■■■■■ Botnet takes advantage of AWS outage to smack 28 countries.
https://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/
https://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/
https://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/
https://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/
The Register
Botnet takes advantage of AWS outage to smack 28 countries
: Even worse, it might have been a 'test run' for future attacks
■■■■□ SectorA01 (Lazarus) employed a highly sophisticated, multi-stage attack chain
https://medium.com/@nshcthreatrecon/a-tsunami-sweeping-the-cyber-battlefield-analysis-of-sectora01s-hacking-activities-e4d006baae2f
https://x.com/blackorbird/status/1994001509944840678
beginning with social engineering via a fake official Deriv trading platform installer (NSIS-based).
The infection progresses through a polyglot payload sequence (NSIS → Electron/JavaScript → Python → .NET), using dynamic code execution via eval() on remotely fetched JavaScript, Pastebin as a dead-drop mechanism with 1,000 pre-generated XOR-encrypted URLs, and Living-off-the-Land techniques by downloading and installing the legitimate official Python interpreter when absent.
Once inside, the malware conducts broad data theft including browser credentials and credit-card information, keylogging with clipboard monitoring and exfiltration, and keyword-based recursive searches for sensitive files (wallet, mnemonic, .env, etc.).
It establishes strong remote access through an AnyDesk backdoor using a pre-configured fixed password via service.conf overwrite, while achieving multi-layered persistence through the startup folder, scheduled tasks, and AnyDesk auto-start.
Defense evasion is comprehensive: it disables Windows Defender and Firewall while adding exclusions, masquerades as the legitimate system process Runtime Broker.exe, tampers PE timestamps to future dates (2070 and 2093), communicates in the final stage exclusively over Tor via a .onion C2 domain, and incorporates automatic client updates with trace self-deletion to hinder detection and analysis.
https://medium.com/@nshcthreatrecon/a-tsunami-sweeping-the-cyber-battlefield-analysis-of-sectora01s-hacking-activities-e4d006baae2f
https://x.com/blackorbird/status/1994001509944840678
■■□□□ The Central Bank of India (RBI) 🇮🇳 has made a good decision from cyber security perspective.
They have forced all bank websites to be subdomains of bank.in
This will effectively cause most phishing campaigns to go astray.
🚫
They have forced all bank websites to be subdomains of bank.in
This will effectively cause most phishing campaigns to go astray.
Please open Telegram to view this post
VIEW IN TELEGRAM
■□□□ 💥 Cyber-War on Israel: Transport display outages; new details on cyber intrusion into "Urban Digital" company.
📱
https://t.me/CyberSecurityIL/8107
🎤Following a widespread disruption in transport information displays in the occupied territories, Hebrew sources confirmed that the incident originated from a cyber intrusion into the infrastructure of the "Urban Digital" company. This attack disabled parts of the smart displays in cities such as Ashkelon and Modiin for about an hour.
🎥The management of the company owning "Urban Digital" announced that to contain the incident, all servers were completely shut down and more than 100 experts were active until morning to control the situation.
🎤Initial assessment indicates that the attackers are from the same groups that have targeted several other organizations of this regime in recent months. Technical investigation is ongoing.
HackerNewsCyberhttps://t.me/CyberSecurityIL/8107
Please open Telegram to view this post
VIEW IN TELEGRAM
■■■□□ Alleged Disclosure of the identity of a 16-year-old teenager; the technical brain of the SLSH ransomware group from Amman, Jordan 🇯🇴
https://t.me/HackerNewscyber/2666
https://t.me/HackerNewscyber/2666
Telegram
هکرنیوز|Hacker News
🚨🚨افشای هویت نوجوان ۱۶ساله؛ مغز فنی گروه باجافزاری SLSH شناسایی شد
🎤در پی هفتهها بررسی منابع اطلاعاتی، هویت واقعی «Rey» یکی از سه مدیر اصلی گروه سایبری Scattered LAPSUS$ Hunters شناسایی و تأیید شد. گروهی که طی سال ۲۰۲۵ با سرقت داده و اخاذی از شرکتهای…
🎤در پی هفتهها بررسی منابع اطلاعاتی، هویت واقعی «Rey» یکی از سه مدیر اصلی گروه سایبری Scattered LAPSUS$ Hunters شناسایی و تأیید شد. گروهی که طی سال ۲۰۲۵ با سرقت داده و اخاذی از شرکتهای…
■□□□□ CVE-2025-5318
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
https://access.redhat.com/errata/RHSA-2025:18231
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
https://access.redhat.com/errata/RHSA-2025:18231
■■□□□ Pakistan infra targeted on a DoS attack. This is per the threat actor; Keymous group. As they mentioned the following victims taken offline.
❌NTDC (National Transmission & Despatch Co.)
❌LESCO (Lahore Electric Supply Co.)
❌FESCO (Faisalabad Electric Supply Company)
❌GEPCO (Gujranwala Electric Power Co.)
❌MEPCO (Multan Electric Power Company)
❌TESCO (Tribal Electric Supply Co.)
❌HESCO (Hyderabad Electric Supply Co.)
❌SEPCO (Sukkur Electric Power Co.)
❌QESCO (Quetta Electric Supply Co.)
❌NTDC (National Transmission & Despatch Co.)
❌LESCO (Lahore Electric Supply Co.)
❌FESCO (Faisalabad Electric Supply Company)
❌GEPCO (Gujranwala Electric Power Co.)
❌MEPCO (Multan Electric Power Company)
❌TESCO (Tribal Electric Supply Co.)
❌HESCO (Hyderabad Electric Supply Co.)
❌SEPCO (Sukkur Electric Power Co.)
❌QESCO (Quetta Electric Supply Co.)
■■■□□ Unconfirmed: GrapheneOS vacates from France amid pressure to implement potential backdoors.
❤1
Forwarded from cKure Red
The zionist entity (Israel) has “Iron” in the name of many 🪖 technologies (defense-related):
Iron Beam – Israel. High-energy laser air-defense system.
Iron Fist – Israel. Active protection system for vehicles.
Iron Curtain – US. APS for close-range RPG/missile interception.
Iron Wolf – Lithuania. Mechanized infantry brigade (NATO).
Iron Sting – Israel. Precision 120mm mortar-guided munition.
Iron Vision – Elbit helmet-mounted 360° situational awareness for tanks.
Please open Telegram to view this post
VIEW IN TELEGRAM
😡2🔥1😁1😭1
■■■□□ TOKYO: Japanese beer giant Asahi said Thursday (Nov 27) it was not negotiating with the hackers behind a "sophisticated and cunning" ransomware attack that is about to enter its third month.
https://www.channelnewsasia.com/east-asia/beer-giant-asahi-not-engaging-ransomware-hackers-5493016
"Even if we had a ransom demand, we would not have paid it," CEO Atsushi Katsuki said.
https://www.channelnewsasia.com/east-asia/beer-giant-asahi-not-engaging-ransomware-hackers-5493016
CNA
Beer giant Asahi not engaging with ransomware hackers
TOKYO: Japanese beer giant Asahi said Thursday (Nov 27) it was not negotiating with the hackers behind a "sophisticated and cunning" ransomware attack that is about to enter its third month."Even if we had a ransom demand, we would not have paid it," CEO…
⚡1🥰1
■■□□□ CodeRED emergency alert system CodeDEAD after INC ransomware attack.
Regions across US affected, and one tore up its contract for the product
https://www.theregister.com/2025/11/26/codered_emergency_alert_ransomware/
Regions across US affected, and one tore up its contract for the product
https://www.theregister.com/2025/11/26/codered_emergency_alert_ransomware/
The Register
CodeRED emergency alert system CodeDEAD after INC ransomware attack
: Regions across US affected, and one tore up its contract for the product
■■■■□ Command Injection in NASA CryptoLib (CVE-2025-59534)
https://aisle.com/blog/command-injection-in-nasa-cryptolib-cve-2025-59534
https://aisle.com/blog/command-injection-in-nasa-cryptolib-cve-2025-59534
AISLE
Command Injection in NASA CryptoLib (CVE-2025-59534)
NASA's CryptoLib had a critical 3-year-old authentication flaw. AISLE's AI detected it and helped ship CVE-2025-59534 fix in just 4 days.
🔥1
■■■■□ OSINT: Interesting thread on United States' 🇺🇸 attacker (Afghan national and traitor) that ambushed 2 national guard commandos.
https://x.com/AmyMek/status/1993977623773630766
https://x.com/AmyMek/status/1993977623773630766
X (formerly Twitter)
Amy Mek (@AmyMek) on X
🚨 NEW: The DC Attack Is Even More Explosive Than First Reported
(This post summarizes what multiple outlets, sources, and public reports are saying. I will update as more information comes out.)
Americans were initially told the shooter near the White House…
(This post summarizes what multiple outlets, sources, and public reports are saying. I will update as more information comes out.)
Americans were initially told the shooter near the White House…
Forwarded from cKure Red
https://securelist.com/tomiris-new-tools/118143/
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1🔥1👏1👌1