⚡ THN Weekly Recap: Alerts on Zero-Day Exploits, AI Breaches, and Crypto Heists
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-12084 | Heap-Based Buffer Overflow in rsync Daemon Enables Potential Remote Code Execution CVE-2024-12084 is a critical (CVSS 9.8) heap-based buffer overflow in the rsync daemon, caused by improper handling of an attacker-controlled checksum length (s2length): when MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH of 16 bytes, a connecting peer can cause an out-of-bounds write into the fixed-size sum2 buffer. A remote attacker who can reach the rsync daemon needs no privileges or user interaction to trigger the flaw, and the resulting heap corruption can lead to remote code execution on the server (as demonstrated in the referenced Google security research) or crash the daemon. Any system running a vulnerable rsync daemon is affected — including rsync shipped with Red Hat Enterprise Linux, SUSE Linux, AlmaLinux, Arch Linux, Gentoo, NixOS and SmartOS — with the highest risk on servers where the daemon is exposed on TCP port 873. No confirmed in-the-wild exploitation is documented yet (the CVE is not on CISA KEV), but a public proof-of-concept exists from Google Cloud researchers and EPSS assigns a 72.1% probability of exploitation within 30 days, indicating high imminent risk. Do: Upgrade rsync to 3.4.1 or later, or install the patched rsync package from your distribution (Red Hat, SUSE, AlmaLinux, Arch, Gentoo, NixOS and SmartOS have all shipped fixes). Until patched, restrict TCP port 873 to trusted networks or disable the rsync daemon where it is not needed. Audit hosts for listening rsync daemons and verify the installed rsync version against your vendor's advisory. | 9.8 | 72% | PoC |
| massmillions of servers ship rsync across the affected distributions, with roughly 30,000–60,000 rsync daemons directly exposed on the public internet | |
| CVE-2024-12085 | A flaw was found in rsync which could be triggered when rsync compares file checksums. A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. NVD description · AI analysis pending | 7.5 group max | 9% | PoC |
| — | |
| CVE-2024-12824 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. This is due to the plugin not properly checking for an empty token value prior updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's password, including administrators, and leverage that to gain access to their account. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2024-34331 | A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, beca A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root. NVD description · AI analysis pending | 9.8 | <1% | — | — | ||
| CVE-2024-50302 | Kernel Memory Leak via Uninitialized HID Report Buffer in Linux Kernel CVE-2024-50302 is a use of uninitialized resource flaw (CWE-908) in the Linux kernel's HID (Human Interface Device) core, where the shared report buffer was not zero-initialized at allocation. An attacker can trigger it by getting the kernel to process a specially crafted HID report, causing uninitialized kernel memory to be exposed to the requesting driver. The impact is an information disclosure: a local attacker, or a malicious/malfunctioning HID device, could leak kernel memory contents, which could in turn aid further attacks. Because nearly all Linux-based systems compile in HID support, affected code is present in Linux distributions, Android, and Siemens industrial products (SIMATIC S7-1500 TM MFP firmware and SINEC OS). The vulnerability is being actively exploited: CISA added it to the KEV catalog on 2025-03-04, and it is among the actively exploited flaws addressed in Google's March 2025 Android security update. Do: Apply the fixes per vendor channels: install the March 2025 Android security update on Android devices (it is listed as actively exploited and is in CISA KEV, required under BOD 22-01 for federal agencies), and apply Debian kernel updates and Siemens (SIMATIC S7-1500 TM MFP firmware / SINEC OS) updates once issued. Operators should inventory systems running Linux kernels with the HID core (most systems) and prioritize patching, since a local attacker or malicious USB HID device can leak kernel memory; the fix zero-initializes the HID report buffer and is included in current stable kernel branches. | 5.5 | <1% | KEV |
| massBillions of devices ship affected Linux kernel HID code (Linux runs on ~3+ billion Android devices plus millions of servers, desktops, and industrial systems),… | |
| CVE-2024-53104 | Out-of-Bounds Write in Linux Kernel UVC Video Driver (CVE-2024-53104) CVE-2024-53104 is an out-of-bounds write (CWE-787) in the Linux kernel's uvcvideo (USB Video Class) driver: uvc_parse_format does not skip frames of type UVC_VS_UNDEFINED, but those frame types were not accounted for when sizing the frames buffer in uvc_parse_streaming. The flaw is triggered when the kernel parses format/frame descriptors from a USB camera device, so a crafted or nonconforming USB video descriptor can corrupt adjacent kernel memory. An attacker with local, low-privileged access (CVSS 3.1: AV:L/AC:L/PR:L, 7.8 High) can gain kernel memory corruption with high impact to confidentiality, integrity and availability, typically yielding local privilege escalation. Any Linux system or Android device running a kernel that ships the UVC driver is in scope, including Debian and other distributions built from affected kernel sources. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV on 2025-02-05, Google fixed it as an actively exploited flaw in the March 2025 Android Security Update, and EPSS currently estimates a 3.4% (88th percentile) probability of exploitation over the next 30 days. Do: Upgrade to a Linux kernel version that contains the uvcvideo fix (apply updated kernel packages from your distribution, e.g. Debian), and for Android devices install the March 2025 Android Security Bulletin patches or later. Follow the CISA KEV required action by applying vendor mitigations or discontinuing use if patches are unavailable. To gauge exposure on unpatched hosts, check whether the UVC driver is loaded (e.g. 'lsmod | grep uvcvideo') and restrict untrusted USB video devices until patched. | 7.8 | 3% | KEV |
| masshundreds of millions of Linux/Android installations potentially carrying the vulnerable driver (Linux kernel runs on billions of devices and the UVC driver… | |
| CVE-2024-53197 | Out-of-Bounds Write in Linux Kernel ALSA USB Audio Driver (CVE-2024-53197) CVE-2024-53197 is an out-of-bounds access/write (CWE-787) in the Linux kernel's USB configuration handling, tied to the ALSA usb-audio driver's handling of Creative Extigy and Mbox devices. A malicious or bogus USB device that reports a bNumConfigurations value larger than the array allocated by usb_get_configuration causes the kernel to access memory beyond the end of dev->config, for example in usb_destroy_configuration. An attacker with local access — or the ability to plug a crafted USB audio device into a target — could corrupt or disclose kernel memory, with high impact to confidentiality, integrity, and availability (CVSS 7.8, local vector), typically as privilege escalation or a kernel crash. Any Linux deployment running a kernel with the vulnerable code is affected, including Debian systems. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-04-09, indicating known exploitation in the wild, though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Update the Linux kernel to a vendor release containing the CVE-2024-53197 fix — for Debian, install the current kernel security update and reboot; other distributions ship the patched kernel in their stable updates. Because exploitation requires a malicious USB audio device, restrict use of untrusted USB peripherals on sensitive or internet-adjacent hosts. Organizations subject to CISA BOD 22-01 must remediate this KEV-listed flaw per the required actions or discontinue use where mitigations are unavailable. | 7.8 | 4% | KEV |
| massmillions of Linux installations (kernel ubiquity across desktops, servers, and Debian; practically reachable only on hosts that accept untrusted USB audio… | |
| CVE-2024-8420 | The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-8425 | The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this may have been patched on an older version than 2.9.2, however, we do not have access to older versions of the software to confirm when the patch was added. The only patched version we have confirmed is 2.9.3. NVD description · AI analysis pending | 9.8 | 4% |
| — | ||
| CVE-2024-9193 | The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.3-revision- The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.3-revision-0 via the whmpress_domain_search_ajax_extended_results() function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. Utilizing the /admin/services.php file, this can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2025-0555 +1 in the same advisory: …0475 | A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2025-0514 | Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on act Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before < 24.8.5. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2025-0690 | The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to real The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, with a line big enough it's possible to make this variable to overflow leading to a out-of-bounds write in the heap based buffer. This flaw may be leveraged to corrupt grub's internal critical data and secure boot bypass is not discarded as consequence. NVD description · AI analysis pending | 6.1 | <1% | — | — | ||
| CVE-2025-1128 | Unauthenticated Arbitrary File Upload in Everest Forms WordPress Plugin CVE-2025-1128 is a critical (CVSS 9.8) unauthenticated arbitrary file upload, read, and deletion flaw in the Everest Forms WordPress plugin (CWE-434), caused by missing file-type and path validation in the 'format' method of the EVF_Form_Fields_Upload class. An attacker with no account and no user interaction can send crafted requests to a site running an affected version to upload files of arbitrary type (potentially including executable PHP scripts), read arbitrary files on the server, or delete arbitrary files. Consequences can include remote code execution, disclosure of sensitive information such as configuration files, or deletion of critical files enabling complete site takeover. All Everest Forms versions up to and including 3.0.9.4 are affected, so any WordPress site running the plugin at one of those versions is in scope. No public proof-of-concept or CISA KEV listing is known at this time, but the 28.8% EPSS score (98th percentile) indicates a high probability of exploitation within the next 30 days. Do: Upgrade Everest Forms to version 3.0.9.5 or later (anything above 3.0.9.4) as soon as possible. If immediate patching is not possible, deactivate the plugin or remove file-upload fields from published forms, and consider a WAF rule blocking unauthenticated requests to the plugin's upload/AJAX endpoints. After patching, check upload directories (including wp-content/uploads/everest_forms) for unexpected or recently modified files, look for newly created rogue administrator accounts, and verify that core files such as wp-config.php have not been deleted or altered. | 9.8 | 29% |
| large≈100,000 WordPress sites (plugin reported at roughly 100k active installs) | ||
| CVE-2025-1564 | The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a users identity through the social login. This makes it possible for unauthenticated attackers to log in as any user, including administrators and take over access to their account. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-1638 | The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.2. The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity through the alloggio_membership_init_rest_api_facebook_login and alloggio_membership_init_rest_api_google_login functions. This makes it possible for unauthenticated attackers to log in as any user, including administrators, without knowing a password. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-1671 | The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user, including site administrators. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-20111 | A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could all A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of specific Ethernet frames. An attacker could exploit this vulnerability by sending a sustained rate of crafted Ethernet frames to an affected device. A successful exploit could allow the attacker to cause the device to reload. NVD description · AI analysis pending | 7.4 | <1% | — | — | ||
| CVE-2025-23363 | A vulnerability has been identified in Teamcenter V14.1 (All versions), Teamcenter V14.2 (All versions), Teamcenter V14.3 (All versions < V14.3.0.14), Teamcente A vulnerability has been identified in Teamcenter V14.1 (All versions), Teamcenter V14.2 (All versions), Teamcenter V14.3 (All versions < V14.3.0.14), Teamcenter V2312 (All versions < V2312.0010), Teamcenter V2406 (All versions < V2406.0008), Teamcenter V2412 (All versions < V2412.0004). The SSO login service of affected applications accepts user-controlled input that could specify a link to an external site. This could allow an attacker to redirect the legitimate user to an attacker-chosen URL to steal valid session data. For a successful exploit, the legitimate user must actively click on an attacker-crafted link. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2025-24752 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addon Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Reflected XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.0.14. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2025-25570 | Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials. Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials. NVD description · AI analysis pending | 9.8 | 2% | — | — | ||
| CVE-2025-26943 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes easy-quotes allows Blind SQL Inj Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes easy-quotes allows Blind SQL Injection.This issue affects Easy Quotes: from n/a through <= 1.2.2. NVD description · AI analysis pending | 9.3 | <1% |
| — | ||
| CVE-2025-27090 | Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed the implant to do so. The only impact that has been shown is the exposure of the server's IP address to a third party. This issue has been addressed in version 1.5.43 and all users are advised to upgrade. There are no known workarounds for this vulnerability. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2025-27364 | Unauthenticated RCE in MITRE Caldera agent compilation service MITRE Caldera, an open-source adversary emulation platform, contains a critical unauthenticated remote code execution flaw (CWE-78 command injection) in the server component that dynamically compiles its Sandcat and Manx agent implants. A remote attacker with no credentials can trigger it by sending a crafted web request to the Caldera server API used for compiling and downloading these agents, abusing the gcc -extldflags linker flag to inject and execute sub-commands. Successful exploitation yields arbitrary code execution on the host running Caldera, with the changed scope and high confidentiality/integrity/availability impact indicating full compromise beyond the application itself. All deployments through 4.2.0 and 5.0.0 builds prior to fix commit 35bc06e are affected. Exploitation has not been confirmed in the wild and no public PoC is known, but EPSS assigns a roughly 26% probability of exploitation within 30 days (98th percentile), so defenders should treat it as likely to be targeted soon. Do: Upgrade Caldera to a 5.0.0 build at or after commit 35bc06e (the fixed version); deployments on 4.x or unpatched 5.0.0 builds should move to the patched code. Until then, restrict network access to the Caldera server and its agent compile/download API, and check server logs for unauthenticated requests to the Sandcat/Manx compilation endpoint containing gcc -extldflags parameters, followed by host-level review for unexpected command execution. | 10.0 | 26% |
| nichelikely on the order of thousands of Caldera server deployments worldwide (estimate; no published install base), with only a fraction internet-exposed |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | bybit-assessment.com | found that the threat actors registered a fake domain named bybit-assessment[.]com a few hours before the theft took place. Silent Push, whi |
Full article2,964 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 03, 2025
This week, a 23-year-old Serbian activist found themselves at the crossroads of digital danger when a sneaky zero-day exploit turned their Android device into a target. Meanwhile, Microsoft pulled back the curtain on a scheme where cybercriminals used AI tools for harmful pranks, and a massive trove of live secrets was discovered, reminding us that even the tools we rely on can hide risky surprises.
We’ve sifted through a storm of cyber threats—from phishing scams to malware attacks—and broken down what it means for you in clear, everyday language. Get ready to dive into the details, understand the risks, and learn how to protect yourself in an increasingly unpredictable online world.
⚡ Threat of the Week
Serbian Youth Activist Targeted by Android 0-Day Exploit Chain — A 23-year-old Serbian youth activist had their Android phone targeted by a zero-day exploit chain developed by Cellebrite to unlock the device and likely deploy an Android spyware called NoviSpy. The flaws combined CVE-2024-53104 with CVE-2024-53197 and CVE-2024-50302 to escalate privileges and achieve code execution. The vulnerabilities, originally present within the Linux kernel, were addressed in December 2024. CVE-2024-53104 has since been addressed in Android as of early February 2025. In response to the development, Cellebrite said it will no longer allow Serbia to use its software, stating "we found it appropriate to stop the use of our products by the relevant customers at this time."
🔔 Top News
- Microsoft Unmasks People Behind LLMjacking Scheme — Microsoft revealed the identities of four individuals who it said were behind an Azure Abuse Enterprise scheme that involves leveraging unauthorized access to generative artificial intelligence (GenAI) services in order to produce offensive and harmful content. The campaign, also referred to as LLMjacking, has targeted various AI service providers, with the threat actors selling the access to other criminal actors to facilitate the illicit generation of non-consensual intimate images of celebrities and other sexually explicit content in violation of its policies.
- Common Crawl Dataset Contains Nearly 12,000 Live Secrets — An analysis of a December 2024 archive from Common Crawl has uncovered nearly 12,000 live secrets, once again highlighting how hard-coded credentials pose a severe security risk to users and organizations alike. Furthermore, they also have the unintended side effect of exacerbating a problem where large language models (LLMs) end up suggesting insecure coding practices to their users due to the presence of hard-coded credentials in training data.
- Silver Fox APT Uses Winos 4.0 to Target Taiwanese Orgs — Taiwanese companies have been targeted via phishing emails that masquerade as the country's National Taxation Bureau with an aim to deliver the Winos 4.0 (aka ValleyRAT) malware. Winos, derived from Gh0st RAT, is a modular malware framework that acts both as a remote access trojan and a command-and-control (C2) framework. The malware has also been propagated via trojanized installers for Philips DICOM viewers. A majority of these artifacts have been detected in the United States and Canada, indicating a possible expansion of the Silver Fox APT's targeting to new regions and sectors.
- Australia Bans Kaspersky Products from Government Networks — Australia has become the latest country to ban the installation of security software from Russian company Kaspersky, citing "unacceptable security risk to Australian Government, networks and data." Under the new directive, government entities are prohibited from installing Kaspersky's products and web services on government systems and devices effective April 1, 2025. They have also been recommended to remove all existing instances by the cutoff date.
- Bybit Hack Formally Attributed to Lazarus Group — The North Korea-linked Lazarus Group has been implicated in the record-breaking hack of crypto exchange Bybit that led to the theft of $1.5 billion in digital assets. The attack has been attributed to a threat cluster dubbed TraderTraitor, which was previously behind the theft of cryptocurrency worth $308 million from cryptocurrency company DMM Bitcoin in May 2024. Further investigation has found that the hack was carried out by compromising one of the developer's machines associated with multisig wallet platform Safe{Wallet} which affected an account operated by Bybit. "The Bybit attack mirrors North Korea’s established tactics of targeting centralized crypto exchanges through methods such as phishing, supply chain compromises, and private key theft-strategies," TRM Labs said. An infrastructure analysis has also found that the threat actors registered a fake domain named bybit-assessment[.]com a few hours before the theft took place. Silent Push, which discovered the domain, told The Hacker News it found no information to tie the bogus domain to the actual hack itself. It's believed that the domain may have been set up as part of another related campaign codenamed Contagious Interview. The company also noted that the threat actors behind the Contagious Interview campaign are actively targeting various cryptocurrency companies such as Stripe, Coinbase, Binance, Block, Ripple, Robinhood, Tether, Circle, Kraken, Gemini, Polygon, Chainalysis, KuCoin, eToro, Bitstamp, Bitfinex, Gate.io, Pantera Capital, Galaxy, Bitwise Asset Management, Bitwise Investments, BingX, Gauntlet, XY Labs, YouHodler, MatChain, Bemo, Barrowwise, Bondex, Halliday, Holidu, Hyphen Connect, and Windranger. "Anyone applying for a job at one of these companies should be on the lookout for suspicious job offers or suspicious interview tactics," the company added.
️🔥 Trending CVEs
Your go-to software could be hiding dangerous security flaws—don’t wait until it’s too late! Update now and stay ahead of the threats before they catch you off guard.
This week’s list includes — CVE-2025-27364 (MITRE Caldera), CVE-2025-24752 (Essential Addons for Elementor plugin), CVE-2025-27090 (Sliver), CVE-2024-34331 and its bypass (Parallels Desktop), CVE-2025-0690 (GRUB2), CVE-2024-12084, CVE-2024-12085,CVE-2024-12086, CVE-2024-12087, CVE-2024-12088 (RSync), CVE-2025-0475, CVE-2025-0555 (GitLab), CVE-2025-20111 (Cisco Nexus 3000 and 9000 Series Switches), CVE-2025-23363 (Siemens Teamcenter), CVE-2025-0514 (CVE-2025-0514), CVE-2025-1564 (SetSail Membership plugin), CVE-2025-1671 (Academist Membership plugin), CVE-2025-1638 (Alloggio Membership plugin), CVE-2024-12824 (Nokri – Job Board WordPress Theme theme), CVE-2024-9193 (WHMpress - WHMCS WordPress Integration Plugin plugin), CVE-2024-8420 (DHVC Form plugin), CVE-2024-8425 (WooCommerce Ultimate Gift Card plugin), CVE-2025-25570 (Vue Vben Admin), CVE-2025-26943 (Jürgen Müller Easy Quotes plugin), and CVE-2025-1128 (Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin).
📰 Around the Cyber World
- Qualcomm and Google Announce Security Partnership — Chipmaker Qualcomm announced a partnership with Google with an aim to enable device manufacturers to provide up to eight years of software and security updates. "Starting with Android smartphones running on the Snapdragon 8 Elite Mobile Platform, Qualcomm Technologies now offers device manufacturers the ability to provide support for up to eight consecutive years of Android software and security updates," the company said. "Smartphones launching on new Snapdragon 8 and 7-series mobile platforms will also be eligible to receive this extended support." The eight-year pledge, however, only applies to devices using Arm-compatible Snapdragon 8 Elite chips and running Android 15, as well as future iterations of the Snapdragon 8 and 7-series.
- Microsoft Removes 2 Malicious VSCode Extensions — Microsoft has taken down two popular VSCode extensions, 'Material Theme – Free' and 'Material Theme Icons – Free,' from the Visual Studio Marketplace for allegedly containing malicious code. The two extensions have been downloaded nearly 9 million times cumulatively. It's believed that the malicious code was introduced in an update to the extensions, indicating either a supply chain attack or a compromise of the developer's account. Microsoft said it also banned the developer, who claimed the issues are caused by outdated Sanity.io dependency that "looks compromised." Another developer commented: "After being targeted for a removal, the reasonable, good faith action that the developer should have taken would be to reach out to the VS Code team, putting himself at their disposal to address any issues they have identified. Instead, he created multiple different accounts in order to submit the same extensions in an attempt to circumvent the restrictions, and implicated the VS Code devs in a conspiracy to personally censor him."
- Over 49,000 Misconfigured Access Management Systems Flagged — New research has uncovered more than 49,000 misconfigured access management systems (AMS) across the world, specifically in construction, healthcare, education, manufacturing, oil, and government sectors. These misconfigurations expose personal data, employee photographs, biometric data, work schedules, payslips, and other sensitive information. They could also be abused to access buildings and compromise physical security. Italy, Mexico, and Vietnam have emerged as the top countries with the most exposures. "These misconfigurations exposed highly sensitive personal information, including employee photographs, full names, identification numbers, access card details, biometric data, vehicle plate numbers, and in some cases, even complete work schedules and facility access histories," Modat said. "Particularly concerning was the discovery of exposed biometric templates and facial recognition data in several modern access control systems, which could pose serious privacy risks if accessed by malicious actors."
- Telegram Remains the Top Platform for Cybercriminals — Despite new commitments from Telegram, the messaging app continues to remain a hub for cybercriminal activity. Some of the other platforms that are gaining traction, according to Flare.io, include Discord, Signal, TOX, Session, and Element/Matrix. While Discord invite links were primarily found on forums like Nulled, Cracked, VeryLeaks, and DemonForums, Matrix and Element protocol based IDs were mainly found on drugs focused forums like RuTOR, RCclub, and BigBro. TOX and Jabber IDs were predominantly shared on XSS, CrdPro, BreachForums, and Exploit forums. "Increased cooperation between Telegram and law enforcement has prompted discussions about alternative platforms, with Signal showing the most significant growth," the company said. "Other messaging apps like Discord, TOX, Matrix, and Session play niche roles, often tied to specific cybercriminal activities or communities. Many threat actors use multiple messaging apps to ensure accessibility and redundancy in their communications."
- OpenSSF Releases Best Practices for Open-Source Projects — The Open Source Security Foundation (OpenSSF) released the Open Source Project Security Baseline (OSPS Baseline), a three-tiered set of requirements that aims to improve the security posture of open source software projects. "The OSPS Baseline offers a tiered framework of security practices that evolve with project maturity. It compiles existing guidance from OpenSSF and other expert groups, outlining tasks, processes, artifacts, and configurations that enhance software development and consumption security," the OpenSSF said. "By adhering to the Baseline, developers can lay a foundation that supports compliance with global cybersecurity regulations, such as the E.U. Cyber Resilience Act (CRA) and U.S. National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF)." The development comes as Google issued calls for standardizing memory safety by "establishing a common framework for specifying and objectively assessing memory safety assurances."
- MITRE Releases OCCULT Framework — The MITRE Corporation has detailed a lightweight operational evaluation framework called OCCULT that allows cyber security experts to quantify the possible risks associated with a large language model (LLM) used in offensive cyber operations. "The OCCULT objective is ultimately about understanding the cyber operation capacity of an AI system, and quantifying performance in these dimensions of cyber reasoning can provide insight into that," MITRE said.
- Michigan Man Indicted on Wire Fraud and Aggravated Identity Theft Charges — Andrew Shenkosky, a 29-year-old man from the U.S. state of Michigan, has been indicted on wire fraud and aggravated identity theft charges after purchasing 2,468 stolen login credentials from the dark web marketplace Genesis Market and using them to make fraudulent financial transactions. Shenkosky is also alleged to have offered some of the stolen account data for sale on other criminal forums, including the now-defunct Raid Forums. The scheme was devised and executed from approximately February 2020 to November 2020, the U.S. Justice Department said.
- 16 Malicious Google Chrome Extensions Flagged — Cybersecurity researchers have uncovered a cluster of at least 16 malicious Chrome extensions that were used to inject code into browsers to facilitate advertising and search engine optimization (SEO) fraud. The browser add-ons, now removed from the Chrome Web Store, collectively impacted 3.2 million users and masqueraded as screen capture tools, ad blockers, and emoji keyboards. According to GitLab, it's suspected that the threat actors acquired access to at least some of the extensions from their original developers to subsequently push out the trojanized versions. The activity has been ongoing since at least July 2024.
- Gmail to Ditch SMS for Two-Factor Authentication — Google is planning to end support for SMS-based two-factor authentication in Gmail so as to "reduce the impact of rampant, global SMS abuse." In lieu of the SMS-based system, the company is expected to display a QR code that users need to scan so as to login to their accounts, Forbes reported.
- Details Emerge About NSA's Alleged Hack of China's Northwestern Polytechnical University — In 2022, China accused the U.S. National Security Agency (NSA) of conducting a string of cyber attacks aimed at the Northwestern Polytechnical University. It said the attack targeting the research university employed no fewer than 40 different cyber weapons that are designed to siphon passwords, network equipment configuration, network management data, and operation and maintenance data. China has given the NSA the threat actor designation APT-C-40. According to a new analysis published by security researcher Lina Lau (aka "inversecos"), the attribution to the agency boils down to a combination of attack times (or lack thereof during Memorial Day and Independence Day holidays), hands-on keyboard activity using American English, human error, and the presence of tools previously discovered during the Shadow Brokers leak. The attack involved the use of a zero-day vulnerability attack platform called Fox Acid to automate the delivery of browser-based exploits when visiting legitimate websites. Some of the other tools deployed included ISLAND for exploiting Solaris systems; SECONDDATE, a framework installed on edge devices to conduct network eavesdropping, MitM attacks, and code injection; NOPEN and FLAME SPRAY for remote access to compromised systems; CUNNING HERETICS, a lightweight implant for covert access to NSA communication channels; STOIC SURGEON, a backdoor targeting Linux, Solaris, JunOS, and FreeBSD systems; DRINKING TEA for credential harvesting; TOAST BREAD, a log manipulation tool that erased evidence of unauthorized access; and Shaver, a program to attack exposed SunOS servers for use as jump servers. It's said that NSA operatives stole classified research data, network infrastructure details, and sensitive operational documents from the university.
- Apple Find My Exploit Can Turn a Bluetooth Device into an AirTag — A group of academics from George Mason University has detailed a new vulnerability in Apple's Find My network called nRootTag that turns devices into trackable "AirTags" without requiring root privileges. "The attack achieves a success rate of over 90% within minutes at a cost of only a few U.S. dollars. Or, a rainbow table can be built to search keys instantly," the researchers said. "Subsequently, it can locate a computer in minutes, posing a substantial risk to user privacy and safety. The attack is effective on Linux, Windows, and Android systems, and can be employed to track desktops, laptops, smartphones, and IoT devices." Apple has released patches in iOS 18.2, iPadOS 17.7.3, 18.2, watchOS 11.2, tvOS 18.2, macOS Ventura 13.7.2, Sonoma 14.7.2, Sequoia 15.2, and visionOS 2.2 to fix the vulnerability. That said, the attack remains effective as long as unpatched iPhones or Apple Watches are in the proximity of a target device running a malicious trojan, which is capable of advertising Bluetooth Low Energy (BLE) broadcasts that are used to glean a device's location by querying Apple's servers. In other words, simply by installing malware that can send BLE advertisements, the technique can make the device it's running on trackable via Apple's Find My network.
- Swedish Authorities Seek Backdoor Access to Encrypted Messaging Apps — Sweden's law enforcement and security agencies are pushing for a legislation that forces encrypted messaging services like Signal and WhatsApp to create technical backdoors allowing them to access communications. Signal Foundation President Meredith Whittaker said the company would rather exit the market than complying with such a law, Swedish news outlet SVT Nyheter reported last week. The development follows Apple's disabling of iCloud's Advanced Data Protection (ADP) feature for users in the U.K. last week in response to reports that the Home Office had requested for the ability to access encrypted contents in the cloud. Tulsi Gabbard, the director of U.S. National Intelligence, said she was not informed in advance about the U.K. government's demand to be able to access Apple customers' encrypted data. U.S. officials are said to be looking at whether the U.K. violated a bilateral agreement by demanding Apple create a "backdoor" to access end-to-end encrypted iCloud data, according to Reuters. It also comes as concerns are being raised over a proposed amendment to the Narcotrafic law in France that seeks to backdoor encrypted messaging systems and hand over chat messages of suspected criminals within 72 hours of a law enforcement request. "A backdoor for the good guys only is a dangerous illusion," Matthias Pfau, CEO of Tuta Mail, said in a statement shared with The Hacker News. "Weakening encryption for law enforcement inevitably creates vulnerabilities that can – and will – be exploited by cybercriminals and hostile foreign actors. This law would not just target criminals, it would destroy security for everyone."
- Cybercriminal Behind More Than 90 Data Leaks Arrested — A joint operation of the Royal Thai Police and the Singapore Police Force has led to the arrest of an individual responsible for more than 90 instances of data leaks worldwide, including 65 in the Asia-Pacific (APAC) region alone. The leaks resulted in the sale of over 13TB of personal data on the dark web, per Singaporean company Group-IB. The individual operated under various aliases ALTDOS, DESORDEN, GHOSTR, and 0mid16B. The identity of the suspect has not been disclosed, but Thai media reported that he goes by the name Chingwei. "The main goal of his attacks was to exfiltrate the compromised databases containing personal data and to demand payment for not disclosing it to the public," Group-IB said. "If the victim refused to pay, he did not announce the leaks on dark web forums. Instead he notified the media or personal data protection regulators, with the aim of inflicting greater reputational and financial damage on his victims." In select instances, the threat actor also encrypted the victim's databases as a means of exerting more pressure. The attacks leveraged SQL injection tools like sqlmap and exploited vulnerable Remote Desktop Protocol (RDP) servers to gain unauthorized access, followed by deploying a cracked version of an adversary simulation tool named Cobalt Strike for controlling compromised servers and exfiltrating data. Targets of the individual's attacks spanned industries such as healthcare, retail, property investment, finance, e-commerce, logistics, technology, hospitality, insurance, and recruitment.
🎥 Expert Webinar
- Webinar 1: Discover How ASPM Bridges Critical Gaps in AppSec Before It’s Too Late — Join our free webinar to learn how ASPM is changing app security. Amir Kaushansky from Palo Alto Networks will show you how ASPM unites your security tools and makes managing risks easier. Hear real success stories from hundreds of users and get clear, practical advice to protect your apps.
- Webinar 2: Transform Your Code Security with One Smart Engine — Join this next webinar to learn how to stop identity-based attacks like phishing and MFA bypass. Discover a secure access solution trusted by over 500 users. With limited spots, don’t miss your chance to protect your identity. Sign up now!
P.S. Know someone who could use these? Share it.
Conclusion
As we close this week’s update, remember that staying informed is the first step to protecting yourself online. Every incident—from targeted exploits to AI misuse—shows that cyber threats are real and constantly changing.
Thank you for reading. Stay alert, update your systems, and use these insights to make smarter choices in your digital life. Stay safe until next week.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/03/thn-weekly-recap-alerts-on-zero-day.html