Sourcewww.cyber.gc.ca
Curated
Daily curated cyber threat intelligence for security professionals.
Sourcewww.cyber.gc.ca
Curated
Sourcewww.govinfosecurity.com
Curated
Hackers used AI-generated code to obfuscate malware in a phishing campaign. The attackers disguised the malicious code within a vector image file, using business-related language and terms to evade detection. Despite the complexity and verbosity of the AI-generated code, Microsoft detected and blocked the campaign using existing security methods.
Published
Iranian cyber group targets European companies with fake job offers
An Iranian cyber group named Nimbus Manticore, also known as MuddyWater, has been targeting European defense, telecom, and aerospace companies with fake job offers. According to a report by HackRead and research by Check Point Research, the group uses sophisticated malware to infiltrate these companies' networks. By enticing employees with deceptive job opportunities, Nimbus Manticore gains access to sensitive data and intellectual property, enabling espionage and potential operational disruptions. The advanced malware employed allows the group to evade detection and conduct prolonged malicious activities. This targeted cyber-espionage campaign poses significant risks to the security and confidentiality of sensitive data within these industries. Additionally, it raises concerns about potential disruptions to critical infrastructure. To mitigate these risks, employee training on recognizing phishing attempts and implementing robust network security protocols is recommended.
Published
Man arrested in connection with airport cyber-attacks
Published
Technical Analysis of Zloader Updates www.zscaler.com/blogs/sec…
Zloader (a.k.a. Terdot, DELoader, or Silent Night) is a Zeus-based modular trojan that emerged in 2015. Zloader was originally designed to facilitate banking, but has since been repurposed for initial access, providing an entry point into corporate environments for the deployment of ransomware. Following an almost two-year hiatus, Zloader reemerged in September 2023 with significant enhancements to its obfuscation techniques, domain generation algorithm (DGA), anti-analysis techniques and network communication, along with a stealthier approach to infections.
Published
Operation Rewrite: Chinese-Speaking Threat Actors Deploy BadIIS in a Wide Scale SEO Poisoning Campaign unit42.paloaltonetworks.com/operation…
In March 2025, we uncovered a search engine optimization (SEO) poisoning campaign. Based on the infrastructure and linguistic artifacts discovered, we assess with high confidence that a Chinese-speaking threat actor operates this campaign. We call this “Operation Rewrite” in reference to the English translation of one of the object names in the threat actor’s code.
We track this cluster of activity as CL-UNK-1037. Our analysis revealed infrastructure and architectural overlaps with the publicly tracked “Group 9” threat cluster and the “DragonRank” campaign.
To perform SEO poisoning, attackers manipulate search engine results to trick people into visiting unexpected or unwanted websites (e.g., gambling and porn websites) for financial gain. This attack used a malicious native Internet Information Services (IIS) module called BadIIS. This module intercepts and alters web traffic, using legitimate compromised servers to serve malicious content to visitors. The compromised web server then acts as a reverse proxy — an intermediary server getting content from other servers and presenting it as its own.
Published
GitHub moves to tighten npm security amid phishing, malware plague www.theregister.com/2025/09/2…
René-Corail also described changes that he hopes will strengthen security. Many existing authentication methods will be removed “in the near future,” including legacy classic tokens and one-time passwords for two-factor authentication (2FA). Token lifetimes will also be shortened, with a switch to trusted publishing and 2FA-enforced local publishing by default.
Published
New EDR-Freeze tool uses Windows WER to suspend security software www.bleepingcomputer.com/news/secu…
A new method and proof-of-concept tool called EDR-Freeze demonstrates that evading security solutions is possible from user mode with Microsoft’s Windows Error Reporting (WER) system.
The technique eliminates the need of a vulnerable driver and puts security agents like endpoint detection and response (EDR) tools into a state of hibernation.
By using the WER framework together with the MiniDumpWriteDump API, security researcher TwoSevenOneThree (Zero Salarium) found a way to suspend indefinitely the activity of EDR and antivirus processes indefinitely.
Published
Major Cyber Threat Detection Vendors Pull Out of MITRE Evaluations Test www.infosecurity-magazine.com/news/cybe…
However, MITRE’s Clancy said he is in close contact with the three vendors and believes he knows the reasons that made them pull out of this year’s test.
First, as the vendors said in their statements, taking part in MITRE ATT&CK Evaluations program requires a resource-intensive commitment, suggesting that the time and personnel dedicated to it are lost on other projects.
Then, Clancy said that the team behind the test strives to make it harder every year and conceded they may have pushed it too far this year.
“Each year, we want to design a test that’s harder than the year before in order to drive the whole industry forward, since the test can offer an opportunity for vendors to upgrade their products in preparation for the test and once they get the results. And sometimes, we don’t get the balance quite right,” he explained.
Published
Researchers Earn $150,000 for L1TF Exploit Leaking Data From Public Cloud www.securityweek.com/researche…
Last month, the academics reported L1TF Reloaded (PDF), a vulnerability that combines L1TF and half-Spectre to bypass commonly deployed software mitigations and leak sensitive data from the hypervisor and a co-tenant on Google Cloud.
“Using a novel technique based on pointer chasing through the host and guest, we leak all information required to manually perform two-dimensional page table walks in software; with this, we can translate arbitrary virtual guest addresses to host physical addresses, enabling the leakage of any byte in the memory of the victim via L1TF,” the academics note.
Paper at openreview.net/pdf
Published
CISA Shares Lessons Learned from an Incident Response Engagement www.cisa.gov/news-even…
CISA began incident response efforts at an FCEB agency after the agency identified potential malicious activity through security alerts generated by the agency’s endpoint detection and response (EDR) tool. CISA discovered cyber threat actors compromised the agency by exploiting CVE-2024-36401 in a GeoServer about three weeks prior to the EDR alerts. Over the three-week period, the cyber threat actors gained separate initial access to a second GeoServer via the same vulnerability and moved laterally to two other servers.
Published
Cloudflare mitigates new record-breaking 22.2 Tbps DDoS attack www.bleepingcomputer.com/news/secu…
Cloudflare has mitigated a distributed denial-of-service (DDoS) attack that peaked at a record-breaking 22.2 terabits per second (Tbps) and 10.6 billion packets per second (Bpps).
The latest DDoS incident, also volumentric, lasted 40 seconds and is by far the largest ever mitigated.
Published
Published
CISA has added two critical vulnerabilities in the Zabbix enterprise monitoring solution (CVE-2022-23131 and CVE-2022-23134) to its Known Exploited Vulnerabilities Catalog. These flaws—found in Zabbix Web Frontend—allow attackers to bypass authentication and gain admin privileges, potentially letting them execute arbitrary commands and compromise the monitored network. The vulnerabilities affect all supported versions before 5.4.8, 5.0.18, and 4.0.36, especially when SAML Single-Sign-On is enabled.
Proof-of-concept code is publicly available, and CISA warns that the vulnerabilities are being exploited in the wild. Patches are available, and agencies are directed to apply them within two weeks as per federal directives. Organizations should urgently update Zabbix Web Frontend to the fixed versions to mitigate risk.
Published
Summary: Chinese-speaking threat actor deploys BadIIS malware via SEO poisoning, redirecting traffic and planting web shells in East and Southeast Asia.
Published
Summary: ShadowV2 botnet exploits misconfigured AWS Docker containers, deploying Go-based malware for DDoS-for-hire using HTTP/2 Rapid Reset.
Published
Fifty Years of Open Source Software Supply-Chain Security cacm.acm.org/practice/…
The contours of the problems in software supply-chain security have not changed in half a century because they are fundamental. There are no easy answers in computer security; software supply-chain security is no exception. The best we can aim to do is keep improving our defenses, and many promising reinforcements are not yet universally deployed. This article aims to highlight promising approaches that should be more widely used as well as point out areas where more work is needed.
Published
Ransomware attack linked to museum break-in and theft of golden exhibits www.theregister.com/2025/09/2…
Dozens of French museums fell victim to a ransomware attack in August 2024, and the nation’s Natural History Museum copped another attack in July 2025.
The Museum’s systems were so damaged that it reportedly cancelled an exhibition.
Last week the Museum discovered that thieves had broken into its minerals display section by using an angle grinder to cut through a door, before wielding a blowtorch to open a case containing gold specimens worth about $705,000.
French media report the heist was possible because the July cyberattack broke the Museum’s alarms and video surveillance systems.
Published
Verified Steam game steals streamer’s cancer treatment donations www.bleepingcomputer.com/news/secu…
BlockBlasters is a 2D platformer that was available on Steam for almost two months, between July 30 and September 21. The game was safe until August 30, when a cryptodrainer component was added.
Published by developer Genesis Interactive and no longer on Steam, the retro-styled game was a free-to-play title promising fast-paced action on responsive controls, and had a few hundred ‘Very Positive’ reviews on the gaming platform.
Crypto investigator ZachXBT told BleepingComputer that the attackers appear to have stolen a total of $150,000 from 261 Steam accounts.
Published
Stellantis detects breach at third-party provider for North American customers www.reuters.com/sustainab…
Stellantis detected unauthorized access to a third-party service provider’s platform that supports its North American customer service operations, the company said in a statement on Sunday. The automaker said the incident, which is under investigation, exposed only basic contact information and did not involve financial details or sensitive personal data. Stellantis did not specify how many customers were affected.
Published
Nimbus Manticore Deploys New Malware Targeting Europe research.checkpoint.com/2025/nimb…
Check Point Research is tracking a long‑running campaign by the Iranian threat actor Nimbus Manticore, which overlaps with UNC1549, Smoke Sandstorm, and the “Iranian Dream Job” operations. The ongoing campaign targets defense manufacturing, telecommunications, and aviation that are aligned with IRGC strategic priorities. Nimbus Manticore’s recent activity indicates a heightened focus on Western Europe, specifically Denmark, Sweden, and Portugal. The threat actor impersonates local and global aerospace, defense manufacturing, and telecommunications organizations.The threat actor uses tailored spear‑phishing from alleged HR recruters directing victims to fake career portals. Each target receives a unique URL and credentials, enabling tracking and controlled access of each victim. This approach demonstrates strong OPSEC and credible pretexting.
Published
How to Gain Control of AI Agents and Non-Human Identities thehackernews.com/2025/09/h…
“We’ve got hundreds of service accounts and AI agents running in the background. We didn’t create most of them. We don’t know who owns them. How are we supposed to secure them?”
Every enterprise today runs on more than users. Behind the scenes, thousands of non-human identities, from service accounts to API tokens to AI agents, access systems, move data, and execute tasks around the clock.
They’re not new. But they’re multiplying fast. And most weren’t built with security in mind.
Published
A verified summary of cyber events disclosed or reported within the past 48 hours (Sept. 20–22, 2025 ET).

Published
Apple’s iPhone 17 cameras blend hardware and computational photography to push smartphone imaging further. This article explains what Apple really means by “8× optical-quality zoom” and why the iPhone Air’s “four cameras” are actually software-defined fields of view, helping buyers set realistic expectations.
Published
UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware thehackernews.com/2025/09/u…
An Iran-nexus cyber espionage group known as UNC1549 has been attributed to a new campaign targeting European telecommunications companies, successfully infiltrating 34 devices across 11 organizations as part of a recruitment-themed activity on LinkedIn.
“The group operates by posing as HR representatives from legitimate entities to engage employees, then compromises them through deployment of a MINIBIKE backdoor variant that communicates with command-and-control (C2) infrastructure proxied through Azure cloud services to bypass detection,” the company said in a report shared with The Hacker News.
Original at catalyst.prodaft.com/public/re…