Category: Uncategorized
-

NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of a new fully-featured Windows backdoor called NANOREMOTE that uses the Google Drive API for command-and-control (C2) purposes. According to a report from Elastic Security Labs, the malware shares code similarities with another implant codenamed FINALDRAFT (aka Squidoor) that employs Microsoft Graph API for C2. FINALDRAFT is attributed to aRead…
-

The Impact of Robotic Process Automation (RPA) on Identity and Access Management [email protected] (The Hacker News)
As enterprises refine their strategies for handling Non-Human Identities (NHIs), Robotic Process Automation (RPA) has become a powerful tool for streamlining operations and enhancing security. However, since RPA bots have varying levels of access to sensitive information, enterprises must be prepared to mitigate a variety of challenges. In large organizations, bots are starting to outnumberRead…
-

WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor [email protected] (The Hacker News)
An advanced persistent threat (APT) known as WIRTE has been attributed to attacks targeting government and diplomatic entities across the Middle East with a previously undocumented malware suite dubbed AshTag since 2020. Palo Alto Networks is tracking the activity cluster under the name Ashen Lepus. Artifacts uploaded to the VirusTotal platform show that the threat…
-

Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active Attacks [email protected] (The Hacker News)
A high-severity unpatched security vulnerability in Gogs has come under active exploitation, with more than 700 compromised instances accessible over the internet, according to new findings from Wiz. The flaw, tracked as CVE-2025-8110 (CVSS score: 8.7), is a case of file overwrite in the file update API of the Go-based self-hosted Git service. A fix…
-

Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw [email protected] (The Hacker News)
Google on Wednesday shipped security updates for its Chrome browser to address three security flaws, including one it said has come under active exploitation in the wild. The vulnerability, rated high in severity, is being tracked under the Chromium issue tracker ID “466192044.” Unlike other disclosures, Google has opted to keep information about the CVE…
-

Active Attacks Exploit Gladinet’s Hard-Coded Keys for Unauthorized Access and Code Execution [email protected] (The Hacker News)
Huntress is warning of a new actively exploited vulnerability in Gladinet’s CentreStack and Triofox products stemming from the use of hard-coded cryptographic keys that have affected nine organizations so far. “Threat actors can potentially abuse this as a way to access the web.config file, opening the door for deserialization and remote code execution,” security researcher…
-

React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors [email protected] (The Hacker News)
React2Shell continues to witness heavy exploitation, with threat actors leveraging the maximum-severity security flaw in React Server Components (RSC) to deliver cryptocurrency miners and an array of previously undocumented malware families, according to new findings from Huntress. This includes a Linux backdoor called PeerBlight, a reverse proxy tunnel named CowTunnel, and a Go-basedRead More
-
Beyond the SBOM: What CISOs should know about CBOMs and HBOMs
SBOMs, CBOMs and HBOMS — oh my! Learn how these bills of materials help manage supply chain risk and assess which of the three your organization needs.Read More
-

.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL [email protected] (The Hacker News)
New research has uncovered exploitation primitives in the .NET Framework that could be leveraged against enterprise-grade applications to achieve remote code execution. WatchTowr Labs, which has codenamed the “invalid cast vulnerability” SOAPwn, said the issue impacts Barracuda Service Center RMM, Ivanti Endpoint Manager (EPM), and Umbraco 8. But the number of affected vendors is likely…
-

Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling [email protected] (The Hacker News)
Three security vulnerabilities have been disclosed in the Peripheral Component Interconnect Express (PCIe) Integrity and Data Encryption (IDE) protocol specification that could expose a local attacker to serious risks. The flaws impact PCIe Base Specification Revision 5.0 and onwards in the protocol mechanism introduced by the IDE Engineering Change Notice (ECN), according to the PCI…
