TECHZONE™
رفتن به کانال در Telegram
TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news
نمایش بیشتر595
مشترکین
-124 ساعت
-37 روز
-1230 روز
آرشیو پست ها
595
Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
https://thehackernews.com/2025/07/scattered-spider-hijacks-vmware-esxi-to.html
The notorious cybercrime group known as Scattered Spider is targeting VMware ESXi hypervisors in attacks targeting retail, airline, and transportation sectors in North America.
"The group's core tactics have remained consistent and do not rely on software exploits. Instead, they use a proven playbook centered on phone calls to an IT help desk," Google's Mandiant team said in an extensive
595
Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems Worldwide
https://thehackernews.com/2025/07/critical-flaws-in-niagara-framework.html
Cybersecurity researchers have discovered over a dozen security vulnerabilities impacting Tridium's Niagara Framework that could allow an attacker on the same network to compromise the system under certain circumstances.
"These vulnerabilities are fully exploitable if a Niagara system is misconfigured, thereby disabling encryption on a specific network device," Nozomi Networks Labs said in a
595
SharePoint under fire: ToolShell attacks hit organizations worldwide
https://www.welivesecurity.com/en/videos/sharepoint-under-fire-toolshell-attacks-hit-organizations-worldwide/
The ToolShell bugs are being exploited by cybercriminals and APT groups alike, with the US on the receiving end of 13 percent of all attacks
595
U.S. Sanctions Firm Behind N. Korean IT Scheme; Arizona Woman Jailed for Running Laptop Farm
https://thehackernews.com/2025/07/us-sanctions-firm-behind-n-korean-it.html
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned a North Korean front company and three associated individuals for their involvement in the fraudulent remote information technology (IT) worker scheme designed to generate illicit revenues for Pyongyang.
The sanctions target Korea Sobaeksu Trading Company (aka Sobaeksu United Corporation), and Kim Se Un, Jo
595
Patchwork Targets Turkish Defense Firms with Spear-Phishing Using Malicious LNK Files
https://thehackernews.com/2025/07/patchwork-targets-turkish-defense-firms.html
The threat actor known as Patchwork has been attributed to a new spear-phishing campaign targeting Turkish defense contractors with the goal of gathering strategic intelligence.
"The campaign employs a five-stage execution chain delivered via malicious LNK files disguised as conference invitations sent to targets interested in learning more about unmanned vehicle systems," Arctic Wolf Labs said
595
Cyber Espionage Campaign Hits Russian Aerospace Sector Using EAGLET Backdoor
https://thehackernews.com/2025/07/cyber-espionage-campaign-hits-russian.html
Russian aerospace and defense industries have become the target of a cyber espionage campaign that delivers a backdoor called EAGLET to facilitate data exfiltration.
The activity, dubbed Operation CargoTalon, has been assigned to a threat cluster tracked as UNG0901 (short for Unknown Group 901).
"The campaign is aimed at targeting employees of Voronezh Aircraft Production Association (VASO), one
595
Soco404 and Koske Malware Target Cloud Services with Cross-Platform Cryptomining Attacks
https://thehackernews.com/2025/07/soco404-and-koske-malware-target-cloud.html
Threat hunters have disclosed two different malware campaigns that have targeted vulnerabilities and misconfigurations across cloud environments to deliver cryptocurrency miners.
The threat activity clusters have been codenamed Soco404 and Koske by cloud security firms Wiz and Aqua, respectively.
Soco404 "targets both Linux and Windows systems, deploying platform-specific malware," Wiz
595
Overcoming Risks from Chinese GenAI Tool Usage
https://thehackernews.com/2025/07/overcoming-risks-from-chinese-genai.html
A recent analysis of enterprise data suggests that generative AI tools developed in China are being used extensively by employees in the US and UK, often without oversight or approval from security teams. The study, conducted by Harmonic Security, also identifies hundreds of instances in which sensitive data was uploaded to platforms hosted in China, raising concerns over compliance, data
595
ToolShell: An all-you-can-eat buffet for threat actors
https://www.welivesecurity.com/en/eset-research/toolshell-an-all-you-can-eat-buffet-for-threat-actors/
ESET Research has been monitoring attacks involving the recently discovered ToolShell zero-day vulnerabilities
595
Rogue CAPTCHAs: Look out for phony verification pages spreading malware
https://www.welivesecurity.com/en/cybersecurity/rogue-captchas-look-out-phony-verification-pages-spreading-malware/
Before rushing to prove that you're not a robot, be wary of deceptive human verification pages as an increasingly popular vector for delivering malware
595
Critical Mitel Flaw Lets Hackers Bypass Login, Gain Full Access to MiVoice MX-ONE Systems
https://thehackernews.com/2025/07/critical-mitel-flaw-lets-hackers-bypass.html
Mitel has released security updates to address a critical security flaw in MiVoice MX-ONE that could allow an attacker to bypass authentication protections.
"An authentication bypass vulnerability has been identified in the Provisioning Manager component of Mitel MiVoice MX-ONE, which, if successfully exploited, could allow an unauthenticated attacker to conduct an authentication bypass attack
595
Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments
https://thehackernews.com/2025/07/fire-ant-exploits-vmware-flaw-to.html
Virtualization and networking infrastructure have been targeted by a threat actor codenamed Fire Ant as part of a prolonged cyber espionage campaign.
The activity, observed this year, is primarily designed Now to infiltrate organizations' VMware ESXi and vCenter environments as well as network appliances, Sygnia said in a new report published today.
"The threat actor leveraged combinations of
595
CastleLoader Malware Infects 469 Devices Using Fake GitHub Repos and ClickFix Phishing
https://thehackernews.com/2025/07/castleloader-malware-infects-469.html
Cybersecurity researchers have shed light on a new versatile malware loader called CastleLoader that has been put to use in campaigns distributing various information stealers and remote access trojans (RATs).
The activity employs Cloudflare-themed ClickFix phishing attacks and fake GitHub repositories opened under the names of legitimate applications, Swiss cybersecurity company PRODAFT said in
595
Sophos and SonicWall Patch Critical RCE Flaws Affecting Firewalls and SMA 100 Devices
https://thehackernews.com/2025/07/sophos-and-sonicwall-patch-critical-rce.html
Sophos and SonicWall have alerted users of critical security flaws in Sophos Firewall and Secure Mobile Access (SMA) 100 Series appliances that could be exploited to achieve remote code execution.
The two vulnerabilities impacting Sophos Firewall are listed below -
CVE-2025-6704 (CVSS score: 9.8) - An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature can lead
595
Watch This Webinar to Uncover Hidden Flaws in Login, AI, and Digital Trust — and Fix Them
https://thehackernews.com/2025/07/watch-this-webinar-to-uncover-hidden.html
Is Managing Customer Logins and Data Giving You Headaches? You're Not Alone!
Today, we all expect super-fast, secure, and personalized online experiences. But let's be honest, we're also more careful about how our data is used. If something feels off, trust can vanish in an instant. Add to that the lightning-fast changes AI is bringing to everything from how we log in to spotting online fraud,
595
Pentests once a year? Nope. It’s time to build an offensive SOC
https://thehackernews.com/2025/07/pentests-once-year-nope-its-time-to.html
You wouldn’t run your blue team once a year, so why accept this substandard schedule for your offensive side?
Your cybersecurity teams are under intense pressure to be proactive and to find your network’s weaknesses before adversaries do. But in many organizations, offensive security is still treated as a one-time event: an annual pentest, a quarterly red team engagement, maybe an audit sprint
595
China-Based APTs Deploy Fake Dalai Lama Apps to Spy on Tibetan Community
https://thehackernews.com/2025/07/china-based-apts-deploy-fake-dalai-lama.html
The Tibetan community has been targeted by a China-nexus cyber espionage group as part of two campaigns conducted last month ahead of the Dalai Lama's 90th birthday on July 6, 2025.
The multi-stage attacks have been codenamed Operation GhostChat and Operation PhantomPrayers by Zscaler ThreatLabz.
"The attackers compromised a legitimate website, redirecting users via a malicious link and
595
Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems
https://thehackernews.com/2025/07/storm-2603-exploits-sharepoint-flaws-to.html
Microsoft has revealed that one of the threat actors behind the active exploitation of SharePoint flaws is deploying Warlock ransomware on targeted systems.
The tech giant, in an update shared Wednesday, said the findings are based on an "expanded analysis and threat intelligence from our continued monitoring of exploitation activity by Storm-2603."
The threat actor attributed to the financially
595
Europol Arrests XSS Forum Admin in Kyiv After 12-Year Run Operating Cybercrime Marketplace
https://thehackernews.com/2025/07/europol-arrests-xss-forum-admin-in-kyiv.html
Europol on Monday announced the arrest of the suspected administrator of XSS.is (formerly DaMaGeLaB), a notorious Russian-speaking cybercrime platform.
The arrest, which took place in Kyiv, Ukraine, on July 222, 2025, was led by the French Police and Paris Prosecutor, in collaboration with Ukrainian authorities and Europol. The action is the result of an investigation that was launched by the
595
Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access
https://thehackernews.com/2025/07/hackers-deploy-stealth-backdoor-in.html
Cybersecurity researchers have uncovered a new stealthy backdoor concealed within the "mu-plugins" directory in WordPress sites to grant threat actors persistent access and allow them to perform arbitrary actions.
Must-use plugins (aka mu-plugins) are special plugins that are automatically activated on all WordPress sites in the installation. They are located in the "wp-content/mu-plugins"
اکنون در دسترس! پژوهش تلگرام ۲۰۲۵ — مهمترین بینشهای سال 
