=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 20-11-2025 18:00 − Freitag 21-11-2025 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ ‘Matrix Push’ C2 Tool Hijacks Browser Notifications for Phishing ∗∗∗
---------------------------------------------
Have you ever given two seconds of thought to a browser notification? No? Thats what hackers are counting on.
---------------------------------------------
https://www.darkreading.com/threat-intelligence/matrix-push-c2-tool-hijacks…
∗∗∗ Schutz vor Betrug: Wo bleibt Österreichs SMS-Firewall? ∗∗∗
---------------------------------------------
Beim angekündigten Schutzmechanismus gegen Phishing-SMS hat sich offenbar kaum etwas getan.
---------------------------------------------
https://futurezone.at/netzpolitik/sms-firewall-oesterreich-spamnachrichten-…
∗∗∗ ToddyCat: your hidden email assistant. Part 1 ∗∗∗
---------------------------------------------
Kaspersky experts analyze the ToddyCat APT attacks targeting corporate email. We examine the new version of TomBerBil, the TCSectorCopy and XstReader tools, and methods for stealing access tokens from Outlook.
---------------------------------------------
https://securelist.com/toddycat-apt-steals-email-data-from-outlook/118044/
∗∗∗ Fired techie admits sabotaging ex-employer, causing $862K in damage ∗∗∗
---------------------------------------------
PowerShell script locked thousands of workers out of their accounts An Ohio IT contractor has pleaded guilty to breaking into his former employers systems and causing nearly $1 million worth of damage after being fired.
---------------------------------------------
https://www.theregister.com/2025/11/20/it_contractor_sabotage/
∗∗∗ LLM-generated malware is improving, but dont expect autonomous attacks tomorrow ∗∗∗
---------------------------------------------
Researchers tried to get ChatGPT to do evil, but it didnt do a good job LLMs are getting better at writing malware - but theyre still not ready for prime time.
---------------------------------------------
https://www.theregister.com/2025/11/20/llmgenerated_malware_improving/
∗∗∗ Virenscanner ClamAV: Große Aufräumaktion der Entwickler angekündigt ∗∗∗
---------------------------------------------
Entrümpelung beim Virenscanner ClamAV: Cisco lässt die Entwickler alte Signaturen rauswerfen, auch alte Docker-Images müssen gehen.
---------------------------------------------
https://www.heise.de/news/Virenscanner-ClamAV-Entwickler-starten-Entruempel…
∗∗∗ Budget Samsung phones shipped with unremovable spyware, say researchers ∗∗∗
---------------------------------------------
Samsung is under fire again for shipping phones in parts of the world with a hidden system app, AppCloud, that users can’t easily remove.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2025/11/budget-samsung-phones-shippe…
∗∗∗ Vorsicht vor Fake-Shops rund um den Black Friday ∗∗∗
---------------------------------------------
Der Black Friday steht vor der Tür und viele Online-Händler locken bereits jetzt mit großzügigen Rabatten. Doch Sparfüchse sollten vor einer Bestellung genau hinsehen, denn auch betrügerische Shops versuchen, von der erhöhten Kauflaune zu profitieren.
---------------------------------------------
https://www.watchlist-internet.at/news/vorsicht-vor-fake-shops-rund-um-den-…
∗∗∗ NIS2: Gesetz für mehr Cybersicherheit ist auf dem Weg ∗∗∗
---------------------------------------------
Die Regierung holt ein Versäumnis nach: Das Gesetz hätte schon vor einem Jahr beschlossen werden sollen
---------------------------------------------
https://www.derstandard.at/story/3000000297503/nis2-gesetz-fuer-mehr-cybers…
∗∗∗ Inside Europe’s AI-Fuelled GLP-1 Scam Epidemic: How Criminal Networks Are Hijacking the Identities of the NHS, AEMPS, ANSM, BfArM and AIFA to Sell Fake Weight-Loss Products ∗∗∗
---------------------------------------------
The global appetite for GLP-1 medications like Ozempic, Wegovy and Mounjaro have created something far more dangerous than a cultural trend. It has created the perfect opening for cyber criminals who understand how desperation, scarcity and online misinformation intersect. As clinics struggle with shortages and manufacturers warn of supply limits extending ..
---------------------------------------------
https://blog.checkpoint.com/research/inside-europes-ai-fuelled-glp-1-scam-e…
∗∗∗ Stolen VPN Credentials Most Common Ransomware Attack Vector ∗∗∗
---------------------------------------------
Compromised VPN credentials are the most common initial access vector for ransomware attacks, according to a new report. Nearly half of ransomware attacks in the third quarter abused compromised VPN credentials as the initial access point, according to research from Beazley Security, the cybersecurity arm of Beazley Insurance. Nearly a quarter of initial access ..
---------------------------------------------
https://thecyberexpress.com/stolen-vpn-credentials-most-common-ransomware-a…
=====================
= Vulnerabilities =
=====================
∗∗∗ ZDI-25-885: (0Day) Digilent DASYLab DSB File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-25-885/
∗∗∗ CVE-2025-50165: Critical Flaw in Windows Graphics Component ∗∗∗
---------------------------------------------
https://www.zscaler.com/blogs/security-research/cve-2025-50165-critical-fla…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 19-11-2025 18:00 − Donnerstag 20-11-2025 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Critics scoff after Microsoft warns AI feature can infect machines and pilfer data ∗∗∗
---------------------------------------------
Integration of Copilot Actions into Windows is off by default, but for how long?
---------------------------------------------
https://arstechnica.com/security/2025/11/critics-scoff-after-microsoft-warn…
∗∗∗ Salesforce investigates customer data theft via Gainsight breach ∗∗∗
---------------------------------------------
Salesforce says it revoked refresh tokens linked to Gainsight-published applications while investigating a new wave of data theft attacks targeting customers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/salesforce-investigates-cust…
∗∗∗ Sicherheitslücke wird ausgenutzt: Angreifer attackieren 7-Zip-Nutzer ∗∗∗
---------------------------------------------
Ältere Versionen des Packprogramms 7-Zip weisen eine gefährliche Schadcode-Lücke auf, die inzwischen ausgenutzt wird. Nutzer sollten handeln.
---------------------------------------------
https://www.golem.de/news/sicherheitsluecke-wird-ausgenutzt-angreifer-attac…
∗∗∗ Fake-Softwareupdates: Cyberspione verteilen Malware über manipulierten DNS-Traffic ∗∗∗
---------------------------------------------
Eine APT-Gruppe leitet gezielt DNS-Traffic kompromittierter Router um, um Anwendern falsche Softwareupdates mit einer Backdoor unterzuschieben.
---------------------------------------------
https://www.golem.de/news/dns-traffic-umgeleitet-cyberspione-verbreiten-mal…
∗∗∗ Banking-Trojaner: Neue Android-Malware liest verschlüsselte Chats mit ∗∗∗
---------------------------------------------
Egal ob Signal, Telegram oder Whatsapp - kein Chat kann sich vor dem Sturnus-Trojaner verstecken. Opfer bemerken den Datenklau nicht.
---------------------------------------------
https://www.golem.de/news/banking-trojaner-neue-android-malware-liest-versc…
∗∗∗ Blockchain and Node.js abused by Tsundere: an emerging botnet ∗∗∗
---------------------------------------------
Kaspersky GReAT experts discovered a new campaign featuring the Tsundere botnet. Node.js-based bots abuse web3 smart contracts and are spread via MSI installers and PowerShell scripts.
---------------------------------------------
https://securelist.com/tsundere-node-js-botnet-uses-ethereum-blockchain/117…
∗∗∗ Inside the dark web job market ∗∗∗
---------------------------------------------
This report examines how employment and recruitment function on the dark web, based on over 2,000 job-related posts collected from shadow forums between January 2023 and June 2025.
---------------------------------------------
https://securelist.com/dark-web-job-market-2023-2025/118057/
∗∗∗ SpiderLabs IDs New Banking Trojan Distributed Through WhatsApp ∗∗∗
---------------------------------------------
Trustwave SpiderLabs researchers have recently identified a banking Trojan we dubbed Eternidade Stealer, which is distributed through WhatsApp hijacking and social engineering lures. In this blog post, we will break down the techniques used in the campaign and highlight the new tools employed by the threat group.
---------------------------------------------
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/spiderlabs-…
∗∗∗ Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt ∗∗∗
---------------------------------------------
Threat actors with ties to Iran engaged in cyber warfare as part of efforts to facilitate and enhance physical, real-world attacks, a trend that Amazon has called cyber-enabled kinetic targeting.The development is a sign that the lines between state-sponsored cyber attacks and kinetic warfare are increasingly blurring, necessitating the need for a new category of warfare, the tech giants ..
---------------------------------------------
https://thehackernews.com/2025/11/iran-linked-hackers-mapped-ship-ais.html
∗∗∗ Zu gut, um wahr zu sein? Vorsicht vor betrügerischen Kredit-Angeboten! ∗∗∗
---------------------------------------------
Kein Einkommensnachweis nötig? Die Zinsen weit unter dem üblichen Niveau? Maximale Flexibilität? Kriminelle locken ihre Opfer mit unrealistischen Kredit-Versprechen in die Falle. Sie drängen sie zur Überweisung verschiedenster Steuern, Gebühren etc. – zu einer Auszahlung kommt es allerdings nie.
---------------------------------------------
https://www.watchlist-internet.at/news/betruegerische-kredit-angebote/
∗∗∗ NSO seeks to overturn WhatsApp case, saying it is ‘catastrophic’ for the spyware maker ∗∗∗
---------------------------------------------
In a court filing ahead of the ruling, NSO told the judge that blocking it from targeting WhatsApp infrastructure to implant its spyware could “put NSO’s entire enterprise at risk” and “force NSO out of business.”
---------------------------------------------
https://therecord.media/nso-seeks-to-overturn-whatsapp-case
∗∗∗ Reoccurring Use of Highly Suspicious PDF Editors to Infiltrate Environments ∗∗∗
---------------------------------------------
The activities observed are the following: — File is downloaded from conmateapp[.]com ortrm[.]conmateapp[.]com (OSINT suggests that these are downloaded through ads but this has not ..
---------------------------------------------
https://www.truesec.com/hub/blog/reoccurring-use-of-highly-suspicious-pdf-e…
∗∗∗ FortiWeb CVE‑2025‑64446: What We’re Seeing in the Wild ∗∗∗
---------------------------------------------
GreyNoise has begun seeing active exploitation of CVE‑2025‑64446, the critical path‑traversal flaw that lets an unauthenticated actor run administrative commands on Fortinet FortiWeb appliances.
---------------------------------------------
https://www.greynoise.io/blog/fortiweb-cve-2025-64446
∗∗∗ Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High ∗∗∗
---------------------------------------------
GreyNoise has identified a significant escalation in malicious activity targeting Palo Alto Networks GlobalProtect portals. Beginning on 14 November 2025, activity rapidly intensified, culminating in a 40x surge within 24 hours, marking a new 90-day high.
---------------------------------------------
https://www.greynoise.io/blog/palo-alto-scanning-surges-90-day-high
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 18-11-2025 18:00 − Mittwoch 19-11-2025 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ New ShadowRay attacks convert Ray clusters into crypto miners ∗∗∗
---------------------------------------------
A global campaign dubbed ShadowRay 2.0 hijacks exposed Ray Clusters by exploiting an old code execution flaw to turn them into a self-propagating cryptomining botnet.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-shadowray-attacks-conver…
∗∗∗ Russian bulletproof hosting provider sanctioned over ransomware ties ∗∗∗
---------------------------------------------
Today, the United States, the United Kingdom, and Australia announced sanctions targeting Russian bulletproof hosting (BPH) providers that have supported ransomware gangs and other cybercrime operations.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/us-sanctions-russian-bulletp…
∗∗∗ Gen Z ist bei Passwörtern so schlecht wie 80-Jährige ∗∗∗
---------------------------------------------
Das beliebteste Passwort weltweit lautet: “Passwort”.
---------------------------------------------
https://futurezone.at/digital-life/passwort-gen-z-aeltere-generation-80-jae…
∗∗∗ Microsoft: Windows 11 bekommt hardwarebeschleunigtes Bitlocker ∗∗∗
---------------------------------------------
Bisher war Bitlocker ausschließlich als Softwareverschlüsselung vorgesehen. Das soll sich in Windows bald ändern.
---------------------------------------------
https://www.golem.de/news/microsoft-windows-11-bekommt-hardwarebeschleunigt…
∗∗∗ NIS-2-Richtlinie: Zentrale Anlaufstelle für Cybervorfälle geplant ∗∗∗
---------------------------------------------
Firmen sollen in der EU künftig Sicherheitsvorfälle nur noch bei einer Behörde melden müssen. Das soll den Berichtsaufwand verringern.
---------------------------------------------
https://www.golem.de/news/nis-2-richtlinie-zentrale-anlaufstelle-fuer-cyber…
∗∗∗ IT threat evolution in Q3 2025. Mobile statistics ∗∗∗
---------------------------------------------
The report features statistics on mobile threats for the third quarter of 2025, along with interesting findings and trends from the quarter, including an increase in ransomware activity in Germany, and more.
---------------------------------------------
https://securelist.com/malware-report-q3-2025-mobile-statistics/118013/
∗∗∗ IT threat evolution in Q3 2025. Non-mobile statistics ∗∗∗
---------------------------------------------
The report presents key trends and statistics on malware that targets personal computers running Windows and macOS, as well as Internet of Things (IoT) devices, during the third quarter of 2025.
---------------------------------------------
https://securelist.com/malware-report-q3-2025-pc-iot-statistics/118020/
∗∗∗ Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar ∗∗∗
---------------------------------------------
The malware authors associated with a Phishing-as-a-Service (PhaaS) kit known as Sneaky 2FA have incorporated Browser-in-the-Browser (BitB) functionality into their arsenal, underscoring the continued evolution of such offerings and further making it easier for ..
---------------------------------------------
https://thehackernews.com/2025/11/sneaky-2fa-phishing-kit-adds-bitb-pop.html
∗∗∗ Tens of thousands more ASUS routers pwned by suspected, evolving China operation ∗∗∗
---------------------------------------------
Researchers say attacks are laying the groundwork for stealthy espionage activity Around 50,000 ASUS routers have been compromised in a sophisticated attack that researchers believe may be linked to China, according to findings released today by SecurityScorecards STRIKE team.
---------------------------------------------
https://www.theregister.com/2025/11/19/thousands_more_asus_routers_pwned/
∗∗∗ Fakeshops: Vorsicht bei Black-Week- und Heizöl-Angeboten ∗∗∗
---------------------------------------------
Die Verbraucherzentrale NRW warnt vor Fakeshops mit vermeintlichen Heizöl-Schnäppchen. Die Black-Week lockt Betrüger auf den Plan.
---------------------------------------------
https://www.heise.de/news/Fakeshops-Vorsicht-bei-Black-Week-und-Heizoel-Ang…
∗∗∗ Sicherheitslücken: Solarwinds Platform und Serv-U für Attacken anfällig ∗∗∗
---------------------------------------------
Angreifer können Solarwinds Netzwerkmonitoringlösung Platform und die Dateitransfersoftware Serv-U attackieren.
---------------------------------------------
https://www.heise.de/news/Sicherheitsluecken-Solarwinds-Platform-und-Serv-U…
∗∗∗ Vorsicht: Kombinierte Phishing & Abo-Falle statt neuem iPhone 17 pro! ∗∗∗
---------------------------------------------
Das neueste iPhone – völlig kostenlos – direkt nach Hause geschickt! Gibt’s nicht? Gibt’s tatsächlich nicht! Hinter dem verlockenden Angebot versteckt sich in Wahrheit nichts anderes als eine Betrugs-Kombi aus Kreditkartendiebstahl und Abo-Falle.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-falle-iphone-17-pro/
∗∗∗ Anatomy of an Akira Ransomware Attack: When a Fake CAPTCHA Led to 42 Days of Compromise ∗∗∗
---------------------------------------------
Unit 42 outlines a Howling Scorpius attack delivering Akira ransomware that originated from a fake CAPTCHA and led to a 42-day compromise.
---------------------------------------------
https://unit42.paloaltonetworks.com/fake-captcha-to-compromise/
∗∗∗ Unwanted Gifts: Major Campaign Lures Targets with Fake Party Invites ∗∗∗
---------------------------------------------
Prolific threat actor delivering RMM packages using variety of lures, including seasonal party invites
---------------------------------------------
https://www.security.com/threat-intelligence/rmm-logmein-attacks
∗∗∗ LG battery subsidiary says ransomware attack targeted overseas facility ∗∗∗
---------------------------------------------
A "specific overseas facility" fell prey to a ransomware attack but is now operating normally, according to LG Energy Solution — the South Korean multinationals battery-making subsidiary.
---------------------------------------------
https://therecord.media/lg-energy-solution-ransomware-incident-battery-maker
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 17-11-2025 18:00 − Dienstag 18-11-2025 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Microsoft: Azure hit by 15 Tbps DDoS attack using 500,000 IP addresses ∗∗∗
---------------------------------------------
Microsoft said today that the Aisuru botnet hit its Azure network with a 15.72 terabits per second (Tbps) DDoS attack, launched from over 500,000 IP addresses.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-aisuru-botnet-use…
∗∗∗ RondoDox botnet malware now hacks servers using XWiki flaw ∗∗∗
---------------------------------------------
The RondoDox botnet malware is now exploiting a critical remote code execution (RCE) flaw in XWiki Platform tracked as CVE-2025-24893.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/rondodox-botnet-malware-now-…
∗∗∗ The Tycoon 2FA Phishing Platform and the Collapse of Legacy MFA ∗∗∗
---------------------------------------------
Tycoon 2FA enables turnkey real-time MFA relays behind 64,000+ attacks this year, proving legacy MFA collapses the moment a phishing kit targets it. Learn from Token Ring how biometric, phishing-proof FIDO2 hardware blocks these relay attacks before they succeed.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/the-tycoon-2fa-phishing-plat…
∗∗∗ Sicherheitslücke in V8: Hacker attackieren Chrome-Nutzer über Javascript-Engine ∗∗∗
---------------------------------------------
Zur Ausnutzung der Chrome-Lücke reicht der bloße Aufruf einer bösartigen Webseite. Angreifer können daraufhin Schadcode zur Ausführung bringen.
---------------------------------------------
https://www.golem.de/news/sicherheitsluecke-in-v8-angreifer-attackieren-chr…
∗∗∗ A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers ∗∗∗
---------------------------------------------
By plugging tens of billions of phone numbers into WhatsApp’s contact discovery tool, researchers found “the most extensive exposure of phone numbers” ever—along with profile photos and more.
---------------------------------------------
https://www.wired.com/story/a-simple-whatsapp-security-flaw-exposed-billion…
∗∗∗ IT-Vorfall: Stadtwerke Detmold nicht mehr erreichbar ∗∗∗
---------------------------------------------
Die Stadtwerke Detmold sind Opfer eines IT-Angriffs geworden. Sie sind derzeit nicht mehr erreichbar. Die Versorgung soll gesichert sein.
---------------------------------------------
https://www.heise.de/news/Stadtwerke-Detmold-nach-IT-Vorfall-offline-110829…
∗∗∗ Common Kubernetes misconfigurations and how to avoid them ∗∗∗
---------------------------------------------
TL;DR Introduction Kubernetes has changed the way we deploy and scale workloads. It’s powerful, flexible, and very good at hiding a lot of complexity. It is also very good at hiding security problems until someone starts poking at it. Attackers usually take the path of least resistance. If they find an exposed API, dashboard, or port, that is often ..
---------------------------------------------
https://www.pentestpartners.com/security-blog/common-kubernetes-misconfigur…
∗∗∗ ASFINAG Phishing-Welle fordert Bezahlung angeblicher Verkehrsstrafe ∗∗∗
---------------------------------------------
Eine Verkehrsstrafe möchte man meist schnell begleichen, um zusätzliche Kosten zu vermeiden. Genau diesen Reflex nutzen derzeit Kriminelle aus: Im Umlauf befindet sich eine gefälschte Mahn-SMS, die angeblich von der ASFINAG stammt.
---------------------------------------------
https://www.watchlist-internet.at/news/asfinag-phishing-welle-fordert-bezah…
∗∗∗ MI5 warns of Chinese spies using LinkedIn to gain intel on lawmakers ∗∗∗
---------------------------------------------
The alert identifies two specific LinkedIn profiles, featuring fake personas, that are being used by China’s Ministry of State Security in an attempt to build relationships in Westminster and gain intelligence.
---------------------------------------------
https://therecord.media/mi5-warns-chinese-spies-using-linkedin-lawmakers
∗∗∗ Russian suspect detained in Thailand is allegedly tied to Void Blizzard group ∗∗∗
---------------------------------------------
More details are emerging about a 35-year-old Russian man arrested by Thai police in Phuket earlier this month with reported help from the FBI.
---------------------------------------------
https://therecord.media/russian-arrested-thailand-allegedly-void-blizzard-a…
∗∗∗ Breaking Down S3 Ransomware: Variants, Attack Paths and Trend Vision One™ Defenses ∗∗∗
---------------------------------------------
In this blog entry, Trend™ Research explores how ransomware actors are shifting their focus to cloud-based assets, including the tactics used to compromise business-critical data in AWS environments.
---------------------------------------------
https://www.trendmicro.com/en_us/research/25/k/s3-ransomware.html
∗∗∗ When Bulletproof Hosting Proves Bulletproof: The Stark Industries Shell Game ∗∗∗
---------------------------------------------
EU sanctions hit Stark Industries in May 2025. GreyNoise data shows how the group quietly rebranded to THE.Hosting and kept its malicious infrastructure running.
---------------------------------------------
https://www.greynoise.io/blog/stark-industries-shell-game
∗∗∗ Nordkoreas Remote-Angestellte: Fünf Helfer in den USA bekennen sich schuldig ∗∗∗
---------------------------------------------
Schon seit Jahren lässt Nordkorea Menschen über das Internet in den USA arbeiten, um an Gehälter zu kommen. Nun zeigt sich in den USA, wie dabei geholfen wird.
---------------------------------------------
https://heise.de/-11082874
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates for Tuesday ∗∗∗
---------------------------------------------
Security updates have been issued by Debian (libwebsockets), Fedora (chromium and fvwm3), Mageia (apache, firefox, and postgresql13, postgresql15), Oracle (idm:DL1), Red Hat (bind, bind9.18, firefox, and openssl), SUSE (alloy, ghostscript, and openssl-1_0_0), and Ubuntu (ffmpeg and freeglut).
---------------------------------------------
https://lwn.net/Articles/1046891/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 14-11-2025 18:00 − Montag 17-11-2025 18:00
Handler: Alexander Riepl
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Jaguar Land Rover cyberattack cost the company over $220 million ∗∗∗
---------------------------------------------
Jaguar Land Rover (JLR) published its financial results for July 1 to September 30, warning that the cost of a recent cyberattack totaled £196 million ($220 million) in the quarter.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/jaguar-land-rover-cyberattac…
∗∗∗ Decades-old 'Finger' protocol abused in ClickFix malware attacks ∗∗∗
---------------------------------------------
The decades-old "finger" command is making a comeback, with threat actors using the protocol to retrieve remote commands to execute on Windows devices.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/decades-old-finger-protocol-…
∗∗∗ DoorDash email spoofing vulnerability sparks messy disclosure dispute ∗∗∗
---------------------------------------------
A vulnerability in DoorDashs systems could allow anyone to send "official" DoorDash-themed emails right from companys authorized servers, paving a near-perfect phishing channel. DoorDash has now patched the issue, but a contentious disclosure dispute has erupted, with both sides accusing each other of acting in bad faith.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/doordash-email-spoofing-vuln…
∗∗∗ Cursor Issue Paves Way for Credential-Stealing Attacks ∗∗∗
---------------------------------------------
Researchers discovered a security weakness in the AI-powered coding tool that allows malicious MCP server to hijack Cursors internal browser.
---------------------------------------------
https://www.darkreading.com/vulnerabilities-threats/cursor-issue-credential…
∗∗∗ Ransomware: Kunden- und Mitarbeiterdaten von Logitech gehackt ∗∗∗
---------------------------------------------
Der Zubehörhersteller Logitech hat ein Datenleck eingeräumt. Der Angriff erfolgte wohl über Oracle-Software.
---------------------------------------------
https://www.golem.de/news/ransomware-kunden-und-mitarbeiterdaten-von-logite…
∗∗∗ Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time ∗∗∗
---------------------------------------------
Google has disclosed that the companys continued adoption of the Rust programming language in Android has resulted in the number of memory safety vulnerabilities falling below 20% for the first time.
---------------------------------------------
https://thehackernews.com/2025/11/rust-adoption-drives-android-memory.html
∗∗∗ Overconfidence is the new zero-day as teams stumble through cyber simulations ∗∗∗
---------------------------------------------
Readiness metrics have flatlined since 2023, with most sectors slipping backward as teams fumble crisis drills. Teams that think theyre ready for a major cyber incident are scoring barely 22 percent accuracy and taking more than a day to contain simulated attacks, according to new data out Monday.
---------------------------------------------
www.theregister.com/2025/11/17/immersive_cyber_resilience_report/
∗∗∗ DOJ Issued Seizure Warrant to Starlink Over Satellite Internet Systems Used at Scam Compound ∗∗∗
---------------------------------------------
A new US law enforcement initiative is aimed at crypto fraudsters targeting Americans—and now seeks to seize infrastructure it claims is crucial to notorious scam compounds.
---------------------------------------------
https://www.wired.com/story/doj-issued-seizure-warrants-to-starlink-over-sa…
∗∗∗ Cyberangriff: Bundestagspolizei warnt Fraktionen vor gefährlichen USB-Sticks ∗∗∗
---------------------------------------------
In vielen Abgeordnetenbüros sind Postsendungen auf Englisch mit einem USB-Stick eingegangen. Die Polizei mahnt, solche Geräte nicht an Computer anzuschließen.
---------------------------------------------
https://www.heise.de/news/Cyberangriff-Bundestagspolizei-warnt-Fraktionen-v…
∗∗∗ Autonome KI-Cyberattacke: Hat sie wirklich so stattgefunden? ∗∗∗
---------------------------------------------
Eine weitgehend autonome, KI-gesteuerte Cyberattacke will Anthropic nicht nur entdeckt, sondern auch gestoppt haben. Aber stimmt das wirklich?
---------------------------------------------
https://www.heise.de/news/Autonomer-KI-Cyberangriff-Zweifel-an-Anthropics-U…
∗∗∗ IT-Vorfall bei Washington Post: Daten von knapp 10.000 Leuten abgeflossen ∗∗∗
---------------------------------------------
Über eine Oracle-Schwachstelle sind Kriminelle auch bei der Washington Post eingedrungen. Daten von fast 10.000 Menschen sind abgeflossen.
---------------------------------------------
https://www.heise.de/news/IT-Vorfall-bei-Washington-Post-Daten-von-knapp-10…
∗∗∗ Cyberangriffe erschüttern Börsen: Massive finanzielle Folgen ∗∗∗
---------------------------------------------
Eine neue Umfrage zeigt drastische finanzielle Folgen von Cyberangriffen: 70 Prozent der börsennotierten Unternehmen mussten ihre Gewinnprognosen anpassen.
---------------------------------------------
https://www.heise.de/news/Studie-Cyberangriffe-treffen-Aktienkurse-und-Fina…
∗∗∗ Scammers are sending bogus copyright warnings to steal your X login ∗∗∗
---------------------------------------------
A copyright violation sounds serious, so cybercriminals are faking messages from the DMCA to lure you into handing over your X credentials.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2025/11/scammers-are-sending-bogus-c…
∗∗∗ Advent, Advent – nicht alles glänzt! Vorsicht vor unseriösen Adventkalender-Shops! ∗∗∗
---------------------------------------------
Adventkalender versüßen Groß und Klein die Vorweihnachtszeit. Doch alle Jahre wieder versuchen auch unseriöse Anbieter, Profit aus dem Weihnachtsgeschäft zu schlagen.
---------------------------------------------
https://www.watchlist-internet.at/news/vorsicht-vor-unserioesen-adventkalen…
∗∗∗ Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT ∗∗∗
---------------------------------------------
Two campaigns delivering Gh0st RAT to Chinese speakers show a deep understanding of the target populations virtual environment and online behavior.
---------------------------------------------
https://unit42.paloaltonetworks.com/impersonation-campaigns-deliver-gh0st-r…
∗∗∗ Initial Access Brokers (IAB) in 2025 – >From Dark Web Listings to Supply Chain Ransomware Events ∗∗∗
---------------------------------------------
Initial access brokers in 2025, how dark web access listings feed ransomware supply chain events like JLR, and what CISOs can do to detect and disrupt them.
---------------------------------------------
https://www.darknet.org.uk/2025/11/initial-access-brokers-iab-in-2025-from-…
∗∗∗ From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion ∗∗∗
---------------------------------------------
The intrusion took place in May 2024, when a user executed a malicious JavaScript file. This JavaScript file has been previously reported as associated with the Lunar Spider initial access group by EclecticIQ. The heavily obfuscated file, masquerading as a legitimate tax form, contained only a small amount of executable code dispersed among extensive filler content used for evasion.
---------------------------------------------
https://thedfirreport.com/2025/09/29/from-a-single-click-how-lunar-spider-e…
∗∗∗ Cat’s Got Your Files: Lynx Ransomware ∗∗∗
---------------------------------------------
The intrusion began in early March 2025 with a single successful Remote Desktop Protocol (RDP) logon to an internet-exposed system. Notably, there was no evidence of credential stuffing, brute forcing, or other failed authentication attempts from the source IP, indicating the threat actor likely possessed valid credentials before the activity occurred.
---------------------------------------------
https://thedfirreport.com/2025/11/17/cats-got-your-files-lynx-ransomware/
∗∗∗ MISP v2.5.25 Release Notes ∗∗∗
---------------------------------------------
This release introduces a security fix, significant performance improvements for REST searches, new default feeds, and several important bug fixes. Security: Fixed a vulnerability that could expose user passwords in workflows.
---------------------------------------------
https://github.com/MISP/MISP/releases/tag/v2.5.25
∗∗∗ AIPAC Discloses Data Breach, Says Hundreds Affected ∗∗∗
---------------------------------------------
AIPAC reports data breach after external system access, hundreds affected, investigation ongoing with added security steps.
---------------------------------------------
https://hackread.com/aipac-data-breach-hundreds-affected/
∗∗∗ EchoGram Flaw Bypasses Guardrails in Major LLMs ∗∗∗
---------------------------------------------
HiddenLayer reveals the EchoGram vulnerability, which bypasses safety guardrails on GPT-5.1 and other major LLMs, giving security teams just a 3-month head start.
---------------------------------------------
https://hackread.com/echogram-flaw-bypass-guardrails-major-llms/
∗∗∗ Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem ∗∗∗
---------------------------------------------
Last year, Mandiant published a blog post highlighting suspected Iran-nexus espionage activity targeting the aerospace, aviation, and defense industries in the Middle East. In this follow-up post, Mandiant discusses additional tactics, techniques, and procedures (TTPs) observed in incidents Mandiant has responded to.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/analysis-of-unc154…
∗∗∗ No Leak, No Problem - Bypassing ASLR with a ROP Chain to Gain RCE ∗∗∗
---------------------------------------------
After my previous post on ARM exploitation, where we crafted an exploit for a known vulnerability, I decided to continue the research on a more modern IoT target. In this follow-up post, I will take you through building a considerably more complex binary exploit. We will explore the path from firmware extraction and analysis to the discovery of a previously unknown vulnerability and its exploitation.
---------------------------------------------
https://modzero.com/en/blog/no-leak-no-problem/
∗∗∗ npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects ∗∗∗
---------------------------------------------
The Socket Threat Research Team recently discovered dino_reborn, an npm threat actor with seven packages constructing an intricate malware campaign. Upon visiting a fake website constructed by one of the packages, the threat actor determines if the visitor is a victim or a security researcher. If the visitor is a victim, they see a fake CAPTCHA, eventually bringing them to a malicious site. If they are a security researcher, only a few tells on the fake website would tip them off that something nefarious may be occurring.
---------------------------------------------
https://socket.dev/blog/npm-malware-campaign-uses-adspect-cloaking-to-deliv…
∗∗∗ MacOS Infection Vector: Using AppleScripts to bypass Gatekeeper ∗∗∗
---------------------------------------------
This gives an overview of how .scpt AppleScript are used to creatively deliver macOS malware, such as fake office documents or fake Zoom/Teams updates. Previously a technique seen with APT campaigns for macOS, we can now see samples coming from the macOS stealer ecosystem like MacSync and Odyssey.
---------------------------------------------
https://pberba.github.io/security/2025/11/11/macos-infection-vector-applesc…
=====================
= Vulnerabilities =
=====================
∗∗∗ Kritische Sicherheitslücke in Fortinet FortiWeb wird aktiv ausgenutzt ∗∗∗
---------------------------------------------
Eine kritische Sicherheitslücke (CVE-2025-64446) in Fortinet FortiWeb erlaubt es unauthentifizierten Angreifer:innen, eigene Admin-Konten zu erstellen und somit die vollständige Kontrolle über betroffene Geräte zu erlangen. Die Schwachstelle wird mindestens seit dem 6. Oktober 2025 aktiv ausgenutzt und Exploitcode ist bereits öffentlich verfügbar.
---------------------------------------------
https://www.cert.at/de/aktuelles/2025/11/kritische-sicherheitslucke-in-fort…
∗∗∗ Mehrere Sicherheitslücken bedrohen Cisco Catalyst Center ∗∗∗
---------------------------------------------
Sicherheitsupdates schließen mehrere Schwachstellen in Ciscos Netzwerk-Kontrollzentrum Catalyst Center.
---------------------------------------------
https://www.heise.de/news/Admin-Sicherheitsluecke-bedroht-Cisco-Catalyst-Ce…
∗∗∗ Microsoft Patch Tuesday, November 2025 Edition ∗∗∗
---------------------------------------------
Microsoft this week pushed security updates to fix more than 60 vulnerabilities in its Windows operating systems and supported software, including at least one zero-day bug that is already being exploited. Microsoft also fixed a glitch that prevented some Windows 10 users from taking advantage of an extra year of security updates, which is nice because the zero-day flaw and other critical weaknesses patched today affect all versions of Windows, including Windows 10.
---------------------------------------------
https://krebsonsecurity.com/2025/11/microsoft-patch-tuesday-november-2025-e…
∗∗∗ Security updates for Monday ∗∗∗
---------------------------------------------
Security updates have been issued by Debian (gst-plugins-base1.0, lasso, and thunderbird), Fedora (bind9-next, chromium, containerd, fvwm3, luksmeta, opentofu, python-pdfminer, python-uv-build, ruff, rust-get-size-derive2, rust-get-size2, rust-regex, rust-regex-automata, rust-reqsign, rust-reqsign-aws-v4, rust-reqsign-command-execute-tokio, rust-reqsign-core, rust-reqsign-file-read-tokio, rust-reqsign-http-send reqwest, suricata, uv, and xmedcon), Mageia (apache-commons-beanutils, apache-commons-fileupload, apache-commons-lang, botan2, python-django, spdlog, stardict, webkit2, and yelp-xsl), Slackware (xpdf), and SUSE (bind, chromedriver, firefox, kernel, libxml2, and openssh).
---------------------------------------------
https://lwn.net/Articles/1046756/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 13-11-2025 18:00 − Freitag 14-11-2025 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ RCE flaw in ImunifyAV puts millions of Linux-hosted sites at risk ∗∗∗
---------------------------------------------
The ImunifyAV malware scanner for Linux server, used by tens of millions of websites, is vulnerable to a remote code execution vulnerability that could be exploited to compromise the hosting environment.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/rce-flaw-in-imunifyav-puts-m…
∗∗∗ New ‘IndonesianFoods’ worm floods npm with 100,000 packages ∗∗∗
---------------------------------------------
A self-spreading package published on npm spams the registry by spawning new packages every every seven seconds, creating large volumes of junk.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-indonesianfoods-worm-flo…
∗∗∗ DoorDash hit by new data breach in October exposing user information ∗∗∗
---------------------------------------------
DoorDash has disclosed a data breach that hit the food delivery platform this October. Beginning yesterday evening, DoorDash, which serves millions of customers across the U.S., Canada, Australia, and New Zealand, started emailing those impacted by the newly discovered security incident.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/doordash-hit-by-new-data-bre…
∗∗∗ ASUS warns of critical auth bypass flaw in DSL series routers ∗∗∗
---------------------------------------------
ASUS has released new firmware to patch a critical authentication bypass security flaw impacting several DSL series router models.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/asus-warns-of-critical-auth-…
∗∗∗ NIS-2-Umsetzung: Bundestag beschließt umstrittenes Cybersicherheitsgesetz ∗∗∗
---------------------------------------------
NIS 2 kann für Netzbetreiber fehlende Rechtssicherheit, Wirtschaftsrisiken und unnötige Bürokratie bringen. Noch kann der Bundesrat etwas ändern.
---------------------------------------------
https://www.golem.de/news/nis-2-umsetzung-bundestag-beschliesst-umstrittene…
∗∗∗ Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded ∗∗∗
---------------------------------------------
Anthropic dubs this the first AI-orchestrated cyber snooping campaign Chinese cyber spies used Anthropics Claude Code AI tool to attempt digital break-ins at about 30 high-profile companies and government organizations – and the government-backed snoops "succeeded in a small number of cases," according to a Thursday report from the AI company.
---------------------------------------------
https://www.theregister.com/2025/11/13/chinese_spies_claude_attacks/
∗∗∗ Cybergang cl0p will Daten von Carglass, Fluke und NHS erbeutet haben ∗∗∗
---------------------------------------------
Auf der Darknet-Seite der kriminellen Bande cl0p sind neue Einträge zu Carglass, Fluke und NHS aufgetaucht. Dort will sie Daten geklaut haben.
---------------------------------------------
https://www.heise.de/news/Datenlecks-Cybergang-cl0p-will-Daten-von-Carglass…
∗∗∗ FBI: Akira gang has received nearly $250 million in ransoms ∗∗∗
---------------------------------------------
The U.S. and European law enforcement released new information to help organizations defend themselves against the Akira ransomware gang, which has attacked small- and medium-sized businesses for years.
---------------------------------------------
https://therecord.media/akira-gang-received-million
∗∗∗ Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition ∗∗∗
---------------------------------------------
Russian news reports and Thai sources said police had detained an alleged Russian hacker on the island of Phuket and transferred him to Bangkok for possible transfer to the U.S.
---------------------------------------------
https://therecord.media/russian-hacker-detained-thailand-possible-us-extrad…
∗∗∗ Increase in Lumma Stealer Activity Coincides with Use of Adaptive Browser Fingerprinting Tactics ∗∗∗
---------------------------------------------
In this blog entry, Trend™ Research analyses the layered command-and-control approaches that Lumma Stealer uses to maintain its ongoing operations while enhancing collection of victim-environment data.
---------------------------------------------
https://www.trendmicro.com/en_us/research/25/k/lumma-stealer-browser-finger…
∗∗∗ When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb (??) Auth. Bypass) ∗∗∗
---------------------------------------------
The Internet is ablaze, and once again we all have a front-row seat - a bad person, if you can believe it, is doing a bad thing!The first warning of such behaviour came from the great team at Defused:As many are now aware, an unnamed (and potentially silently
---------------------------------------------
https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-imp…
∗∗∗ Fortinet: Neuer Exploit missbraucht Zero-Day-Lücke in Firewalls ∗∗∗
---------------------------------------------
IT-Forscher haben neuen Exploit-Code in ihrem Honeypot gefunden. Der attackiert eine bislang unbekannte Fortinet-Sicherheitslücke.
---------------------------------------------
https://heise.de/-11078310
∗∗∗ Nation state threat actor used Claude Code to orchestrate cyber attacks ∗∗∗
---------------------------------------------
We recently argued that an inflection point had been reached in cybersecurity: a point at which AI models had become genuinely useful for cybersecurity operations, both for good and for ill. This was based on systematic evaluations showing cyber capabilities doubling in six months ..
---------------------------------------------
https://www.anthropic.com/news/disrupting-AI-espionage
=====================
= Vulnerabilities =
=====================
∗∗∗ Security Vulnerabilities fixed in Thunderbird 145 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2025-90/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 140.5 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2025-91/
∗∗∗ Path confusion vulnerability in GUI ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-25-910
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 12-11-2025 18:00 − Donnerstag 13-11-2025 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ November Patch Tuesday does its chores ∗∗∗
---------------------------------------------
A cleanup month brings 63 patches… wait, no, 68… how about 61?
---------------------------------------------
https://news.sophos.com/en-us/2025/11/12/november-patch-tuesday-does-its-ch…
∗∗∗ Over 67,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack ∗∗∗
---------------------------------------------
Cybersecurity researchers are calling attention to a large-scale spam campaign that has flooded the npm registry with thousands of fake packages since early 2024 as part of a likely financially motivated effort."The packages were systematically published ..
---------------------------------------------
https://thehackernews.com/2025/11/over-46000-fake-npm-packages-flood.html
∗∗∗ Zohocorp ManageEngine: Mehrere Sicherheitslücken in unterschiedlichen Produkten ∗∗∗
---------------------------------------------
Mehrere Schwachstellenberichte zu Lücken in mehreren Zohocorp-ManageEngine-Produkten sind erschienen. Updates stehen bereit.
---------------------------------------------
https://www.heise.de/news/Zohocorp-ManageEngine-Mehrere-Sicherheitsluecken-…
∗∗∗ Operation Endgame 3: 1025 Server von Netz genommen ∗∗∗
---------------------------------------------
Internationalen Strafverfolgern ist ein neuerlicher Schlag gegen Malware und dahinterliegende Infrastruktur gelungen.
---------------------------------------------
https://www.heise.de/news/Operation-Endgame-3-1025-Server-von-Netz-genommen…
∗∗∗ Citrix Netscaler ADC und Gateway: Update schließt Cross-Site-Scripting-Lücke ∗∗∗
---------------------------------------------
In den Netscaler ADCs und Gateways von Citrix können Angreifer eine Cross-Site-Scripting-Lücke ausnutzen. Updates schließen sie.
---------------------------------------------
https://www.heise.de/news/Citrix-Netscaler-ADC-und-Gateway-Update-schliesst…
∗∗∗ Google Sues to Disrupt Chinese SMS Phishing Triad ∗∗∗
---------------------------------------------
Google is suing more than two dozen unnamed individuals allegedly involved in peddling a popular China-based mobile phishing service that helps scammers impersonate hundreds of trusted brands, blast out text message lures, and convert phished payment card data into mobile wallets from Apple and Google.
---------------------------------------------
https://krebsonsecurity.com/2025/11/google-sues-to-disrupt-chinese-sms-phis…
∗∗∗ Wenn sich die angebliche Copyright-Verletzung als Betrugsversuch entpuppt ∗∗∗
---------------------------------------------
Immer wieder sorgen E-Mails von vermeintlichen Anwaltskanzleien für Aufregung. Die Empfänger:innen haben angeblich gegen Urheberrechte verstoßen, die Geschädigten fordern Wiedergutmachung. Tatsächlich stimmt hier aber gar nichts. Die Copyright-Verletzung hat nicht stattgefunden, die Anwaltskanzlei existiert nicht.
---------------------------------------------
https://www.watchlist-internet.at/news/copyright-verletzung-betrugsversuch/
∗∗∗ TAG Bulletin: Q3 2025 ∗∗∗
---------------------------------------------
Our bulletin covering coordinated influence operation campaigns terminated on our platforms in Q3 2025.
---------------------------------------------
https://blog.google/threat-analysis-group/tag-bulletin-q3-2025/
∗∗∗ Contagious Interview Actors Now Utilize JSON Storage Services for Malware Delivery ∗∗∗
---------------------------------------------
NVISO reports a new development to the Contagious Interview campaign. The threat actors have recently resorted to utilizing JSON storage services like JSON Keeper, JSONsilo and npoint.io to host and deliver malware from trojanized code projects, with the lure being a use case or demo project as part of an interview process. Background Contagious Interview ..
---------------------------------------------
https://blog.nviso.eu/2025/11/13/contagious-interview-actors-now-utilize-js…
∗∗∗ CISA and Partners Release Advisory Update on Akira Ransomware ∗∗∗
---------------------------------------------
Today, Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Federal Bureau of Investigation, Department of Defense Cyber Crime Center, Department of Health and Human Services, and international partners, released an updated joint Cybersecurity Advisory, #StopRansomware: Akira Ransomware, to provide network defenders with the latest indicators ..
---------------------------------------------
https://www.cisa.gov/news-events/alerts/2025/11/13/cisa-and-partners-releas…
=====================
= Vulnerabilities =
=====================
∗∗∗ Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2025-006
∗∗∗ Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2025-005
∗∗∗ Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2025-008
∗∗∗ Drupal core - Moderately critical - Defacement - SA-CORE-2025-007 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2025-007
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 11-11-2025 18:00 − Mittwoch 12-11-2025 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Rhadamanthys infostealer disrupted as cybercriminals lose server access ∗∗∗
---------------------------------------------
The Rhadamanthys infostealer operation has been disrupted, with numerous “customers” of the malware-as-a-service reporting that they no longer have access to their servers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/rhadamanthys-infostealer-dis…
∗∗∗ VU#553375: Unprotected temporary directories in Wolfram Cloud version 14.2 may result in privilege escalation ∗∗∗
---------------------------------------------
Wolfram Cloud version 14.2 allows Java Virtual Machine (JVM) unrestricted access to temporary resources in the /tmp/ directory of the cloud environment which may result in privilege escalation, information exfiltration, and remote code execution. In the same cloud instance, temporary directories of other users may be accessible.
---------------------------------------------
https://kb.cert.org/vuls/id/553375
∗∗∗ WhatsApp Malware Maverick Hijacks Browser Sessions to Target Brazils Biggest Banks ∗∗∗
---------------------------------------------
Threat hunters have uncovered similarities between a banking malware called Coyote and a newly disclosed malicious program dubbed Maverick that has been propagated via WhatsApp.
---------------------------------------------
https://thehackernews.com/2025/11/whatsapp-malware-maverick-hijacks.html
∗∗∗ Cl0p Ransomware Lists NHS UK as Victim, Days After Washington Post Breach ∗∗∗
---------------------------------------------
Cl0p ransomware lists NHS UK as a victim days after The Washington Post confirms a major Oracle E-Business breach linked to CVE-2025-61882
---------------------------------------------
https://hackread.com/cl0p-ransomware-nhs-uk-washington-post-breach/
∗∗∗ @facebookmail.com Invites Exploited to Phish Facebook Business Users ∗∗∗
---------------------------------------------
If you manage Facebook advertising for a small or medium-sized business, open your inbox with suspicion, because attackers have been sending highly convincing invites that look like they come straight from Meta.
---------------------------------------------
https://hackread.com/facebookmail-com-invites-phish-facebook-business/
∗∗∗ Hackers Use KakaoTalk and Google Find Hub in Android Spyware Attack ∗∗∗
---------------------------------------------
North Korea-linked KONNI hackers used KakaoTalk and Google Find Hub to spy on victims and remotely wipe Android devices in a targeted phishing campaign.
---------------------------------------------
https://hackread.com/hackers-kakaotalk-google-find-hub-android-spyware/
∗∗∗ Is It CitrixBleed4? Well, No. Is It Good? Also, No. (Citrix NetScaler Memory Leak & RXSS CVE-2025-12101) ∗∗∗
---------------------------------------------
There’s an elegance to vulnerability research that feels almost poetic - the quiet dance between chaos and control. It’s the art of peeling back the layers of complexity, not to destroy but to understand; to trace the fragile threads that hold systems together and see where they might fray.
---------------------------------------------
https://labs.watchtowr.com/is-it-citrixbleed4-well-no-is-it-good-also-no-ci…
∗∗∗ Miniatur Wunderland Ziel von IT-Angriff: Kreditkartendaten abgeflossen ∗∗∗
---------------------------------------------
Cyberkriminelle konnten in das Buchungssystem vom Miniatur Wunderland Hamburg eindringen. Dabei konnten sie offenbar Informationen aus dem Zahlungsverkehr mitlesen. Die Untersuchungen dauern noch an.
---------------------------------------------
https://www.heise.de/news/Miniatur-Wunderland-Ziel-von-IT-Angriff-Kreditkar…
=====================
= Vulnerabilities =
=====================
∗∗∗ Microsoft November 2025 Patch Tuesday fixes 1 zero-day, 63 flaws ∗∗∗
---------------------------------------------
Today is Microsoft's November 2025 Patch Tuesday, which includes security updates for 63 flaws, including one actively exploited zero-day vulnerability.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2025-pat…
∗∗∗ Synology fixes BeeStation zero-days demoed at Pwn2Own Ireland ∗∗∗
---------------------------------------------
Synology has addressed a critical-severity remote code execution (RCE) vulnerability in BeeStation products that was demonstrated at the recent Pwn2Own hacking competition. The security issue (CVE-2025-12686) is described as a ‘buffer copy without checking the size of input’ problem, and can be exploited to allow arbitrary code execution.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/synology-fixes-beestation-ze…
∗∗∗ Avast und AVG: Kritische Sicherheitslücke stillschweigend behoben ∗∗∗
---------------------------------------------
In den Malware-Schutzprogrammen der Marken Avast und AVG stand eine als kritisch eingeordnete Sicherheitslücke offen. Die ist inzwischen geschlossen, ebenso eine weitere, weniger schwerwiegende in Avast Free Antivirus.
---------------------------------------------
https://www.heise.de/news/Avast-und-AVG-Kritische-Sicherheitsluecke-stillsc…
∗∗∗ Security updates for Wednesday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (kernel, kernel-rt, and libtiff), Debian (kernel, libarchive, rust-sudo-rs, and squid), Fedora (chromium, dotnet8.0, forgejo, ruby, and webkitgtk), Oracle (bind, bind9.18, kernel, kernel-uek*, libtiff, and runc), Red Hat (firefox, kernel, and kernel-rt), Slackware (mozilla), SUSE (buildah, colord, containerd, kernel, lasso, libsoup, micropython, ongres-scram, openssh, proxy-helm, uyuni-tools, python-pdfminer.six, qatengine, qatlib, regclient, and runc), and Ubuntu (raptor and raptor2).
---------------------------------------------
https://lwn.net/Articles/1046173/
∗∗∗ Patchday Adobe: Schadcode-Lücken bedrohen InDesign & Co. ∗∗∗
---------------------------------------------
Es sind wichtige Sicherheitsupdates für unter anderem Adobe Illustrator, InCopy und Photoshop erschienen.
---------------------------------------------
https://heise.de/-11074930
∗∗∗ Patchday: Intel dichtet zig Sicherheitslücken ab ∗∗∗
---------------------------------------------
Intel hat auch einen Patchday veranstaltet und 30 Sicherheitsmitteilungen mit Updates veröffentlicht. Davon sind sieben hochriskant.
---------------------------------------------
https://heise.de/-11075454
∗∗∗ DSA-6053-1 linux - security update ∗∗∗
---------------------------------------------
https://lists.debian.org/debian-security-announce/2025/msg00219.html
∗∗∗ ZDI-25-991: Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-25-991/
∗∗∗ CVE-2025-13042: Stable Channel Update for Desktop ∗∗∗
---------------------------------------------
http://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desk…
∗∗∗ CISA Adds Three Known Exploited Vulnerabilities to Catalog ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/alerts/2025/11/12/cisa-adds-three-known-ex…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 10-11-2025 18:00 − Dienstag 11-11-2025 18:00
Handler: Guenes Holler
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Quantum Route Redirect PhaaS targets Microsoft 365 users worldwide ∗∗∗
---------------------------------------------
A new phishing automation platform named Quantum Route Redirect is using around 1,000 domains to steal Microsoft 365 users credentials.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/quantum-route-redirect-phaas…
∗∗∗ How a CPU spike led to uncovering a RansomHub ransomware attack ∗∗∗
---------------------------------------------
A sudden CPU spike turned out to be the first clue of an in-progress RansomHub ransomware attack. Varonis breaks down how their team traced the attack from fake browser updates to domain-admin takeover, ultimately stopping the attack before files were encrypted.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/how-a-cpu-spike-led-to-uncov…
∗∗∗ Fernzugriff aus China: Briten untersuchen ihre Elektrobusse auf Kill-Switch ∗∗∗
---------------------------------------------
Eine Untersuchung aus Norwegen ruft weitere Behörden auf den Plan. Der chinesische Hersteller Yutong soll aus der Ferne seine E-Busse lahmlegen können.
---------------------------------------------
https://www.golem.de/news/fernzugriff-aus-china-briten-untersuchen-ihre-ele…
∗∗∗ GootLoader Is Back, Using a New Font Trick to Hide Malware on WordPress Sites ∗∗∗
---------------------------------------------
The malware known as GootLoader has resurfaced yet again after a brief spike in activity earlier this March, according to new findings from Huntress. The cybersecurity company said it observed three GootLoader infections since October 27, 2025, out of which two resulted in hands-on keyboard intrusions with domain controller compromise taking place within 17 hours of initial infection.
---------------------------------------------
https://thehackernews.com/2025/11/gootloader-is-back-using-new-font-trick.h…
∗∗∗ Phishers try to lure 5K Facebook advertisers with fake business pages ∗∗∗
---------------------------------------------
One company alone was hit with more than 4,200 emails More than 5,000 businesses that use Facebook for advertising were bombarded by tens of thousands of phishing emails in a credential- and data-stealing campaign.
---------------------------------------------
www.theregister.com/2025/11/10/5k_facebook_advertising_customers_phishing/
∗∗∗ Unsichtbarer Wurm in Visual Studio Extensions: GlassWorm lebt ∗∗∗
---------------------------------------------
Der Mitte Oktober entdeckte Supply-Chain-Angriff über die Marktplätze von Visual Studio Code geht offenbar weiter: Auf dem Open-VSX-Marktplatz der Eclipse Foundation sind drei weitere Pakete mit GlassWorm aufgetaucht.
---------------------------------------------
https://www.heise.de/news/Schadsoftware-weiter-aktiv-GlassWorm-erneut-in-Op…
∗∗∗ Achtung Phishing: WKO fordert keine Datenaktualisierung per E-Mail! ∗∗∗
---------------------------------------------
Aktuell kursiert eine neue Phishing-Variante im Namen der WKO. In der E-Mail werden Sie aufgefordert, Ihre Handelsregister-, Verzeichnis- oder Unternehmensdaten zu aktualisieren.
---------------------------------------------
https://www.watchlist-internet.at/news/achtung-phishing-wko-fordert-keine-d…
∗∗∗ You Thought It Was Over? Authentication Coercion Keeps Evolving ∗∗∗
---------------------------------------------
A new type of authentication coercion attack exploits an obscure and rarely monitored remote procedure call (RPC) interface.
---------------------------------------------
https://unit42.paloaltonetworks.com/authentication-coercion/
∗∗∗ Russian hacker to plead guilty to aiding Yanluowang ransomware group ∗∗∗
---------------------------------------------
Court documents show evidence proving Volkov served as an initial access broker for the ransomware gang — breaking into the network of victims and then offering his access for a percentage of the ransom.
---------------------------------------------
https://therecord.media/russian-hacker-to-plead-guilty-aiding-ransomware-gr…
∗∗∗ Cyber Action Toolkit: breaking down the barriers to resilience ∗∗∗
---------------------------------------------
How the NCSC’s "Cyber Action Toolkit" is helping small businesses to improve their cyber security.
---------------------------------------------
https://www.ncsc.gov.uk/blog-post/cat-breaking-down-resilience-barriers
∗∗∗ Cisco Finds Open-Weight AI Models Easy to Exploit in Long Chats ∗∗∗
---------------------------------------------
Cisco’s new research shows that open-weight AI models, while driving innovation, face serious security risks as multi-turn attacks, including conversational persistence, can bypass safeguards and expose data.
---------------------------------------------
https://hackread.com/cisco-open-weight-ai-models-long-chat-exploit/
∗∗∗ Fake NPM Package With 206K Downloads Targeted GitHub for Credentials ∗∗∗
---------------------------------------------
Veracode Threat Research exposed a targeted typosquatting attack on npm, where the malicious package @acitons/artifact stole GitHub tokens. Learn how this supply chain failure threatened the GitHub organisations code.
---------------------------------------------
https://hackread.com/fake-npm-package-downloads-github-credentials/
∗∗∗ BSI zur Cybersicherheit: Stabil unsicher ∗∗∗
---------------------------------------------
Das aktuelle BSI-Lagebild zeigt eklatante Probleme auf – während der zuständige Minister auf die Wirksamkeit neuer Maßnahmen hofft.
---------------------------------------------
https://heise.de/-11074222
∗∗∗ MacOS Infection Vector: Using AppleScripts to bypass Gatekeeper ∗∗∗
---------------------------------------------
TLDR This gives an overview of how .scpt AppleScript are used to creatively deliver macOS malware, such as fake office documents or fake Zoom/Teams updates. Previously a technique seen with APT campaigns for macOS, we can now see samples coming from the macOS stealer ecosystem like MacSync and Odyssey.
---------------------------------------------
https://pberba.github.io/security/2025/11/11/macos-infection-vector-applesc…
=====================
= Vulnerabilities =
=====================
∗∗∗ Popular JavaScript library expr-eval vulnerable to RCE flaw ∗∗∗
---------------------------------------------
A critical vulnerability in the popular expr-eval JavaScript library, with over 800,000 weekly downloads on NPM, can be exploited to execute code remotely through maliciously crafted input.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/popular-javascript-library-e…
∗∗∗ SAP fixes hardcoded credentials flaw in SQL Anywhere Monitor ∗∗∗
---------------------------------------------
SAP has released its November security updates that address multiple security vulnerabilities, including a maximum severity flaw in the non-GUI variant of the SQL Anywhere Monitor and a critical code injection issue in the Solution Manager platform.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/sap-fixes-hardcoded-credenti…
∗∗∗ Root-Sicherheitslücke bedroht IBMs Datenbanksystem Db2 ∗∗∗
---------------------------------------------
Angreifer können Systeme mit IBM Db2 und Business Automation Workflow attackieren und im schlimmsten Fall Root-Rechte erlangen, um PCs zu kompromittieren. Sicherheitspatches stehen zum Download bereit.
---------------------------------------------
https://www.heise.de/news/Root-Sicherheitsluecke-bedroht-IBMs-Datenbanksyst…
∗∗∗ Sicherheitslücke in Dell Display and Peripheral Manager gefährdet PCs ∗∗∗
---------------------------------------------
Wenn Angreifer erfolgreich an einer Lücke in Dell Display and Peripheral Manager unter Windows ansetzen, können sie sich höhere Nutzerrechte verschaffen. In einer aktuellen Version der Software haben die Entwickler eine Sicherheitslücke geschlossen. Bislang gibt es keine Hinweise auf bereits laufende Attacken.
---------------------------------------------
https://heise.de/-11073226
∗∗∗ Security Vulnerabilities fixed in Firefox 145 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2025-87/
∗∗∗ Ivanti November 2025 Security Update ∗∗∗
---------------------------------------------
https://www.ivanti.com/blog/november-2025-security-update
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 07-11-2025 18:00 − Montag 10-11-2025 18:00
Handler: Alexander Riepl
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Malicious NuGet packages drop disruptive time bombs ∗∗∗
---------------------------------------------
Several malicious packages on NuGet have sabotage payloads scheduled to activate in 2027 and 2028, targeting database implementations and Siemens S7 industrial control devices.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/malicious-nuget-packages-dro…
∗∗∗ ClickFix Campaign Targets Hotels, Spurs Secondary Customer Attacks ∗∗∗
---------------------------------------------
Attackers compromise hospitality providers with an infostealer and RAT malware and then use stolen data to launch phishing attacks against customers via both email and WhatsApp.
---------------------------------------------
https://www.darkreading.com/cyberattacks-data-breaches/clickfix-targets-hot…
∗∗∗ Secure boot certificate rollover is real but probably wont hurt you ∗∗∗
---------------------------------------------
LWN wrote an article which opens with the assertion "Linux users who have Secure Boot enabled on their systems knowingly or unknowingly rely on a key from Microsoft that is set to expire in September". This is, depending on interpretation, either misleading or just plain wrong, but also theres not a good source of truth here, so.
---------------------------------------------
https://mjg59.dreamwidth.org/72892.html
∗∗∗ Whisper Leak: A novel side-channel attack on remote language models ∗∗∗
---------------------------------------------
Microsoft has discovered a side-channel attack on language models which allows adversaries to conclude model conversation topics, despite being encrypted.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-nov…
∗∗∗ Honeypot: Requests for (Code) Repositories ∗∗∗
---------------------------------------------
This is just a quick diary entry to report that I saw requests on my honeypot for (code) repositories.
---------------------------------------------
https://isc.sans.edu/diary/rss/32460
∗∗∗ Slot Gacor: The Rise of Online Casino Spam ∗∗∗
---------------------------------------------
Online casino spam has been without a doubt one of the most prevalent types of spam content that we’ve seen on infected websites in recent years. An extremely common method of promoting low-quality or otherwise undesirable websites is for spammers to hack websites and fill them full of backlinks to pump their SEO.
---------------------------------------------
https://blog.sucuri.net/2025/11/slot-gacor-the-rise-of-online-casino-spam.h…
∗∗∗ Allianz UK joins growing list of Clop’s Oracle E-Business Suite victims ∗∗∗
---------------------------------------------
Insurance giant’s UK arm says cybercriminals misattributed the real victim Allianz UK confirms it was one of the many companies that fell victim to the Clop gangs Oracle E-Business Suite (EBS) attack after crims reported that they had attacked a subsidiary.
---------------------------------------------
www.theregister.com/2025/11/10/allianz_uk_joins_growing_list/
∗∗∗ Watchguard Firebox: Gefährdung durch Standardpasswort für Admin ∗∗∗
---------------------------------------------
Watchguard versieht die Firebox-Firewalls mit Standardpasswörtern. Angreifer können sich dadurch leicht Admin-Rechte verschaffen.
---------------------------------------------
https://www.heise.de/news/Watchguard-Firebox-Gefaehrdung-durch-Standardpass…
∗∗∗ Drilling Down on Uncle Sam’s Proposed TP-Link Ban ∗∗∗
---------------------------------------------
The U.S. government is reportedly preparing to ban the sale of wireless routers and other networking gear from TP-Link Systems, a tech company that currently enjoys an estimated 50% market share among home users and small businesses. Experts say while the proposed ban may have more to do with TP-Links ties to China than any specific technical threats, much of the rest of the industry serving this market also sources hardware from China and ships products that are insecure fresh out of the box.
---------------------------------------------
https://krebsonsecurity.com/2025/11/drilling-down-on-uncle-sams-proposed-tp…
∗∗∗ Handy-Guthaben aufladen? Vorsicht vor gefälschter HoT-Website ∗∗∗
---------------------------------------------
Eine neue Betrugsmasche richtet sich derzeit gegen Kund:innen des Mobilfunkanbieters HoT. Im Internet ist eine täuschend echt gestaltete Website aufgetaucht, die vorgibt, den offiziellen Aufladeservice von HoT bereitzustellen. Wer dort sein Guthaben für Handy oder WLAN aufladen möchte, läuft Gefahr, seine Kreditkartendaten an Kriminelle weiterzugeben.
---------------------------------------------
https://www.watchlist-internet.at/news/handy-guthaben-aufladen-vorsicht-vor…
∗∗∗ Hack halts Dutch broadcaster, forcing radio hosts back to LPs ∗∗∗
---------------------------------------------
A Dutch TV and radio broadcaster has found itself at the mercy of cybercriminals after suffering a cyber attack, and leaving it scrambling to find ways to play music to its listeners. Read more in my article on the Hot for Security blog.
---------------------------------------------
https://www.bitdefender.com/en-us/blog/hotforsecurity/hack-halts-dutch-broa…
∗∗∗ Dont call it Cyber Command 2.0: Master plan for digital forces will take years to implement ∗∗∗
---------------------------------------------
The latest model for improving U.S. Cyber Command is circulating at the Pentagon. Some of the initiatives will spill into the next decade — an approach that is sure to create friction on Capitol Hill and beyond.
---------------------------------------------
https://therecord.media/revised-cyber-command-master-plan-dod-pentagon
∗∗∗ Short-term renewal of cyber information sharing law appears in bill to end shutdown ∗∗∗
---------------------------------------------
An expired 2015 law that gives companies liability protection when they share cyberthreat information with the federal government would be renewed through January 30 under Senate legislation to end the government shutdown.
---------------------------------------------
https://therecord.media/cisa-2015-information-sharing-law-renewal-bill-endi…
∗∗∗ Russian missile barrage disrupts internet, customs databases in Ukraine ∗∗∗
---------------------------------------------
Emergency blackouts lasting up to 12 hours were introduced following the attack, with Kyiv and other regions facing widespread internet and communication outages, according to internet watchdog NetBlocks.
---------------------------------------------
https://therecord.media/russian-missile-barrage-disrupts-internet-ukraine
∗∗∗ Phishing-Kampagne zielt auf Führungskräfte ∗∗∗
---------------------------------------------
In letzter Zeit scheinen Führungskräfte und leitende Angestellte aus unterschiedlichen Branchen verstärkt ins Visier von Cyberkriminellen zu geraten. Diese versuchen die Adressaten mittels Phishing-Mails zur Herausgabe von Daten zu überlisten.
---------------------------------------------
https://www.borncity.com/blog/2025/11/08/phishing-kampagne-zielt-auf-fuehru…
∗∗∗ No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480 ∗∗∗
---------------------------------------------
Mandiant Threat Defense has uncovered exploitation of an unauthenticated access vulnerability within Gladinet’s Triofox file-sharing and remote access platform. This now-patched n-day vulnerability, assigned CVE-2025-12480, allowed an attacker to bypass authentication and access the application configuration pages, enabling the upload and execution of arbitrary payloads.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerabil…
∗∗∗ EU will DSGVO schleifen – nicht nur bei Cookie-Bannern ∗∗∗
---------------------------------------------
Der von der EU-Kommission geplante "digitale Omnibus" würde bestehende Datenschutzrechte aufweichen. Es geht etwa um Cookies und das Training von KI-Systemen.
---------------------------------------------
https://heise.de/-11071630
∗∗∗ The state of the Rust dependency ecosystem ∗∗∗
---------------------------------------------
Over the past few days, I analyzed over 200,000 crates from crates.io to uncover patterns in maintenance, developer engagement, security, and overall ecosystem health. The results: a mix of fascinating insights, concerning trends, and reasons for optimism.
---------------------------------------------
https://00f.net/2025/10/17/state-of-the-rust-ecosystem/
∗∗∗ Balancer hack analysis and guidance for the DeFi ecosystem ∗∗∗
---------------------------------------------
On November 3, 2025, attackers exploited a vulnerability in Balancer v2 to drain more than $100M across nine blockchain networks. The attack targeted a number of Balancer v2 pools, exploiting a rounding direction error.
---------------------------------------------
https://blog.trailofbits.com/2025/11/07/balancer-hack-analysis-and-guidance…
=====================
= Vulnerabilities =
=====================
∗∗∗ QNAP fixes seven NAS zero-day flaws exploited at Pwn2Own ∗∗∗
---------------------------------------------
QNAP has fixed seven zero-day vulnerabilities that security researchers exploited to hack QNAP network-attached storage (NAS) devices during the Pwn2Own Ireland 2025 competition.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/qnap-fixes-seven-nas-zero-da…
∗∗∗ Sicherheitslücken in RunC: Angreifer können aus Docker-Containern ausbrechen ∗∗∗
---------------------------------------------
Administratoren sollten aufpassen, welche Docker-Images sie nutzen. Angreifer können sich Root-Zugriff auf das Hostsystem verschaffen.
---------------------------------------------
https://www.golem.de/news/sicherheitsluecken-in-runc-angreifer-koennen-aus-…
∗∗∗ runC Container Escape Vulnerabilities ∗∗∗
---------------------------------------------
High-severity vulnerabilities in runc (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) were disclosed in early November 2025. A malicious or compromised container image can abuse how runc handles masked paths, bind-mounts, and special files to write to the host /proc filesystem and escape the container boundary - enabling remote code execution on the host, persistence, or cluster-wide denial-of-service. These issues affect virtually all Linux container stacks that use runc (Docker, containerd, CRI-O, Kubernetes, and managed services).
---------------------------------------------
https://fortiguard.fortinet.com/threat-signal-report/6248
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/