Intel Encyclopedia
33 subscribers
3.15K links
Daily Cybersecurity feeds
Download Telegram
General Cyber News

🏴‍☠️ Stormous has just published a new victim : !



Summary:
VPN access to the company’s internal network is provided



Source: Ransomware.live RSS Feed
Published: 2025-11-08 01:45

#just #general_cyber_news #stormous

https://www.ransomware.live/id/IUBzdG9ybW91cw==
General Cyber News

🏴‍☠️ Akira has just published a new victim : Mold In Graphic Systems



Summary:
Mold In Graphic Systems specializes in providing permanent labeli
ng solutions for plastic durable goods using their unique Polymer
Fusion Labels.

We will upload 15gb of corporate documents soon. Employee informa
tion (Driver licenses, credit cards scans, medical information an
d so on), projects information, internal confidential files, agre
ements and contracts, NDAs, etc.



Source: Ransomware.live RSS Feed
Published: 2025-11-08 00:44

#akira #general_cyber_news #just

https://www.ransomware.live/id/TW9sZCBJbiBHcmFwaGljIFN5c3RlbXNAYWtpcmE=
Vulnerabilities & Exploits

🏴‍☠️ Dragonforce has just published a new victim : GB Mail



Summary:
GB Mail is a privately owned and leading mailing house located centrally in the home counties. With a strong ethos of delivering mail with no fuss, on time and in full, the company boasts a dedicated and knowledgeable team passionate about all aspects of print and mail. Their services include storage & fulfilment, postal solutions, print personalisation, database cleansing, international mail, direct mail, and subscription mail.



Source: Ransomware.live RSS Feed
Published: 2025-11-07 22:53

#just #dragonforce #vulnerabilities__exploits

https://www.ransomware.live/id/R0IgTWFpbEBkcmFnb25mb3JjZQ==
Vulnerabilities & Exploits

🏴‍☠️ Dragonforce has just published a new victim : DCS TECHNOLOGIES INC.



Summary:
DCS Technology Inc. is providing complete IT Solutions since 2004. They are specialized in Point of Sale systems, Website Designing, Technical Support, and Computer Networking Solutions. With 17 years of experience, DCS serving over 5000 businesses in North America.



Source: Ransomware.live RSS Feed
Published: 2025-11-07 21:50

#just #dragonforce #vulnerabilities__exploits

https://www.ransomware.live/id/RENTIFRFQ0hOT0xPR0lFUyBJTkMuQGRyYWdvbmZvcmNl
Malware Analysis

Balancer hack analysis and guidance for the DeFi ecosystem



Summary:
TL;DR

The root cause of the hack was a rounding direction issue that had been present in the code for many years.
When the bug was first introduced, the threat landscape of the blockchain ecosystem was significantly different, and arithmetic issues in particular were not widely considered likely vectors for exploitation.
As low-hanging attack paths have become increasingly scarce, attackers have become more sophisticated and will continue to hunt for novel threats, such as arithmetic edge...



Source: The Trail of Bits Blog
Published: 2025-11-07 23:00

#malware_analysis #hack #balancer

https://blog.trailofbits.com/2025/11/07/balancer-hack-analysis-and-guidance-for-the-defi-ecosystem/
General Cyber News

After MD-11 Crash Boeing Tells UPS to Ground Its Planes



Summary:
UPS has announced nearly 10% of its airplanes will be grounded, per the recommendation of Boeing. Out of an abundance of caution and in the interest of safety, we have made the decision to temporarily ground our MD-11 fleet. MD-11s are approximately 9% of the UPS Airlines fleet. The grounding is effective immediately. We made … Continue reading After MD-11 Crash Boeing Tells UPS to Ground Its Planes →



Source: flyingpenguin
Published: 2025-11-08 10:53 | Author: Davi Ottenheimer

#general_cyber_news #after #md11

https://www.flyingpenguin.com/?p=73949
General Cyber News

Nick Fuentes: 40% of White House Are Nazis (((America First)))



Summary:
First, the infamous hate group leader Fuentes says the Heritage Foundation has mainstreamed his extremism, such that a large percentage of the White House staff have been compromised. He’s saying clearly that “America First” is back in the White House again, which isn’t really news. However, people perhaps are starting to realize or remember why … Continue reading Nick Fuentes: 40% of White House Are Nazis (((America First))) →



Source: flyingpenguin
Published: 2025-11-08 01:38 | Author: Davi Ottenheimer

#fuentes #general_cyber_news #nick

https://www.flyingpenguin.com/?p=73924
Threat Intelligence

AI-Powered Cyber Threats Rise: Attackers Target Manufacturing Sector



Summary:
A comprehensive new report reveals that manufacturing organizations are grappling with a dual challenge: rapidly adopting generative AI technologies while simultaneously defending against attackers who exploit these same platforms and trusted cloud services to launch sophisticated attacks. The findings underscore an urgent need for enhanced security controls as the sector balances innovation with data protection. […]
The post AI-Powered Cyber Threats Rise: Attackers Target Manufacturing...



Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-11-08 06:41 | Author: Mayura Kathir

#threat_intelligence #aipowered #cyber

https://gbhackers.com/ai-powered-cyber-threats/
Vulnerabilities & Exploits

New “LANDFALL” Android Malware Uses Samsung 0-Day Vulnerability Hidden in WhatsApp Images



Summary:
Cybersecurity researchers at Unit 42 have uncovered a sophisticated Android spyware campaign that exploited a previously unknown zero-day vulnerability in Samsung Galaxy devices. The malware, dubbed LANDFALL, leveraged a critical vulnerability in Samsung’s image processing library to deliver commercial-grade surveillance capabilities through maliciously crafted image files sent via WhatsApp. The LANDFALL campaign exploited CVE-2025-21042, a […]
The post New “LANDFALL” Android...



Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-11-08 05:34 | Author: Mayura Kathir

#landfall #vulnerabilities__exploits #android

https://gbhackers.com/samsung-0-day-vulnerability/
Threat Intelligence

New Microsoft Teams Feature Exposes Users to Phishing and Malware Risks



Summary:
Microsoft is poised to roll out a significant update to Teams, enabling users to initiate chats with anyone using just an email address even if the recipient isn’t a Teams user. While the feature, launching in targeted releases by early November 2025 and globally by January 2026, promises expanded connectivity across Android, desktop, iOS, Linux, […]
The post New Microsoft Teams Feature Exposes Users to Phishing and Malware Risks appeared first on GBHackers Security | #1 Globally Trusted...



Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-11-08 05:00 | Author: Mayura Kathir

#threat_intelligence #microsoft #teams

https://gbhackers.com/microsoft-teams-feature/
General Cyber News

How FedRAMP Agencies Evaluate CSP SAR Submissions



Summary:
FedRAMP is the federal government’s framework for evaluating and enforcing standardized security across the cloud service providers operating as contractors. They take security seriously, and the protection of controlled information is their top priority. A key part of validating the security of a CSP is the SAR, or Security Assessment Report. What is the SAR, […]



Source: Ignyte
Published: 2025-11-07 23:07 | Author: Dan Page

#general_cyber_news #agencies #fedramp

https://www.ignyteplatform.com/blog/fedramp/fedramp-csp-sar-submissions/
General Cyber News

Honeypot: Requests for (Code) Repositories, (Sat, Nov 8th)



Summary:
This is just a quick diary entry to report that I saw requests on my honeypot for (code) repositories:



Source: SANS Internet Storm Center, InfoCON: green
Published: 2025-11-08 06:09

#general_cyber_news #honeypot #requests

https://isc.sans.edu/diary/rss/32460
General Cyber News

Критическая уязвимость в популярной библиотеке expr-eval угрожает системам искусственного интеллекта



Summary:
В широко используемой JavaScript-библиотеке expr-eval обнаружена критическая уязвимость удаленного выполнения кода (RCE), затрагивающая тысячи проектов в области искусственного интеллекта и обработки естественного языка. Уязвимость, получившая идентификатор CVE-2025-12735, представляет серьезную угрозу для серверных сред и AI-приложений, обрабатывающих пользовательский ввод. Детали уязвимости Эксперты по безопасности особенно обеспокоены масштабами потенциального воздействия, учитывая широкое...



Source: SEC-1275-1
Published: 2025-11-10 13:21 | Author: Vulner Queen

#expreval #general_cyber_news

https://1275.ru/vulnerability/kriticheskaya-uyazvimost-v-populyarnoy-biblioteke-expr-eval-ugrozhaet-sistemam-iskusstvennogo-intellekta_16167
General Cyber News

Киберпреступники возродили опасную кампанию Gootloader с новыми методами обхода защиты



Summary:
Группа исследователей кибербезопасности из компании Huntress зафиксировала возвращение печально известной кампании Gootloader, которая после временного затишья вновь активизировалась с усовершенствованными методами атак. Об этом первыми сообщил аналитик под псевдонимом RussianPanda, чьи наблюдения позволили раскрыть новые тактики злоумышленников. Gootloader продолжает свою пятилетнюю историю использования юридической тематики в качестве приманки. Злоумышленники создали более 100 веб-сайтов с...



Source: SEC-1275-1
Published: 2025-11-10 13:07 | Author: SEC-1275

#gootloader #general_cyber_news

https://1275.ru/ioc/kiberprestupniki-vozrodili-opasnuyu-kampaniyu-gootloader-s-novymi-metodami-obhoda-zaschity_16078
General Cyber News

Группа Dragon Breath атакует игорный бизнес Юго-Восточной Азии



Summary:
Китайский центр анализа угроз компании QiAnXin раскрыл детали многолетней хакерской кампании, нацеленной на онлайн-казино и букмекерские компании Юго-Восточной Азии. Группа, отслеживаемая под кодовым названием APT-Q-27 (Advanced Persistent Threat), демонстрирует высочайший уровень технической подготовки и адаптивности, используя сложные схемы проникновения в инфраструктуру игорного бизнеса. Специалисты отмечают, что сфера онлайн-гемблинга стала особенно привлекательной для киберпреступников в...



Source: SEC-1275-1
Published: 2025-11-10 12:42 | Author: SEC-1275

#dragon #breath #general_cyber_news

https://1275.ru/ioc/gruppa-dragon-breath-atakuet-igornyy-biznes-yugo-vostochnoy-azii_16077
General Cyber News

В Японии обнаружена сеть киберпреступников с использованием Cobalt Strike и других инструментов



Summary:
В ходе еженедельного исследования угроз безопасности, проведенного в 43-ю неделю 2025 года, в Японии была выявлена активность семи серверов управления и контроля, известных как C2-инфраструктура. Исследование проводилось с 20 по 26 октября с использованием платформы Censys, специализирующейся на сканировании интернет-активов. Обнаруженные серверы связаны с различными семействами вредоносного программного обеспечения, включая известные инструменты киберпреступников Cobalt Strike,...



Source: SEC-1275-1
Published: 2025-11-10 11:00 | Author: SEC-1275

#strike #cobalt #general_cyber_news

https://1275.ru/ioc/v-yaponii-obnaruzhena-set-kiberprestupnikov-s-ispolzovaniem-cobalt-strike-i-drugih-instrumentov_16075
General Cyber News

В Польше обнаружили новую схему мошенничества с банковскими картами через NFC-ретрансляцию



Summary:
Польский компьютерный координационный центр CERT Polska сообщил о выявлении новой вредоносной кампании, нацеленной на клиентов польских банков. Злоумышленники используют технику NFC-ретрансляции для несанкционированного снятия наличных в банкоматах без физического завладения картами жертв. Атака получила название NGate и представляет собой сложный многоэтапный сценарий. На первом этапе жертвы получают фишинговые сообщения по электронной почте или SMS, содержащие […]
Сообщение В Польше...



Source: SEC-1275-1
Published: 2025-11-10 10:53 | Author: SEC-1275

#general_cyber_news

https://1275.ru/ioc/v-polshe-obnaruzhili-novuyu-shemu-moshennichestva-s-bankovskimi-kartami-cherez-nfc-retranslyatsiyu_16071