• A significant milestone for cybersecurity experts is the disclosure of specific tactics, methods, and procedures (TTPs) used by Mustang Panda, an advanced persistent threat (APT) group based in China, which has illuminated their intricate activities. First observed in 2017 but potentially active since 2014, Mustang Panda is a state-sponsored actor specializing in cyber espionage, targeting […]

    The post China-Based Threat Actor Mustang Panda’s TTPs Leaked appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The KC-46 tanker’s refueling boom has gotten stuck in at least three fighter jets during missions, resulting in three accidents and damage measured in the tens of millions of dollars, the Air Force has found.

    Two of the accidents took place in 2022 and another last year, according to investigation reports released on Aug. 25. 

    The tanker’s “stiff boom” is just one of the program’s category 1 deficiencies. The boom’s stiffness requires more force to move it in and out of position. Boeing is working on a redesign to the boom’s actuator system and the Air Force has previously said that a fix will be ready in fiscal 2026, but the service did not confirm a timeline in time for publication.

    “Challenges with adding a new aircraft to the fleet are not uncommon but we do not take these incidents lightly. We have used the lessons learned to refine our KC-46 operations, including focused training and guidance while partnering with the contractor to implement long-term solutions,” Lt. Gen. Rebecca Sonkiss, Air Mobility Command’s deputy commander, said in the press release that accompanied the reports. 

    The first report released by the service details a mishap on Oct. 15, 2022, when a KC-46 refueled an F-15E Strike Eagle and the boom got stuck in the jet during a breakaway. The boom then hit the tanker’s tail and caused $8.3 million in damages. The accident investigation board found that a “limitation” in the boom control system caused the operator to inadvertently place force on the boom and the nozzle became stuck in the receiver’s receptacle. 

    The second mishap, on Nov. 7, 2022, occurred after another “nozzle-binding” event. The investigation found that the boom operator failed to verify that the nozzle was clear of an F-22 Raptor’s refueling receptacle before making control inputs, causing the nozzle to be stuck in the fighter jet’s receptacle. The resulting damage to the nozzle cost about $100,000 to repair.

    In both 2022 incidents, the investigation board put some blame on the fighter pilots, finding that they “did not consider the KC-46A stiff-boom characteristics” which “substantially contributed” to the mishap.

    The third accident, on Aug. 21, 2024, occurred when a KC-46 was refueling a F-15E. The boom got stuck in the jet’s receptacle, then released with enough recoil to strike the tanker. The boom broke apart, resulting in $14 million in damages. That mishap was primarily caused by the boom operator’s control inputs, investigators found. 

    To prevent more accidents, the service increased the “refueling envelope”—the distance between the tanker and refueling aircraft—from six feet to 10 feet. That adjustment gives boom operators more time to “react during critical situations” and “better visual cues” of the receiver aircraft, according to AMC.

    That restriction was put in place in November, after the August incident, according to an AMC spokesperson. But another accident involving the tanker’s boom happened this July—raising questions about how effective the new restriction has been. 

    The Air Force acknowledged in their press release that “another nozzle-binding incident” occurred in July but said it remains under investigation. “Upon completion, the command will determine if further mitigation efforts are required,” the service said. 

    The two 2022 accident reports also mention problems with the tanker’s Remote Vision System, another category 1 deficiency, which displays a “HI-LOAD” warning when force is exerted beyond what the nozzle can handle. 

    But the service has found that the warning doesn’t work “due to a lack of contrast against the imagery provided by the Remote Vision System and its placement outside the [Aerial Refueling Operator’s] direct field of view,” according to the reports. 

    A fleet-wide fix, called Remote Vision System 2.0, is in the works, but has been delayed for years and won’t be ready until summer 2027.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Securden Unified PAM is a comprehensive privileged access management platform that is used to store, manage, and monitor credentials across human, machine, and AI identities in a variety of environments. Security researchers discovered four critical vulnerabilities in this platform during a series of ongoing red teaming operations using Rapid7’s Vector Command service. These flaws, spanning […]

    The post Securden Unified PAM Flaw Allows Attackers to Bypass Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • When every minute counts, it’s important to have access to fresh threat intelligence at the tip of your finger. That’s what all high-performing SOC teams have in common. Learn where to get relevant threat data for free and how to triage incidents in seconds using it.

    Getting & Applying Free Threat Intelligence

    Enriching your indicators with threat intelligence is a process that shouldn’t be overlooked. It equips SOCs with data and tools for the achievement of key goals of security teams, such as:

    • Acceleration of alert triage
    • Detection rate growth
    • Reduction of alert fatigue

    The first step to take in this direction is to find a reliable source of data on attacks, which can be quickly and effortlessly accessed during triage. For that, you can try Threat Intelligence Lookup, a searchable database of threat intel.

    Main page of ANY.RUN’s TI Lookup

    By accumulating data from public malware investigations done by over 15,000 SOC teams and 500,000 individual researchers, it makes valuable indicators and their context available to you.

    This means that in one simple query, you can tap into millions of malware analyses to identify and enrich your indicators, as well as find new ones for updates of proactive defense systems. For instance, during alert triage, you can verify a suspicious domain with a TI Lookup query like this:

    domainName:”technologyenterdo.shop”

    TI Lookup’s conclusion on the query and list of analyses for further investigation

    Almost instantly you’ll be given the answer: the indicator is malicious. More info can be found in ANY.RUN Sandbox. That’s where TI Lookup’s data comes from, so each indicator you can find there is tied with a corresponding analysis session.

    For proactive investigation of current threats in your location, try a compound search like this to collect IOCs and update detection rules in advance:

    threatName:”tycoon” AND submissionCountry:”de”

    Search results for Tycoon threats submitted in Germany

    It includes the name of the threat (Tycoon) and the short name of the country it was detected in (de—Germany). Moments after you enter it, TI Lookup will return the overview of fitting threats and up to 20 recent analysis sessions done in ANY.RUN’s Interactive Sandbox. Use this info for proactive detection of potential threats and renewal of detection systems.

    TI Lookup shares links to relevant ANY.RUN sandbox sessions like this one

    Other use cases of Threat Intelligence Lookup include checking not only domains, but also IPs and file hashes, as well as tracking threats by TTPs via interactive MITRE ATT&CK matrix. Through them, TI Lookup brings significant improvements to SOC performance rates:

    • Deeper and Faster Threat Investigations: Uncover rich data by linking artifacts to real-world attack patterns and cut MTTR by understanding threat behavior and TTPs.
    • Stronger Proactive Defense: Track relevant threats and stay ahead of them by making smarter detection rules in SIEM, IDS/IPS, and EDR.
    • Better SOC Expertise: Close the knowledge gap in your team—analysts can study malware and adversary TTPs within the interactive sandbox and MITRE ATT&CK matrix.

    Achieve faster, data-fueled triage and response -> Enrich IOCs for free 

    Premium Access to Threat Intel for Enterprises

    The use cases described above are available in the free version of TI Lookup. This can be enough to simplify and accelerate your threat investigation. But in case you’re looking for an enterprise-grade solution with unlimited functionality, consider trying TI Lookup Premium.

    It unlocks access to extra query operators and over 40 parameters, all available analysis sessions, private searches and YARA search. With these features, you can create more advanced requests and see all threat data there is. The paid version of TI Lookup can also be integrated using API and SDK for an automated and smooth workflow.

    • Automated, Real-Time Detection: Correlate alerts against extensive IOCs, IOBs, and IOAs, while integrating TI Lookup with SIEM, TIP, or SOAR platforms for continuous monitoring.
    • Precision Hunting & Investigation: Build and search custom YARA rules in ANY.RUN’s database, and refine investigations with 40+ parameters and advanced operators.
    • Proactive Threat Awareness: Automate alerts for specific IOCs or behaviors, and leverage expert TI Reports to stay ahead of evolving malware trends across industries.

    Unlock Premium threat intelligence -> Try TI Lookup

    The post How SOCs Triage Incidents in Seconds with Threat Intelligence appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Citrix has released fixes to address three security flaws in NetScaler ADC and NetScaler Gateway, including one that it said has been actively exploited in the wild. The vulnerabilities in question are listed below – CVE-2025-7775 (CVSS score: 9.2) – Memory overflow vulnerability leading to Remote Code Execution and/or Denial-of-Service CVE-2025-7776 (CVSS score: 8.8) – Memory overflow

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A team of academics has devised a novel attack that can be used to downgrade a 5G connection to a lower generation without relying on a rogue base station (gNB). The attack, per the ASSET (Automated Systems SEcuriTy) Research Group at the Singapore University of Technology and Design (SUTD), relies on a new open-source software toolkit named Sni5Gect (short for “Sniffing 5G Inject”) that’s

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new ransomware has been identified, which is believed to be the first-ever ransomware strain that leverages a local AI model to generate its malicious components.

    Dubbed “PromptLock” by the ESET Research team that discovered it, the malware uses OpenAI’s gpt-oss:20b model via the Ollama API to create custom, cross-platform Lua scripts for its attack chain.

    While the malware appears to be a proof-of-concept (PoC) and not yet deployed in active campaigns, its novel architecture represents a significant and worrying evolution in malware design, demonstrating how threat actors are beginning to integrate local large language models (LLMs) to create more dynamic and evasive threats.

    On-the-Fly Code Generation

    PromptLock is written in Golang and has been identified in both Windows and Linux variants on the VirusTotal repository.

    Its core functionality deviates from traditional ransomware, which typically contains pre-compiled malicious logic. Instead, PromptLock carries hard-coded prompts that it feeds to a locally running gpt-oss:20b model.

    Analysis of the malware’s network traffic reveals POST requests to a local Ollama API endpoint (172.42.0[.]253:8443). These requests contain prompts instructing the AI model to act as a “Lua code generator.”

    An example of Lua code generation request for malware PromptLock
    An example of Lua code generation request for malware PromptLock

    The prompts task the model with creating scripts for specific malicious activities, including:

    • System Enumeration: Generating Lua code to gather system parameters like OS type, username, hostname, and current working directory. The prompts specifically demand cross-platform compatibility for Windows, Linux, and macOS.
    • File System Inspection: Creating scripts to scan the local filesystem, identify target files, and analyze their contents, with instructions to look for PII or sensitive information.
    • Data Exfiltration & Encryption: Once target files are identified, the AI-generated scripts are executed to handle data exfiltration and subsequent encryption.

    The use of Lua is a strategic choice, as its lightweight and embeddable nature allows the generated scripts to run seamlessly across multiple operating systems, maximizing the malware’s potential target base.

    For its encryption payload, PromptLock utilizes the SPECK 128-bit block cipher, a lightweight algorithm suitable for this flexible attack model.

    ESET researchers emphasize that multiple indicators suggest PromptLock is still in a developmental stage. For instance, a function intended for data destruction appears to be defined but not yet implemented.

    Further intrigue is added by an unusual artifact found within one of the prompts: a Bitcoin address that seemingly belongs to Satoshi Nakamoto, the pseudonymous creator of Bitcoin. While this is likely a placeholder or a misdirection, it adds a peculiar signature to this early-stage malware.

    Despite its PoC status, ESET made the decision to disclose its findings publicly. “We believe it is our responsibility to inform the cybersecurity community about such developments,” the researchers stated, highlighting the need for proactive defense against this emerging threat vector.

    As local LLMs become more powerful and accessible, security teams must prepare for a future where malware is no longer static but generated dynamically on victim machines.

    Indicators of Compromise (IoCs)

    Malware Family: Filecoder.PromptLock.A

    SHA1 Hashes:

    • 24BF7B72F54AA5B93C6681B4F69E579A47D7C102
    • AD223FE2BB4563446AEE5227357BBFDC8ADA3797
    • BB8FB75285BCD151132A3287F2786D4D91DA58B8
    • F3F4C40C344695388E10CBF29DDB18EF3B61F7EF
    • 639DBC9B365096D6347142FCAE64725BD9F73270
    • 161CDCDB46FB8A348AEC609A86FF5823752065D2

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post First AI Ransomware ‘PromptLock’ Uses OpenAI gpt-oss-20b Model for Encryption appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated credential harvesting campaign has emerged targeting ScreenConnect cloud administrators with spear phishing attacks designed to steal super administrator credentials.

    The ongoing operation, designated MCTO3030, has maintained consistent tactics since 2022 while operating largely undetected through low-volume distribution strategies that send up to 1,000 emails per campaign run.

    The campaign specifically targets senior IT professionals including directors, managers, and security personnel who possess elevated privileges in ScreenConnect environments.

    Login alert (Source – Mimecast)

    Attackers leverage Amazon Simple Email Service accounts to deliver convincing phishing emails that claim suspicious login activity from unusual IP addresses or geographic locations, creating urgency to prompt immediate action from victims.

    Mimecast analysts identified this persistent threat as particularly concerning due to its apparent connection to ransomware operations, with research indicating similar targeting patterns by Qilin ransomware affiliates.

    The harvested super admin credentials serve as initial access vectors for subsequent ransomware deployment, enabling attackers to push malicious ScreenConnect clients to multiple endpoints simultaneously.

    The campaign employs country code top-level domains with ScreenConnect-themed naming conventions, including domains like connectwise.com.ar, connectwise.com.be, and connectwise.com.cm to create convincing impersonations of legitimate ConnectWise portals.

    Phishing pages (Source – Mimecast)

    Once victims click the “Review Security” button in phishing emails, they are redirected to sophisticated fake login pages that closely mimic authentic ScreenConnect interfaces.

    Advanced Adversary-in-the-Middle Techniques

    The technical sophistication of this campaign centers on its implementation of adversary-in-the-middle phishing using the EvilGinx framework, an open-source tool specifically designed for intercepting both credentials and multi-factor authentication codes in real-time.

    This capability allows attackers to bypass modern authentication protections that many organizations rely upon for security.

    The EvilGinx framework operates by positioning itself between the victim and the legitimate authentication service, capturing login credentials while simultaneously forwarding authentication requests to the real ScreenConnect portal.

    This technique enables the harvesting of time-sensitive MFA tokens, allowing attackers to maintain persistent access to compromised accounts even when multi-factor authentication is enabled.

    The consistent use of Amazon SES infrastructure provides high deliverability rates while bypassing traditional email security controls through trusted cloud services, demonstrating the campaign’s operational sophistication and long-term strategic planning.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post New Attack Targeting ScreenConnect Cloud Administrators to Steal Login Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Zimperium’s zLabs research team has identified a sophisticated new variant of the Hook Android banking trojan, marking a significant escalation in mobile threat sophistication. This iteration incorporates ransomware-style overlays that display extortion messages, demanding payments via dynamically fetched wallet addresses from the command-and-control (C2) server. Activated by the “ransome” command, these full-screen overlays embed HTML […]

    The post New Hook Android Banking Malware Emerges with Advanced Features and 107 Remote Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Navy is waiting for Pentagon leaders to pick a company to build the service’s sixth-generation F/A-XX fighter jet, now that Congress moved to restore funding, according to the service’s air boss.

    “It's going to be a very exciting aircraft. I'm looking forward to the downselect. I'll leave it to the professional acquisition folks…but I'm looking forward to that because that sixth-generation means air superiority in that timeframe in the future, which means sea control. And as long as you have air superiority, you have sea control around the globe,” Vice Adm. Daniel Cheever, commander of Naval Air Forces, said today during a CSIS event.

    In March, the Navy was reportedly close to picking a company to build F/A-XX, but an announcement never came, and the service ended up gutting funding for the aircraft in its 2026 budget request, throwing the program into limbo. 

    But Congress is on track to reverse those cuts: Senate appropriators added $1.4 billion to F/A-XX in their draft defense spending bill and House appropriators added $972 million to their version. Cheever’s comments today appear to confirm that F/A-XX is in fact moving ahead.

    Northrop Grumman and Boeing are in the running to build the sixth-gen fighter; Lockheed dropped out in March. Boeing was selected earlier this year to build the Air Force's sixth-gen F-47 fighter, and Pentagon leaders have expressed concern that U.S. defense companies can’t handle building two sixth-gen jets at once—a claim industry executives have refuted

    F/A-XX will operate from aircraft carriers and replace both the F/A-18 Super Hornet and EA-18 Growler. Service officials have previously indicated that they want the jet to have 25% more range than today’s jets.  

    Fielding a sixth-gen platform with collaborative combat aircraft alongside it will "ensure" that the Navy maintains control in the future, Cheever said.

    “I'm sure that fourth, fifth, sixth generation is that mix, and then unmanned teaming is the thing that gets us there,” he said.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶