TECHZONE™
رفتن به کانال در Telegram
TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news
نمایش بیشتر596
مشترکین
اطلاعاتی وجود ندارد24 ساعت
-37 روز
-1130 روز
آرشیو پست ها
596
China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services
https://thehackernews.com/2025/11/china-linked-apt31-launches-stealthy.html
The China-linked advanced persistent threat (APT) group known as APT31 has been attributed to cyber attacks targeting the Russian information technology (IT) sector between 2024 and 2025 while staying undetected for extended periods of time.
"In the period from 2024 to 2025, the Russian IT sector, especially companies working as contractors and integrators of solutions for government agencies,
596
Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks
https://thehackernews.com/2025/11/matrix-push-c2-uses-browser.html
Bad actors are leveraging browser notifications as a vector for phishing attacks to distribute malicious links by means of a new command-and-control (C2) platform called Matrix Push C2.
"This browser-native, fileless framework leverages push notifications, fake alerts, and link redirects to target victims across operating systems," Blackfog researcher Brenda Robb said in a Thursday report.
In
596
CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability
https://thehackernews.com/2025/11/cisa-warns-of-actively-exploited.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting Oracle Identity Manager to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability in question is CVE-2025-61757 (CVSS score: 9.8), a case of missing authentication for a critical function that can result in pre-authenticated
596
Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation
https://thehackernews.com/2025/11/grafana-patches-cvss-100-scim-flaw.html
Grafana has released security updates to address a maximum severity security flaw that could allow privilege escalation or user impersonation under certain configurations.
The vulnerability, tracked as CVE-2025-41115, carries a CVSS score of 10.0. It resides in the System for Cross-domain Identity Management (SCIM) component that allows automated user provisioning and management. First
596
Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security
https://thehackernews.com/2025/11/google-adds-airdrop-compatibility-to.html
In a surprise move, Google on Thursday announced that it has updated Quick Share, its peer-to-peer file transfer service, to work with Apple's equipment AirDrop, allowing users to more easily share files and photos between Android and iPhone devices.
The cross-platform sharing feature is currently limited to the Pixel 10 lineup and works with iPhone, iPad, and macOS devices, with plans to expand
596
Why IT Admins Choose Samsung for Mobile Security
https://thehackernews.com/2025/11/why-it-admins-choose-samsung-for-mobile.html
Ever wonder how some IT teams keep corporate data safe without slowing down employees? Of course you have.
Mobile devices are essential for modern work—but with mobility comes risk. IT admins, like you, juggle protecting sensitive data while keeping teams productive. That’s why more enterprises are turning to Samsung for mobile security.
Hey—you're busy, so here's a quick-read article on what
596
APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ Domains
https://thehackernews.com/2025/11/apt24-deploys-badaudio-in-years-long.html
A China-nexus threat actor known as APT24 has been observed using a previously undocumented malware dubbed BADAUDIO to establish persistent remote access to compromised networks as part of a nearly three-year campaign.
"While earlier operations relied on broad strategic web compromises to compromise legitimate websites, APT24 has recently pivoted to using more sophisticated vectors targeting
596
SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny
https://thehackernews.com/2025/11/sec-drops-solarwinds-case-after-years.html
The U.S. Securities and Exchange Commission (SEC) has abandoned its lawsuit against SolarWinds and its chief information security officer, alleging that the company had misled investors about the security practices that led to the 2020 supply chain attack.
In a joint motion filed November 20, 2025, the SEC, along with SolarWinds and its CISO Timothy G. Brown, asked the court to voluntarily
596
Salesforce Flags Unauthorized Data Access via Gainsight-Linked OAuth Activity
https://thehackernews.com/2025/11/salesforce-flags-unauthorized-data.html
Salesforce has warned of detected "unusual activity" related to Gainsight-published applications connected to the platform.
"Our investigation indicates this activity may have enabled unauthorized access to certain customers’ Salesforce data through the app's connection," the company said in an advisory.
The cloud services firm said it has taken the step of revoking all active access and refresh
596
The OSINT playbook: Find your weak spots before attackers do
https://www.welivesecurity.com/en/privacy/osint-playbook-find-weak-spots-attackers-do/
Here’s how open-source intelligence helps trace your digital footprint and uncover your weak points, plus a few essential tools to connect the dots
596
Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt
https://thehackernews.com/2025/11/iran-linked-hackers-mapped-ship-ais.html
Threat actors with ties to Iran engaged in cyber warfare as part of efforts to facilitate and enhance physical, real-world attacks, a trend that Amazon has called cyber-enabled kinetic targeting.
The development is a sign that the lines between state-sponsored cyber attacks and kinetic warfare are increasingly blurring, necessitating the need for a new category of warfare, the tech giant's
596
PlushDaemon compromises network devices for adversary-in-the-middle attacks
https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/
ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks
596
TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign
https://thehackernews.com/2025/11/tamperedchef-malware-spreads-via-fake.html
Threat actors are leveraging bogus installers masquerading as popular software to trick users into installing malware as part of a global malvertising campaign dubbed TamperedChef.
The end goal of the attacks is to establish persistence and deliver JavaScript malware that facilitates remote access and control, per a new report from Acronis Threat Research Unit (TRU). The campaign, per the
596
Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)
https://thehackernews.com/2025/11/hackers-actively-exploiting-7-zip.html
A recently disclosed security flaw impacting 7-Zip has come under active exploitation in the wild, according to an advisory issued by the U.K. NHS England Digital on Tuesday.
The vulnerability in question is CVE-2025-11001 (CVSS score: 7.0), which allows remote attackers to execute arbitrary code. It has been addressed in 7-Zip version 25.00 released in July 2025.
"The specific flaw exists
596
Python-Based WhatsApp Worm Spreads Eternidade Stealer Across Brazilian Devices
https://thehackernews.com/2025/11/python-based-whatsapp-worm-spreads.html
Cybersecurity researchers have disclosed details of a new campaign that leverages a combination of social engineering and WhatsApp hijacking to distribute a Delphi-based banking trojan named Eternidade Stealer as part of attacks targeting users in Brazil.
"It uses Internet Message Access Protocol (IMAP) to dynamically retrieve command-and-control (C2) addresses, allowing the threat actor to
596
WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide
https://thehackernews.com/2025/11/wrthug-exploits-six-asus-wrt-flaws-to.html
A newly discovered campaign has compromised tens of thousands of outdated or end-of-life (EoL) ASUS routers worldwide, predominantly in Taiwan, the U.S., and Russia, to rope them into a massive network.
The router hijacking activity has been codenamed Operation WrtHug by SecurityScorecard's STRIKE team. Southeast Asia and European countries are some of the other regions where infections have
596
Application Containment: How to Use Ringfencing to Prevent the Weaponization of Trusted Software
https://thehackernews.com/2025/11/application-containment-how-to-use.html
The challenge facing security leaders is monumental: Securing environments where failure is not an option. Reliance on traditional security postures, such as Endpoint Detection and Response (EDR) to chase threats after they have already entered the network, is fundamentally risky and contributes significantly to the half-trillion-dollar annual cost of cybercrime.
Zero Trust fundamentally shifts
596
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates
https://thehackernews.com/2025/11/edgestepper-implant-reroutes-dns.html
The threat actor known as PlushDaemon has been observed using a previously undocumented Go-based network backdoor codenamed EdgeStepper to facilitate adversary-in-the-middle (AitM) attacks.
EdgeStepper "redirects all DNS queries to an external, malicious hijacking node, effectively rerouting the traffic from legitimate infrastructure used for software updates to attacker-controlled infrastructure
596
ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts
https://thehackernews.com/2025/11/servicenow-ai-agents-can-be-tricked.html
Malicious actors can exploit default configurations in ServiceNow's Now Assist generative artificial intelligence (AI) platform and leverage its agentic capabilities to conduct prompt injection attacks.
The second-order prompt injection, according to AppOmni, makes use of Now Assist's agent-to-agent discovery to execute unauthorized actions, enabling attackers to copy and exfiltrate sensitive
596
Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited in the Wild
https://thehackernews.com/2025/11/fortinet-warns-of-new-fortiweb-cve-2025.html
Fortinet has warned of a new security flaw in FortiWeb that it said has been exploited in the wild.
The medium-severity vulnerability, tracked as CVE-2025-58034, carries a CVSS score of 6.7 out of a maximum of 10.0.
"An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb may allow an authenticated attacker to execute
اکنون در دسترس! پژوهش تلگرام ۲۰۲۵ — مهمترین بینشهای سال 
