TECHZONE™
前往频道在 Telegram
TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news
显示更多596
订阅者
-124 小时
-37 天
-1130 天
帖子存档
596
WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability
https://thehackernews.com/2025/12/watchguard-warns-of-active-exploitation.html
WatchGuard has released fixes to address a critical security flaw in Fireware OS that it said has been exploited in real-world attacks.
Tracked as CVE-2025-14733 (CVSS score: 9.3), the vulnerability has been described as a case of out-of-bounds write affecting the iked process that could allow a remote unauthenticated attacker to execute arbitrary code.
"This vulnerability affects both the
596
Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks
https://thehackernews.com/2025/12/nigeria-arrests-raccoono365-phishing.html
Authorities in Nigeria have announced the arrest of three "high-profile internet fraud suspects" who are alleged to have been involved in phishing attacks targeting major corporations, including the main developer behind the RaccoonO365 phishing-as-a-service (PhaaS) scheme.
The Nigeria Police Force National Cybercrime Centre (NPF–NCCC) said investigations conducted in collaboration with
596
New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards
https://thehackernews.com/2025/12/new-uefi-flaw-enables-early-boot-dma.html
Certain motherboard models from vendors like ASRock, ASUSTeK Computer, GIGABYTE, and MSI are affected by a security vulnerability that leaves them susceptible to early-boot direct memory access (DMA) attacks across architectures that implement a Unified Extensible Firmware Interface (UEFI) and input–output memory management unit (IOMMU).
UEFI and IOMMU are designed to enforce a security
596
China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
https://thehackernews.com/2025/12/china-aligned-threat-group-uses-windows.html
A previously undocumented China-aligned threat cluster dubbed LongNosedGoblin has been attributed to a series of cyber attacks targeting governmental entities in Southeast Asia and Japan.
The end goal of these attacks is cyber espionage, Slovak cybersecurity company ESET said in a report published today. The threat activity cluster has been assessed to be active since at least September 2023.
"
596
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
https://thehackernews.com/2025/12/hpe-oneview-flaw-rated-cvss-100-allows.html
Hewlett Packard Enterprise (HPE) has resolved a maximum-severity security flaw in OneView Software that, if successfully exploited, could result in remote code execution.
The critical vulnerability, assigned the CVE identifier CVE-2025-37164, carries a CVSS score of 10.0. HPE OneView is an IT infrastructure management software that streamlines IT operations and controls all systems via a
596
ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories
https://thehackernews.com/2025/12/threatsday-bulletin-whatsapp-hijacks.html
This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could come from.
From shifting infrastructures to clever social hooks, the week’s activity shows just how fluid the threat landscape has become.
Here’s the full rundown of what
596
North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft
https://thehackernews.com/2025/12/north-korea-linked-hackers-steal-202.html
Threat actors with ties to the Democratic People's Republic of Korea (DPRK or North Korea) have been instrumental in driving a surge in global cryptocurrency theft in 2025, accounting for at least $2.02 billion out of more than $3.4 billion stolen from January through early December.
The figure represents a 51% increase year-over-year and $681 million more than 2024, when the threat actors stole
596
The Case for Dynamic AI-SaaS Security as Copilots Scale
https://thehackernews.com/2025/12/the-case-for-dynamic-ai-saas-security.html
Within the past year, artificial intelligence copilots and agents have quietly permeated the SaaS applications businesses use every day. Tools like Zoom, Slack, Microsoft 365, Salesforce, and ServiceNow now come with built-in AI assistants or agent-like features. Virtually every major SaaS vendor has rushed to embed AI into their offerings.
The result is an explosion of AI capabilities across
596
Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App
https://thehackernews.com/2025/12/kimsuky-spreads-docswap-android-malware.html
The North Korean threat actor known as Kimsuky has been linked to a new campaign that distributes a new variant of Android malware called DocSwap via QR codes hosted on phishing sites mimicking Seoul-based logistics firm CJ Logistics (formerly CJ Korea Express).
"The threat actor leveraged QR codes and notification pop-ups to lure victims into installing and executing the malware on their mobile
596
CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation
https://thehackernews.com/2025/12/cisa-flags-critical-asus-live-update.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting ASUS Live Update to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2025-59374 (CVSS score: 9.3), has been described as an "embedded malicious code vulnerability" introduced by means of a supply chain compromise
596
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances
https://thehackernews.com/2025/12/cisco-warns-of-active-attacks.html
Cisco has alerted users of a maximum-severity zero-day flaw in Cisco AsyncOS software that has been actively exploited by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686 in attacks targeting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.
The networking equipment major said it became aware of the intrusion campaign on December 10, 2025, and that it
596
SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances
https://thehackernews.com/2025/12/sonicwall-fixes-actively-exploited-cve.html
SonicWall has rolled out fixes to address a security flaw in Secure Mobile Access (SMA) 100 series appliances that it said has been actively exploited in the wild.
The vulnerability, tracked as CVE-2025-40602 (CVSS score: 6.6), concerns a case of local privilege escalation that arises as a result of insufficient authorization in the appliance management console (AMC).
It affects the following
596
Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks
https://thehackernews.com/2025/12/kimwolf-botnet-hijacks-18-million.html
A new distributed denial-of-service (DDoS) botnet known as Kimwolf has enlisted a massive army of no less than 1.8 million infected devices comprising Android-based TVs, set-top boxes, and tablets, and may be associated with another botnet known as AISURU, according to findings from QiAnXin XLab.
"Kimwolf is a botnet compiled using the NDK [Native Development Kit]," the company said in a report
596
APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign
https://thehackernews.com/2025/12/apt28-targets-ukrainian-ukr-net-users.html
The Russian state-sponsored threat actor known as APT28 has been attributed to what has been described as a "sustained" credential-harvesting campaign targeting users of UKR[.]net, a webmail and news service popular in Ukraine.
The activity, observed by Recorded Future's Insikt Group between June 2024 and April 2025, builds upon prior findings from the cybersecurity company in May 2024 that
596
New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails
https://thehackernews.com/2025/12/new-forumtroll-phishing-attacks-target.html
The threat actor linked to Operation ForumTroll has been attributed to a fresh set of phishing attacks targeting individuals within Russia, according to Kaspersky.
The Russian cybersecurity vendor said it detected the new activity in October 2025. The origins of the threat actor are presently unknown.
"While the spring cyberattacks focused on organizations, the fall campaign honed in on
596
Fix SOC Blind Spots: See Threats to Your Industry & Country in Real Time
https://thehackernews.com/2025/12/fix-soc-blind-spots-see-threats-to-your.html
Modern security teams often feel like they’re driving through fog with failing headlights. Threats accelerate, alerts multiply, and SOCs struggle to understand which dangers matter right now for their business. Breaking out of reactive defense is no longer optional. It’s the difference between preventing incidents and cleaning up after them.
Below is the path from reactive firefighting to a
596
China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT Malware
https://thehackernews.com/2025/12/china-linked-ink-dragon-hacks.html
The threat actor known as Jewelbug has been increasingly focusing on government targets in Europe since July 2025, even as it continues to attack entities located in Southeast Asia and South America.
Check Point Research is tracking the cluster under the name Ink Dragon. It's also referenced by the broader cybersecurity community under the names CL-STA-0049, Earth Alux, and REF7707. The
596
GhostPoster Malware Found in 17 Firefox Add-ons with 50,000+ Downloads
https://thehackernews.com/2025/12/ghostposter-malware-found-in-17-firefox.html
A new campaign named GhostPoster has leveraged logo files associated with 17 Mozilla Firefox browser add-ons to embed malicious JavaScript code designed to hijack affiliate links, inject tracking code, and commit click and ad fraud.
The extensions have been collectively downloaded over 50,000 times, according to Koi Security, which discovered the campaign. The add-ons are no longer available.
596
ESET Threat Report H2 2025
https://www.welivesecurity.com/en/eset-research/eset-threat-report-h2-2025/
A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts
596
Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign
https://thehackernews.com/2025/12/compromised-iam-credentials-power-large.html
An ongoing campaign has been observed targeting Amazon Web Services (AWS) customers using compromised Identity and Access Management (IAM) credentials to enable cryptocurrency mining.
The activity, first detected by Amazon's GuardDuty managed threat detection service and its automated security monitoring systems on November 2, 2025, employs never-before-seen persistence techniques to hamper
现已上线!2025 年 Telegram 研究 — 年度关键洞察 
