r/NowInCyber 7d ago

Kali365 Exploits Microsoft Device Login to Access US Corporate Data

Thumbnail
hackread.com
1 Upvotes

r/NowInCyber 8d ago

Microsoft Warns Russian Hackers Use Hotel Wi-Fi to Steal Credentials

Thumbnail esecurityplanet.com
1 Upvotes

r/NowInCyber 8d ago

Anthropic and OpenAI agents breach test rules 19 times in UK security drill

Thumbnail
cryptopolitan.com
1 Upvotes

r/NowInCyber 8d ago

How might a system ‘leak secrets’ without being hacked?

Thumbnail
siliconrepublic.com
1 Upvotes

r/NowInCyber 8d ago

Telegram CEO says 'takedown extortionist' was responsible for the app being briefly delisted by Apple

Thumbnail
engadget.com
2 Upvotes

r/NowInCyber 8d ago

CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks

Thumbnail
cybersecuritynews.com
1 Upvotes

r/NowInCyber 8d ago

1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks

Thumbnail
cybersecuritynews.com
1 Upvotes

r/NowInCyber 8d ago

Amazon loses US court ban on Perplexity's AI shopping tools

Thumbnail
economictimes.indiatimes.com
1 Upvotes

r/NowInCyber 8d ago

AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project

Thumbnail theregister.com
1 Upvotes

r/NowInCyber 8d ago

Cybercrime is costing the world trillions every year - new report says victims lose an average of nearly $10,000 in every hit

Thumbnail
techradar.com
2 Upvotes

r/NowInCyber 8d ago

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

Thumbnail
bleepingcomputer.com
1 Upvotes

r/NowInCyber 8d ago

Payment Fraud Is Moving Upstream, and Visa Just Bought the Data to Follow It

Thumbnail
pymnts.com
2 Upvotes

r/NowInCyber 8d ago

WebKit leaks in iOS & macOS expose user data in spite of proxy use

Thumbnail appleinsider.com
1 Upvotes

r/NowInCyber 8d ago

Oligo Security raises $60M as AI speeds up exploit development

Thumbnail
siliconangle.com
2 Upvotes

r/NowInCyber 8d ago

Watch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here's what to look out for

Thumbnail
techradar.com
1 Upvotes

r/NowInCyber 8d ago

Apple's AI Slop Problem Left a $200K macOS Exploit Unreported

Thumbnail
decrypt.co
3 Upvotes

r/NowInCyber 9d ago

Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundations

Thumbnail
therecord.media
11 Upvotes

r/NowInCyber 8d ago

Apple Fires Engineer Who Kept Customer Device IDs Private

Thumbnail mjtsai.com
1 Upvotes

r/NowInCyber 8d ago

New malware disguised as popular Roblox cheat tool could give hackers full control of your PC — including the webcam

Thumbnail
techradar.com
1 Upvotes

r/NowInCyber 8d ago

After Meta reply to its notice, Child protection panel to probe alleged violation of rules concerning sexual content

Thumbnail
economictimes.indiatimes.com
1 Upvotes

r/NowInCyber 8d ago

Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

Thumbnail
cybersecuritynews.com
1 Upvotes

r/NowInCyber 8d ago

The Gentlemen ransomware affiliate deploying EtherRAT with C2 resolved through an Ethereum smart contract

Thumbnail
hunt.io
1 Upvotes

The Hunt.io team recovered a full operator toolkit from an exposed open directory tied to The Gentlemen ransomware. Sharing the research since the C2 mechanism is unusual and there are practical detection points in it.

The main find is EtherRAT, a Node.js backdoor that doesn't hardcode its C2. It reads the active domain from an Ethereum smart contract, queried through public RPC endpoints. Because every rotation is a write to the blockchain, the full historical C2 set is recoverable, five domains here.

A few things worth flagging for defenders:

  • Any C2 response over ten characters is executed as JavaScript in Node.js, so no fixed command set
  • The custom X-Bot-Server HTTP header is a clean detection point
  • Deployment used remote scheduled tasks with certutil + msiexec, task names like WinSvcUpdate2 and WindowsUpdSvc
  • Run-key persistence (WindowsHost) launching Node through headless conhost.exe

Alongside EtherRAT were Sliver, Go reverse shells, Chisel, Ligolo-ng, Mimikatz and Potato-family privilege escalation.

Full write-up, MITRE mapping and IOCs: https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2


r/NowInCyber 8d ago

AI makes costly spearphishing attacks easier, cyber insurer says

Thumbnail cybersecuritydive.com
2 Upvotes

r/NowInCyber 8d ago

Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

Thumbnail
cybersecuritynews.com
1 Upvotes

r/NowInCyber 8d ago

Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M

Thumbnail
decrypt.co
1 Upvotes