๐จ ACTIVE EXPLOITATION
-
State-Sponsored Hackers Exploit AnySign4PC in South Korea to Deploy Backdoors
CVE-...Hackers exploited AnySign4PC vulnerabilities via compromised Korean sites to install backdoors silently.- Targets: South Korean users of AnySign4PC financial-security software versions 1.1.4.4 to 1.1.4.6
- Vulnerability: Buffer overflow allowing remote code execution without user prompts
- Attack vector: Compromised trusted domestic websites used as watering holes and spear-phishing emails
- Payloads: SIGNBT (Struggle) and COPPERHEDGE (Brandoor) backdoors enabling remote control and data theft
- Overlap found with Gunra ransomware attacks sharing infrastructure and tactics but no confirmed single actor ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
SilverFox Uses 3-Driver BYOVD Chain to Deploy ValleyRAT on Japanese Manufacturer SilverFox targeted a Japanese industrial manufacturer using a multi-driver BYOVD attack to deploy ValleyRAT.
- Targets Japanese industrial manufacturing sector organizations
- Exploits new and known vulnerable drivers in a three-driver BYOVD framework
- Attack starts with invoice-themed phishing delivering a ZIP archive for DLL side-loading
- Uses drivers BootRepair.sys, EnPortv.sys, and wsftprm.sys for kernel access and evasion
- Deploys ValleyRAT (Winos 4.0) via thread-context hijacking and dual watchdog persistence ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ฅ BREACHES & INCIDENTS
- Hackers steal 607,000 records in cyberattack on UK Department for Education
Hackers accessed 607,000 records from the UK Department for Education in a cyberattack.
- Applies to UK Department for Education and related education sector entities
- 607,000 records including telephone numbers and email addresses were stolen
- No bank details or highly sensitive information were accessed
- Attack affected Turing Scheme portal and DfE online help desk services
- Incident contained quickly; DfE working with National Cyber Security Centre and National Crime Agency ๐ Coverage: bbc.com ยท ๐ via @metacurity@infosec.exchange
๐ต๏ธ RESEARCH & DEEP DIVES
-
Chinese-Speaking Threat Actor Uses Autonomous AI for Multi-Vulnerability Cyberattacks A Chinese-speaking threat actor launched autonomous AI-driven cyberattacks exploiting seven vulnerabilities.
- Targets infrastructure across 10 product families with seven prioritized vulnerabilities
- Uses Hermes Agent framework with DeepSeek AI for autonomous vulnerability enumeration and exploitation
- Orchestrates attacks via Telegram, combining AI-driven scanning with manual exploitation
- Leverages multiple large language models including Qwen, GLM, Kimi, MiniMax, and tests Western tools like Claude Code and Codex
- Employs proxy services and anti-attribution settings to evade detection and limit traceability ๐ Coverage: unit42.paloaltonetworks.com ยท ๐ Original: unit42.paloaltonetworks.com ยท ๐ via Palo Alto Unit 42
-
OctLurk and SilkLurk backdoors target Central Asian government organizations since 2025 Researchers discovered OctLurk and SilkLurk backdoors used in cyber-espionage campaigns in Central Asia.
- Targets include government, healthcare, research, law enforcement, and educational sectors in Central Asia and Syria
- Backdoors operate primarily in memory and use customized loaders with victim-specific decryption
- Capabilities include plugin injection for shells, network scanning, credential dumping, keylogging, and email harvesting
- Deployment involves scheduled tasks and malicious services loading obfuscated DLL loaders
- Attribution suggests a Chinese-speaking threat actor with no confirmed group linkage ๐ Coverage: securelist.com ยท ๐ Original: securelist.com ยท ๐ via Securelist (Kaspersky)
๐ CVEs & KEV
- Other: 16 CVEs (worst 8.8)