ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-10215
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4.

The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

NVD description · AI analysis pending
9.8<1%
  • iqonic wpbookit
CVE-2024-11350
The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6.

The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adforest_reset_password() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

NVD description · AI analysis pending
9.8<1%
  • scriptsbundle adforest
CVE-2024-12847
Unauthenticated Root RCE in NETGEAR DGN1000 via setup.cgi

CVE-2024-12847 is an authentication bypass (CWE-306) in NETGEAR DGN1000 routers that allows a remote, unauthenticated attacker to inject and execute arbitrary operating system commands (CWE-78) as root. The flaw is triggered by sending crafted HTTP requests to the device's setup.cgi endpoint; no credentials or user interaction are required, and the network vector and low complexity yield a critical CVSS 3.1 score of 9.8. A successful attacker gains full root control of the router, which can be used for device compromise, traffic interception, or botnet recruitment. All DGN1000 units running firmware before 1.1.00.48 are affected; these are aging consumer/ISP-supplied routers, many of which remain connected to the public internet with management interfaces exposed. The vulnerability has been exploited in the wild since at least 2017 and was specifically observed by the Shadowserver Foundation on 2025-02-06 UTC; it has two public PoCs on Exploit-DB, a 29.9% EPSS (98th percentile), is not yet in CISA KEV, and broader botnet activity against consumer routers (e.g., RondoDox, reported to target 56 flaws across 30+ device types) suggests continued scanning pressure against this device class.

Do: Upgrade affected DGN1000 units to firmware 1.1.00.48 or later; if the device is end-of-life or no update is available, block or restrict WAN-side access to the web management interface (particularly setup.cgi) or replace the router. Review device and firewall logs for suspicious unauthenticated requests to setup.cgi, and treat any unit with an internet-exposed management interface as potentially compromised given exploitation has been observed since at least 2017.

9.830% PoC ×2
  • netgear dgn1000 firmware before 1.1.00.48
largeon the order of 10,000-100,000 internet-exposed DGN1000 devices (total units shipped over the product's lifetime likely higher)
CVE-2024-12877
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 vi

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server that makes remote code execution possible. Please note this was only partially patched in 3.19.3, a fully sufficient patch was not released until 3.19.4. However, another CVE was assigned by another CNA for version 3.19.3 so we will leave this as affecting 3.19.2 and before. We have recommended the vendor use JSON encoding to prevent any further deserialization vulnerabilities from being present.

NVD description · AI analysis pending
9.81%
  • givewp givewp
CVE-2024-13239
Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA):

Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.

NVD description · AI analysis pending
9.8<1%
  • two-factor authentication project two-factor authentication
CVE-2024-46981
Redis is an open source, in-memory database that persists on disk.

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage collector and potentially lead to remote code execution. The problem is fixed in 7.4.2, 7.2.7, and 6.2.17. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.

NVD description · AI analysis pending
9.88% PoC ×2
  • redis redis
  • redis debian linux
CVE-2024-50603
Unauthenticated OS Command Injection (RCE) in Aviatrix Controller

CVE-2024-50603 is an unauthenticated OS command injection flaw (CWE-78) in Aviatrix Controllers, rated critical (CVSS 3.1: 9.8), that allows arbitrary code execution. It is triggered by sending shell metacharacters to the controller's /v1/api endpoint - in the cloud_type parameter for the list_flightpath_destination_instances action or the src_cloud_type parameter for the flightpath_connection_test action - where the input is not properly neutralized before being used in an OS command. An attacker who can reach the controller's API gains the ability to run arbitrary commands on the controller, and in observed attacks this has been used to install backdoors and cryptocurrency miners. Organizations running Aviatrix Controller versions before 7.1.4191, or 7.2.x versions before 7.2.4996, are affected. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-16 and carries a 98.5% EPSS probability of exploitation within 30 days.

Do: Upgrade to Aviatrix Controller 7.1.4191 or later on the 7.1 branch, or 7.2.4996 or later on the 7.2 branch, per the vendor's instructions; if patching is not immediately possible, restrict network access to the controller's /v1/api endpoint or discontinue use as required by CISA's KEV action. Given active exploitation deploying backdoors and crypto miners, check controllers for signs of compromise (unexpected processes, persistence mechanisms, unusual outbound traffic) and rotate credentials accessible from the controller.

9.899% KEV PoC
  • Aviatrix Controller before 7.1.4191; 7.2.x before 7.2.4996
moderatelikely thousands of controller deployments (estimate; enterprise-only install base, with low thousands of controllers observed internet-exposed in public scans)
CVE-2024-51818
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-designer.This

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.

NVD description · AI analysis pending
9.316%
  • WordPress
CVE-2024-51919
Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer:

Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.

NVD description · AI analysis pending
9.0<1%
  • WordPress
CVE-2024-52875
CRLF Injection/Open Redirect in GFI Kerio Control Enables Reflected XSS and RCE

CVE-2024-52875 is an HTTP response splitting flaw (CWE-113) in GFI Kerio Control 9.2.5 through 9.4.5, where the unauthenticated 'dest' GET parameter on the /nonauth/addCertException.cs, /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is placed into the Location header of a 302 redirect without sanitization. An attacker triggers it by convincing a user to open a crafted link containing CRLF sequences in the 'dest' parameter, which yields open redirects, HTTP response splitting, and reflected cross-site scripting. Beyond XSS, the flaw can be escalated to remote command execution by abusing the upgrade feature in the Kerio Control admin interface, as demonstrated in published research. Any organization running Kerio Control 9.2.5 through 9.4.5 — typically SMB firewall/VPN gateway appliances or virtual appliances — is affected. No confirmed in-the-wild exploitation is documented and the issue is not in CISA KEV, but two public proofs of concept exist and a 29.6% EPSS score (98th percentile) indicates a high likelihood of exploitation attempts within 30 days.

Do: Upgrade Kerio Control to a release later than 9.4.5, which resolves this issue. Until patched, minimize internet exposure of the Kerio Control admin and /nonauth/ pages (restrict management access to trusted networks) and treat any emailed or linked URLs pointing to the appliance's addCertException.cs, guestConfirm.cs or expiration.cs pages as untrusted. Monitor the appliance for unexpected upgrade activity or admin-interface sessions, since the known escalation path runs through the admin upgrade feature.

8.830% PoC ×2
  • GFI Kerio Control 9.2.5 through 9.4.5
large≈ tens of thousands of internet-exposed Kerio Control instances (estimated, no official install base in source data)
CVE-2024-53704
Authentication Bypass in SonicWall SonicOS SSLVPN

CVE-2024-53704 is a critical (CVSS 9.8) improper authentication flaw (CWE-287) in the SSLVPN authentication mechanism of SonicWall's SonicOS. A remote, unauthenticated attacker can exploit it over the network without user interaction, bypassing SSLVPN authentication to gain unauthorized access to the VPN and a foothold into protected internal networks. CISA notes known ransomware use, making this a high-value entry point for follow-on attacks. Any organization running SonicWall SonicOS with SSLVPN enabled is affected. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-02-18, public scans show 5,000+ internet-exposed SonicWall firewalls still unpatched, and EPSS rates the 30-day exploitation probability at 95.1%.

Do: Upgrade affected SonicOS deployments to the patched releases listed in SonicWall's advisory, prioritizing internet-facing SSLVPN endpoints. Until patched, restrict or disable SSLVPN exposure where feasible and hunt for signs of exploitation, since ransomware use is known. Remediation must satisfy CISA KEV required actions (apply vendor mitigations or discontinue use).

9.895% KEV ransomware
  • SonicWall SonicOS
largeestimated tens of thousands of SSLVPN-enabled SonicWall firewall deployments, with at least ~5,000 confirmed still exposed and unpatched on the public internet
CVE-2024-54676
Unsafe Java deserialization in Apache OpenMeetings clustering deployments

Apache OpenMeetings versions 2.1.0 through versions before 8.0.0 are vulnerable to deserialization of untrusted data (CWE-502) because the project's default clustering instructions do not configure OpenJPA serialization class blacklists or whitelists. In deployments that enable clustering following the published default setup, an attacker who can reach the clustered OpenMeetings service over the network can supply a crafted serialized Java object that the server deserializes without validation. Consistent with the CVSS 3.1 critical score of 9.8 (network vector, no privileges or user interaction required, high confidentiality/integrity/availability impact), successful exploitation could enable unauthenticated remote code execution and full system compromise. Only installations running affected versions with clustering enabled are exposed; standalone deployments without clustering are less likely to be impacted. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 65.2% probability of exploitation within 30 days (99th percentile), so defenders should treat this as likely to be exploited soon.

Do: Upgrade to Apache OpenMeetings 8.0.0 or later and, as part of the upgrade, add the documented 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' settings to startup scripts, since upgrading alone is not sufficient. Organizations that cannot upgrade immediately should apply equivalent OpenJPA serialization filters or restrict network access to clustered OpenMeetings endpoints. Given the high EPSS score, prioritize patching of internet-exposed instances and monitor Apache security channels for signs of exploitation.

9.865%
  • The Apache Software Foundation Apache OpenMeetings all releases from 2.1.0 up to but excluding 8.0.0
nichelikely hundreds to low thousands of clustered OpenMeetings deployments worldwide
CVE-2024-8474
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorize

OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic

NVD description · AI analysis pending
7.5<1%
  • openvpn connect
CVE-2024-9138
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138.

Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk.

NVD description · AI analysis pending
8.61%
CVE-2024-9140
Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140.

Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s security and functionality.

NVD description · AI analysis pending
9.32%
CVE-2025-0103
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashe

An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.

NVD description · AI analysis pending
9.2<1%
  • paloaltonetworks expedition
CVE-2025-0282
Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways

CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known.

Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin.

9.0100% KEV ransomware PoC ×3
  • Ivanti Connect Secure
  • Ivanti Policy Secure
  • Ivanti ZTA Gateways
largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways)
CVE-2025-23016
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

NVD description · AI analysis pending
9.3<1%
Full article2,056 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 13, 2025

The cyber world’s been buzzing this week, and it’s all about staying ahead of the bad guys. From sneaky software bugs to advanced hacking tricks, the risks are real, but so are the ways to protect yourself. In this recap, we’ll break down what’s happening, why it matters, and what you can do to stay secure.

Let’s turn awareness into action and keep one step ahead of the threats.

⚡ Threat of the Week

Critical Ivanti Flaw Comes Under Exploitation — A newly discovered critical security vulnerability in Ivanti Connect Secure appliances has been exploited as a zero-day since mid-December 2024. The flaw (CVE-2025-0282, CVSS score: 9.0) is a stack-based buffer overflow bug that could lead to unauthenticated remote code execution. According to Google-owned Mandiant, the flaw has been exploited to deploy the SPAWN ecosystem of malware – the SPAWNANT installer, SPAWNMOLE tunneler, and the SPAWNSNAIL SSH backdoor – as well as two other previously undocumented malware families dubbed DRYHOOK and PHASEJAM. There is a possibility that multiple threat actor groups, including the China-linked UNC5337, are behind the exploitation.

AI Risk Assessment AI Risk Assessment

Advance Your Cybersecurity Career with SANS Across the U.S.

Unlock top-tier cybersecurity training at SANS with fast, focused, and expert-led courses designed to take your cyber career to the next tier in six days or less.

Find Your Course Now!

🔔 Top News

  • Microsoft Pursues Legal Action Against Hacking Group — Microsoft said it's taking legal action against an unknown foreign-based threat-actor group for abusing stolen Azure API keys and customer Entra ID authentication information to breach its systems and gain unauthorized access to the Azure OpenAI Service with the goal of generating harmful content that bypasses safety guardrails, as well as monetizing that access by offering it to other customers. It accused three unnamed individuals of creating a "hacking-as-a-service" infrastructure for this purpose.
  • Exploitation Attempts Recorded Against GFI KerioControl Firewalls — Threat actors are actively attempting to exploit a recently disclosed security flaw impacting GFI KerioControl firewalls that, if successfully exploited, could allow malicious actors to achieve remote code execution (RCE). The vulnerability, CVE-2024-52875, is a carriage return line feed (CRLF) injection that could result in a cross-site scripting (XSS) attack. Attempts to exploit the vulnerability commenced around December 28, 2024.
  • Updated EAGERBEE Malware Targets the Middle East — Internet service providers (ISPs) and governmental entities in the Middle East have been targeted using an updated variant of the EAGERBEE (aka Thumtais) malware framework. The new variant is capable of deploying additional payloads, enumerating file systems, and executing command shells. It can also manage processes, maintain remote connections, manage system services, and list network connections.
  • Southeast Asia Comes Under Mustang Panda Attacks — Several entities in Mongolia, Taiwan, Myanmar, Vietnam, and Cambodia have been targeted by the China-nexus Mustang Panda threat actor to deliver a customized version of the PlugX backdoor between July 2023 and December 2024. The attacks involve the use of Windows Shortcut (LNK), Windows Installer (MSI), and Microsoft Management Console (MSC) files, likely distributed via spear-phishing, as the first-stage component to trigger the infection chain, ultimately leading to the deployment of PlugX using DLL side-loading techniques.
  • U.S. Government Formally Unveils Cyber Trust Mark — The U.S. government announced the launch of the U.S. Cyber Trust Mark, a new cybersecurity safety label for Internet-of-Things (IoT) consumer devices that details the support period as well as the steps users can take to change the default password and configure the device securely. Eligible products that come under the purview of the Cyber Trust Mark program include internet-connected home security cameras, voice-activated shopping devices, smart appliances, fitness trackers, garage door openers, and baby monitors.

‎️‍🔥 Trending CVEs

Your favorite software might be hiding serious security cracks—don’t wait for trouble to find you. Update now and stay one step ahead of the threats!

This week’s list includes — CVE-2024-8474 (OpenVPN Connect), CVE-2024-46981 (Redis), CVE-2024-51919, CVE-2024-51818 (Fancy Product Designer plugin), CVE-2024-12877 (GiveWP – Donation Plugin and Fundraising Platform), CVE-2024-12847 (NETGEAR DGN1000), CVE-2025-23016 (FastCGI fcgi2), CVE-2024-10215 (WPBookit plugin), CVE-2024-11350 (AdForest theme), CVE-2024-13239 (Drupal), CVE-2024-54676 (Apache OpenMeetings) CVE-2025-0103 (Palo Alto Networks Expedition), CVE-2024-53704 (SonicWall SonicOS), CVE-2024-50603 (Aviatrix Controller), CVE-2024-9138, and CVE-2024-9140 (Moxa).

📰 Around the Cyber World

  • Pastor Indicted for "Dream" Solano Fi Project — Francier Obando Pinillo, a 51-year-old pastor at a Pasco, Washington, church, has been indicted on 26 counts of fraud for allegedly operating a cryptocurrency scam that defrauded investors of millions between November 2021 and October 2023. Pinillo is said to have used his position as pastor to induce members of his congregation and others to invest their money in a cryptocurrency investment business known as Solano Fi. He claimed the idea for the scheme had "come to him in a dream." According to the U.S. Department of Justice (DoJ), "rather than investing funds on victims' behalf as he had promised, Pinillo defrauded victims into making cryptocurrency transfers into accounts he designated, then converted the victims' funds to himself and his co-schemers." Pinillo has also been accused of convincing investors to recruit other investors in exchange for additional returns for each new investor they recruited. The fraud charges carry a maximum sentence of up to 20 years in prison. The defendant is estimated to have targeted at least 1,515 customers in the U.S., netting him $5.9 million in illicit profits. The development comes as a Delaware man, Mohamed Diarra, pleaded guilty to his participation in a widespread international sextortion and money laundering scheme from May 2020 and through December 2022. "Diarra conspired with co-conspirators in Côte d'Ivoire who sextorted victims and utilized a network of Delaware-based 'money mules,' including Diarra, to assist with laundering the victims' illegally obtained funds," the DoJ said. He faces a maximum penalty of 20 years in prison. In recent months, the DoJ has also prosecuted Robert Purbeck; Kiara Graham, Cortez Tarmar Crawford, and Trevon Demar Allen; and Charles O. Parks III in connection with extortion, SIM-swapping, and cryptojacking operations, respectively.
  • Washington State Sues T-Mobile Over 2021 Data Breach — The U.S. state of Washington has sued T-Mobile over allegations the phone giant failed to secure the personal data of more than 2 million state residents prior to an August 2021 data breach, which went on to affect more than 79 million customers across the country. The lawsuit asserted that "T-Mobile knew for years about certain cybersecurity vulnerabilities and did not do enough to address them" and that the company "misrepresented to consumers that the company prioritizes protecting the personal data it collects." The complaint noted that T-Mobile "used weak credentials" on accounts for accessing its internal systems and did not implement rate-limiting on login attempts, thus allowing the attackers to brute-force the credentials without locking the employee accounts in question. A year after the incident, T-Mobile agreed to pay $350 million to settle a class-action lawsuit. John Binns, an American citizen living in Turkey, took credit for the attack. He was subsequently arrested in May 2024 for his participation in the Snowflake extortion campaign.
  • Telegram Complies With More User Data Requests Following CEO Arrest — Telegram has been increasingly sharing user data at the request of law enforcement authorities following the arrest of its CEO Pavel Durov last year, according to information compiled from its periodic transparency reports. India, Germany, the U.S., France, Brazil, South Korea, Belgium, Spain, Poland, and Italy accounted for the top 10 countries with the most number of requests. Days after his arrest, Telegram promised to make significant improvements in an effort to tackle criticisms about the lack of oversight and the abuse of the platform for illicit activities. It also pledged to provide the IP addresses and phone numbers of users who violate rules in response to valid legal requests. Despite the policy changes, Telegram continues to be a major hub for cybercriminals to carry out their operations due to its "established" user base and functionality. "While Signal, Discord, and other alternative platforms are used by cybercriminals, it doesn’t appear they will fully replace Telegram in the future, and rather serve as additional methods for threat actors to perform malicious activities," KELA said last month.
  • MLOps Platforms Could Become a New Attack Target — As companies rush to leverage artificial intelligence (AI) applications, MLOps platforms used to develop, train, deploy and monitor such applications could be targeted by attackers, allowing them to not only gain unauthorized access, but also impact the confidentiality, integrity and availability of the machine learning (ML) models and the data they provide. Such actions could permit an adversary to perform a model extraction attack, poison or access training data, and bypass AI-based classification systems. "The increased usage of MLOps platforms to create, manage and deploy ML models will cause attackers to view these platforms as attractive targets," IBM X-Force said. "As such, properly securing these MLOps platforms and understanding how an attacker could abuse them to conduct attacks such as data poisoning, data extraction and model extraction is critical."
  • Popular Windows Applications Vulnerable to WorstFit Attack — Several Windows-based applications such as curl.exe, excel.exe, openssl.exe, plink.exe, tar.exe, and wget.exe have been found susceptible to a brand-new attack surface called WorstFit, which exploits a character conversion feature built into Windows called Best-Fit. Taiwanese cybersecurity company DEVCORE said the Best-Fit conversion is designed to handle situations where the operating system needs to convert characters from UTF-16 to ANSI, but the equivalent character doesn't exist in the target code page. That said, this "unexpected character transformation" could be harnessed to achieve path traversal and remote code execution via techniques such as filename smuggling, argument splitting, and environment variable confusion. "As for how to mitigate such attacks, unfortunately, since this is an operating system-level problem, similar issues will continue to reappear – until Microsoft chooses to enable UTF-8 by default in all of their Windows editions," researchers Orange Tsai and Splitline Huang said. In the meantime, developers are recommended to phase out ANSI and switch to the Wide Character API.

🎥 Expert Webinar

  1. Future-Ready Trust: Manage Certificates Like Never Before — Managing digital trust shouldn’t feel impossible. Join us to discover how DigiCert ONE transforms certificate management—streamlining trust operations, ensuring compliance, and future-proofing your digital strategy. Don’t let outdated systems hold you back. Reserve your spot today and see the future of trust management in action!..
  2. AI in Cybersecurity—Game-Changer or Hype? — Is AI the future of cybersecurity or just another buzzword? Find out as 200 industry experts share real-world insights on AI-driven vulnerability management and how it can strengthen your defenses. Cut through the noise and gain strategies you can use right now. Secure your spot today.

🔧 Cybersecurity Tools

  • MLOKit — It’s a MLOps attack toolkit that leverages REST API vulnerabilities to simulate real-world attacks on MLOps platforms. From reconnaissance to data and model extraction, this modular toolkit is built for adaptability—empowering security pros to stay ahead.
  • HackSynth — It's an AI-powered agent designed for autonomous penetration testing. With its Planner and Summarizer modules, HackSynth generates commands, processes feedback, and iterates efficiently. Tested on 200 diverse challenges from PicoCTF and OverTheWire.

🔒 Tip of the Week

Know Your Browser Extensions — Your browser is the heart of your online activity—and a prime target for cyber threats. Malicious extensions can steal sensitive data, while sneaky DOM manipulations exploit vulnerabilities to run harmful code in the background. These threats often go unnoticed until it’s too late. So, how do you stay protected? Tools like CRXaminer and DOMspy make it simple. CRXaminer scans Chrome extensions to uncover risky permissions or dangerous code before you install them. DOMspy helps you spot hidden threats by monitoring your browser’s behavior in real-time, and flagging suspicious activities like DOM clobbering or prototype pollution. Stay safe by reviewing your extensions regularly, only granting permissions when absolutely necessary, and keeping your browser and tools up to date.

Conclusion

Every click, download, and login contributes to your digital footprint, shaping how secure or vulnerable you are online. While the risks may feel overwhelming, staying informed and taking proactive steps are your best defenses.

As you finish this newsletter, take a moment to assess your online habits. A few simple actions today can save you from significant trouble tomorrow. Stay ahead, stay secure.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/01/thn-weekly-recap-top-cybersecurity_01424177917.html