ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-22467
+1 in the same advisory: …10644
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.

NVD description · AI analysis pending
8.8
group max
5%
  • ivanti connect secure
CVE-2024-10763
The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_product

The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

NVD description · AI analysis pending
9.84%
  • apuswp campress
CVE-2024-12213
The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16.

The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites. Please note that this may have been patched sooner, however, the oldest available version for us to confirm this is patched in was 1.2.85.

NVD description · AI analysis pending
9.8<1%
  • apusthemes superio
CVE-2024-12562
The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input

The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the 's2member_pro_remote_op' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

NVD description · AI analysis pending
9.8<1%
  • s2member s2member
CVE-2024-12797
Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshake

Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode is set. Impact summary: TLS and DTLS connections using raw public keys may be vulnerable to man-in-middle attacks when server authentication failure is not detected by clients. RPKs are disabled by default in both TLS clients and TLS servers. The issue only arises when TLS clients explicitly enable RPK use by the server, and the server, likewise, enables sending of an RPK instead of an X.509 certificate chain. The affected clients are those that then rely on the handshake to fail when the server's RPK fails to match one of the expected public keys, by setting the verification mode to SSL_VERIFY_PEER. Clients that enable server-side raw public keys can still find out that raw public key verification failed by calling SSL_get_verify_result(), and those that do, and take appropriate action, are not affected. This issue was introduced in the initial implementation of RPK support in OpenSSL 3.2. The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.

NVD description · AI analysis pending
6.33%
CVE-2024-13182
The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5.

The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator.

NVD description · AI analysis pending
9.8<1%
  • WordPress
CVE-2024-13365
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives w

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

NVD description · AI analysis pending
9.82%
  • cleantalk security \& malware scan
CVE-2024-13421
The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1.

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.

NVD description · AI analysis pending
9.8<1%
  • contempothemes real estate 7
CVE-2024-13513
The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality. This makes it possible for unauthenticated attackers to extract sensitive data including the plugin's clientToken, which in turn can be used to change user account information including emails and account type. This allows attackers to then change account passwords resulting in a complete site takeover. Version 2.4.2.3 disabled logging but left sites with existing log files vulnerable.

NVD description · AI analysis pending
9.8<1%
  • oliverpos oliver pos
CVE-2024-32838
SQL Injection vulnerability in various API endpoints - offices, dashboards, etc.

SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API endpoints' query parameter. Users are recommended to upgrade to version 1.10.1, which fixes this issue. A SQL Validator has been implemented which allows us to configure a series of tests and checks against our SQL queries that will allow us to validate and protect against nearly all potential SQL injection attacks.

NVD description · AI analysis pending
9.42%
  • apache fineract
CVE-2024-38657
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated

External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.

NVD description · AI analysis pending
4.92%
  • ivanti connect secure
  • ivanti policy secure
CVE-2024-47908
OS Command Injection in Ivanti Cloud Services Appliance Admin Console Enables Admin RCE

CVE-2024-47908 is an OS command injection flaw (CWE-78) in the admin web console of Ivanti's Cloud Services Appliance (CSA), fixed in version 5.0.5. A remote attacker who has authenticated with administrator privileges to the console can inject operating system commands and achieve remote code execution on the appliance. Because the console is typically reachable over the network and high-privileged credentials are the only barrier, risk depends heavily on admin credential hygiene and how widely the admin interface is exposed. All CSA deployments running versions before 5.0.5 are affected. There is no known public proof-of-concept and the flaw is not yet in the CISA KEV catalog, so no confirmed in-the-wild exploitation is currently documented, though EPSS assigns a fairly high ~22% probability of exploitation within 30 days.

Do: Upgrade Ivanti CSA to version 5.0.5 or later as the primary remediation. Until patched, restrict access to the admin web console to trusted management networks (VPN/allowlist), enforce strong and unique admin credentials with MFA where available, and review appliance logs for unusual commands or unexpected admin sessions. Monitor Ivanti advisories, as the vendor has recently patched multiple CSA and Connect Secure issues and exploitation activity may follow.

7.222%
  • Ivanti Cloud Services Appliance (CSA) all versions before 5.0.5
moderateplausibly on the order of thousands of deployed CSA appliances (1k–10k range), many internet-exposed
CVE-2024-52577
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints.

In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose class is present in the Ignite server classpath and sends it to Ignite server endpoints. Deserialization of such a message by the Ignite server may result in the execution of arbitrary code on the Apache Ignite server side.

NVD description · AI analysis pending
9.53%
  • apache ignite
CVE-2024-56132
+4 in the same advisory: …56131 …56133 …56134 …56135
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows :

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive)

NVD description · AI analysis pending
6.86%
  • progress multi-tenant loadmaster
  • progress loadmaster
CVE-2024-7102
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.

NVD description · AI analysis pending
7.5<1%
  • gitlab gitlab
CVE-2025-0108
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2025-0108 is a missing-authentication flaw (CWE-306) in the PAN-OS management web interface of Palo Alto Networks firewalls that lets an unauthenticated attacker with network access to that interface bypass login and invoke certain PHP scripts, reportedly via path-confusion tricks in the web server stack. Invoking the scripts does not yield remote code execution, but it can compromise the confidentiality and integrity of PAN-OS, such as by reading or modifying management-plane information. Any PAN-OS firewall whose management web interface is reachable by an attacker — for example, exposed to the internet or reachable from a compromised internal network — is affected, while Cloud NGFW and Prisma Access are not. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-18, a public proof-of-concept is available, EPSS puts the 30-day exploitation probability at 98.5%, and headlines report attackers chaining this bug with other PAN-OS flaws to breach firewalls.

Do: Upgrade PAN-OS to a fixed release per the Palo Alto Networks advisory (security.paloaltonetworks.com/CVE-2025-0108), since the vendor has patched the flaw. Until patched, restrict management web interface access to trusted internal IP addresses or management-only network zones as recommended in the vendor's hardening guidance. Check management-interface logs for unauthenticated requests to PHP scripts and for signs of chaining with other recently exploited PAN-OS vulnerabilities.

8.898% KEV PoC ×3
  • Palo Alto Networks PAN-OS
large≈ tens of thousands of internet-exposed PAN-OS management interfaces (subset of a much larger firewall install base)
CVE-2025-1094
SQL Injection in PostgreSQL libpq escaping functions and command-line tools

Improper neutralization of quoting syntax (CWE-149) in PostgreSQL's libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn(), and in PostgreSQL command-line utility programs, allows SQL injection. SQL injection is triggered when an application takes attacker-influenced database input, escapes it with these functions, and uses the result to construct input passed to the psql interactive terminal; the command-line utility variant requires client_encoding BIG5 with server_encoding EUC_TW or MULE_INTERNAL. An attacker who exploits this can run arbitrary SQL, with high confidentiality, integrity, and availability impact (CVSS 3.1: 8.1, high). All PostgreSQL releases before 17.3, 16.7, 15.11, 14.16, and 13.19 are affected across cloud and self-hosted deployments, though real-world exploitability depends on the specific usage patterns described. The flaw was exploited as a zero-day before the fixes, including in the US Treasury Department breach and in targeted attacks chained with a BeyondTrust zero-day, and EPSS puts the 30-day exploitation probability at 90%.

Do: Upgrade all PostgreSQL installations to version 17.3, 16.7, 15.11, 14.16, or 13.19 (or later). Audit application code paths that pass libpq-escaped values (PQescapeLiteral/PQescapeIdentifier/PQescapeString/PQescapeStringConn) into psql, and check any use of PostgreSQL command-line utilities where client_encoding is BIG5 and server_encoding is EUC_TW or MULE_INTERNAL. Because this flaw was chained with the BeyondTrust zero-day in targeted attacks, review the exposure of remote-access appliances and hunt for anomalous SQL/psql activity.

8.190%
  • PostgreSQL (incl. libpq and psql), major version 17 before 17.3
  • PostgreSQL (incl. libpq and psql), major version 16 before 16.7
  • PostgreSQL (incl. libpq and psql), major version 15 before 15.11
  • +2 more
mass≈1,000,000+ PostgreSQL installations; hundreds of thousands of PostgreSQL servers exposed on the public internet per public scans
CVE-2025-1126
A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.

A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.

NVD description · AI analysis pending
9.3<1%
CVE-2025-1240
WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability.

WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of WinZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 7Z files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24986.

NVD description · AI analysis pending
8.810%
  • winzip winzip
CVE-2025-21298
Use-After-Free RCE in Windows OLE (CVE-2025-21298)

CVE-2025-21298 is a use-after-free (CWE-416) vulnerability in the Windows OLE (Object Linking and Embedding) component that permits remote code execution. According to the published CVSS vector, it is network-exploitable without privileges or user interaction, triggered when the system processes maliciously crafted OLE content. A successful attacker gains arbitrary code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. The flaw affects nearly the entire supported Windows estate — Windows 10 1507 through 22H2, Windows 11 22H2 through 24H2, and Windows Server 2008 through 2019. As of the January 2025 Patch Tuesday release there is no known public proof-of-concept or confirmed in-the-wild exploitation, but the EPSS score of 80.9% (100th percentile) indicates a very high probability of exploitation within 30 days.

Do: Apply Microsoft's January 2025 Windows cumulative security updates to all affected Windows 10/11 and Windows Server hosts immediately, prioritizing internet-facing and server systems given the network-exploitable, critical rating. Verify via patch-reporting tools that the OLE update is present on each host; no vendor mitigations were noted in the available data, so updating is the primary defense. Although no exploitation is confirmed yet, the 80.9% EPSS score argues for completing remediation before a PoC or in-the-wild exploitation emerges.

9.881%
  • microsoft Windows 10 1507
  • microsoft Windows 10 1607
  • microsoft Windows 10 1809
  • +9 more
mass≈1 billion+ Windows installations (essentially the entire supported Windows client and Server estate)
CVE-2025-21418
+1 in the same advisory: …21391
Local Privilege Escalation via Heap Overflow in Windows WinSock AFD Driver

CVE-2025-21418 is a heap-based buffer overflow (CWE-122) in the Windows Ancillary Function Driver for WinSock (AFD.sys), a kernel-mode driver that services Winsock auxiliary socket operations. A local attacker with limited user privileges can trigger the overflow by issuing crafted Winsock requests to the AFD driver, requiring no user interaction. Successful exploitation elevates the attacker's privileges on the local machine (confidentiality, integrity, and availability all impacted), which is typically used to gain SYSTEM-level control as part of a broader intrusion or ransomware chain. Any system running the affected Windows 10, Windows 11, or Windows Server releases is exposed, since the AFD driver is a core component present on all of them. The flaw was a zero-day exploited in the wild before Microsoft patched it in the February 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-11.

Do: Deploy Microsoft's February 2025 Patch Tuesday security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing multi-user servers, jump hosts, and endpoints in ransomware-prone environments since exploitation was already active before patching. Verify deployment through your patch management/SCCM update history; there is no public PoC or known standalone mitigation, so patching is the required action per the CISA KEV entry.

7.8
group max
2% KEV
  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008 supported editions as listed
  • +4 more
masson the order of 1 billion+ Windows devices (all listed Windows 10/11 client and Windows Server releases)
CVE-2025-24865
+2 in the same advisory: …25067 …22896
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitiv

The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.

NVD description · AI analysis pending
10.0
group max
7%
  • myscada mypro
CVE-2025-23359
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container i

NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

NVD description · AI analysis pending
8.14% PoC
  • nvidia nvidia container toolkit
  • nvidia nvidia gpu operator
CVE-2025-24200
Incorrect Authorization in Apple iOS/iPadOS Lets Attackers Disable USB Restricted Mode

CVE-2025-24200 is an incorrect authorization flaw (CWE-863) in Apple iOS and iPadOS, caused by an authorization issue in state management that Apple resolved with improved state handling. An attacker with brief physical access to a locked device can exploit the flaw to disable USB Restricted Mode, the feature that locks down a locked iPhone or iPad's USB data port against accessories after a set period. This allows USB accessories, including data-extraction and attack peripherals, to communicate with the device while it remains locked, with a high confidentiality and integrity impact (CVSS 6.1, physical attack vector). Any iPhone or iPad user running a version prior to the applicable fixed release is affected, with fixes shipped in iOS 15.8.4, iOS 16.7.11, iOS 18.3.1, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.5, and iPadOS 18.3.1. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-12.

Do: Update iPhones to iOS 15.8.4, iOS 16.7.11, or iOS 18.3.1 and iPads to iPadOS 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable to each device's branch, checking Settings > General > Software Update for unmanaged devices. Because exploitation requires physical access, prioritize high-risk users (executives, journalists, government personnel), confirm no fleet devices remain on unpatched builds, and avoid untrusted USB accessories and charging ports until updated. CISA's KEV listing requires federal agencies to apply the vendor patch per the required action or discontinue use of the product.

6.14% KEV
  • Apple iOS (iPhone) Versions prior to the fixed releases in each branch: iOS < 15.8.4, iOS < 16.7.11, and iOS < 18.3.1
  • Apple iPadOS (iPad) Versions prior to the fixed releases in each branch: iPadOS < 15.8.4, iPadOS < 16.7.11, iPadOS < 17.7.5, and iPadOS < 18.3.1
mass≈1 billion+ devices (Apple's active installed base; every iPhone/iPad running a pre-patch iOS/iPadOS release at the time of disclosure)
CVE-2025-26506
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privil

Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.

NVD description · AI analysis pending
9.21%
  • hp 4ra85f firmware
  • hp 4ra85v firmware
  • hp 4ra86a firmware
  • +1 more
CVE-2025-26793
The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, passwor

The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents' PII. NOTE: the Supplier's perspective is that the "vulnerable systems are not following manufacturers' recommendations to change the default password."

NVD description · AI analysis pending
9.32%
Full article3,007 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 17, 2025Cyber Threats / Cybersecurity

Welcome to this week’s Cybersecurity News Recap. Discover how cyber attackers are using clever tricks like fake codes and sneaky emails to gain access to sensitive data. We cover everything from device code phishing to cloud exploits, breaking down the technical details into simple, easy-to-follow insights.

⚡ Threat of the Week

Russian Threat Actors Leverage Device Code Phishing to Hack Microsoft Accounts — Microsoft and Volexity have revealed that threat actors with ties to Russia are leveraging a technique known as device code phishing to gain unauthorized access to victim accounts, and use that access to get hold of sensitive data and enable persistent access to the victim environment. At least three different Russia-linked clusters have been identified abusing the technique to date. The attacks entail sending phishing emails that masquerade as Microsoft Teams meeting invitations, which, when clicked, urge the message recipients to authenticate using a threat actor-generated device code, thereby allowing the adversary to hijack the authenticated session using the valid access token.

🔔 Top News

  • whoAMI Attack Exploits AWS AMI Name Confusion for Remote Code Execution — A new type of name confusion attack called whoAMI allows anyone who publishes an Amazon Machine Image (AMI) with a specific name to gain code execution within the Amazon Web Services (AWS) account. Datadog, which detailed the attack, said roughly 1% of organizations monitored by the company were affected by the whoAMI, and that it found public examples of code written in Python, Go, Java, Terraform, Pulumi, and Bash shell using the vulnerable criteria. AWS told The Hacker News that there is no evidence of malicious exploitation of the security weakness.
  • RansomHub Targets Over 600 Orgs Globally — The RansomHub ransomware operation has targeted over 600 organizations across the world, spanning sectors such as healthcare, finance, government, and critical infrastructure, making it one of the most active cybercrime groups in 2024. One such attack has been found to weaponize now-patched security flaws in Microsoft Active Directory and the Netlogon protocol to escalate privileges and gain unauthorized access to a victim network's domain controller as part of their post-compromise strategy.
  • REF7707 Uses Outlook Drafts for Command-and-Control — A previously undocumented threat activity cluster dubbed REF7707 has been observed using a remote administration tool named FINALDRAFT that parses commands stored in the mailbox's drafts folder and writes the results of the execution into new draft emails for each command. It makes use of the Outlook email service via the Microsoft Graph API for command-and-control (C2) purposes. The group has been observed targeting the foreign ministry of an unnamed South American nation, as well as a telecommunications entity and a university, both located in Southeast Asia.
  • Kimsuky Embraces ClickFix-Style Attack Strategy — The North Korean threat actor known as Kimsuky (aka Black Banshee) is using a new tactic that involves deceiving targets into running PowerShell as an administrator and then instructing them to paste and run malicious code provided by them. "To execute this tactic, the threat actor masquerades as a South Korean government official and over time builds rapport with a target before sending a spear-phishing email with an [sic] PDF attachment," Microsoft said. Users are then convinced to click on a URL, urging them to register their device in order to read the PDF attachment. The end goal of the attack is to establish a data communication mechanism that allows the adversary to exfiltrate data.
  • Law Enforcement Op Takes Down 8Base — A consortium of law enforcement agencies has arrested four Russian nationals and seized over 100 servers linked to the 8Base ransomware gang. The arrests were made in Thailand. Two of the suspects are accused of operating a cybercrime group that used Phobos ransomware to victimize more than 1,000 public and private entities in the country and across the world. The development comes in the aftermath of a series of high-profile ransomware disruptions associated with Hive, LockBit, and BlackCat in recent years. Late last year, Evgenii Ptitsyn, a 42-year-old Russian national believed to be the administrator of the Phobos ransomware, was extradited to the U.S.

‎️‍🔥 Trending CVEs

Your go-to software could be hiding dangerous security flaws—don’t wait until it’s too late! Update now and stay ahead of the threats before they catch you off guard.

This week’s list includes — CVE-2025-1094 (PostgreSQL), CVE-2025-0108 (Palo Alto Networks PAN-OS), CVE-2025-23359 (NVIDIA Container Toolkit), CVE-2025-21391 (Microsoft Windows Storage), CVE-2025-21418 (Microsoft Windows Ancillary Function Driver for WinSock), CVE-2024-38657, CVE-2025-22467, CVE-2024-10644 (Ivanti Connect Secure), CVE-2024-47908 (Ivanti Cloud Services Application), CVE-2024-56131, CVE-2024-56132, CVE-2024-56133, CVE-2024-56134, CVE-2024-56135 (Progress Kemp LoadMaster), CVE-2025-24200 (Apple iOS and iPadOS), CVE-2024-12797 (OpenSSL), CVE-2025-21298 (Microsoft Windows OLE), CVE-2025-1240 (WinZip), CVE-2024-32838 (Apache Fineract), CVE-2024-52577 (Apache Ignite), CVE-2025-26793 (Hirsch Enterphone MESH), CVE-2024-12562 (s2Member Pro plugin), CVE-2024-13513 (Oliver POS – A WooCommerce Point of Sale (POS) plugin), CVE-2025-26506 (HP LaserJet), CVE-2025-22896, CVE-2025-25067, CVE-2025-24865 (mySCADA myPRO Manager), CVE-2024-13182 (WP Directorybox Manager plugin), CVE-2024-10763 (Campress theme), CVE-2024-7102 (GitLab CE/EE), CVE-2024-12213 (WP Job Board Pro plugin), CVE-2024-13365 (Security & Malware scan by CleanTalk plugin), CVE-2024-13421 (Real Estate 7 theme), and CVE-2025-1126 (Lexmark Print Management Client).

📰 Around the Cyber World

  • Former Google Engineer Charged with Plan to Steal Trade Secrets — Linwei Ding, a former Google engineer who was arrested last March for transferring "sensitive Google trade secrets and other confidential information from Google's network to his personal account," has now been charged with seven counts of economic espionage and seven counts of theft of trade secrets related to the company's AI technology between 2022 and 2023. This included detailed information about the architecture and functionality of Google's Tensor Processing Unit (TPU) chips and systems and Graphics Processing Unit (GPU) systems, the software that allows the chips to communicate and execute tasks, and the software that orchestrates thousands of chips into a supercomputer capable of training and executing cutting-edge AI workloads. The trade secrets also relate to Google's custom-designed SmartNIC, a type of network interface card used to enhance Google's GPU, high performance, and cloud networking products. "Ding intended to benefit the PRC government by stealing trade secrets from Google," the U.S. Department of Justice said. "Ding allegedly stole technology relating to the hardware infrastructure and software platform that allows Google's supercomputing data center to train and serve large AI models." The superseding indictment also stated that Chinese-sponsored talent programs incentivize individuals engaged in research and development outside the country to transmit such information in exchange for salaries, research funds, lab space, or other incentives. If convicted, Ding faces a maximum penalty of 10 years in prison and up to a $250,000 fine for each trade-secret count and 15 years in prison and a $5,000,000 fine for each economic espionage count.
  • Windows UI Flaw Exploited by Mustang Panda — Israeli cybersecurity company ClearSky has warned that a suspected Chinese nation-state group known as Mustang Panda is actively exploiting a UI vulnerability in Microsoft Windows. "When files are extracted from compressed 'RAR' files they are hidden from the user," the company said. "If the compressed files are extracted into a folder, the folder appears empty in the Windows Explorer GUI. When using the 'dir' command to list all files and folders inside the target folder, the extracted files and folders are 'invisible/hidden' to the user. Threat actors or users can also execute those compressed files from a command line prompt, if they know the exact path. As a result of executing 'attrib -s -h' to system protected files, an unknown file type is created from the type 'Unknown' ActiveX component." It's currently not clear who are the targets of the attack, and what the end goals of the campaign are. When reached for comment, Microsoft said it did not have anything to share at this time.
  • Meta Paid Over $2.3M in Bug Bounty Rewards in 2024 — Meta said it paid out more than $2.3 million in rewards to nearly 200 security researchers as part of its bug bounty program in 2024. In total, the company has handed out more than $20 million since the creation of the program in 2011. The top three countries based on bounties awarded in 2024 are India, Nepal, and the United States.
  • Critical ThinkPHP and OwnCloud Flaws Under Active Exploitation — Threat actors are attempting to actively exploit two known security vulnerabilities impacting ThinkPHP (CVE-2022-47945, CVSS score: 9.8) and OwnCloud (CVE-2023-49103, CVSS score: 10.0) over the past few days, with attacks originating from hundreds of unique IP addresses, most of which are based in Germany, China, the U.S., Singapore, Hong Kong, the Netherlands, the U.K., and Canada. Organizations are recommended to apply the necessary patches (ThinkPHP to 6.0.14+ and ownCloud GraphAPI to 0.3.1+) and restrict access to reduce the attack surface.
  • FSB Mole Arrested in Ukraine — The Secret Service of Ukraine (SSU) said it had detained one of its own high-level officials, accusing them of acting as a mole for Russia. The individual, one of the officials of the SSU Counterterrorism Center, is alleged to have been recruited by Russia's Federal Security Service (FSB) in Vienna in 2018, and actively began engaging in espionage at the end of December last year, transmitting documents containing state secrets, to the intelligence agency via a "special mobile phone." The SSU, upon learning of the man's actions, said it "used him in a counterintelligence 'game': through the traitor the SSU fed the enemy a large amount of disinformation." The individual's name was not disclosed, but the Kyiv Independent said it's Colonel Dmytro Kozyura, citing unnamed SSU sources.
  • LLMjacking Hits DeepSeek — Malicious actors have been observed capitalizing on the popularity of AI chatbot platform DeepSeek to conduct what's called LLMjacking attacks that involve selling the access obtained to legitimate cloud environments to other actors for a price. These attacks involve the use of stolen credentials to allow access to machine learning services via the OpenAI Reverse Proxy (ORP), which acts as a reverse proxy server for LLMs of various providers. The ORP operators hide their IP addresses using TryCloudflare tunnels. Ultimately, the illicit LLM access is used to generate NSFW content, and malicious scripts, and even circumvent bans on ChatGPT in countries like China and Russia, where the service is blocked. "Cloud-based LLM usage costs can be staggering, surpassing several hundreds of thousands of dollars monthly," Sysdig said. "The high cost of LLMs is the reason cybercriminals choose to steal credentials rather than pay for LLM services. Due to steep costs, a black market for access has developed around OAI Reverse Proxies — and underground service providers have risen to meet the needs of consumers."
  • Romance Baiting Scams Jump 40% YoY Pig butchering scams, also called romance baiting, have accounted for 33.2% of the estimated $9.9 billion revenue earned by cybercriminals in 2024 from cryptocurrency scams, growing nearly 40% year-over-year. However, the average deposit amount to pig butchering scams declined 55% YoY, likely indicating a shift in how these scams are conducted. "Pig butchering scammers have also evolved to diversify their business model beyond the 'long con' of pig butchering scams — which can take months and even years of developing a relationship before receiving victim payments — to quicker turnaround employment or work-from-home scams that typically yield smaller victim deposits," Chainalysis said. Further analysis of on-chain activity has found that HuiOne Guarantee is heavily used for illicit crypto-based activities supporting the pig butchering industry in Southeast Asia. Scammers have also been observed using generative AI technology to facilitate crypto scams, often to impersonate others or generate realistic content.
  • Security Issues in RedNote Flagged — It's not just DeepSeek. A new network security analysis undertaken by the Citizen Lab has uncovered multiple issues in RedNote's (aka Xiaohongshu) Android and iOS apps. This includes fetching viewed images and videos over HTTP, transmitting insufficiently encrypted device metadata, as well as a vulnerability that enables network attackers to learn the contents of any files that RedNote has permission to read on the users' devices. While the second vulnerability was introduced by an upstream analytics SDK, MobTech, the third issue was introduced by NEXTDATA. As of writing, all the flaws remain unpatched. The vulnerabilities "could enable surveillance by any government or ISP, and not just the Chinese government," the Citizen Lab said.
  • CISA Urges Orgs to Address Buffer Overflows — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have released a Secure by Design Alert, urging organizations to eliminate buffer overflow vulnerabilities in software. "These vulnerabilities can lead to data corruption, sensitive data exposure, program crashes, and unauthorized code execution," the agencies said, labeling them as unforgivable defects. "Threat actors frequently exploit these vulnerabilities to gain initial access to an organization's network and then move laterally to the wider network." Saeed Abbasi, manager of vulnerability research at Qualys Threat Research Unit (TRU), emphasized the need to switch from memory unsafe languages. "Legacy excuses are out; the world has zero tolerance for memory-unsafe code in 2025," Abbasi said. "Yes, rewriting old systems is daunting, but letting attackers exploit decades-old buffer overflows is worse. Organizations still clinging to unsafe languages risk turning minor vulnerabilities into massive breaches—and they can't claim surprise. We've had proven fixes for ages: phased transitions to Rust or other memory-safe options, compiler-level safeguards, thorough adversarial testing, and public commitments to a secure-by-design roadmap. The real challenge is collective will: leadership must demand memory-safe transitions, and software buyers must hold vendors accountable."
  • Foreign Adversaries Target Local Communities in the U.S. for Influence Ops — A new report from the Alliance for Securing Democracy (ASD) has found that foreign nation-state actors from Russia, China, and Iran are running influence operations that exploit trust in local sources and impact state and local communities in the U.S. with an aim to manipulate public opinion, stoke discord, and undermine democratic institutions. "In some cases, adversarial nations seek favorable outcomes around local policy issues; in others, they use local debates as Trojan horses to advance their broader geopolitical agendas," the research said. Russia emerged as the most active threat actor, with 26 documented cases designed to polarize Americans through themes related to immigration and election integrity. Beijing, on the other hand, sought to cultivate support for Chinese state interests.
  • Financial Orgs Asked to Switch to Quantum-Safe Cryptography — Europol is urging financial institutions and policymakers to transition to quantum-safe cryptography, citing an "imminent" threat to cryptographic security due to the rapid advancement of quantum computing. The primary risk is that threat actors could steal encrypted data today with the intention of decrypting it in the future using quantum computing, a technique called "harvest now, decrypt later" or retrospective decryption. "A sufficiently advanced quantum computer has the potential to break widely used public-key cryptographic algorithms, endangering the confidentiality of financial transactions, authentication processes, and digital contracts," the agency said. "While estimates suggest that quantum computers capable of such threats could emerge within the next 10 to 15 years, the time required to transition away from vulnerable cryptographic methods is significant. A successful transition to post-quantum cryptography requires collaboration among financial institutions, technology providers, policymakers, and regulators." Last year, the U.S. National Institute of Standards and Technology (NIST) formally announced the first three "quantum-safe" algorithms.
  • Google Addresses High Impact Flaws — Google has addressed a pair of security flaws that could be chained by malicious actors to unmask the email address of any YouTube channel owner. The first of the two is a vulnerability identified in a YouTube API that could leak a user's GAIA ID, a unique identifier used by Google to manage accounts across its network of sites. This ID could then be fed as input to an outdated web API associated with Pixel Recorder to convert it into an email when sharing a recording. Following responsible disclosure on September 24, 2024, the issues were resolved as of February 9, 2025. There is no evidence that these shortcomings were ever abused in the wild.
  • New DoJ Actions Target Crypto Fraud — Eric Council Jr., 25, of Alabama, has pleaded guilty to charges related to the January 2024 hacking of the U.S. Securities and Exchange Commission's (SEC) X account. The account was taken over to falsely announce that the SEC approved BTC Exchange Traded Funds, causing a spike in the price of bitcoin. The attack was carried out through an unauthorized Subscriber Identity Module (SIM) swap carried out by the defendant, tricking a mobile phone provider store to reassign the victim's phone number to a SIM card in their possession using a fraudulent identity card printed using an ID card printer. Council, who was arrested in December 2024, pleaded guilty to conspiracy to commit aggravated identity theft and access device fraud. If convicted, he faces a maximum penalty of five years in prison. In a related development, a 22-year-old man from Indiana, Evan Frederick Light, was sentenced to 20 years in federal prison for running a massive cryptocurrency theft scheme from his mother's basement. Light broke into an investment holdings company in South Dakota in February 2022, stealing customers' personal data and cryptocurrency worth over $37 million from nearly 600 victims. The stolen cryptocurrency was then funneled to various locations throughout the world, including several mixing services and gambling websites to conceal his identity and to hide the virtual currency. Separately, the Justice Department has also charged Canadian national Andean Medjedovic, 22, for exploiting smart contract vulnerabilities in two decentralized finance crypto platforms, KyberSwap and Indexed Finance, to fraudulently obtain about $65 million from the protocols' investors between 2021 and 2023. A master's degree holder in mathematics from the University of Waterloo, Medjedovic is also alleged to have laundered the proceeds through mixers and bridge transactions in an attempt to conceal the source and ownership of the funds. Medjedovic is charged with one count of wire fraud, one count of unauthorized damage to a protected computer, one count of attempted Hobbs Act extortion, one count of money laundering conspiracy, and one count of money laundering. He faces over 30 years in prison.
  • U.S. Lawmakers Warn Against U.K. Order for Backdoor to Apple Data — After reports emerged that security officials in the U.K. have ordered Apple to create a backdoor to access any Apple user's iCloud content, U.S. Senator Ron Wyden and Member of Congress Andy Biggs have sent a letter to Tulsi Gabbard, the Director of National Intelligence, urging the U.K. to retract its order, citing it threatens the privacy and security of both the American people and the U.S. government. "If the U.K. does not immediately reverse this dangerous effort, we urge you to reevaluate U.S.-U.K. cybersecurity arrangements and programs as well as U.S. intelligence sharing with the U.K.," they added. The purported Apple backdoor request would reportedly allow authorities to access data currently secured by Advanced Data Protection, potentially affecting users worldwide. Wyden has also released a draft version of the Global Trust in American Online Services Act that seeks to "secure Americans' communications against abusive foreign demands to weaken the security of communications services and software used by Americans." While the security experts have criticized the order, British officials have neither confirmed nor denied it.

🎥 Cybersecurity Webinars

  • Webinar 1: From Code to Runtime: Transform Your App Security — Join our webinar with Amir Kaushansky from Palo Alto Networks and see how ASPM can change your app security. Learn how to connect code details with live data to fix gaps before they become risks. Discover smart, proactive ways to protect your applications in real-time.
  • Webinar 2: From Debt to Defense: Fix Identity Gaps Fast — Join our free webinar with experts Karl Henrik Smith and Adam Boucher as they show you how to spot and close identity gaps with Okta’s Secure Identity Assessment. Learn simple steps to streamline your security process, focus on key fixes, and build a stronger defense against threats.

P.S. Know someone who could use these? Share it.

🔧 Cybersecurity Tools

  • WPProbe — It's a fast WordPress plugin scanner that uses REST API enumeration to stealthily detect installed plugins without brute force, scanning by querying exposed endpoints and matching them against a precompiled database of over 900 plugins. It even maps detected plugins to known vulnerabilities (CVE) and outputs results in CSV or JSON format, making your scans both speedy and less likely to trigger security defenses.
  • BruteShark — It's a powerful and user-friendly Network Forensic Analysis Tool built for security researchers and network administrators. It digs deep into PCAP files or live network captures to extract passwords, rebuild TCP sessions, map your network visually, and even convert password hashes for offline brute force testing with Hashcat. Available as a Windows GUI or a versatile CLI for Windows and Linux.

🔒 Tip of the Week

Segment Your Wi-Fi Network for Better Protection — In today's smart home, you likely have many connected devices—from laptops and smartphones to smart TVs and various IoT gadgets. When all these devices share the same Wi‑Fi network, a breach in one device could potentially put your entire network at risk. Home network segmentation helps protect you by dividing your network into separate parts, similar to how large businesses isolate sensitive information.

To set this up, use your router’s guest network or VLAN features to create different SSIDs, such as "Home_Private" for personal devices and "Home_IoT" for smart gadgets. Ensure each network uses strong encryption (WPA3 or WPA2) with unique passwords, and configure your router so devices on one network cannot communicate with those on another. Test your setup by connecting your devices accordingly and verifying that cross-network traffic is blocked, then periodically check your router’s dashboard to keep the configuration working smoothly.

Conclusion

That wraps up this week’s cybersecurity news. We’ve covered a broad range of stories—from the case of a former Google engineer charged with stealing key AI secrets to hackers taking advantage of a Windows user interface flaw. We’ve also seen how cybercriminals are moving into new areas like AI misuse and cryptocurrency scams, while law enforcement and industry experts work hard to catch up.

These headlines remind us that cyber threats come in many forms, and every day, new risks emerge that can affect everyone from large organizations to individual users. Keep an eye on these developments and take steps to protect your digital life. Thank you for joining us, and we look forward to keeping you informed next week.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/02/thn-weekly-recap-google-secrets-stolen.html