امنیت سایبری SOC
327 subscribers
160 photos
10 videos
169 files
212 links
Information about soc , cyber security defence and cyber security news
Download Telegram
امنیت سایبری SOC
Lumma Stealer Malware Delivered via Fake CAPTCHA PDFs A large-scale phishing campaign is using fake CAPTCHA images in malicious PDFs to distribute Lumma Stealer malware, targeting 1,150+ organizations across North America, Southern Europe, and Asia. Hosted…
یک کمپین فیشینگ گسترده با استفاده از تصاویر جعلی CAPTCHA در فایل‌های PDF مخرب، بدافزار Lumma Stealer را توزیع می‌کند و بیش از 1,150 سازمان در آمریکای شمالی، جنوب اروپا و آسیا را هدف قرار داده است.

این PDFها که در Webflow CDN، GoDaddy و Wix میزبانی شده‌اند، هنگام تعامل قربانیان با CAPTCHA، اسکریپت‌های PowerShell را اجرا می‌کنند که منجر به سرقت اطلاعات کاربری و دسترسی از راه دور از طریق بدافزار پروکسی GhostSocks می‌شود.
راهکارهای مقابله:

از دانلود فایل‌های PDF ناشناس خودداری کنید.
با CAPTCHAهای مشکوک و ناخواسته تعامل نداشته باشید.
امنیت سایبری SOC
Lumma Stealer Malware Delivered via Fake CAPTCHA PDFs A large-scale phishing campaign is using fake CAPTCHA images in malicious PDFs to distribute Lumma Stealer malware, targeting 1,150+ organizations across North America, Southern Europe, and Asia. Hosted…
Public indicators:

https[://]booking[.]procedeed-verific[.]com/goo_pdf

https[://]payment-confirmation[.]82736[.]store/pgg46

0419A1942AF24E21F988249DB2C1748509471CCA6B5B7FE9305EAC817C5C4D41

64C9723E61808E95716485B020F24CE3DADFD982E2BF3E94E7EE5E8CED388DC2

71FE618A360C3D077AF47DDB17B35DE5300C94D3F46FB173A039C01D8CA6B86C

7B3BD767FF532B3593E28085940646F145B9F32F2AE97DFA7CDD652A6494257D

8C408B29CBD76F60ECDF703F737408C5C0AE4D87BFA9C43F3307A36DF408122B

AAF43AAB8C08B41682F2B682B05D612651A2B43E235ABC06BB5C4FDE01BF50BE
Security Updates
Account Takeover Vulnerability in ADSelfService Plus (CVE-2025-1723)
The UAE Cyber Security Council has identified a high-severity vulnerability in ManageEngine ADSelfService Plus, a widely used self-service password management and single sign-on (SSO) solution. Organizations utilizing affected versions are advised to apply security updates immediately to mitigate potential risks.
Details
Vulnerability Details • CVE Identifier: CVE-2025-1723
• Severity: High
• Vulnerability Type: Improper Session Handling
• Description:
• The vulnerability arises due to improper session handling in ADSelfService Plus, potentially allowing unauthorized access to user enrollment data.
• If Multi-Factor Authentication (MFA) is not enabled for ADSelfService Plus login, attackers could exploit this flaw to access sensitive user information and potentially compromise accounts.
Affected Products and Services • ADSelfService Plus builds 6510 and earlier
Fixed Versions • ADSelfService Plus build 6511
Mitigation/Workaround • Immediate Upgrade: Update ADSelfService Plus to build 6511 or later to patch the vulnerability.
• Enforce Multi-Factor Authentication (MFA): Enable MFA for ADSelfService Plus logins to reduce the risk of unauthorized access.
• Monitor User Activity: Regularly audit access logs for signs of unauthorized login attempts or unusual user behavior.
References
https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html
Security Updates – Android
Google has issued the Android Security Bulletin for March 2025, addressing multiple high-risk vulnerabilities affecting Android devices. Among these, CVE-2024-43093 and CVE-2024-50302 have been confirmed as actively exploited, posing serious security threats. Organizations and users are urged to apply security updates immediately.
Details
Vulnerability Details Actively Exploited Vulnerabilities
• CVE-2024-43093 – Elevation of Privilege (EoP) in Android Framework
o Affects Google Play system updates
o Exploits a weakness in the Documents UI component
o Could allow attackers to gain elevated privileges and access sensitive user data
• CVE-2024-50302 – Kernel Memory Exposure in Linux Kernel (HID: core)
o Enables unauthorized access to kernel memory
o Exploited in real-world attacks for device compromise and spyware installation
Critical Remote Code Execution (RCE) Vulnerabilities
• CVE-2025-0074, CVE-2025-0075, CVE-2025-0084, CVE-2025-22403, CVE-2025-22408, CVE-2025-22410, CVE-2025-22411, CVE-2025-22412
o Multiple critical RCE vulnerabilities in the Android System
o Allow attackers to execute code remotely without user interaction
o Could be used for malware deployment, device takeover, and data theft
Affected Products and Services • Android 13, 14, and 15
Mitigation/Workaround • Immediate Update: Apply the latest Android security patch (March 2025 update)
• Restrict App Permissions: Minimize excessive app privileges to prevent exploitation
• Monitor Device Activity: Look for unusual behavior, slow performance, or unexpected app installations
• Enable Google Play Protect: Ensure Google Play Protect is active to detect and remove malware
References
https://source.android.com/docs/security/bulletin/2025-03-01
👍1
Malicious Code Found in VSCode Extensions

Microsoft removed two popular VSCode extensions, ‘Material Theme – Free’ and ‘Material Theme Icons – Free,’ after researchers found malicious obfuscated JavaScript capable of stealing credentials. The extensions, installed 9 million+ times, were disabled across all VSCode instances.

IoCs: equinusocio.moxer-theme, equinusocio.vsc-material-theme, equinusocio.vsc-material-theme-icons, equinusocio.vsc-community-material-theme, equinusocio.moxer-icons.

Mitigation: Uninstall affected extensions, review all installed VSCode extensions for anomalies, and ensure dependencies come from trusted sources.
👍1
امنیت سایبری SOC
Malicious Code Found in VSCode Extensions Microsoft removed two popular VSCode extensions, ‘Material Theme – Free’ and ‘Material Theme Icons – Free,’ after researchers found malicious obfuscated JavaScript capable of stealing credentials. The extensions,…
کد مخرب در افزونه‌های VSCode شناسایی شد

مایکروسافت دو افزونه محبوب VSCode با نام‌های "Material Theme – Free" و "Material Theme Icons – Free" را پس از شناسایی جاوا اسکریپت مخرب و مبهم‌سازی‌شده که قادر به سرقت اطلاعات کاربری بود، حذف کرد. این افزونه‌ها بیش از ۹ میلیون بار نصب شده بودند و در تمامی نسخه‌های VSCode غیرفعال شدند.
شاخص‌های نفوذ (IoCs):

equinusocio.moxer-theme
equinusocio.vsc-material-theme
equinusocio.vsc-material-theme-icons
equinusocio.vsc-community-material-theme
equinusocio.moxer-icons

راهکارهای مقابله:

افزونه‌های آلوده را حذف کنید.
تمامی افزونه‌های نصب‌شده در VSCode را برای یافتن موارد مشکوک بررسی کنید.
اطمینان حاصل کنید که وابستگی‌ها (Dependencies) از منابع معتبر دریافت شده‌اند.
👍1
Windows Disk Cleanup Privilege Escalation (CVE-2025-21420)
A high-severity vulnerability in Windows Disk Cleanup Tool (cleanmgr.exe) allows local privilege escalation (LPE) to SYSTEM via DLL sideloading. A proof-of-concept has been published on GitHub, increasing the risk of exploitation.
Mitigation: Apply the February 2025 Patch Tuesday update

Everest Forms Plugin Vulnerability (CVE-2025-1128)
A critical vulnerability has been identified in the Everest Forms WordPress plugin (versions ≤ 3.0.9.4), affecting over 100,000 sites. This flaw allows unauthenticated attackers to upload, read, and delete arbitrary files, potentially leading to full site takeover. ​
Fix: Everest Forms version 3.0.9.5 or later

GitLab XSS Vulnerabilities (CVE-2025-0475 & CVE-2025-0555): High-severity XSS flaws in GitLab CE/EE 15.10–17.9.0 allow JavaScript injection. Fix: Update to 17.9.1, 17.8.4, 17.7.6.

Cisco Nexus Switches DoS (CVE-2025-20111): Denial of Service flaw in Nexus 3100, 3200, 3400, 3600, 9200, 9300, 9400 Series (NX-OS mode).
Fixed Versions: Refer to Cisco bug IDs CSCwj98161 and CSCwk41797 for specific fixed versions.
امنیت سایبری SOC
Windows Disk Cleanup Privilege Escalation (CVE-2025-21420) A high-severity vulnerability in Windows Disk Cleanup Tool (cleanmgr.exe) allows local privilege escalation (LPE) to SYSTEM via DLL sideloading. A proof-of-concept has been published on GitHub, increasing…
### مجموعه آسیب‌پذیری‌های امنیتی جدید

#### ۱. افزایش سطح دسترسی در Windows Disk Cleanup (CVE-2025-21420)
یک آسیب‌پذیری با شدت بالا در ابزار Windows Disk Cleanup (cleanmgr.exe) امکان افزایش سطح دسترسی محلی (LPE) به SYSTEM را از طریق DLL Sideloading فراهم می‌کند. انتشار PoC در GitHub خطر بهره‌برداری را افزایش داده است.
✅ راهکار: به‌روزرسانی Patch Tuesday فوریه ۲۰۲۵ را اعمال کنید.

---
#### ۲. آسیب‌پذیری در افزونه Everest Forms (CVE-2025-1128)
یک آسیب‌پذیری بحرانی در افزونه Everest Forms برای وردپرس (نسخه‌های ≤ 3.0.9.4) شناسایی شده که بیش از ۱۰۰,۰۰۰ سایت را تحت تأثیر قرار می‌دهد. این نقص به مهاجمان غیرمجاز اجازه می‌دهد تا فایل‌های دلخواه را آپلود، خوانده و حذف کنند که می‌تواند به تسلط کامل بر سایت منجر شود.
✅ راهکار: به‌روزرسانی به نسخه Everest Forms 3.0.9.5 یا جدیدتر.

---
#### ۳. آسیب‌پذیری‌های XSS در GitLab (CVE-2025-0475 & CVE-2025-0555)
دو آسیب‌پذیری با شدت بالا از نوع XSS در GitLab CE/EE نسخه‌های 15.10 تا 17.9.0 شناسایی شده که به مهاجمان امکان تزریق جاوا اسکریپت را می‌دهد.
✅ راهکار: به‌روزرسانی به نسخه‌های 17.9.1، 17.8.4، 17.7.6.

---
#### ۴. آسیب‌پذیری DoS در سوئیچ‌های Cisco Nexus (CVE-2025-20111)
یک آسیب‌پذیری Denial of Service (DoS) در سوئیچ‌های Cisco Nexus 3100، 3200، 3400، 3600، 9200، 9300، 9400 (NX-OS mode) شناسایی شده است.
✅ راهکار: برای نسخه‌های اصلاح‌شده به Bug IDهای CSCwj98161 و CSCwk41797 در سایت سیسکو مراجعه کنید.
👍1
محققان Forescout یک گروه جدید باج‌افزار را شناسایی کرده‌اند که با نام Mora_001 شناخته می‌شود. این گروه با سوءاستفاده از دو آسیب‌پذیری بحرانی در محصولات Fortinet، به‌صورت غیرمجاز به فایروال‌ها دسترسی پیدا کرده و سپس یک ابزار رمزگذاری سفارشی به نام SuperBlack را اجرا می‌کند.

این دو آسیب‌پذیری شامل دور زدن احراز هویت هستند و با شناسه‌های CVE-2024-55591 (امتیاز CVSS: 9.8) و CVE-2025-24472 (امتیاز CVSS: 8.1) ثبت شده‌اند. Fortinet این نقص‌ها را در ژانویه 2025 به‌صورت عمومی افشا کرد. درحالی‌که CVE-2024-55591 بلافاصله به‌عنوان یک آسیب‌پذیری در حال بهره‌برداری شناخته شد، CVE-2025-24472 در ابتدا باعث سردرگمی شد—Fortinet ابتدا بهره‌برداری از آن را رد کرد اما بعداً تأیید کرد که این آسیب‌پذیری مورد سوءاستفاده قرار گرفته است.

Forescout برای اولین بار حملات مرتبط با SuperBlack را در اواخر ژانویه 2025 مشاهده کرد و تأیید نمود که هکرها از آسیب‌پذیری CVE-2025-24472 سوءاستفاده کرده‌اند. پس از این کشف، Fortinet توصیه‌نامه امنیتی خود را به‌روزرسانی کرد و بهره‌برداری فعال از این آسیب‌پذیری را تأیید نمود.
نحوه اجرای حملات SuperBlack:

دسترسی اولیه و افزایش سطح دسترسی:
مهاجمان ابتدا با انجام حملات jsconsole مبتنی بر WebSocket یا ارسال درخواست‌های HTTPS دستکاری‌شده به رابط فایروال، سطح دسترسی خود را به "super_admin" افزایش می‌دهند.
حرکت در شبکه و سرقت اطلاعات:
پس از دسترسی، مهاجمان شبکه را اسکن کرده و اطلاعات حساس مانند اعتبارنامه‌های VPN، WMI، SSH و TACACS+/RADIUS را سرقت می‌کنند.
آن‌ها سپس به‌صورت جانبی در زیرساخت هدف حرکت می‌کنند.
رمزگذاری داده‌ها و حذف ردپاها:
قبل از رمزگذاری فایل‌ها، مهاجمان داده‌های حساس را استخراج می‌کنند.
پس از استخراج داده‌ها، آن‌ها فرایند رمزگذاری را آغاز کرده و سپس ابزار WipeBlack را اجرا می‌کنند تا ردپاهای فعالیت رمزگذاری را پاک کنند و تحقیقات پزشکی قانونی را مختل نمایند.

ارتباط SuperBlack با عملیات LockBit

شواهد اولیه نشان می‌دهد که باج‌افزار SuperBlack به‌شدت با عملیات LockBit مرتبط است:

SuperBlack بر اساس کد منبع فاش‌شده‌ی LockBit 3.0 ساخته شده است.
آدرس‌های IP مورد استفاده در حملات Mora_001 با کمپین‌های قبلی LockBit همپوشانی دارند.
ابزار WipeBlack قبلاً در حملات مرتبط با LockBit مانند BrainCipher، EstateRansomware و SenSayQ شناسایی شده است.

این یافته‌ها نشان می‌دهد که ممکن است بین گروه Mora_001 و اعضای سابق یا همکاران کلیدی LockBit ارتباطی وجود داشته باشد.
👍2
Storm-1865 Phishing Campaign Targets Booking.com
The Storm-1865 phishing campaign is impersonating Booking.com, using ClickFix social engineering to trick victims into executing malware manually via the Windows Run command. Attackers send fake Booking.com emails referencing guest reviews, account verifications, and payment issues, leading to a phishing page with a fake CAPTCHA that prompts users to copy and run a malicious command. This results in the execution of credential-stealing malware, including XWorm, Lumma Stealer, VenomRAT, AsyncRAT, Danabot, and NetSupport RAT, facilitating financial fraud and data theft. Storm-1865 has evolved from targeting hotel guests (2023) and e-commerce buyers (2024) to now leveraging more deceptive tactics like ClickFix to bypass traditional security controls.