Cyber Threat Zip

@cyberthreat.zip

Cyber Threat intelligence Alert Contact: contact@cyberthreat.zip

⚠️ JACKSKID: BEYOND A MIRAI FORK Nokia Deepfield & Comcast exposed an advanced botnet with 80K+ samples & 13 releases in 5 months. • Dual infection: Telnet + Android TV ADB • 3-layer encryption: RC4+ChaCha20+TEA • DNS-over-HTTPS for stealthy C2 • Fast-flux: 40-50 IPs/domain • 17 DDoS attacks

APT31's Arsenal: SharpADUserIP (Recon) SharpChrome (Password theft) StickyNotesExtract (Data theft) Tailscale VPN (Tunneling) CloudSorcerer/OneDriveDoor (Cloud C2) VtChatter (VirusTotal C2) LocalPlugX (Lateral movement) Various backdoors (Linux/Windows)

Cyber Threat Zip@cyberthreat.zip · 8mo ago

APT31 (China) targeted Russian gov't IT contractors in 2025 & earlier. The group operated undetected for extended periods, gathering intelligence through sophisticated cyber espionage campaigns.

APT31 (China) targeted Russian gov't IT contractors in 2025 & earlier. The group operated undetected for extended periods, gathering intelligence through sophisticated cyber espionage campaigns.

⚠️ 7-Zip RCE Vulnerability CVE-2025-11001: Critical vulnerability in 7-Zip! A malicious ZIP file can allow remote code execution on your computer. Simply opening the file is enough. ❕ Users are advised to update to 7-Zip version 25.00 or later.

⚠️ OpenVPN RCE Vulnerability CVE-2025-10680: High-severity flaw enabling authenticated VPN servers to execute OS commands on clients. Scope: OpenVPN Client (Linux, macOS) Requirement: --dns-updown enabled

⚠️ Fortinet FortiOS/FortiProxy Zero Day Vulnerability CVE-2024-55591: (CVSS score: 9.6) is an authentication bypass vulnerability in FortiOS and FortiProxy. It allows attackers to gain super admin privileges through specially crafted Node.js websocket requests.

⚠️ 7-Zip RCE Vulnerability CVE-2024-11477: CVE-2024-11477: An integer underflow vulnerability in 7-Zip’s Zstandard decompression function (CVSS 7.8) allows attackers to execute malicious code. ❕ Users are advised to update to 7-Zip version 24.07 or later.

⚠️ Palo Alto Networks Authentication bypass vulnerability CVE-2024-0012: An authentication bypass vulnerability in PAN-OS allows attackers to gain administrator privileges.

⚠️ DragonRank Hits IIS Servers in Asia, Europe Over 35 IIS servers compromised using BadIIS malware and ASPXspy, exploiting web app vulnerabilities for SEO fraud.

⚠️ Windows TCP/IP 0-Click RCE Vulnerability CVE-2024-38063: Microsoft released an urgent update for a critical vulnerability. It allows remote code execution via specially crafted IPv6 packets. All Windows and Windows Server versions are affected.

⚠️ Critical GeoServer RCE Flaw CVE-2024-36401: GeoServer versions before 2.24.4, 2.25.2, and 2.23.6 have a critical RCE vulnerability (CVSS 9.8). Users should upgrade to the latest versions to mitigate the threat.

⚠️VMware ESXi Authentication Bypass Vulnerability CVE-2024-37085: VMware ESXi Vulnerability On July 29, Microsoft announced that ransomware groups were exploiting a vulnerability identified as CVE-2024-37085.

Ollama Vulnerability CVE-2024-37032: Ollama Remote Code Execution(RCE) vulnerability. Exploitation involved overwriting /etc/ld.so.preload to load a malicious shared library, escalating from arbitrary file write to remote code execution.