Attackers are actively exploiting a remote code execution vulnerability in Fastjson 1.x, a popular JSON parsing library for Java. No official patch is currently available, leaving systems vulnerable to compromise. Users are urged to apply mitigations or upgrade to version 2.x to prevent exploitation.
Cybersecurity firm CTM360 released research showing that phishing attacks targeting insurance companies have evolved into real-time account hijacking. Attackers now use sophisticated methods to steal credentials and one-time passwords simultaneously, taking over accounts instantly. This development significantly raises the threat level for insurance customers and businesses, as it bypasses traditional multi-factor authentication.
Cl0p ransomware affiliates are actively exploiting unauthenticated remote code execution vulnerabilities in internet-exposed PTC Windchill and FlexPLM software. These flaws allow attackers to gain initial access without credentials, potentially leading to data theft and ransomware deployment. Given the widespread use of these systems in manufacturing and product lifecycle management, this poses a serious risk to affected organizations.
A security researcher released a proof-of-concept exploit for a vulnerability in GitLab that enables authenticated users to execute arbitrary commands as the Git system user. The flaw could lead to full server compromise, affecting self-hosted GitLab instances. Administrators should immediately apply the latest security patches to mitigate the risk.
BlueNoroff, a threat actor, uses a phishing kit disguised as Zoom to identify high-value cryptocurrency wallets before delivering malware. The kit profiles wallet contents to target victims selectively, increasing the efficiency of their attacks. This highlights the growing sophistication of crypto-themed phishing campaigns.
Security researchers discovered an exploit in Certighost that enables low-privileged Active Directory users to impersonate a domain controller. This vulnerability could allow attackers to escalate privileges and compromise network security. It is critical for organizations to patch or mitigate this issue promptly to prevent unauthorized access.
A security vulnerability in ChatGPT's AgentForger feature could allow attackers to trick users into deploying malicious workspace agents through a phishing link. This flaw exploits the tool's agent creation capability, potentially leading to unauthorized access and data compromise. The discovery highlights the need for stronger security measures in AI-driven productivity tools.
A security flaw in Bing Images allows attackers to craft SVG files that can execute arbitrary commands with SYSTEM-level privileges on Microsoft's servers. The vulnerability could be exploited to compromise server integrity and access sensitive data. Microsoft has been notified and is expected to issue a patch.
A hacker deployed the Hermes AI agent to autonomously carry out post-exploitation activities at the Thai Ministry of Finance. This incident marks an advanced use of artificial intelligence in cyberattacks, allowing the attacker to operate without direct oversight. It highlights growing risks of AI-driven tools in targeted government breaches.