βFerocious Kitten APT Uses MarkiRAT for Keystroke and Clipboard Surveillance
https://gbhackers.com/ferocious-kitten-apt/
https://gbhackers.com/ferocious-kitten-apt/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Ferocious Kitten APT Uses MarkiRAT for Keystroke and Clipboard Surveillance
Ferocious Kitten, a covert cyber-espionage group active since at least 2015, has emerged as a persistent threat to Persian-speaking dissidents and activists within Iran.
βNorth Korea-linked Konni APT used Google Find Hub to erase data and spy on defectors
https://securityaffairs.com/184474/intelligence/north-korea-konni-apt-used-google-find-hub-to-erase-data-and-spy-on-defectors.html
https://securityaffairs.com/184474/intelligence/north-korea-konni-apt-used-google-find-hub-to-erase-data-and-spy-on-defectors.html
Security Affairs
North Korea-linked Konni APT used Google Find Hub to erase data and spy on defectors
North Korea-linked APT Konni posed as counselors to steal data and wipe Android phones via Google Find Hub in Sept 2025.
βNew Phishing Campaign Targets Meta Business Suite Users
https://gbhackers.com/meta-business-suite/
https://gbhackers.com/meta-business-suite/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
New Phishing Campaign Targets Meta Business Suite Users
With more than 5.4 billion social media users worldwide, Facebook remains a critical marketing channel for businesses of all sizes.
βNew βKomeXβ Android RAT Hits Hacker Forums with Tiered Subscriptions
https://gbhackers.com/komex-android-rat/
https://gbhackers.com/komex-android-rat/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
New βKomeXβ Android RAT Hits Hacker Forums with Tiered Subscriptions
A sophisticated Android remote-access trojan named KomeX RAT has emerged on underground hacking forums.
βSAP Releases Security Update to Fix Critical Code Execution and Injection Flaws
https://gbhackers.com/sap-releases-security-update-to-fix-critical-code-execution/
https://gbhackers.com/sap-releases-security-update-to-fix-critical-code-execution/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
SAP Releases Security Update to Fix Critical Code Execution and Injection Flaws
SAP has released an update addressing 18 new vulnerabilities, including several critical flaws related to code execution and data injection.
βWinRAR Vulnerability Exploited by APT-C-08 to Target Government Agencies
https://gbhackers.com/winrar-vulnerability-2/
https://gbhackers.com/winrar-vulnerability-2/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
WinRAR Vulnerability Exploited by APT-C-08 to Target Government Agencies
The notorious APT-C-08 hacking group, also known as BITTER, has been observed weaponizing a critical WinRAR directory traversal vulnerability.
βZoom Workplace for Windows Flaw Allows Local Privilege Escalation
https://gbhackers.com/zoom-workplace-for-windows-flaw/
https://gbhackers.com/zoom-workplace-for-windows-flaw/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Zoom Workplace for Windows Flaw Allows Local Privilege Escalation
A security vulnerability has been discovered in Zoom Workplace's VDI Client for Windows that could allow attackers to escalate their privileges.
βFantasy Hub: Russian-sold Android RAT boasts full device espionage as MaaS
https://securityaffairs.com/184488/malware/fantasy-hub-russian-sold-android-rat-boasts-full-device-espionage-as-maas.html
https://securityaffairs.com/184488/malware/fantasy-hub-russian-sold-android-rat-boasts-full-device-espionage-as-maas.html
Security Affairs
Fantasy Hub: Russian-sold Android RAT boasts full device espionage as MaaS
Researchers found Fantasy Hub, a Russian MaaS Android RAT that lets attackers spy, steal data, and control devices via Telegram.
βSeeing Inside the Vortex: Detecting Living off the Land Techniques
https://blogs.cisco.com/security/seeing-inside-the-vortex-detecting-living-off-the-land-techniques/
https://blogs.cisco.com/security/seeing-inside-the-vortex-detecting-living-off-the-land-techniques/
Cisco Blogs
Seeing Inside the Vortex: Detecting Living off the Land Techniques
Networking infrastructure is an often-overlooked threat surface being targeted by sophisticated threat actors. Learn more about this topic.
βWhat is the Pixnapping vulnerability, and how to protect your Android smartphone? | Kaspersky official blog
https://www.kaspersky.com/blog/pixnapping-cve-2025-48561/54756/
https://www.kaspersky.com/blog/pixnapping-cve-2025-48561/54756/
Kaspersky official blog
What is the Pixnapping vulnerability, and how to protect your Android smartphone?
The Android vulnerability CVE-2025-48561 (Pixnapping) enables the theft of any data displayed on a smartphone's screen. We explain how Pixnapping works and provide advice on mitigating the risk.
βIvanti Endpoint Manager Vulnerabilities Let Attackers Write Files Anywhere on Target Systems
https://gbhackers.com/ivanti-endpoint-manager-vulnerabilities-3/
https://gbhackers.com/ivanti-endpoint-manager-vulnerabilities-3/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Ivanti Endpoint Manager Vulnerabilities Let Attackers Write Files Anywhere on Target Systems
Ivanti has released critical security updates for Ivanti Endpoint Manager to address three high-severity vulnerabilities.
βThe November 2025 Security Update Review
https://www.thezdi.com/blog/2025/11/11/the-november-2025-security-update-review
https://www.thezdi.com/blog/2025/11/11/the-november-2025-security-update-review
Zero Day Initiative
Zero Day Initiative β The November 2025 Security Update Review
Iβve made it through Pwn2Own Ireland , and while many are celebrated those who served their country in the armed services, patch Tuesday stops for no one. So affix your poppy accordingly, and letβs take a look at the latest security offerings from Adobeβ¦
β€1
βHitachi subsidiary GlobalLogic impacted by Clopβs attack spree on Oracle customers
https://cyberscoop.com/globallogic-oracle-clop-attacks/
https://cyberscoop.com/globallogic-oracle-clop-attacks/
CyberScoop
Hitachi subsidiary GlobalLogic impacted by Clopβs attack spree on Oracle customers
The digital engineering services firm said human resources data on nearly 10,500 current and former employees was exposed.
βMicrosoft Patch Tuesday addresses 63 defects, including one actively exploited zero-day
https://cyberscoop.com/microsoft-patch-tuesday-november-2025/
https://cyberscoop.com/microsoft-patch-tuesday-november-2025/
CyberScoop
Microsoft Patch Tuesday addresses 63 defects, including one actively exploited zero-day
Researchers warn that although exploitation of the zero-day is complex, a functional exploit exists in the wild.
βWikipedia Fights Back: Paid API Launches as AI Traffic Steals 8% of Human Visitors
https://securityonline.info/wikipedia-fights-back-paid-api-launches-as-ai-traffic-steals-8-of-human-visitors/
https://securityonline.info/wikipedia-fights-back-paid-api-launches-as-ai-traffic-steals-8-of-human-visitors/
Daily CyberSecurity
Wikipedia Fights Back: Paid API Launches as AI Traffic Steals 8% of Human Visitors
Wikipedia launches a paid API for AI companies to stop web scraping and generate revenue after sophisticated AI crawlers caused an 8% drop in human traffic.
βAI Boom Creates 2-Year HDD Backlog, Forcing Shift to QLC SSDs and Price Hikes
https://securityonline.info/ai-boom-creates-2-year-hdd-backlog-forcing-shift-to-qlc-ssds-and-price-hikes/
https://securityonline.info/ai-boom-creates-2-year-hdd-backlog-forcing-shift-to-qlc-ssds-and-price-hikes/
Daily CyberSecurity
AI Boom Creates 2-Year HDD Backlog, Forcing Shift to QLC SSDs and Price Hikes
AI demand caused a 2-year backlog for hard drives, forcing data centers to buy QLC SSDs. This shift threatens consumer SSD supply and drives up memory prices.
βNew Android Rule: Google to Flag Battery-Draining Apps on Play Store Listings
https://securityonline.info/new-android-rule-google-to-flag-battery-draining-apps-on-play-store-listings/
https://securityonline.info/new-android-rule-google-to-flag-battery-draining-apps-on-play-store-listings/
Daily CyberSecurity
New Android Rule: Google to Flag Battery-Draining Apps on Play Store Listings
Google launches the "Excessive Wake Lock" metric. Apps that overuse wake locks (over 2 hours in 24 hrs) will get a red battery drain warning on the Play Store starting Mar 2026.
βGalaxy S26 Standard Model Gets Thicker: Hinting at a Possible Battery Upgrade
https://securityonline.info/galaxy-s26-standard-model-gets-thicker-hinting-at-a-possible-battery-upgrade/
https://securityonline.info/galaxy-s26-standard-model-gets-thicker-hinting-at-a-possible-battery-upgrade/
Daily CyberSecurity
Galaxy S26 Standard Model Gets Thicker: Hinting at a Possible Battery Upgrade
Samsung reportedly made last-minute Galaxy S26 dimension changes, making it slightly thicker. This suggests a potential battery upgrade for the standard model.
βMeta Open-Sources Omnilingual ASR: State-of-the-Art Speech Recognition for 1,600+ Languages
https://securityonline.info/meta-open-sources-omnilingual-asr-state-of-the-art-speech-recognition-for-1600-languages/
https://securityonline.info/meta-open-sources-omnilingual-asr-state-of-the-art-speech-recognition-for-1600-languages/
Daily CyberSecurity
Meta Open-Sources Omnilingual ASR: State-of-the-Art Speech Recognition for 1,600+ Languages
Meta's FAIR team open-sourced Omnilingual ASR, an LLM-based system offering SOTA speech recognition for 1,600+ languages, including a "Bring Your Own Language" feature.