffic. Advanced application control and contextual security offer precision and adaptability.

    Gartner rates Palo Alto as a Magic Quadrant Leader, highlighting their commitment to rapid innovation.

    Specifications

    Palo Alto Networks appliances range from compact models for branch offices to modular chassis for large-scale data centers, all driven by a single-pass architecture and function-specific processing.

    They support various deployment modes including cloud, virtual, and on-premises, and are designed to deliver predictable performance and scalability.

    Features

    Integrated threat prevention, robust application awareness, advanced malware analysis, seamless SD-WAN, and deep-learning analytics are supported, with simplified orchestration across environments.

    Proactive security with AI/ML capabilities enables rapid adaptive protection.

    Reason to Buy

    Trusted by Fortune 10 companies, Palo Alto NGFWs reduce operational complexity, maximize security visibility, and ensure compliance for organizations with stringent security needs.

    Their platform’s reliability and continual improvement make it a premier choice for enterprises that prioritize dynamic, scalable security.

    Pros

    • Performance enhancing
    • Reliable and scalable
    • Continually improving product

    Cons

    • High cost compared to competition
    • May require advanced expertise for configuration

    ✅ Best For: Large enterprises, data centers, multi-cloud environments.

    🔗 Try Palo Alto Networks here → Palo Alto Networks Official Website

    2. Fortinet

    Best Next‑Generation Firewall
    Fortinet

    Why We Picked It

    Fortinet’s FortiGate NGFWs combine AI-powered threat intelligence, ASIC-based acceleration, and a strong, unified security fabric, creating a performance-to-cost leader in the market.

    Known for their robust SD-WAN integration and universal management tools, Fortinet excels in high-throughput and hybrid architectures.

    The platform addresses the rise of distributed networks and cloud migration, delivering consistent security and operational efficiency.

    Industry recognition is reinforced by their position in Gartner’s Magic Quadrant.

    Specifications

    FortiGate appliances utilize patented security processors for scalable acceleration and unified threat management, catering to environments of all sizes from SMBs to hyperscale enterprises.

    Multiple form factors support hybrid mesh deployments, cloud integration, and dynamic segmentation.

    Features

    AI-centric threat intelligence, integrated SD-WAN, ZTNA, cloud-ready deployment, real-time protection against evolving threats, intuitive unified management interface, and fast security processing are core features.

    Reason to Buy

    Organizations benefit from reliable, high-performance network security with flexible deployment and cost-effective licensing, making Fortinet ideal for scaling businesses and distributed teams.

    Automation and deep visibility reduce operational overhead and risk.

    Pros

    • High security throughput
    • Intuitive management
    • Cost-effective operation

    Cons

    • Complex initial configuration
    • Advanced features may need expertise

    ✅ Best For: SMBs, hybrid enterprises, distributed networks.

    🔗 Try Fortinet here → Fortinet Official Website

    3. Check Point

     ngfw providers
    Check Point

    Why We Picked It

    Check Point is celebrated for best-in-class prevention, integrated management, and modular scalability.

    Its Maestro architecture and SmartConsole UI support ultra-efficient policy management and compliance readiness.

    Trusted globally, Check Point focuses on real-time threat intelligence, easy license expansion, and operational accuracy, setting high standards for regulated industries and multi-layered architectures.

    Specifications

    Check Point offers scalable platforms with throughput up to 1 Tbps, modular interfaces, and unified policies for on-prem and cloud deployments.

    Their firewalls include zero-day attack defense, flexible licensing, and integration with third-party SOCs.

    Features

    Automatic, real-time threat intelligence, deep threat prevention, hyperscale support, API-based integration for automation, comprehensive logging, and lowest false positive rates are notable features.

    Reason to Buy

    Consistent innovation and robust security maturity make Check Point ideal for businesses focused on compliance and operational efficiency.

    Their platform handles multi-cloud, regulated environments with ease.

    Pros

    • Deep threat prevention
    • Modular scalability
    • Integrated policy management

    Cons

    • Premium pricing
    • Complex advanced configuration

    ✅ Best For: Heavily regulated industries, multi-cloud enterprises.

    🔗 Try Check Point here → Check Point Official Website

    4. Cisco Systems

     ngfw providers
    Cisco Systems

    Why We Picked It

    Cisco Secure Firewall delivers seamless integration with Cisco’s network stack, advanced malware defense via AMP, and powerful network visibility positioning it well for enterprises leveraging Cisco infrastructure.

    With unique NGIPS rules and easy AD/ISE/AMP device integration, Cisco streamlines policy enforcement and reduces administrative overhead.

    Cisco’s global threat intelligence (Talos) propels rapid updates and zero-day protection.

    Specifications

    Cisco appliances support flexible deployment (on-prem, cloud, remote), customizable IPS rules, and advanced VPN options, all managed through a unified GUI.

    The platform blends DPI, encrypted traffic analysis, and network discovery for superior visibility.

    Features

    Customizable NGIPS, deep threat intelligence, easy device integration, cloud and remote support, streamlined GUI for policy management, continuous security updates.

    Reason to Buy

    Best suited to Cisco-aligned enterprise networks, offering seamless, efficient integration, rapid threat response, and comprehensive endpoint connectivity.

    Pros

    • Reliable and effective
    • Efficient service
    • Powerful integration options

    Cons

    • Higher hardware and license costs
    • Initial setup can be complex

    ✅ Best For: Enterprises using Cisco infrastructure, multi-site organizations.

    🔗 Try Cisco Systems here → Cisco Systems Official Website

    5. Juniper Networks

    enterprise firewalls
    Juniper Networks

    Why We Picked It

    Juniper Networks NGFWs provide robust multi-layer protection with high performance, scalability, and deep analytics.

    Leveraging advanced threat intelligence, application awareness, and easy-to-use interfaces, Juniper’s SRX Series and cloud integrations serve businesses needing flexible, high-availability defenses.

    Specifications

    Juniper appliances scale from small business deployments to large data center environments, offering application-level inspection, real-time analytics, and comprehensive reporting.

    Deep packet inspection and load balancing ensure both security and uptime.

    Features

    Real-time threat intelligence, dynamic policy management, seamless cloud integration, automated compliance support, application control, high availability, and intuitive management interface.

    Reason to Buy

    Juniper delivers future-proof technology tailored to industry-specific use cases, providing granular control and reliable protection across hybrid and virtualized environments.

    Pros

    • High scalability
    • Advanced threat intelligence
    • User-friendly interface

    Cons

    • Limited integrations for third-party feeds
    • Requires specialized skill for advanced setup

    ✅ Best For: Performance-driven enterprises, industry-specific security requirements.

    🔗 Try Juniper Networks here → Juniper Networks Official Website

    6. Sophos

    enterprise firewalls
    Sophos

    Why We Picked It

    Sophos Firewall leverages cloud-powered AI, deep learning, and zero-day anti-malware capabilities for hyper-effective, low-latency protection.

    Centralized cloud management and automated threat sharing maximize operational efficiency, making Sophos a favorite among organizations with distributed networks and remote workforces.

    Specifications

    Sophos appliances support cloud, SD-WAN, and on-prem deployments, powered by the Xstream architecture to accelerate SaaS and critical application performance.

    Management is unified across endpoints and cloud with real-time analytics and protection.

    Features

    Cloud-based NDR, AI-driven malware prevention, instant blocking of risky URLs, flexible ZTNA integration, SD-WAN orchestration, and granular policy controls.

    Reason to Buy

    Sophos delivers powerful, value-focused protection, with high customer satisfaction ratings for usability, integration, and automated threat response across diverse infrastructures.

    Pros

    • Comprehensive AI analytics
    • Simplified cloud management
    • High user satisfaction

    Cons

    • Some advanced features require cloud connectivity
    • Occasional support delays

    ✅ Best For: Cloud-driven SMBs, distributed enterprises, remote workforces.

    🔗 Try Sophos here → Sophos Official Website

    7. Barracuda Networks

    firewall comparison
    Barracuda Networks

    Why We Picked It

    Barracuda CloudGen Firewall excels in cost-effective, cloud-integrated protection with multi-layered defense against ransomware, DDoS, and web exploits.

    Its remote-access capabilities and centralized management are tailored for MSPs and organizations with distributed teams. Barracuda’s adaptive threat protection delivers rapid response and actionability.

    Specifications

    Barracuda’s firewalls are highly customizable, supporting cloud (Azure, AWS, GCP) and on-premises deployments.

    Real-time and historical reporting, unified remote access, and straightforward dashboard interfaces ease administration.

    Features

    Advanced threat protection, cloud-ready architecture, unified security management, behavioral and sandbox analysis, robust VPN options, DNS sinkholing, and streamlined policy creation.

    Reason to Buy

    Ideal for organizations needing multi-cloud resilience, rapid threat response, and cost-efficient, scalable security for email, web, and network environments.

    Pros

    • Easy customization
    • Strong cloud integration
    • Simple management

    Cons

    • Limited advanced analytics
    • Some features require detailed configuration

    ✅ Best For: Multi-cloud enterprises, MSPs, cost-conscious businesses.

    🔗 Try Barracuda Networks here → Barracuda Networks Official Website

    8. Forcepoint

    firewall comparison
    Forcepoint

    Why We Picked It

    Forcepoint NGFW blends award-winning intelligence-aware protection with SD-WAN, SASE security, and centralized management for large enterprises.

    Its architecture supports high-availability clustering, granular privacy controls, and anti-malware sandboxing.

    Rapid response and centralized policy configuration stand out for managing large, distributed networks.

    Specifications

    Forcepoint offers eight appliance series to fit all organizational sizes, supporting physical, virtual, and cloud deployments.

    The SMC server manages thousands of devices from a single pane, with high-availability and scalable architecture.

    Features

    SD-WAN connectivity, built-in IPS, sandboxing, cloud integration, centralized management, anti-evasion defense, proactive threat intelligence, and seamless SASE inclusion.

    Reason to Buy

    Forcepoint’s easy policy management, high-availability, and award-winning security posture make it suitable for large enterprises, especially those requiring strong compliance and multi-environment cohesion.

    Pros

    • Easy policy management
    • Integrated SD-WAN
    • High availability

    Cons

    • Some integrations are time-consuming
    • License renewal issues reported

    ✅ Best For: Large enterprises, compliance-driven organizations, distributed architecture.

    🔗 Try Forcepoint here → Forcepoint Official Website

    9. Huawei

     advanced threat protection
    Huawei

    Why We Picked It

    Huawei NGFWs deliver high-performance, cost-efficient protection, with advanced prevention, application control, and centralized security management.

    Designed for global scalability and flexible deployment, Huawei is a strong choice for cost-sensitive organizations and those operating in hybrid environments.

    Specifications

    Huawei supports virtualization and cloud integration, with modular deployments for businesses of all sizes.

    The architecture delivers deep packet inspection, advanced threat intelligence, and reliable intrusion prevention without sacrificing speed.

    Features

    Application control, advanced threat prevention, deep threat intelligence, centralized management, flexible deployment options, high availability, automated policy scheduling.

    Reason to Buy

    Best for organizations with Huawei infrastructure or those prioritizing budget, Huawei NGFWs excel at scalable, adaptive protection while keeping operational costs low.

    Pros

    • Cost-effective
    • Intuitive management
    • Consistent performance

    Cons

    • Technical support can be slow
    • Some advanced integrations less robust

    ✅ Best For: Cost-sensitive enterprises, hybrid deployments, Huawei infrastructure.

    🔗 Try Huawei here → Huawei Official Website

    10. WatchGuard

     advanced threat protection
    WatchGuard

    Why We Picked It

    WatchGuard is a user-friendly, feature-rich NGFW with a comprehensive portfolio of security services for small to mid-market businesses and MSPs.

    Their integrated portfolio includes application control, anti-malware sandboxing, secure Wi-Fi, multi-factor authentication, and powerful centralized management.

    Specifications

    WatchGuard appliances come in various form factors, supporting easy cloud integration and centralized management across multiple devices and locations.

    Their Firebox platform is praised for cost-effective reliability and ease of deployment.

    Features

    Integrated intrusion prevention, gateway antivirus, URL filtering, application control, real-time threat intelligence, endpoint protection, secure remote access, and expandable via cloud services.

    Reason to Buy

    WatchGuard excels in usability, efficient management, and strong customer support, making it a top choice for growing businesses needing scalable, user-friendly security.

    Pros

    • Easy to use
    • Efficient service
    • Strong customer support

    Cons

    • Cost of advanced features
    • License renewal confusion

    ✅ Best For: Small and mid-sized businesses, MSPs, user-focused organizations.

    🔗 Try WatchGuard here → WatchGuard Official Website

    Conclusion

    Selecting the right Next‑Generation Firewall provider is critical for robust network security, operational efficiency, and scalable growth in 2025.

    Each of these top ten NGFW solutions offers a distinct blend of threat protection, management features, integration options, and performance that can meet the needs of enterprises, SMBs, and cloud-driven organizations.

    Detailed research into specifications, features, pros, and cons ensures decisions align with specific business requirements and future infrastructure plans.

    The post Top 10 Best Next‑Generation Firewall (NGFW) Providers in 2025 appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has released an urgent security update for Chrome browser users worldwide, addressing four critical vulnerabilities, including one zero-day exploit that is currently being actively exploited in the wild. The company is urging all users to update their browsers immediately to protect against potential attacks. Critical Zero-Day Vulnerability Discovered The most concerning vulnerability in this […]

    The post Google Chrome 0-Day Under Active Attack – Update Immediately appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Dynamic Application Security Testing (DAST) platforms have become fundamental for safeguarding web applications as digital assets and attack surfaces scale in both size and complexity.

    The modern DAST landscape is shaped by increased API adoption, rapid deployment cycles, and the rise of AI-driven vulnerabilities, making 2025 a turning point for intelligent, automated security solutions.

    This article presents a comprehensive and SEO-optimized review of the top 10 DAST platforms for 2025, featuring technical evaluation, clear pros and cons, and direct comparison.

    Web application threats have evolved significantly, with the majority of breaches today resulting from vulnerabilities in running code exposed by dynamic user interactions and APIs.

    DAST platforms are uniquely suited to identify these runtime weaknesses, deliver actionable insights for remediation, and verify security postures across modern environments.

    Why Dynamic Application Security Testing (DAST) Platforms In 2025

    The explosion of cloud-native apps, APIs, and AI services means threats are no longer static new vulnerabilities and misconfigurations rapidly emerge during runtime.

    DAST platforms merge automated, continuous scanning, smart integrations, and threat intelligence, making them indispensable for organizations prioritizing uninterrupted development, regulatory compliance, and risk reduction.

    In 2025, leading tools leverage AI, predictive analytics, and continuous monitoring for superior protection, supporting both traditional web architectures and API-first, microservices environments.

    Comparison Table: Dynamic Application Security Testing (DAST) Platforms In 2025

    Tool Name Verified DASTAPI ScanningCI/CD IntegrationAI CapabilitiesProof-Based Detection
    Invicti✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Acunetix✅ Yes✅ Yes✅ YesLimited✅ Yes
    Burp Suite✅ Yes✅ Yes✅ YesLimited✅ Yes
    Checkmarx✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Rapid7✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Veracode✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    OpenText Fortify✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes
    Intruder✅ Yes✅ Yes✅ YesLimited✅ Yes
    Astra Security✅ Yes✅ Yes✅ YesLimited✅ Yes
    Aikido Security✅ Yes✅ Yes✅ Yes✅ Yes✅ Yes

    1. Invicti

    Best Dynamic Application Security Testing
    Invicti

    Why We Picked It

    Invicti stands out for delivering a DAST-first AppSec platform built for enterprise-scale automation.

    Its proof-based scanning technology ensures exploitability confirmation with industry-leading accuracy, drastically reducing false positives and accelerating remediation.

    AI-powered features surface complex vulnerabilities and prioritize actionable risks through predictive scoring and in-depth technical reports.

    Integration with over 50 developer tools makes Invicti seamless across CI/CD and development pipelines. Native IAST and full API testing covering REST, SOAP, GraphQL, and gRPC ensure coverage of modern architectures.

    The platform merges DAST, API Security, SCA, and ASPM, providing unified risk insights in real time.

    Invicti is ideal for large organizations needing scale, compliance-driven workflows, and measurable security outcomes.

    Specifications

    Invicti supports automated scanning at scale and integrates natively with developer toolchains, CI/CD platforms, and ticketing systems.

    The engine offers predictive risk modeling, technical remediation guidance, and role-based access management for compliance and large teams.

    Scanning covers single-page apps, advanced login mechanisms, and hidden API endpoints.

    Invicti achieves 99.98% vulnerability validation using its proprietary scanner, and is upgradable to include SAST/SCA modules from Mend.io for complete AppSec management.

    Reason to Buy

    Organizations benefit from Invicti’s proof-based results, comprehensive reporting, and regulatory compliance support.

    AI-enhanced vulnerability detection addresses real-world and emerging threats, minimizing manual overhead for AppSec teams.

    Extensive integrations streamline security testing into SDLC workflows, and multi-policy scanning enables tailored risk management across complex environments.

    Features

    Invicti delivers proof-based scanning, predictive analytics, native API testing, 50+ integrations, role-based access control, large-scale scheduling, advanced reporting, compliance mapping, and optional SAST/SCA modules.

    Its continuous learning engine improves detection of novel web and API threats.

    Pros

    • Superior accuracy, minimal false positives
    • Deep coverage including modern web tech and APIs
    • AI-augmented threat prioritization
    • Compliance and audit-ready reporting

    Cons

    • Higher price point for smaller teams
    • Complex initial setup for non-technical operators

    ✅ Best For: Large enterprises, compliance-focused teams, CI/CD workflows

    🔗 Try Invicti here → InvictiOfficial Website

    2. Acunetix

    Best Dynamic Application Security Testing
    Acunetix

    Why We Picked It

    Acunetix delivers powerful DAST and IAST capabilities optimized for SMBs and mid-market organizations needing reliable, granular vulnerability detection.

    Its focus on deep web scanning includes advanced crawling and proof-based findings, reducing false positives and supporting compliance programs.

    The platform is approachable for mid-sized teams, blending automation with fine-tuned scanning logic suitable for both simple and complex web apps.

    Integration options allow Acunetix to fit seamlessly into CI/CD pipelines, while its detailed reports help expedite remediation and compliance documentation.

    Comprehensive training resources and technical support are available for onboarding and skill development.

    Specifications

    Acunetix utilizes dynamic and interactive scanning engines to analyze live web apps, APIs, and password-protected or multi-page forms.

    It includes automated vulnerability management, compliance-ready reporting, and CI/CD integration support. The pricing model supports SMB adoption.

    Its AcuSensor feature provides IAST-like insights identifying more vulnerabilities inside runtime environments compared to pure black-box scanners.

    Reason to Buy

    With proof-based validation and extensive vulnerability coverage, Acunetix efficiently meets compliance and remediation needs for organizations that want certainty in their app security.

    The platform balances configuration granularity with usability, making accurate testing readily accessible for teams without extensive security expertise.

    Features

    Automated scanning, IAST-style proof agent, advanced crawl and API discovery, compliance reporting, customizable dashboard, CI/CD and ticketing integration, and support for OpenAPI3, Swagger2, and RAML APIs.

    Pros

    • Intuitive interface and strong reporting
    • Granular scanning for complex web technologies
    • Good value for SMBs
    • Compliance-specific scan modules

    Cons

    • Multi-domain apps require separate configs
    • Limited AI and automation depth compared to enterprise platforms

    ✅ Best For: SMBs, compliance-driven programs, technical security analysts

    🔗 Try Acunetix here → AcunetixOfficial Website

    3. PortSwigger (Burp Suite)

    best DAST platforms
    PortSwigger (Burp Suite)

    Why We Picked It

    Burp Suite DAST provides scalable enterprise scanning, reputable for minimizing false positives and maximizing operational efficiency across complex portfolios.

    Automation capabilities extend from basic web scanning to continuous and out-of-band testing, targeting web apps, APIs, and advanced login flows.

    Burp’s deep integration into CI/CD and reporting tools supports DevSecOps, and its role-based access model makes it a fit for organizations scaling development and security teams.

    The platform is well-recognized for flexibility, scheduling, and bulk scan operation.

    Specifications

    Server-deployed, accessed via a web interface and REST API, Burp Suite DAST supports extreme scalability and multi-user management.

    Automated scanning modules are configurable for target navigation and privileged areas, including SPAs and API endpoints with OpenAPI, Swagger, and Postman support.

    Advanced scan modes balance depth and speed, with scalable parallel scans across portfolios.

    Reason to Buy

    Burp Suite DAST is a top choice for automated, scheduled scanning needs while delivering robust reporting, compliance, and CI/CD-friendly integration for web application teams.

    Organizations benefit from broad portfolio coverage and operational flexibility.

    Features

    Automated and scalable scanning, API scanning, advanced browser navigation, continuous schedule, CI/CD integration, OAST capabilities, and customizable reporting with broad format support.

    Pros

    • Highly scalable architecture
    • Bulk scheduling and automation
    • Deep API and SPA scan support
    • Industry low false positives

    Cons

    • Steeper learning curve for initial setup
    • Separate licensing needed for some features

    ✅ Best For: Enterprise teams, DevSecOps environments, high-volume scanning

    🔗 Try Burp Suite here → BurpSuiteOfficial Website

    4. Checkmarx

    best DAST platforms
    Checkmarx

    Why We Picked It

    Checkmarx offers a unified security testing experience with effortless setup and actionable insights, making it suitable for both developer-centric and compliance-driven security teams.

    The platform’s integration with AI and ASPM ensures ongoing risk prioritization and the ability to streamline scans into CI/CD pipelines.

    Comprehensive API security and advanced authentication flows set Checkmarx apart for organizations dealing with interconnected web applications.

    The streamlined interface expedites onboarding, offering immediate value through automated configuration and clear vulnerability mapping.

    Specifications

    Checkmarx DAST supports real-time analysis, full SDLC integration, browser-based and automated authentication, API security scanning (REST, SOAP, gRPC), and risk-based vulnerability scoring.

    Compliance mapping and detailed reporting make it suitable for regulated industries.

    Reason to Buy

    Organizations seeking actionable, risk-based insights benefit from Checkmarx’s ability to prioritize and automate discovery and remediation, blending coverage with operational simplicity.

    Features

    Effortless authentication recording, multi-environment API scanning, CI/CD automation, unified compliance mapping, centralized reporting, advanced analytics.

    Pros

    • Unified platform with SAST/DAST
    • Smart authentication and API testing
    • Risk-based prioritization
    • Fast onboarding

    Cons

    • Feature depth may require premium licensing
    • Custom API scan flows require scripting

    ✅ Best For: DevSecOps teams, complex API environments, regulated industries

    🔗 Try Checkmarx here → CheckmarxOfficial Website

    5. Rapid7

    dynamic application security testing tools
    Rapid7

    Why We Picked It

    Rapid7 InsightAppSec reimagines vulnerability management for hybrid and AI-powered applications, integrating threat intelligence with exposure command for context-rich remediation.

    New features include advanced LLM scanning for AI-powered threats, developer-centric reporting, and seamless cloud-to-code visibility.

    Automated pre-production testing extends coverage to internal web apps on closed networks for organizations needing layered security assurance.

    Specifications

    Rapid7 provides black-box testing and universal translation for modern web, mobile, and cloud APIs.

    The platform supports advanced dashboard customization, SOAR integration, and context-driven risk scoring. LLM-specific test modules address prompt injection and AI app risks.

    Reason to Buy

    Organizations deploying both legacy and GenAI-based applications benefit from Rapid7’s focus on new attack surfaces and intelligent remediation workflows that reduce operational overhead

    Features

    Cloud-native architecture, universal translator, LLM security modules, SOAR escalation, hybrid scan engine, customizable reporting.

    Pros

    • AI-powered scanning and risk prioritization
    • Hybrid app and cloud support
    • In-depth developer reporting
    • Integrated exposure and remediation management

    Cons

    • Custom pricing may be costlier for SMBs
    • Feature set may be overwhelming for small teams

    ✅ Best For: Enterprise, cloud-native, and GenAI-powered application security

    🔗 Try Rapid7 here → Rapid7Official Website

    6. Veracode

    dynamic application security testing tools
    Veracode

    Why We Picked It

    Veracode’s cloud-native platform stands out for rapid onboarding, automated scanning, and actionable results with industry-low false positive rates.

    Real-time feedback, flexible scheduling, and granular scan management are ideal for companies needing both depth and scale in their security program.

    The unified dashboard visualizes AppSec status and remediation priorities across dynamic assets and APIs. Integrations allow for continuous security throughout development and deployment.

    Specifications

    Automated DAST and API scanning, multi-environment support, AI-based login script creation, centralized risk dashboard, and compliance reporting.

    Platform scales from single web apps to hundreds of assets across internal and external environments.

    Reason to Buy

    Speed, scalability, and <5% false positive rates make Veracode a reliable choice for security teams needing trusted, automated protection and actionable remediation insights.

    Features

    Cloud-native scan engine, developer-centric feedback, API/endpoint coverage, compliance mapping, multi-faceted insights, flexible scan scheduling.

    Pros

    • Quick start onboarding
    • Low false positive rate
    • Scalable scanning for large portfolios
    • Excellent developer feedback integration

    Cons

    • Advanced features require enterprise licensing
    • Custom reporting may require additional configuration

    ✅ Best For: Large-scale portfolios, automated scan environments, developer security teams

    🔗 Try Veracode here → VeracodeOfficial Website

    7. OpenText (Fortify)

    dynamic application security testing platforms
    OpenText (Fortify)

    Why We Picked It

    OpenText Fortify DAST merges in-depth web application scanning with event-based macro recording and advanced multi-policy scans, suitable for organizations needing flexibility and precision.

    Its intelligent engines customize attacks based on app structure, offering real-time audit and crawl logic.

    Composite settings allow for tailored configurations, marrying traditional and AI-driven assessment across service-oriented architectures.

    Specifications

    Supports composite scan settings, multi-policy scanning, modern authentication flows, expanded gRPC and OpenAPI/YAML API coverage, customizable reporting, and event-driven macro recorder.

    Reason to Buy

    OpenText Fortify’s flexible configuration, advanced multi-service and API scanning, and compliance reporting make it indispensable for teams handling complex or regulated environments.

    Features

    Macro recording, gRPC/REST/SOAP API scan, event-driven configuration, composite scan settings, customizable user agents, multi-format reporting.

    Pros

    • Versatile scan configurations
    • Supports advanced authentication workflows
    • Comprehensive vulnerability database
    • Detailed remediation and prevention guidance

    Cons

    • Complex configuration for new users
    • Premium support required for custom setups

    ✅ Best For: Regulated sectors, APIs, organizations with complex authentication needs

    🔗 Try Fortify here → FortifyOfficial Website

    8. Intruder

    dynamic application security testing platforms
    Intruder

    Why We Picked It

    Intruder delivers automated attack surface management and DAST scanning focusing on simplicity, continuous monitoring, and deep integration with DevOps and issue trackers.

    Combining commercial and open-source engines, it efficiently identifies known vulnerabilities and configuration weaknesses for SMBs and lean security teams.

    Specifications

    Cloud-based, easy-to-configure, integrates with CI/CD and ticketing systems, and offers continuous asset monitoring. Supports authenticated and unauthenticated web app scanning.

    Reason to Buy

    Intruder’s straightforward setup, automated vulnerability scanning, and prioritization make it ideal for smaller organizations or those seeking low-overhead security management.

    Features

    Continuous scanning, asset monitoring, API integration, DevOps pipeline connection, consolidated reporting, multi-engine scan logic.

    Pros

    • Easy to deploy and operate
    • Simple pricing for SMBs
    • High-level automation
    • Reporting for auditors and customers

    Cons

    • Limited advanced and AI features
    • May not scale for large enterprise needs

    ✅ Best For: SMBs, low-overhead teams, automated monitoring

    🔗 Try Intruder here → IntruderOfficial Website

    9. Astra Security

    web application security
    Astra Security

    Why We Picked It

    Astra Security blends automated vulnerability scanning with manual pentesting and AI-first defensive strategies, providing a 360° view of security posture and continuous proactive insights.

    The platform supports more than 10,000 security checks per scan and targets known vulnerabilities as well as custom exploits.

    Specifications

    Intelligent scanner, manual pentest augmentation, real-time reporting, and compliance-driven scan options. Designed to simplify findings interpretation and empower both security experts and business users.

    Reason to Buy

    Astra Security simplifies security for organizations needing actionable, interpretable results and manual expert guidance on top of automated DAST scanning.

    Features

    AI-driven security posture management, automated scanner, manual pentesting support, compliance modules, continuous reporting, proactive defensive checks.

    Pros

    • Hybrid automation/manual approach
    • Continuous defensive scanning
    • Compliance-friendly reporting

    Cons

    • Limited enterprise-scale built-in integrations
    • Full manual pentest coverage may incur extra cost

    ✅ Best For: SMBs, hybrid automation/manual security workflows

    🔗 Try Astra Security here → AstraSecurityOfficial Website

    10. Aikido Security

    web application security
    Aikido Security

    Why We Picked It

    Aikido Security unifies SAST and DAST scanning, offering developer-friendly, context-aware vulnerability identification and AI-powered autofix features.

    It’s designed for “no-nonsense security” that integrates directly with developer workflows (CI/CD, IDEs, GitHub, Slack) and provides one-click remediation for typical findings.

    Automated API discovery, authenticated scans, and actionable advice distinguish the platform for collaborative security teams.

    Specifications

    Cloud-based, auto-remediation engine, GDPR/OWASP risk prioritization, REST/GraphQL API scan, developer tool integrations, continuous scan scheduling.

    Reason to Buy

    Developer-centric organizations benefit from real-time feedback as part of daily workflows, AI-generated fixes, and high accessibility for both lean and enterprise teams.

    Features

    Unified dashboard, context-aware DAST/SAST scans, automated API scan/discovery, authenticated scan, Slack/Email alerts, auto-remediation.

    Pros

    • Instant actionable findings
    • Highly integrated developer experience
    • AI-powered autofix
    • Systematic coverage for APIs and front-end

    Cons

    • Custom enterprise modules may require extra setup
    • Rapid remediation may omit deep manual analysis

    ✅ Best For: Developer teams, CI/CD integration, API-heavy applications

    🔗 Try Aikido Security here → AikidoSecurityOfficial Website

    Conclusion

    Choosing the best DAST platform in 2025 means balancing automation, integration, API and cloud coverage, proof-based validation, and AI-driven insights for sustainable web security.

    Invicti, Acunetix, and Burp Suite deliver enterprise-grade automation and accuracy; Checkmarx and Veracode excel in unified, API-ready workflows; Rapid7 and Fortify add compliance and risk intelligence; Intruder, Astra, and Aikido provide agile, developer-friendly experiences for lean teams.

    As attack surfaces expand, these platforms deliver essential protection for organizations of any scale and digital maturity.

    The post Top 10 Best Dynamic Application Security Testing (DAST) Platforms in 2025 appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has released an emergency security update for its Chrome web browser to address a high-severity zero-day vulnerability that is being actively exploited in the wild.

    Users are strongly urged to update their browsers immediately to protect against potential attacks. The vulnerability, tracked as CVE-2025-10585, is the latest in a series of zero-days discovered and patched in Chrome this year.

    The new stable channel version has been updated to 140.0.7339.185/.186 for Windows and Mac, and 140.0.7339.185 for Linux.

    Google has stated that the update will be rolling out to all users over the coming days and weeks. To mitigate the immediate threat, users should manually trigger the update process to ensure they are protected.

    Zero-Day Vulnerability Exploited

    The actively exploited vulnerability, CVE-2025-10585, is a Type Confusion flaw in the V8 JavaScript and WebAssembly engine.

    Type confusion bugs occur when a program allocates a resource or object using one type but later accesses it with a different, incompatible type. This can lead to logical errors, memory corruption, and ultimately, arbitrary code execution.

    A successful exploit could allow a remote attacker to escape the browser’s security sandbox by tricking a user into visiting a specially crafted, malicious webpage.

    The vulnerability was reported on September 16, 2025, by Google’s own Threat Analysis Group (TAG), which typically finds zero-days being used in targeted attacks by sophisticated threat actors.

    Other Vulnerabilities

    In addition to the zero-day, this security update addresses three other high-severity vulnerabilities discovered by external security researchers.

    The first, CVE-2025-10500, is a use-after-free vulnerability in Dawn, a graphics abstraction layer. The second, CVE-2025-10501, is also a use-after-free flaw, found in the WebRTC component, which enables real-time communication.

    The third vulnerability, CVE-2025-10502, is a heap buffer overflow in ANGLE, a graphics engine translation layer. Use-after-free and heap overflow vulnerabilities can also lead to memory corruption and arbitrary code execution.

    Google has awarded bug bounty payments of $15,000 and $10,000 for the discovery of two of these flaws.

    Given the confirmation of active exploitation, the risk to unpatched systems is significant. All Google Chrome users on Windows, macOS, and Linux are advised to update their browsers to the latest version without delay.

    To check your Chrome version and apply the update, navigate to the “Help” menu and select “About Google Chrome.” The browser will automatically check for and download the latest update, after which a restart will be required to apply the patch.

    Google is currently restricting access to the bug details and links related to CVE-2025-10585 to prevent further abuse while the patch is being rolled out to the majority of its user base.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Google Chrome 0-Day Vulnerability Actively Exploited in the Wild – Patch Now appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The State Department wants to have artificial intelligence agents that can take action for employees, the department's chief information officer Kelly Fletcher said Wednesday. 

    The department already has an enterprise generative-AI chatbot, dubbed StateChat, which it launched last year. That chatbot can help with translations or answer questions from the department's foreign-affairs manual, Fletcher said at an ACT-IAC event Wednesday.

    Now the department is looking at “AI agents that will take actions for humans,” said Fletcher. “I want it to not only tell me, ‘How much leave do I have’ … but then I want it to put in my leave slip, which is in a different system. We're building to that.”

    That action-taking is what distinguishes AI agents from generative AI. It’s something that the AI company Anthropic, behind large language model Claude, is zeroed in on. 

    Co-founder Jack Clark said Monday during a D.C forum that, by the end of 2026 or early 2027, Anthropic expects to build systems that “won’t just passively answer questions,” but can “be given tasks that take hours, days or weeks to complete and then go off and do them autonomously.”

    Although agentic AI offers the potential to help automate operations and increase productivity, the technology also comes with risks, including oversight challenges, difficulties in testing and evaluation and the potential for job displacement. 

    The government’s chief information officer, Greg Barbaccia, has said that he wants to use AI to help make up for losses across the federal workforce as the Trump administration has shed thousands of workers. Among them is State's own former chief data officer and AI officer, Matthew Graviss, who left the department in February after over four years working there.

    Despite AI's potential, Fletcher said that adoption hasn’t necessarily been easy at State.

    The department initially rolled out its chatbot to 3,000 beta testers. Now it is being used by 45,000 to 50,000 of the department’s 80,000 workers, said Fletcher, who noted that “it has taken a huge amount of education and training” to get those users. 

    “One month ago, I answered the question, ‘Is it allowable for me to use it?'” she said. “Something I wildly underestimated with AI is the amount of training and education and conversation required to get folks who would benefit greatly from it to use it.”

    The chatbot can help State employees navigate internal policies.

    “If you need to know how to move your cat with you to Conakry,” she offered as an example, the chatbot will show you “all the locations [in State policies] that explain how to move a cat.”

    “Then we'll let you click on them and read the actual text or give you a summary,” she said. “The idea here is, in large part, to reduce administrative toil.”

    For agents, Fletcher said that her goal is to put the department's administrative functions behind one chatbot and consolidate other potential agents around certain mission sets. 

    “Looking forward, I think that AI is going to be embedded in just about everything,” said Fletcher, offering the potential for AI to prioritize cybersecurity alerts as an example. State is also testing a chatbot to help users navigate its electronic health record patient portal.

    “I think the trick is going to be, 'How do we embed it smartly, and how do we ensure that people know what to use it for?'” she said. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • After the Sept. 10, 2025, assassination of conservative political activist Charlie Kirk, President Donald Trump claimed that radical leftist groups foment political violence in the U.S., and “they should be put in jail.” 

    “The radical left causes tremendous violence,” he said, asserting that “they seem to do it in a bigger way” than groups on the right.

    Top presidential adviser Stephen Miller also weighed in after Kirk’s killing, saying that left-wing political organizations constitute “a vast domestic terror movement.”

    “We are going to use every resource we have…throughout this government to identify, disrupt, dismantle and destroy these networks and make America safe again,” Miller said.

    But policymakers and the public need reliable evidence and actual data to understand the reality of politically motivated violence. From our research on extremism, it’s clear that the president’s and Miller’s assertions about political violence from the left are not based on actual facts. 

    Based on our own research and a review of related work, we can confidently say that most domestic terrorists in the U.S. are politically on the right, and right-wing attacks account for the vast majority of fatalities from domestic terrorism.

    The understanding of political violence is complicated by differences in definitions and the recent Department of Justice removal of an important government-sponsored study of domestic terrorists.

    Political violence in the U.S. has risen in recent months and takes forms that go unrecognized. During the 2024 election cycle, nearly half of all states reported threats against election workers, including social media death threats, intimidation and doxing.

    Kirk’s assassination illustrates the growing threat. The man charged with the murder, Tyler Robinson, allegedly planned the attack in writing and online. 

    This follows other politically motivated killings, including the June assassination of Democratic Minnesota state Rep. and former House Speaker Melissa Hortman and her husband.

    These incidents reflect a normalization of political violence. Threats and violence are increasingly treated as acceptable for achieving political goals, posing serious risks to democracy and society.

    This article relies on some of our research on extremismother academic research, federal reports, academic datasets and other monitoring to assess what is known about political violence. 

    Support for political violence in the U.S. is spreading from extremist fringes into the mainstream, making violent actions seem normal. Threats can move from online rhetoric to actual violence, posing serious risks to democratic practices

    But different agencies and researchers use different definitions of political violence, making comparisons difficult. 

    The FBI and Department of Homeland Security define domestic violent extremism as threats involving actual violence. They do not investigate people in the U.S. for constitutionally protected speech, activism or ideological beliefs. 

    Domestic violent extremism is defined by the FBI and Department of Homeland Security as violence or credible threats of violence intended to influence government policy or intimidate civilians for political or ideological purposes. This general framing, which includes diverse activities under a single category, guides investigations and prosecutions. 

    Datasets compiled by academic researchers use narrower and more operational definitions. The Global Terrorism Database counts incidents that involve intentional violence with political, social or religious motivation. 

    These differences mean that the same incident may or may not appear in a dataset, depending on the rules applied.

    The FBI and Department of Homeland Security emphasize that these distinctions are not merely academic. Labeling an event “terrorism” rather than a “hate crime” can change who is responsible for investigating an incident and how many resources they have to investigate it.

    For example, a politically motivated shooting might be coded as terrorism in federal reporting, cataloged as political violence by the Armed Conflict Location and Event Data Project, and prosecuted as homicide or a hate crime at the state level. 

    Despite differences in definitions, several consistent patterns emerge from available evidence. 

    Politically motivated violence is a small fraction of total violent crime, but its impact is magnified by symbolic targets, timing and media coverage

    In the first half of 2025, 35% of violent events tracked by University of Maryland researchers targeted U.S. government personnel or facilities – more than twice the rate in 2024.

    Right-wing extremist violence has been deadlier than left-wing violence in recent years

    Based on government and independent analyses, right-wing extremist violence has been responsible for the overwhelming majority of fatalities, amounting to approximately 75% to 80% of U.S. domestic terrorism deaths since 2001. 

    Illustrative cases include the 2015 Charleston church shooting, when white supremacist Dylann Roof killed nine Black parishioners; the 2018 Tree of Life synagogue attack in Pittsburgh, where 11 worshippers were murdered; the 2019 El Paso Walmart massacre, in which an anti-immigrant gunman killed 23 people. The 1995 Oklahoma City bombing, an earlier but still notable example, killed 168 in the deadliest domestic terrorist attack in U.S. history.

    By contrast, left-wing extremist incidents, including those tied to anarchist or environmental movements, have made up about 10& to 15% of incidents and less than 5% of fatalities. 

    Examples include the Animal Liberation Front and Earth Liberation Front arson and vandalism campaigns in the 1990s and 2000s, which were more likely to target property rather than people. 

    Violence occurred during Seattle May Day protests in 2016, with anarchist groups and other demonstrators clashing with police. The clashes resulted in multiple injuries and arrests. In 2016, five Dallas police officers were murdered by a heavily armed sniper who was targeting white police officers.

    There’s another reason it’s hard to account for and characterize certain kinds of political violence and those who perpetrate it. 

    The U.S. focuses on prosecuting criminal acts rather than formally designating organizations as terrorist, relying on existing statutes such as conspiracy, weapons violations, RICO provisions and hate crime laws to pursue individuals for specific acts of violence.

    Unlike foreign terrorism, the federal government does not have a mechanism to formally charge an individual with domestic terrorism. That makes it difficult to characterize someone as a domestic terrorist. 

    The State Department’s Foreign Terrorist Organization list applies only to groups outside of the United States. By contrast, U.S. law bars the government from labeling domestic political organizations as terrorist entities because of First Amendment free speech protections. 

    Without harmonized reporting and uniform definitions, the data will not provide an accurate overview of political violence in the U.S.

    But we can make some important conclusions.

    Politically motivated violence in the U.S. is rare compared with overall violent crime. Political violence has a disproportionate impact because even rare incidents can amplify fear, influence policy and deepen societal polarization.

    Right-wing extremist violence has been more frequent and more lethal than left-wing violence. The number of extremist groups is substantial and skewed toward the right, although a count of organizations does not necessarily reflect incidents of violence.

    High-profile political violence often brings heightened rhetoric and pressure for sweeping responses. Yet the empirical record shows that political violence remains concentrated within specific movements and networks rather than spread evenly across the ideological spectrum. Distinguishing between rhetoric and evidence is essential for democracy.

    Trump and members of his administration are threatening to target whole organizations and movements and the people who work in them with aggressive legal measures – to jail them or scrutinize their favorable tax status. But research shows that the majority of political violence comes from people following right-wing ideologies.

    This article is republished from The Conversation under a Creative Commons license. Read the original article.

    The Conversation

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Since early 2025, cybersecurity teams have observed a marked resurgence in operations attributed to MuddyWater, an Iranian state–sponsored advanced persistent threat (APT) actor.

    Emerging initially through broad remote monitoring and management (RMM) exploits, the group has pivoted to highly targeted campaigns employing custom malware backdoors and multi-stage payloads designed to evade detection.

    Rather than relying solely on off-the-shelf tools, the adversary has expanded its arsenal to include bespoke implants such as BugSleep, StealthCache, and the Phoenix backdoor.

    These components work in concert to establish covert footholds, extract sensitive data, and mask infrastructure using commercial services at scale.

    Attack vectors continue to center on spear-phishing emails embedding malicious Microsoft Office documents.

    Threat actor profile (Source – Group-IB)

    Victims receive decoy documents laced with VBA macros that drop and execute secondary payloads from Cloudflare-protected domains.

    Infected hosts then reach out to command-and-control (C2) servers hosted across mainstream and bulletproof providers—ranging from AWS and DigitalOcean to Stark Industries—before shifting communication behind Cloudflare proxies to obscure origin IPs.

    Group-IB analysts noted that Cloudflare’s reverse-proxy service dramatically increases the difficulty of tracking active C2 endpoints, as all traffic appears to originate from shared Cloudflare hosts.

    Initial loader

    Upon execution, the initial loader (commonly named wtsapi32.dll) decrypts and injects the StealthCache backdoor into legitimate processes.

    Infection Chain (Source – Group-IB)

    StealthCache establishes a pseudo-TLV protocol over HTTPS, sending and receiving encrypted commands at endpoint /aq36 and reporting errors at /q2qq32.

    Group-IB analysts identified custom XOR routines that dynamically derive decryption keys from the victim’s device and username strings, thwarting sandbox analysis when executed on mismatched hosts.

    In its latest operational phase, MuddyWater’s multi-stage approach has delivered a trio of payloads: an initial VBA dropper, a loader such as Fooder, and a feature-rich backdoor like StealthCache.

    Upon receiving a command code, StealthCache executes actions ranging from interactive shells to file exfiltration:

    // Decrypt function snippet
    void decrypt_payload(uint8_t *buffer, size_t size, const char *key) {
        for (size_t i = 0; i < size; ++i) {
            buffer[i] ^= key[i % strlen(key)];
        }
    }

    Subsequently, the Phoenix backdoor is deployed from the loader’s memory space. Phoenix registers with its C2 via /register, then periodically posts beacons to /imalive and polls /request for further instructions.

    This modular design enables seamless command updates and payload swaps without writing to disk, reinforcing persistence and minimizing forensic artifacts.

    By leveraging Cloudflare to mask true server endpoints and integrating dynamic decryption keyed to host identifiers, MuddyWater has crafted a resilient, multi-stage infection chain that remains elusive to network defenders.

    Continuous monitoring of Cloudflare-associated domains, alongside vigilant analysis of unique mutex names and C2 URL patterns, is essential for preempting new campaigns and safeguarding critical infrastructure.

    Free live webinar on new malware tactics from our analysts! Learn advanced detection techniques -> Register for Free

    The post MuddyWater Hackers Using Custom Malware With Multi-Stage Payloads and Uses Cloudflare to Mask Fingerprints appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶