■□□□□ CVE-2025-5318
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
https://access.redhat.com/errata/RHSA-2025:18231
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
https://access.redhat.com/errata/RHSA-2025:18231
■■□□□ Pakistan infra targeted on a DoS attack. This is per the threat actor; Keymous group. As they mentioned the following victims taken offline.
❌NTDC (National Transmission & Despatch Co.)
❌LESCO (Lahore Electric Supply Co.)
❌FESCO (Faisalabad Electric Supply Company)
❌GEPCO (Gujranwala Electric Power Co.)
❌MEPCO (Multan Electric Power Company)
❌TESCO (Tribal Electric Supply Co.)
❌HESCO (Hyderabad Electric Supply Co.)
❌SEPCO (Sukkur Electric Power Co.)
❌QESCO (Quetta Electric Supply Co.)
❌NTDC (National Transmission & Despatch Co.)
❌LESCO (Lahore Electric Supply Co.)
❌FESCO (Faisalabad Electric Supply Company)
❌GEPCO (Gujranwala Electric Power Co.)
❌MEPCO (Multan Electric Power Company)
❌TESCO (Tribal Electric Supply Co.)
❌HESCO (Hyderabad Electric Supply Co.)
❌SEPCO (Sukkur Electric Power Co.)
❌QESCO (Quetta Electric Supply Co.)
■■■□□ Unconfirmed: GrapheneOS vacates from France amid pressure to implement potential backdoors.
❤1
Forwarded from cKure Red
The zionist entity (Israel) has “Iron” in the name of many 🪖 technologies (defense-related):
Iron Beam – Israel. High-energy laser air-defense system.
Iron Fist – Israel. Active protection system for vehicles.
Iron Curtain – US. APS for close-range RPG/missile interception.
Iron Wolf – Lithuania. Mechanized infantry brigade (NATO).
Iron Sting – Israel. Precision 120mm mortar-guided munition.
Iron Vision – Elbit helmet-mounted 360° situational awareness for tanks.
Please open Telegram to view this post
VIEW IN TELEGRAM
😡2🔥1😁1😭1
■■■□□ TOKYO: Japanese beer giant Asahi said Thursday (Nov 27) it was not negotiating with the hackers behind a "sophisticated and cunning" ransomware attack that is about to enter its third month.
https://www.channelnewsasia.com/east-asia/beer-giant-asahi-not-engaging-ransomware-hackers-5493016
"Even if we had a ransom demand, we would not have paid it," CEO Atsushi Katsuki said.
https://www.channelnewsasia.com/east-asia/beer-giant-asahi-not-engaging-ransomware-hackers-5493016
CNA
Beer giant Asahi not engaging with ransomware hackers
TOKYO: Japanese beer giant Asahi said Thursday (Nov 27) it was not negotiating with the hackers behind a "sophisticated and cunning" ransomware attack that is about to enter its third month."Even if we had a ransom demand, we would not have paid it," CEO…
⚡1🥰1
■■□□□ CodeRED emergency alert system CodeDEAD after INC ransomware attack.
Regions across US affected, and one tore up its contract for the product
https://www.theregister.com/2025/11/26/codered_emergency_alert_ransomware/
Regions across US affected, and one tore up its contract for the product
https://www.theregister.com/2025/11/26/codered_emergency_alert_ransomware/
The Register
CodeRED emergency alert system CodeDEAD after INC ransomware attack
: Regions across US affected, and one tore up its contract for the product
■■■■□ Command Injection in NASA CryptoLib (CVE-2025-59534)
https://aisle.com/blog/command-injection-in-nasa-cryptolib-cve-2025-59534
https://aisle.com/blog/command-injection-in-nasa-cryptolib-cve-2025-59534
AISLE
Command Injection in NASA CryptoLib (CVE-2025-59534)
NASA's CryptoLib had a critical 3-year-old authentication flaw. AISLE's AI detected it and helped ship CVE-2025-59534 fix in just 4 days.
🔥1
■■■■□ OSINT: Interesting thread on United States' 🇺🇸 attacker (Afghan national and traitor) that ambushed 2 national guard commandos.
https://x.com/AmyMek/status/1993977623773630766
https://x.com/AmyMek/status/1993977623773630766
X (formerly Twitter)
Amy Mek (@AmyMek) on X
🚨 NEW: The DC Attack Is Even More Explosive Than First Reported
(This post summarizes what multiple outlets, sources, and public reports are saying. I will update as more information comes out.)
Americans were initially told the shooter near the White House…
(This post summarizes what multiple outlets, sources, and public reports are saying. I will update as more information comes out.)
Americans were initially told the shooter near the White House…
Forwarded from cKure Red
https://securelist.com/tomiris-new-tools/118143/
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1🔥1👏1👌1
■■■□□ New Unauthenticated DoS Vulnerability Crashes Next.js Servers with a Single Request.
https://cybersecuritynews.com/next-js-servers-dos-vulnerability/
https://cybersecuritynews.com/next-js-servers-dos-vulnerability/
Cyber Security News
New Unauthenticated DoS Vulnerability Crashes Next.js Servers with a Single Request
A newly discovered critical vulnerability in the Next.js framework allows attackers to crash self-hosted servers using a single HTTP request, requiring negligible resources to execute.
😁3
■■■□□ Inside 💭 💭 💭 💭
Origins, Motives, and Methods of a Rapidly Expanding Hacktivist Collective.
ckure.org/archives/18075
Origins, Motives, and Methods of a Rapidly Expanding Hacktivist Collective.
ckure.org/archives/18075
Please open Telegram to view this post
VIEW IN TELEGRAM
❤4🔥3✍2
■■■■□ Dead Man’s Switch – Widespread npm Supply Chain Attack Driving Malware Attacks.
https://cybersecuritynews.com/dead-mans-switch-npm-supply-chain-attack/
https://cybersecuritynews.com/dead-mans-switch-npm-supply-chain-attack/
Cyber Security News
Dead Man’s Switch – Widespread npm Supply Chain Attack Driving Malware Attacks
GitLab uncovered a vulnerability large-scale supply chain attack spreading a destructive malware variant through the npm ecosystem.
■■■■□ Cyber-Attack by Iranian state sponsored hacker group.
The Hendala group announces that it sent flowers to an Israeli scientist, after gaining access to a system allegedly related to the Soreq nuclear center.
It is likely that the flower delivery was carried out by a local collaborator, who placed the bouquet inside the scientist's car and documented the action with several photos and videos.
The attackers publish several screenshots from the system, allegedly showing administrative access and exposure to information about various parties involved in the Seraph project at Soreq (particle accelerator).
The Hendala group announces that it sent flowers to an Israeli scientist, after gaining access to a system allegedly related to the Soreq nuclear center.
It is likely that the flower delivery was carried out by a local collaborator, who placed the bouquet inside the scientist's car and documented the action with several photos and videos.
The attackers publish several screenshots from the system, allegedly showing administrative access and exposure to information about various parties involved in the Seraph project at Soreq (particle accelerator).
■■□□□ Google Says Some VPN Apps Are Actually Dangerous Malware.
https://www.gizchina.com/google-2/google-says-some-vpn-apps-are-actually-dangerous-malware
https://www.gizchina.com/google-2/google-says-some-vpn-apps-are-actually-dangerous-malware
Gizchina
Google Says Some VPN Apps Are Actually Dangerous Malware
Google warns that malicious apps disguised as VPNs are stealing bank data and private messages. Learn how to protect yourself using Google Play Protect.
■■■■□ Thread actor "Sylhet Gang-SG" has targeted Moroccan Airlines website on their latest attack.
https://check-host.net/check-report/336a069cka52
https://check-host.net/check-report/336a069cka52
check-host.net
Check report was removed
: Check host - online website monitoring
: Check host - online website monitoring
Check report was removed:
website monitoring with useful tools, Check IP, Check website
website monitoring with useful tools, Check IP, Check website