🛑 آسیبپذیری DoS در Apache Tomcat (CVE-2025-31650)
نقصی با شدت بالا در Apache Tomcat به مهاجمان این امکان را میدهد که با ارسال هدرهای نادرست HTTP Priority، حملهی انکار سرویس (DoS) انجام دهند.
🔹 علت: اعتبارسنجی نادرست ورودی ← نشت حافظه ← خطای OutOfMemoryException
🔸 نسخههای آسیبپذیر:
Tomcat 9.0.76 تا 9.0.102
Tomcat 10.1.10 تا 10.1.39
Tomcat 11.0.0-M2 تا 11.0.5
✅ راهکار: ارتقاء به نسخههای 9.0.104، 10.1.40 یا 11.0.6
🐞 آسیبپذیری اجرای کد از راه دور در Apache Parquet Java (CVE-2025-46762)
نقصی با شدت بالا در کتابخانه parquet-avro به مهاجمان اجازه میدهد که با وارد کردن بار مخرب در metadata فایل Parquet، کد دلخواه خود را از راه دور اجرا کنند.
🔸 نسخههای آسیبپذیر: Apache Parquet Java نسخه ۱.۱۵.۱ و پایینتر، هنگام استفاده از مدلهای Avro بهصورت "specific" یا "reflect"
✅ راهکار: ارتقاء به نسخه 1.15.2
🦊 بهروزرسانیهای امنیتی Mozilla
وصلههای امنیتی برای مرورگر Firefox و برنامه Thunderbird منتشر شدهاند که آسیبپذیریهای زیر را برطرف میکنند:
CVE-2025-2817: ارتقاء سطح دسترسی از طریق بهروزرسان
CVE-2025-4083: فرار از sandbox با استفاده از URI نوع javascript
CVE-2025-4084: تزریق دستور از طریق قابلیت “Copy as cURL” در ویندوز
CVE-2025-4091 تا 4093: نقصهای ایمنی حافظه که ممکن است به اجرای کد از راه دور منجر شوند
✅ راهکار: بهروزرسانی به نسخههای Firefox 138، ESR 128.10 یا Thunderbird 138
🌐 بهروزرسانی امنیتی Google Chrome
در نسخه ۱۳۶ مرورگر Chrome، هشت آسیبپذیری امنیتی اصلاح شدهاند. برخی از مهمترین آنها عبارتند از:
CVE-2025-4096 (شدید): سرریز بافر heap که میتواند منجر به اجرای کد از راه دور شود
CVE-2025-4050 / 4051 / 4052: مشکلات مربوط به حافظه و اعتبارسنجی در ابزارهای توسعه (DevTools)
✅ نسخههای اصلاحشده:
• ویندوز / مک: 136.0.7103.48 / 49
• لینوکس: 136.0.7103.59
• اندروید: 136.0.7103.60
• iOS: 136.0.7103.56
نقصی با شدت بالا در Apache Tomcat به مهاجمان این امکان را میدهد که با ارسال هدرهای نادرست HTTP Priority، حملهی انکار سرویس (DoS) انجام دهند.
🔹 علت: اعتبارسنجی نادرست ورودی ← نشت حافظه ← خطای OutOfMemoryException
🔸 نسخههای آسیبپذیر:
Tomcat 9.0.76 تا 9.0.102
Tomcat 10.1.10 تا 10.1.39
Tomcat 11.0.0-M2 تا 11.0.5
✅ راهکار: ارتقاء به نسخههای 9.0.104، 10.1.40 یا 11.0.6
🐞 آسیبپذیری اجرای کد از راه دور در Apache Parquet Java (CVE-2025-46762)
نقصی با شدت بالا در کتابخانه parquet-avro به مهاجمان اجازه میدهد که با وارد کردن بار مخرب در metadata فایل Parquet، کد دلخواه خود را از راه دور اجرا کنند.
🔸 نسخههای آسیبپذیر: Apache Parquet Java نسخه ۱.۱۵.۱ و پایینتر، هنگام استفاده از مدلهای Avro بهصورت "specific" یا "reflect"
✅ راهکار: ارتقاء به نسخه 1.15.2
🦊 بهروزرسانیهای امنیتی Mozilla
وصلههای امنیتی برای مرورگر Firefox و برنامه Thunderbird منتشر شدهاند که آسیبپذیریهای زیر را برطرف میکنند:
CVE-2025-2817: ارتقاء سطح دسترسی از طریق بهروزرسان
CVE-2025-4083: فرار از sandbox با استفاده از URI نوع javascript
CVE-2025-4084: تزریق دستور از طریق قابلیت “Copy as cURL” در ویندوز
CVE-2025-4091 تا 4093: نقصهای ایمنی حافظه که ممکن است به اجرای کد از راه دور منجر شوند
✅ راهکار: بهروزرسانی به نسخههای Firefox 138، ESR 128.10 یا Thunderbird 138
🌐 بهروزرسانی امنیتی Google Chrome
در نسخه ۱۳۶ مرورگر Chrome، هشت آسیبپذیری امنیتی اصلاح شدهاند. برخی از مهمترین آنها عبارتند از:
CVE-2025-4096 (شدید): سرریز بافر heap که میتواند منجر به اجرای کد از راه دور شود
CVE-2025-4050 / 4051 / 4052: مشکلات مربوط به حافظه و اعتبارسنجی در ابزارهای توسعه (DevTools)
✅ نسخههای اصلاحشده:
• ویندوز / مک: 136.0.7103.48 / 49
• لینوکس: 136.0.7103.59
• اندروید: 136.0.7103.60
• iOS: 136.0.7103.56
SentinelOne Bypass & Babuk Ransomware Deployment
Security researchers at Aon’s Stroz Friedberg Incident Response team have discovered a new EDR evasion technique targeting SentinelOne, enabling the deployment of Babuk ransomware by exploiting the SentinelOne agent upgrade mechanism.
This method—dubbed “Bring Your Own Installer”—uses legitimate SentinelOne installers to disable endpoint protection without admin console access, leaving systems exposed to ransomware attacks.
Attack Detail:
Technique: “Bring Your Own Installer”
Targeted Product: SentinelOne EDR
Ransomware Deployed: Babuk (RaaS)
Attack Chain:
1. Method: Abuse of legitimate SentinelOne agent MSI installer
1. Steps:
1. Attacker gains local admin access by exploiting a known vulnerability in a public-facing service.
1. Deploys legitimate SentinelOne installer (e.g., SentinelInstaller_windows_64bit_v23_4_6_347.msi).
1. Installer halts SentinelOne processes.
1. Attacker executes taskkill on msiexec.exe before EDR reinstalls.
1. SentinelOne remains inactive — endpoint appears “offline” in management console.
1. Ransomware Deployed: Babuk
1. Persistence Observed: No use of malicious drivers; relies solely on trusted installer behavior.
1. Forensic Indicators
• SentinelOne Logs: EventID 93 with CommandType: unload
• Application Logs: EventID 1042 from MsiInstaller
• No SentinelOne services observed running post-execution
Screenshots
Mitigation/workaround SentinelOne Response:
SentinelOne has confirmed the issue and recommends enabling a specific policy to prevent this bypass.
Recommended Actions:
• Enable the Online Authorization feature in SentinelOne policies to block local agent upgrades or downgrades without console approval.
• Monitor for version anomalies and unexpected SentinelOne installer activity.
• Audit event logs for termination of SentinelOne processes and Windows Installer during upgrades.
• Restrict local administrative access on exposed systems.
• Apply timely patches to prevent exploitation via public vulnerabilities.
References
https://cybersecuritynews.com/threat-actor-bypass-sentinelone-edr/
https://gbhackers.com/threat-actor-evades-sentinelone-edr/
Security researchers at Aon’s Stroz Friedberg Incident Response team have discovered a new EDR evasion technique targeting SentinelOne, enabling the deployment of Babuk ransomware by exploiting the SentinelOne agent upgrade mechanism.
This method—dubbed “Bring Your Own Installer”—uses legitimate SentinelOne installers to disable endpoint protection without admin console access, leaving systems exposed to ransomware attacks.
Attack Detail:
Technique: “Bring Your Own Installer”
Targeted Product: SentinelOne EDR
Ransomware Deployed: Babuk (RaaS)
Attack Chain:
1. Method: Abuse of legitimate SentinelOne agent MSI installer
1. Steps:
1. Attacker gains local admin access by exploiting a known vulnerability in a public-facing service.
1. Deploys legitimate SentinelOne installer (e.g., SentinelInstaller_windows_64bit_v23_4_6_347.msi).
1. Installer halts SentinelOne processes.
1. Attacker executes taskkill on msiexec.exe before EDR reinstalls.
1. SentinelOne remains inactive — endpoint appears “offline” in management console.
1. Ransomware Deployed: Babuk
1. Persistence Observed: No use of malicious drivers; relies solely on trusted installer behavior.
1. Forensic Indicators
• SentinelOne Logs: EventID 93 with CommandType: unload
• Application Logs: EventID 1042 from MsiInstaller
• No SentinelOne services observed running post-execution
Screenshots
Mitigation/workaround SentinelOne Response:
SentinelOne has confirmed the issue and recommends enabling a specific policy to prevent this bypass.
Recommended Actions:
• Enable the Online Authorization feature in SentinelOne policies to block local agent upgrades or downgrades without console approval.
• Monitor for version anomalies and unexpected SentinelOne installer activity.
• Audit event logs for termination of SentinelOne processes and Windows Installer during upgrades.
• Restrict local administrative access on exposed systems.
• Apply timely patches to prevent exploitation via public vulnerabilities.
References
https://cybersecuritynews.com/threat-actor-bypass-sentinelone-edr/
https://gbhackers.com/threat-actor-evades-sentinelone-edr/
Cyber Security News
Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware
A sophisticated new attack method that disables endpoint security protection has been identified by security researchers.
🔥1
افزونه مخرب وردپرس که خود را بهعنوان ابزار ضد بدافزار معرفی میکند
نمونهای از بدافزار با نام WP-antymalwary-bot.php شناسایی شده که سایتهای وردپرس را هدف قرار داده و در ظاهر، به شکل یک افزونه قانونی ظاهر میشود. این بدافزار که توسط تیم Wordfence کشف شده است، امکان دسترسی غیرمجاز به سطح مدیر، اجرای کد از راه دور از طریق REST API، و آلودگی مجدد مداوم با استفاده از wp-cron.php را فراهم میسازد.
🔸 این بدافزار از نامهای فایل مبهمشده مانند addons.php و scr.php استفاده میکند و یک ورود اضطراری از پیش تعریفشده (hardcoded) برای ربودن حسابهای مدیر دارد.
🔹 علاوه بر این، کدهای جاوااسکریپت مخرب را به قالب سایت تزریق میکند، با سرور فرماندهی (C2) در آدرس 45.61[.]136.85 ارتباط برقرار مینماید و حتی پس از حذف، خودش را دوباره نصب میکند.
🛡 راهکارهای مقابله:
اسکن کامل افزونهها برای شناسایی موارد مشکوک
بررسی و پاکسازی فایل wp-cron.php
حذف فایلهای آلوده
بازیابی از بکآپهای مطمئن
تغییر رمزهای عبور مدیر سایت
✅ امضایهای فایروال مربوط به این تهدید از سوی Wordfence ارائه شده و قابل استفاده برای شناسایی است.
نمونهای از بدافزار با نام WP-antymalwary-bot.php شناسایی شده که سایتهای وردپرس را هدف قرار داده و در ظاهر، به شکل یک افزونه قانونی ظاهر میشود. این بدافزار که توسط تیم Wordfence کشف شده است، امکان دسترسی غیرمجاز به سطح مدیر، اجرای کد از راه دور از طریق REST API، و آلودگی مجدد مداوم با استفاده از wp-cron.php را فراهم میسازد.
🔸 این بدافزار از نامهای فایل مبهمشده مانند addons.php و scr.php استفاده میکند و یک ورود اضطراری از پیش تعریفشده (hardcoded) برای ربودن حسابهای مدیر دارد.
🔹 علاوه بر این، کدهای جاوااسکریپت مخرب را به قالب سایت تزریق میکند، با سرور فرماندهی (C2) در آدرس 45.61[.]136.85 ارتباط برقرار مینماید و حتی پس از حذف، خودش را دوباره نصب میکند.
🛡 راهکارهای مقابله:
اسکن کامل افزونهها برای شناسایی موارد مشکوک
بررسی و پاکسازی فایل wp-cron.php
حذف فایلهای آلوده
بازیابی از بکآپهای مطمئن
تغییر رمزهای عبور مدیر سایت
✅ امضایهای فایروال مربوط به این تهدید از سوی Wordfence ارائه شده و قابل استفاده برای شناسایی است.
malicious drivers hash.txt
55 KB
هش های درایورهای آلوده -حتما اینا رو توی لاگ های سازمان تون جستجو کنید
امنیت سایبری SOC
https://raw.githubusercontent.com/magicsword-io/LOLDrivers/refs/heads/main/detections/hashes/samples_vulnerable.sha1
این هش های درایورها رو سیگما رول هم داره
یکی اومده پنل های لاک بیت رو هک کرده و توش چت یه ایرانی هم بوده :
[2025-04-14 05:29:13] I want to be completely honest with you: I don't have access to any international banking systems. I don't have a foreign account, and I can't legally buy cryptocurrency like Bitcoin in my country. I live in Iran, and we are under heavy sanctions. Our currency the Toman has lost almost all its value. Even earning just a small amount of BTC is a nearly impossible task here.
I'm not a business owner with income in dollars or euros. I'm just an individual who has lost everything 20 servers gone. What you are asking for is simply beyond my means, even with a discount. If there was a way to pay in Toman, I could try to gather something, but I know it may not be useful to you.
Please, I am desperate. I'm not trying to avoid responsibility I just need a chance to recover even part of what I've lost. If you can reduce the amount to something that someone like me could possibly afford, I will do everything I can to make it happen.
This is my last hope. I'm asking not as a company or target just as a human being.
GitHub
Criminal-Leaks/Lockbit/Timestamped_LB_Chats.txt at main · D4RK-R4BB1T/Criminal-Leaks
Lockbit, URSIF, BlackBasta etc. Contribute to D4RK-R4BB1T/Criminal-Leaks development by creating an account on GitHub.
امنیت سایبری SOC
اینجا یه سری کویری های آماده داره sentinel microsoft که میشه برای شکار تهدیدات استفاده کرد 💫
این کویری ها رو میتونیم خودمون هم بنویسیم ،هر کویری ای که برای شکار تهدیدات میخوایم
VMware Aria Automation XSS (CVE-2025-22249)
A high-severity DOM-based Cross-Site Scripting (XSS) vulnerability in VMware Aria Automation could allow attackers to steal access tokens from authenticated users by luring them into clicking a specially crafted URL.
Affected: Aria Automation < 8.18.1 Patch 2, Cloud Foundation (refer KB394224), Telco Cloud Platform < 8.18.1 Patch 2 Fix: Upgrade to 8.18.1 Patch 2
VMware Tools Insecure File Handling Vulnerability (CVE-2025-22247)
A medium-severity vulnerability in VMware Tools allows local file tampering by malicious users with non-admin privileges on guest VMs.
Affected Versions: VMware Tools 12.x.x and 11.x.x Fix: Upgrade to VMware Tools 12.5.2 or later
macOS sips ICC RCE (CVE-2024-44236)
A critical memory corruption flaw in Apple’s sips tool allows arbitrary code execution via malformed ICC profile files.
Affected: macOS systems using sips (default in all versions prior to macOS 15.0.1)
Fix: Upgrade to macOS 15.0.1 or later
Cisco IOS XE WLC RCE (CVE-2025-20188)
A critical vulnerability in Cisco IOS XE Wireless LAN Controllers (WLC) allows unauthenticated remote attackers to upload files and execute commands with root privileges, leading to full device takeover.
Affected: Catalyst 9800 Series (Cloud, Embedded, Standalone), Embedded WLC on Catalyst Aps
Fix: Apply Cisco’s latest IOS XE WLC firmware
A high-severity DOM-based Cross-Site Scripting (XSS) vulnerability in VMware Aria Automation could allow attackers to steal access tokens from authenticated users by luring them into clicking a specially crafted URL.
Affected: Aria Automation < 8.18.1 Patch 2, Cloud Foundation (refer KB394224), Telco Cloud Platform < 8.18.1 Patch 2 Fix: Upgrade to 8.18.1 Patch 2
VMware Tools Insecure File Handling Vulnerability (CVE-2025-22247)
A medium-severity vulnerability in VMware Tools allows local file tampering by malicious users with non-admin privileges on guest VMs.
Affected Versions: VMware Tools 12.x.x and 11.x.x Fix: Upgrade to VMware Tools 12.5.2 or later
macOS sips ICC RCE (CVE-2024-44236)
A critical memory corruption flaw in Apple’s sips tool allows arbitrary code execution via malformed ICC profile files.
Affected: macOS systems using sips (default in all versions prior to macOS 15.0.1)
Fix: Upgrade to macOS 15.0.1 or later
Cisco IOS XE WLC RCE (CVE-2025-20188)
A critical vulnerability in Cisco IOS XE Wireless LAN Controllers (WLC) allows unauthenticated remote attackers to upload files and execute commands with root privileges, leading to full device takeover.
Affected: Catalyst 9800 Series (Cloud, Embedded, Standalone), Embedded WLC on Catalyst Aps
Fix: Apply Cisco’s latest IOS XE WLC firmware
کمپین APT گروه Kimsuky با استفاده از فایلهای LNK تسلیحشده
گروه APT تحت حمایت دولت کره شمالی با نام Kimsuky (که با نامهای Black Banshee یا APT43 نیز شناخته میشود)، عملیاتهای جاسوسی سایبری خود را با اجرای کمپینهای فیشینگ پیشرفته تشدید کرده است. این کمپینها معمولاً با پیوست فایلهای ZIP آغاز میشوند که حاوی فایلهای میانبر مخرب با پسوند .lnk هستند.
وقتی این فایلهای LNK اجرا میشوند، اسکریپتهای VBScript یا PowerShell مبهمسازیشدهای را فعال میکنند که برای جمعآوری اطلاعات سیستم، ایجاد ماندگاری از طریق تسکهای زمانبندیشده و دانلود بارهای مخرب اضافی از پلتفرمهای معتبری مانند Dropbox طراحی شدهاند.
گروه APT تحت حمایت دولت کره شمالی با نام Kimsuky (که با نامهای Black Banshee یا APT43 نیز شناخته میشود)، عملیاتهای جاسوسی سایبری خود را با اجرای کمپینهای فیشینگ پیشرفته تشدید کرده است. این کمپینها معمولاً با پیوست فایلهای ZIP آغاز میشوند که حاوی فایلهای میانبر مخرب با پسوند .lnk هستند.
وقتی این فایلهای LNK اجرا میشوند، اسکریپتهای VBScript یا PowerShell مبهمسازیشدهای را فعال میکنند که برای جمعآوری اطلاعات سیستم، ایجاد ماندگاری از طریق تسکهای زمانبندیشده و دانلود بارهای مخرب اضافی از پلتفرمهای معتبری مانند Dropbox طراحی شدهاند.
کمپین بدافزار PupkinStealer
بدافزار PupkinStealer یک ابزار سرقت اطلاعات مبتنی بر .NET است که به یک بازیگر تهدید با نام مستعار "Ardent" نسبت داده میشود و از آوریل ۲۰۲۵ فعال بوده است. این بدافزار معمولاً از طریق مهندسی اجتماعی، ایمیلهای فیشینگ، یا دانلودهای مخرب که بهصورت برنامههای قانونی یا نرمافزارهای کرکشده جعلی ظاهر میشوند، توزیع میگردد.
پس از اجرا، این فایل اجرایی ۳۲ بیتی مخصوص ویندوز اطلاعات زیر را هدف قرار میدهد:
اعتبارنامههای ذخیرهشده مرورگرها
دادههای نشست در پیامرسانهای Telegram و Discord
فایلهای موجود در دسکتاپ
تصاویر اسکرینشات از سیستم کاربر
این اطلاعات از طریق Telegram Bot API به مهاجم ارسال میشوند.
PupkinStealer برای سرقت رمزهای عبور مرورگر از الگوریتم رمزنگاری AES-GCM استفاده کرده و پوشههای .tdata را برای ربودن حساب تلگرام کپی میکند. همچنین برای یافتن فایلهایی با پسوند .pdf، .txt و .jpg سیستم را اسکن میکند.
این بدافزار دارای ویژگیهای پیشرفتهای مانند ماندگاری یا مبهمسازی پیچیده نیست، اما با تکیه بر کد ماژولار نوشتهشده با C# و عملکرد پنهانکارانه خود عمل میکند.
اقدامات پیشگیرانه:
آموزش کاربران برای جلوگیری از آلودگی
مسدودسازی دسترسی به API تلگرام
اجرای سیاستهای حداقل دسترسی (Least-Privilege)
بدافزار PupkinStealer یک ابزار سرقت اطلاعات مبتنی بر .NET است که به یک بازیگر تهدید با نام مستعار "Ardent" نسبت داده میشود و از آوریل ۲۰۲۵ فعال بوده است. این بدافزار معمولاً از طریق مهندسی اجتماعی، ایمیلهای فیشینگ، یا دانلودهای مخرب که بهصورت برنامههای قانونی یا نرمافزارهای کرکشده جعلی ظاهر میشوند، توزیع میگردد.
پس از اجرا، این فایل اجرایی ۳۲ بیتی مخصوص ویندوز اطلاعات زیر را هدف قرار میدهد:
اعتبارنامههای ذخیرهشده مرورگرها
دادههای نشست در پیامرسانهای Telegram و Discord
فایلهای موجود در دسکتاپ
تصاویر اسکرینشات از سیستم کاربر
این اطلاعات از طریق Telegram Bot API به مهاجم ارسال میشوند.
PupkinStealer برای سرقت رمزهای عبور مرورگر از الگوریتم رمزنگاری AES-GCM استفاده کرده و پوشههای .tdata را برای ربودن حساب تلگرام کپی میکند. همچنین برای یافتن فایلهایی با پسوند .pdf، .txt و .jpg سیستم را اسکن میکند.
این بدافزار دارای ویژگیهای پیشرفتهای مانند ماندگاری یا مبهمسازی پیچیده نیست، اما با تکیه بر کد ماژولار نوشتهشده با C# و عملکرد پنهانکارانه خود عمل میکند.
اقدامات پیشگیرانه:
آموزش کاربران برای جلوگیری از آلودگی
مسدودسازی دسترسی به API تلگرام
اجرای سیاستهای حداقل دسترسی (Least-Privilege)
F5 BIG-IP Command Injection Vulnerability – CVE-2025-31644
A newly disclosed high-severity vulnerability, CVE-2025-31644, affects F5 BIG-IP devices operating in Appliance mode. This vulnerability allows authenticated administrative users to execute arbitrary Bash commands as root, bypassing appliance-mode shell restrictions. A public proof-of-concept (PoC) is available, significantly increasing the likelihood of exploitation.
Details
Vulnerability Details
• CVE ID: CVE-2025-31644
• Severity: High
• Type: Authenticated command injection
• Attack Vector: Exploited via the file parameter in the save command through:
o iControl REST API (/mgmt)
o TMSH CLI (via SSH)
• Impact: Root command execution, bypass of shell restrictions, full system compromise
Impacted Versions
This vulnerability affects the following F5 BIG-IP versions:
• Version 17.x from 17.1.0 to 17.1.2
• Version 16.x from 16.1.0 to 16.1.5
• Version 15.x from 15.1.0 to 15.1.10
These issues are fixed in:
• Version 17.1.2.2 or later
• Version 16.1.6 or later
• Version 15.1.10.7 or later
Mitigation/workaround
• Patch Immediately: Upgrade affected systems to the latest fixed versions.
• Restrict Administrative Access: Ensure access is limited to trusted networks or controlled through secure jump hosts.
• Monitor Logs: Review system logs for unusual or suspicious usage of the save command or REST API activity involving abnormal file parameters.
• Harden Environment: Follow F5's hardening guides and disable unnecessary administrative interfaces if not in use.
References
https://my.f5.com/manage/s/article/K000148591
A newly disclosed high-severity vulnerability, CVE-2025-31644, affects F5 BIG-IP devices operating in Appliance mode. This vulnerability allows authenticated administrative users to execute arbitrary Bash commands as root, bypassing appliance-mode shell restrictions. A public proof-of-concept (PoC) is available, significantly increasing the likelihood of exploitation.
Details
Vulnerability Details
• CVE ID: CVE-2025-31644
• Severity: High
• Type: Authenticated command injection
• Attack Vector: Exploited via the file parameter in the save command through:
o iControl REST API (/mgmt)
o TMSH CLI (via SSH)
• Impact: Root command execution, bypass of shell restrictions, full system compromise
Impacted Versions
This vulnerability affects the following F5 BIG-IP versions:
• Version 17.x from 17.1.0 to 17.1.2
• Version 16.x from 16.1.0 to 16.1.5
• Version 15.x from 15.1.0 to 15.1.10
These issues are fixed in:
• Version 17.1.2.2 or later
• Version 16.1.6 or later
• Version 15.1.10.7 or later
Mitigation/workaround
• Patch Immediately: Upgrade affected systems to the latest fixed versions.
• Restrict Administrative Access: Ensure access is limited to trusted networks or controlled through secure jump hosts.
• Monitor Logs: Review system logs for unusual or suspicious usage of the save command or REST API activity involving abnormal file parameters.
• Harden Environment: Follow F5's hardening guides and disable unnecessary administrative interfaces if not in use.
References
https://my.f5.com/manage/s/article/K000148591
F5
Appliance mode BIG-IP iControl REST and tmsh vulnerability CVE-2025-31644
Security Advisory Description When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with administrator role privileges to execute…
Apple Ecosystem – May 2025 Patch
Apple has released urgent security updates to address multiple critical vulnerabilities across its ecosystem. These flaws affect iOS, iPadOS, macOS, watchOS, tvOS, Safari, and visionOS. Some of these vulnerabilities allow remote code execution, privilege escalation, or sensitive data exposure, triggered through malicious content or crafted network traffic.
Details
Key Vulnerability Details
Key Vulnerabilities Patched
• CVE-2025-31214 – Baseband Vulnerability
Allows attackers with privileged network position to intercept traffic.
• CVE-2025-31222 – mDNSResponder
Privilege escalation issue allowing unauthorized access to higher permissions.
• CVE-2024-8176 – libexpat Vulnerabilities
Can cause app crashes or allow arbitrary code execution when parsing XML.
• CVE-2025-31258 – Sandbox Escape
Malicious applications could break out of sandbox and access restricted system resources.
Apple has provided security fixes in the following latest versions:
• iOS / iPadOS 18.5
iPhone XS and later, iPad Pro (13"/12.9"/11"), iPad Air 3rd gen+, iPad 7th gen+, iPad mini 5th gen+
• iPadOS 17.7.7
iPad Pro 12.9-inch (2nd gen), Pro 10.5-inch, iPad 6th gen
• macOS Sequoia 15.5
• macOS Sonoma 14.7.6
• macOS Ventura 13.7.6
• watchOS 11.5
Apple Watch Series 6 and newer
• tvOS 18.5
Apple TV HD and all Apple TV 4K models
• visionOS 2.5
Apple Vision Pro
• Safari 18.5
For macOS Ventura and Sonoma
Mitigation/workaround • Immediate Action:
Apply the latest updates across all Apple devices listed above.
• Best Practices:
o Avoid opening suspicious links or attachments from untrusted sources.
o Encourage organization-wide update enforcement for all Apple endpoints.
o Monitor logs for abnormal application behaviors post-update.
References
https://support.apple.com/en-us/100100
Apple has released urgent security updates to address multiple critical vulnerabilities across its ecosystem. These flaws affect iOS, iPadOS, macOS, watchOS, tvOS, Safari, and visionOS. Some of these vulnerabilities allow remote code execution, privilege escalation, or sensitive data exposure, triggered through malicious content or crafted network traffic.
Details
Key Vulnerability Details
Key Vulnerabilities Patched
• CVE-2025-31214 – Baseband Vulnerability
Allows attackers with privileged network position to intercept traffic.
• CVE-2025-31222 – mDNSResponder
Privilege escalation issue allowing unauthorized access to higher permissions.
• CVE-2024-8176 – libexpat Vulnerabilities
Can cause app crashes or allow arbitrary code execution when parsing XML.
• CVE-2025-31258 – Sandbox Escape
Malicious applications could break out of sandbox and access restricted system resources.
Apple has provided security fixes in the following latest versions:
• iOS / iPadOS 18.5
iPhone XS and later, iPad Pro (13"/12.9"/11"), iPad Air 3rd gen+, iPad 7th gen+, iPad mini 5th gen+
• iPadOS 17.7.7
iPad Pro 12.9-inch (2nd gen), Pro 10.5-inch, iPad 6th gen
• macOS Sequoia 15.5
• macOS Sonoma 14.7.6
• macOS Ventura 13.7.6
• watchOS 11.5
Apple Watch Series 6 and newer
• tvOS 18.5
Apple TV HD and all Apple TV 4K models
• visionOS 2.5
Apple Vision Pro
• Safari 18.5
For macOS Ventura and Sonoma
Mitigation/workaround • Immediate Action:
Apply the latest updates across all Apple devices listed above.
• Best Practices:
o Avoid opening suspicious links or attachments from untrusted sources.
o Encourage organization-wide update enforcement for all Apple endpoints.
o Monitor logs for abnormal application behaviors post-update.
References
https://support.apple.com/en-us/100100
Apple Support
Apple security releases - Apple Support
This document lists security updates for Apple software.
Microsoft Outlook Remote Code Execution Vulnerability (CVE-2025-32705)
Microsoft has patched a critical remote code execution (RCE) vulnerability in its Outlook client as part of the May 2025 Patch Tuesday updates. Tracked as CVE-2025-32705, the flaw stems from an out-of-bounds read issue that can be triggered when a user opens a malicious file within Outlook. This vulnerability could allow attackers to execute arbitrary code, potentially leading to full system compromise.
The Outlook Preview Pane is not affected — exploitation requires the user to actively open a specially crafted file.
Details
Vulnerability Details
• CVE ID: CVE-2025-32705
• Severity: Important
• Attack Vector: Local, via malicious file opened in Outlook
• Impact: Arbitrary code execution on the victim’s system
• Exploitation Prerequisites: Requires user interaction (file must be opened manually)
• Affected Products:
o Microsoft Office LTSC 2021 (32-bit and 64-bit)
o Microsoft Office LTSC 2024 (32-bit and 64-bit)
o Microsoft 365 Apps for Enterprise (32-bit and 64-bit)
This flaw was responsibly disclosed by Haifei Li of EXPMON, with credit acknowledged by Microsoft.
Mitigation/workaround
• Apply Microsoft Security Updates: Ensure all Outlook installations across the organization are patched immediately using official Microsoft update channels.
• Avoid Opening Suspicious Attachments: Users should avoid interacting with unexpected files, even if sent from known sources.
• Reinforce Endpoint Security: Ensure antivirus and EDR solutions are active and up-to-date to detect any exploitation attempts.
• Monitor Microsoft Security Advisories: Stay alert for future updates or possible exploit attempts targeting CVE-2025-32705.
References
https://cybersecuritynews.com/outlook-remote-code-execution-vulnerability/
Microsoft has patched a critical remote code execution (RCE) vulnerability in its Outlook client as part of the May 2025 Patch Tuesday updates. Tracked as CVE-2025-32705, the flaw stems from an out-of-bounds read issue that can be triggered when a user opens a malicious file within Outlook. This vulnerability could allow attackers to execute arbitrary code, potentially leading to full system compromise.
The Outlook Preview Pane is not affected — exploitation requires the user to actively open a specially crafted file.
Details
Vulnerability Details
• CVE ID: CVE-2025-32705
• Severity: Important
• Attack Vector: Local, via malicious file opened in Outlook
• Impact: Arbitrary code execution on the victim’s system
• Exploitation Prerequisites: Requires user interaction (file must be opened manually)
• Affected Products:
o Microsoft Office LTSC 2021 (32-bit and 64-bit)
o Microsoft Office LTSC 2024 (32-bit and 64-bit)
o Microsoft 365 Apps for Enterprise (32-bit and 64-bit)
This flaw was responsibly disclosed by Haifei Li of EXPMON, with credit acknowledged by Microsoft.
Mitigation/workaround
• Apply Microsoft Security Updates: Ensure all Outlook installations across the organization are patched immediately using official Microsoft update channels.
• Avoid Opening Suspicious Attachments: Users should avoid interacting with unexpected files, even if sent from known sources.
• Reinforce Endpoint Security: Ensure antivirus and EDR solutions are active and up-to-date to detect any exploitation attempts.
• Monitor Microsoft Security Advisories: Stay alert for future updates or possible exploit attempts targeting CVE-2025-32705.
References
https://cybersecuritynews.com/outlook-remote-code-execution-vulnerability/
Cyber Security News
Outlook RCE Vulnerability Allows Attackers to Execute Arbitrary Code
Microsoft addressed a significant security flaw in its Outlook email client during the May 2025 Patch Tuesday, releasing fixes for 72 vulnerabilities.
👍1
Microsoft – May 2025 Patch Tuesday
Microsoft has released security and feature updates for all supported versions of Windows as part of its May 2025 Patch Tuesday rollout. A total of 78 vulnerabilities were addressed, including five actively exploited zero-day vulnerabilities and two publicly disclosed zero-days. The updates cover critical flaws across the Windows OS, Defender, Edge, Internet Explorer, and development tools like Visual Studio.
Details
Key Vulnerability Highlights
• CVE-2025-30400 – DWM Core Library Elevation of Privilege
o Use-after-free vulnerability exploited to gain SYSTEM privileges.
• CVE-2025-32701 & CVE-2025-32706 – Common Log File System (CLFS) Driver Privilege Escalation
o Exploited in the wild; allows attackers to elevate local privileges to SYSTEM level using use-after-free and input validation flaws.
• CVE-2025-32709 – Ancillary Function Driver for WinSock Privilege Escalation
o Use-after-free issue exploited locally to escalate privileges.
• CVE-2025-30397 – Scripting Engine Memory Corruption (RCE)
o Type confusion vulnerability can be exploited via malicious Edge/IE links.
• CVE-2025-26685 – Defender for Identity Spoofing (Publicly disclosed)
o Allows an attacker with LAN access to spoof another identity.
• CVE-2025-32702 – Visual Studio Command Injection (RCE) (Publicly disclosed)
o Exploitable by unauthenticated users to run code locally via malformed commands.
Affected Platforms & Updates
• Windows 10 (22H2): 34 vulnerabilities (3 critical)
o KB5058379: Security fixes, Event Viewer bug fix, new drivers added to blocklist.
• Windows 11 (22H2/23H2): 35 vulnerabilities (3 critical)
o KB5058405: Lock screen widgets, Phone Link enhancements, UI bug fixes.
• Windows 11 (24H2): 36 vulnerabilities (3 critical)
o KB5058411: Includes Recall preview, Click to Do AI actions, natural language search.
• Windows Server (2008 to 2025): Up to 38 vulnerabilities
o Includes privilege escalation, DoS, spoofing, and remote code execution fixes.
Mitigation/workaround
• Apply the cumulative updates released for your respective Windows versions (see KB references).
• Monitor for anomalous behavior such as SYSTEM privilege elevations, unexpected scheduled tasks, or DLL injections.
• Enable behavioral analytics and audit privileged operations using EDR/SIEM platforms.
• For Visual Studio users, ensure only signed extensions and packages are trusted and executed.
References
https://msrc.microsoft.com/update-guide/releaseNote/2025-May
https://www.ghacks.net/2025/05/13/microsoft-windows-security-updates-for-may-2025-are-now-available/
https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2025-patch-tuesday-fixes-5-exploited-zero-days-72-flaws/
Microsoft has released security and feature updates for all supported versions of Windows as part of its May 2025 Patch Tuesday rollout. A total of 78 vulnerabilities were addressed, including five actively exploited zero-day vulnerabilities and two publicly disclosed zero-days. The updates cover critical flaws across the Windows OS, Defender, Edge, Internet Explorer, and development tools like Visual Studio.
Details
Key Vulnerability Highlights
• CVE-2025-30400 – DWM Core Library Elevation of Privilege
o Use-after-free vulnerability exploited to gain SYSTEM privileges.
• CVE-2025-32701 & CVE-2025-32706 – Common Log File System (CLFS) Driver Privilege Escalation
o Exploited in the wild; allows attackers to elevate local privileges to SYSTEM level using use-after-free and input validation flaws.
• CVE-2025-32709 – Ancillary Function Driver for WinSock Privilege Escalation
o Use-after-free issue exploited locally to escalate privileges.
• CVE-2025-30397 – Scripting Engine Memory Corruption (RCE)
o Type confusion vulnerability can be exploited via malicious Edge/IE links.
• CVE-2025-26685 – Defender for Identity Spoofing (Publicly disclosed)
o Allows an attacker with LAN access to spoof another identity.
• CVE-2025-32702 – Visual Studio Command Injection (RCE) (Publicly disclosed)
o Exploitable by unauthenticated users to run code locally via malformed commands.
Affected Platforms & Updates
• Windows 10 (22H2): 34 vulnerabilities (3 critical)
o KB5058379: Security fixes, Event Viewer bug fix, new drivers added to blocklist.
• Windows 11 (22H2/23H2): 35 vulnerabilities (3 critical)
o KB5058405: Lock screen widgets, Phone Link enhancements, UI bug fixes.
• Windows 11 (24H2): 36 vulnerabilities (3 critical)
o KB5058411: Includes Recall preview, Click to Do AI actions, natural language search.
• Windows Server (2008 to 2025): Up to 38 vulnerabilities
o Includes privilege escalation, DoS, spoofing, and remote code execution fixes.
Mitigation/workaround
• Apply the cumulative updates released for your respective Windows versions (see KB references).
• Monitor for anomalous behavior such as SYSTEM privilege elevations, unexpected scheduled tasks, or DLL injections.
• Enable behavioral analytics and audit privileged operations using EDR/SIEM platforms.
• For Visual Studio users, ensure only signed extensions and packages are trusted and executed.
References
https://msrc.microsoft.com/update-guide/releaseNote/2025-May
https://www.ghacks.net/2025/05/13/microsoft-windows-security-updates-for-may-2025-are-now-available/
https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2025-patch-tuesday-fixes-5-exploited-zero-days-72-flaws/
ghacks.net
Microsoft Windows Security Updates for May 2025 are now available
Microsoft released security updates for Windows on the May 2025 Patch Day. Read our overview for recommendations, support links, and much more.
👍1
FortiOS Authentication Bypass Vulnerability (CVE-2025-22252)
Fortinet has patched a critical authentication bypass vulnerability affecting FortiOS, FortiProxy, and FortiSwitchManager when configured with TACACS+ and ASCII authentication. The flaw allows unauthorized administrative access without valid credentials.
Details
Key Vulnerability: FortiOS Auth Bypass
• CVE: CVE-2025-22252
• Impact: Complete administrative access without authentication
• Cause: Missing authentication check for critical function using ASCII authentication
Affected Versions
• FortiOS: 7.6.0, 7.4.4–7.4.6
• FortiProxy: 7.6.0–7.6.1
• FortiSwitchManager: 7.2.5
Fixed Versions
• FortiOS: 7.6.1+, 7.4.7+
• FortiProxy: 7.6.2+
• FortiSwitchManager: 7.2.6+
Mitigation/workaround • Immediate Action:
o Upgrade to the latest versions listed above
o If upgrade isn’t possible, switch to alternative TACACS+ authentication methods like PAP, MSCHAP, or CHAP
• Configuration Advice:
o Use CLI to change TACACS+ settings
o Avoid ASCII authentication until patched
References
https://cybersecuritynews.com/fortios-authentication-bypass-vulnerability/
Fortinet has patched a critical authentication bypass vulnerability affecting FortiOS, FortiProxy, and FortiSwitchManager when configured with TACACS+ and ASCII authentication. The flaw allows unauthorized administrative access without valid credentials.
Details
Key Vulnerability: FortiOS Auth Bypass
• CVE: CVE-2025-22252
• Impact: Complete administrative access without authentication
• Cause: Missing authentication check for critical function using ASCII authentication
Affected Versions
• FortiOS: 7.6.0, 7.4.4–7.4.6
• FortiProxy: 7.6.0–7.6.1
• FortiSwitchManager: 7.2.5
Fixed Versions
• FortiOS: 7.6.1+, 7.4.7+
• FortiProxy: 7.6.2+
• FortiSwitchManager: 7.2.6+
Mitigation/workaround • Immediate Action:
o Upgrade to the latest versions listed above
o If upgrade isn’t possible, switch to alternative TACACS+ authentication methods like PAP, MSCHAP, or CHAP
• Configuration Advice:
o Use CLI to change TACACS+ settings
o Avoid ASCII authentication until patched
References
https://cybersecuritynews.com/fortios-authentication-bypass-vulnerability/
Cyber Security News
FortiOS Authentication Bypass Vulnerability Lets Attackers Take Full Control of Device
Fortinet has disclosed a significant security vulnerability affecting multiple Fortinet products, allowing attackers to bypass authentication and gain administrative access to affected systems.
👍1
Fortinet Zero-Day Vulnerability in FortiVoice Actively Exploited
Fortinet has disclosed a critical zero-day vulnerability actively exploited in the wild, affecting FortiVoice and other Fortinet products. The flaw, a stack-based buffer overflow, allows unauthenticated remote code execution via malicious HTTP requests. Multiple malicious activities have been observed, including credential harvesting, log tampering, and network scanning.
Details
Key Vulnerability:
FortiVoice RCE (CWE-121 - Stack-based Buffer Overflow)
• Impact: Unauthenticated remote code/command execution
• Affected Products: FortiVoice, FortiMail, FortiNDR, FortiRecorder, FortiCamera
• Attack Actions Observed:
o Log manipulation to erase crash data
o FastCGI debugging to steal SSH credentials
o Malicious cron jobs extracting passwords every 12 hours
Affected Versions and Fixes
• FortiVoice: Upgrade to 7.2.1+, 7.0.7+, or 6.4.11+
• FortiMail: Upgrade to 7.6.3+, 7.4.5+, 7.2.8+, or 7.0.9+
• FortiNDR: Upgrade to 7.6.1+, 7.4.8+, 7.2.5+, 7.0.7+
• FortiRecorder: Upgrade to 7.2.4+, 7.0.6+, 6.4.6+
• FortiCamera: Upgrade to 2.1.4+ or migrate from 2.0/1.1
Fixed Versions
• FortiOS: 7.6.1+, 7.4.7+
• FortiProxy: 7.6.2+
• FortiSwitchManager: 7.2.6+
Mitigation/workaround
• If patching is delayed, disable the HTTP/HTTPS administrative interface.
• Monitor FastCGI logs and system binaries for manipulation.
• Review /etc/pam.d/sshd and /etc/httpd.conf for unauthorized changes.
References
https://gbhackers.com/fortinet-fortivoice-o-day-vulnerability/
Fortinet has disclosed a critical zero-day vulnerability actively exploited in the wild, affecting FortiVoice and other Fortinet products. The flaw, a stack-based buffer overflow, allows unauthenticated remote code execution via malicious HTTP requests. Multiple malicious activities have been observed, including credential harvesting, log tampering, and network scanning.
Details
Key Vulnerability:
FortiVoice RCE (CWE-121 - Stack-based Buffer Overflow)
• Impact: Unauthenticated remote code/command execution
• Affected Products: FortiVoice, FortiMail, FortiNDR, FortiRecorder, FortiCamera
• Attack Actions Observed:
o Log manipulation to erase crash data
o FastCGI debugging to steal SSH credentials
o Malicious cron jobs extracting passwords every 12 hours
Affected Versions and Fixes
• FortiVoice: Upgrade to 7.2.1+, 7.0.7+, or 6.4.11+
• FortiMail: Upgrade to 7.6.3+, 7.4.5+, 7.2.8+, or 7.0.9+
• FortiNDR: Upgrade to 7.6.1+, 7.4.8+, 7.2.5+, 7.0.7+
• FortiRecorder: Upgrade to 7.2.4+, 7.0.6+, 6.4.6+
• FortiCamera: Upgrade to 2.1.4+ or migrate from 2.0/1.1
Fixed Versions
• FortiOS: 7.6.1+, 7.4.7+
• FortiProxy: 7.6.2+
• FortiSwitchManager: 7.2.6+
Mitigation/workaround
• If patching is delayed, disable the HTTP/HTTPS administrative interface.
• Monitor FastCGI logs and system binaries for manipulation.
• Review /etc/pam.d/sshd and /etc/httpd.conf for unauthorized changes.
References
https://gbhackers.com/fortinet-fortivoice-o-day-vulnerability/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Fortinet FortiVoice O-Day Vulnerability Actively Exploited in The Wild
A critical zero-day vulnerability in FortiVoice systems is being actively exploited in the wild. It allows unauthenticated attackers to execute arbitrary code
🔥1
توزیع بدافزار از طریق سایتهای جعلی تولید ویدیو با هوش مصنوعی
یک گروه تهدید وابسته به ویتنام در حال توزیع بدافزارهای Noodlophile Stealer و XWorm RAT از طریق سایتهای جعلی تولید ویدیو با هوش مصنوعی است که با پستهای ویروسی در فیسبوک تبلیغ میشوند.
این سایتهای جعلی کاربران—بهویژه تولیدکنندگان محتوا و کسبوکارهای کوچک—را فریب میدهند تا فایلهای رسانهای خود را آپلود کرده و فایلهای ZIP آلوده (مانند VideoDreamAI.zip) را که بهعنوان خروجی هوش مصنوعی جا زده شدهاند، دانلود کنند.
محموله مخرب شامل موارد زیر است:
سرقت اطلاعات ورود (Credential theft)
سرقت کیف پولهای رمزارز
کنترل از راه دور با استفاده از RAT
استخراج اطلاعات از طریق Telegram
این حمله از طریق یک زنجیره آلودگی چندمرحلهای و پیچیده انجام میشود که ابزارهایی مانند CapCut.exe، certutil.exe، و RegAsm.exe را بهکار میگیرد و بهشدت مبهمسازی (Obfuscation) شده است.
این بدافزارها بهعنوان بخشی از یک عملیات بدافزار به عنوان سرویس (Malware-as-a-Service یا MaaS) ارائه میشوند.
یک گروه تهدید وابسته به ویتنام در حال توزیع بدافزارهای Noodlophile Stealer و XWorm RAT از طریق سایتهای جعلی تولید ویدیو با هوش مصنوعی است که با پستهای ویروسی در فیسبوک تبلیغ میشوند.
این سایتهای جعلی کاربران—بهویژه تولیدکنندگان محتوا و کسبوکارهای کوچک—را فریب میدهند تا فایلهای رسانهای خود را آپلود کرده و فایلهای ZIP آلوده (مانند VideoDreamAI.zip) را که بهعنوان خروجی هوش مصنوعی جا زده شدهاند، دانلود کنند.
محموله مخرب شامل موارد زیر است:
سرقت اطلاعات ورود (Credential theft)
سرقت کیف پولهای رمزارز
کنترل از راه دور با استفاده از RAT
استخراج اطلاعات از طریق Telegram
این حمله از طریق یک زنجیره آلودگی چندمرحلهای و پیچیده انجام میشود که ابزارهایی مانند CapCut.exe، certutil.exe، و RegAsm.exe را بهکار میگیرد و بهشدت مبهمسازی (Obfuscation) شده است.
این بدافزارها بهعنوان بخشی از یک عملیات بدافزار به عنوان سرویس (Malware-as-a-Service یا MaaS) ارائه میشوند.
🔥1