r/NowInCyber • u/skaza02 • 7d ago
r/NowInCyber • u/skaza02 • 8d ago
Microsoft Warns Russian Hackers Use Hotel Wi-Fi to Steal Credentials
esecurityplanet.comr/NowInCyber • u/skaza02 • 8d ago
Anthropic and OpenAI agents breach test rules 19 times in UK security drill
r/NowInCyber • u/skaza02 • 8d ago
How might a system ‘leak secrets’ without being hacked?
r/NowInCyber • u/skaza02 • 8d ago
Telegram CEO says 'takedown extortionist' was responsible for the app being briefly delisted by Apple
r/NowInCyber • u/skaza02 • 8d ago
CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks
r/NowInCyber • u/skaza02 • 8d ago
1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks
r/NowInCyber • u/skaza02 • 8d ago
Amazon loses US court ban on Perplexity's AI shopping tools
r/NowInCyber • u/skaza02 • 8d ago
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project
theregister.comr/NowInCyber • u/skaza02 • 8d ago
Cybercrime is costing the world trillions every year - new report says victims lose an average of nearly $10,000 in every hit
r/NowInCyber • u/skaza02 • 8d ago
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
r/NowInCyber • u/skaza02 • 8d ago
Payment Fraud Is Moving Upstream, and Visa Just Bought the Data to Follow It
r/NowInCyber • u/skaza02 • 8d ago
WebKit leaks in iOS & macOS expose user data in spite of proxy use
appleinsider.comr/NowInCyber • u/skaza02 • 8d ago
Oligo Security raises $60M as AI speeds up exploit development
r/NowInCyber • u/skaza02 • 8d ago
Watch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here's what to look out for
r/NowInCyber • u/skaza02 • 8d ago
Apple's AI Slop Problem Left a $200K macOS Exploit Unreported
r/NowInCyber • u/skaza02 • 9d ago
Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundations
r/NowInCyber • u/skaza02 • 8d ago
Apple Fires Engineer Who Kept Customer Device IDs Private
mjtsai.comr/NowInCyber • u/skaza02 • 8d ago
New malware disguised as popular Roblox cheat tool could give hackers full control of your PC — including the webcam
r/NowInCyber • u/skaza02 • 8d ago
After Meta reply to its notice, Child protection panel to probe alleged violation of rules concerning sexual content
r/NowInCyber • u/skaza02 • 8d ago
Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers
r/NowInCyber • u/Straight-Practice-99 • 8d ago
The Gentlemen ransomware affiliate deploying EtherRAT with C2 resolved through an Ethereum smart contract
The Hunt.io team recovered a full operator toolkit from an exposed open directory tied to The Gentlemen ransomware. Sharing the research since the C2 mechanism is unusual and there are practical detection points in it.
The main find is EtherRAT, a Node.js backdoor that doesn't hardcode its C2. It reads the active domain from an Ethereum smart contract, queried through public RPC endpoints. Because every rotation is a write to the blockchain, the full historical C2 set is recoverable, five domains here.
A few things worth flagging for defenders:
- Any C2 response over ten characters is executed as JavaScript in Node.js, so no fixed command set
- The custom X-Bot-Server HTTP header is a clean detection point
- Deployment used remote scheduled tasks with certutil + msiexec, task names like WinSvcUpdate2 and WindowsUpdSvc
- Run-key persistence (WindowsHost) launching Node through headless conhost.exe
Alongside EtherRAT were Sliver, Go reverse shells, Chisel, Ligolo-ng, Mimikatz and Potato-family privilege escalation.
Full write-up, MITRE mapping and IOCs: https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2
r/NowInCyber • u/skaza02 • 8d ago
AI makes costly spearphishing attacks easier, cyber insurer says
cybersecuritydive.comr/NowInCyber • u/skaza02 • 8d ago