cKure
■■■■■ CVE-2025-64446: Critical Vulnerability in Fortinet FortiWeb Exploited in the Wild. https://www.rapid7.com/blog/post/etr-critical-vulnerability-in-fortinet-fortiweb-exploited-in-the-wild/ https://www.fortiguard.com/psirt/FG-IR-25-910
■■□□□ Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited in the Wild.
https://thehackernews.com/2025/11/fortinet-warns-of-new-fortiweb-cve-2025.html
https://thehackernews.com/2025/11/fortinet-warns-of-new-fortiweb-cve-2025.html
❤1
■■■■□ Interesting thread: ATM Hacking Group UNC2891 Technical Summary.
https://x.com/blackorbird/status/1991516037968457814
https://x.com/blackorbird/status/1991516037968457814
X (formerly Twitter)
blackorbird (@blackorbird) on X
#ATM Hacking Group UNC2891 Technical Summary:
Core Tools / Malware ArsenalCAKETAP → Solaris/Linux kernel rootkit, hooks ATM → HSM traffic, modifies ARQC/ARPC in real time
SLAPSTICK → PAM backdoor + per-server unique "magic password" (SSH passwordless…
Core Tools / Malware ArsenalCAKETAP → Solaris/Linux kernel rootkit, hooks ATM → HSM traffic, modifies ARQC/ARPC in real time
SLAPSTICK → PAM backdoor + per-server unique "magic password" (SSH passwordless…
❤1👍1
Forwarded from cKure Red
https://cybersecuritynews.com/7-zip-rce-vulnerability-exploited/
Please open Telegram to view this post
VIEW IN TELEGRAM
Cyber Security News
Hackers Actively Exploiting 7-Zip RCE Vulnerability in the Wild
Hackers have begun actively exploiting a critical remote code execution (RCE) vulnerability in the popular file archiver 7-Zip, putting millions of users at risk of malware infection and system compromise.
👍2❤🔥1❤1🔥1
■■■■■ New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices.
https://thehackernews.com/2025/11/new-sturnus-android-trojan-quietly.html
https://thehackernews.com/2025/11/new-sturnus-android-trojan-quietly.html
❤1
■■■■□ CSA Announces Zigbee 4.0, with New "Suzi" Sub-Gigahertz Long-Range Support
New sub-brand offers improved range and penetration at low power, while the main standard enjoys improved security.
https://www.hackster.io/news/csa-announces-zigbee-4-0-with-new-suzi-sub-gigahertz-long-range-support-3c6f18540c35
New sub-brand offers improved range and penetration at low power, while the main standard enjoys improved security.
https://www.hackster.io/news/csa-announces-zigbee-4-0-with-new-suzi-sub-gigahertz-long-range-support-3c6f18540c35
Hackster.io
CSA Announces Zigbee 4.0, with New "Suzi" Sub-Gigahertz Long-Range Support
New sub-brand offers improved range and penetration at low power, while the main standard enjoys improved security.
❤1
■□□□□ Veeam bets on more VMware alternatives, including Red Hat and China’s Sangfor
Plans a universal API to back up all hypervisors, too.
https://www.theregister.com/2025/11/21/veeam_13_hypervisor_support/
Plans a universal API to back up all hypervisors, too.
https://www.theregister.com/2025/11/21/veeam_13_hypervisor_support/
The Register
Veeam bets on more VMware alternatives, including Red Hat and China’s Sangfor
: Plans a universal API to back up all hypervisors, too
❤1👍1
■■■■■ Iran: Interesting thread on APT-35 (Charming Kitten's) elaborate cyber-espionage and HUMINT operation.
https://x.com/blackorbird/status/1992075483836744154
https://x.com/blackorbird/status/1992075483836744154
X (formerly Twitter)
blackorbird (@blackorbird) on X
Massive APT35 (Charming Kitten)
internal leak exposes a highly mature, quota-driven cyber-espionage machine focused on long-term mailbox persistence & HUMINT collection.
Core technical tradecraft is Exchange-centric & credential-obsessed:
Initial Access…
internal leak exposes a highly mature, quota-driven cyber-espionage machine focused on long-term mailbox persistence & HUMINT collection.
Core technical tradecraft is Exchange-centric & credential-obsessed:
Initial Access…
❤1🤣1
■■■■■ CVE-2025-41115: Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation.
https://thehackernews.com/2025/11/grafana-patches-cvss-100-scim-flaw.html
https://thehackernews.com/2025/11/grafana-patches-cvss-100-scim-flaw.html
❤1
Forwarded from cKure Red
https://cybersecuritynews.com/critical-windows-graphics-vulnerability/
Please open Telegram to view this post
VIEW IN TELEGRAM
Cyber Security News
Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image
A critical remote code execution flaw in Microsoft's Windows Graphics Component allows attackers to seize control of systems using specially crafted JPEG images.
❤1🥴1
■■■■□ Unkraine | Electronic Warfare: How Spoofing Is Diverting Russian Missiles Into Empty Fields.
Allegedly 21 Kinzhal Hypersonic missiles have been diverted by Ukrainian forces upto 144 meters in one case.
https://www.forbes.com/sites/davidhambling/2025/11/20/how-spoofing-is-diverting-russian-missiles-into-empty-fields/
Allegedly 21 Kinzhal Hypersonic missiles have been diverted by Ukrainian forces upto 144 meters in one case.
https://www.forbes.com/sites/davidhambling/2025/11/20/how-spoofing-is-diverting-russian-missiles-into-empty-fields/
Forbes
How Spoofing Is Diverting Russian Missiles Into Empty Fields
Ukraine's Night Watch unit is spoofing the navigation systems of Russian hypersonic Kinzhal missiles and sending them away from targets.
■■■■□ Brazilian Campaign: Spreading the Malware via WhatsApp.
https://labs.k7computing.com/index.php/brazilian-campaign-spreading-the-malware-via-whatsapp/
https://labs.k7computing.com/index.php/brazilian-campaign-spreading-the-malware-via-whatsapp/
K7 Labs
Brazilian Campaign: Spreading the Malware via WhatsApp
K7 Labs found out from a tweet about a massive phishing campaign going on against Brazil, spreading the malware via […]
■■■□□ ShinyHunters 'does not like Salesforce at all,' claims the crew accessed Gainsight 3 months ago.
https://www.theregister.com/2025/11/21/shinyhunters_salesforce_gainsight_breach/
https://www.theregister.com/2025/11/21/shinyhunters_salesforce_gainsight_breach/
The Register
ShinyHunters 'does not like Salesforce at all,' claims the crew accessed Gainsight 3 months ago
EXCLUSIVE: Shiny talks to The Reg
■■■■□ OSINT on social media accounts of Israelis allowed Palestinian army (Hamas) to get technical knowledge of Merkava 4 tanks of postal including a kill switch.
An interesting thread: https://x.com/grok/status/1992604660516241461
An interesting thread: https://x.com/grok/status/1992604660516241461
X (formerly Twitter)
Grok (@grok) on X
@psp_bassem @tamerqdh Yes, reports from Israeli Army Radio (via journalist Doron Kadosh) and outlets like Israel National News confirm Hamas collected Merkava 4 tank intel from soldiers' social media, including a secret disable button. They trained elites…
■■■■□ Weaponized file name flaw makes updating glob an urgent job.
https://www.theregister.com/2025/11/23/infosec_news_in_brief/
https://www.theregister.com/2025/11/23/infosec_news_in_brief/
The Register
Weaponized file name flaw makes updating glob an urgent job
Infosec In Brief: PLUS: CISA issues drone warning; China-linked DNS-hijacking malware; Prison for BTC Samourai; And more
cKure
■■■□□ Kode Dot; hardware hacking tool. https://www.hackster.io/news/kode-dot-wants-to-dethrone-the-flipper-zero-bdd5ae75b6a5
■■■□□ The Octopus-Packing Multi-Functional High Boy Aims to Beat the Flipper Zero
Built-in Wi-Fi gives the High Boy an edge over the competition, and an open source release has been promised post-crowdfunding.
https://www.hackster.io/news/the-octopus-packing-multi-functional-high-boy-aims-to-beat-the-flipper-zero-1c95c36da7e3
Built-in Wi-Fi gives the High Boy an edge over the competition, and an open source release has been promised post-crowdfunding.
https://www.hackster.io/news/the-octopus-packing-multi-functional-high-boy-aims-to-beat-the-flipper-zero-1c95c36da7e3
Hackster.io
The Octopus-Packing Multi-Functional High Boy Aims to Beat the Flipper Zero
Built-in Wi-Fi gives the High Boy an edge over the competition, and an open source release has been promised post-crowdfunding.
■■□□□ Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet.
cybersecuritynews.com/wireshark-vulnerabilities-4-6-1
cybersecuritynews.com/wireshark-vulnerabilities-4-6-1
Cyber Security News
Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet
The Wireshark Foundation has rolled out a crucial security update for its widely used network protocol analyzer, addressing multiple vulnerabilities that could lead to denial-of-service conditions.
■■■■■ Shai Hulud is a self-replicating npm worm that executes malicious code via the postinstall script during package installation. It uses the TruffleHog tool to scan the system, steal sensitive information (such as API keys and tokens), and upload it to randomly named repositories on GitHub.
https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
Shai-Hulud 2.0: Ongoing Supply Chain Attack
https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack
These repositories have a uniform description of “Sha1-Hulud: The Second Coming”, and over 26.8k such repositories have been discovered so far.
Unlike the previous attack, this time it introduces the setup_bun.js script to install the Bun runtime, followed by executing the core malicious file bun_environment.js.
If GitHub or npm authentication fails, the attacker will delete all files in the user's home directory. The attack started at 3:16 AM, with the first wave targeting go-template and 36 AsyncAPI packages, then expanding to PostHog (4:11) and Postman (5:09), with targets increasing from 20 to a maximum of 100.
https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
Shai-Hulud 2.0: Ongoing Supply Chain Attack
https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack