⚠️ JACKSKID: BEYOND A MIRAI FORK Nokia Deepfield & Comcast exposed an advanced botnet with 80K+ samples & 13 releases in 5 months. • Dual infection: Telnet + Android TV ADB • 3-layer encryption: RC4+ChaCha20+TEA • DNS-over-HTTPS for stealthy C2 • Fast-flux: 40-50 IPs/domain • 17 DDoS attacks
Cyber Threat Zip
@cyberthreat.zip
Cyber Threat intelligence Alert Contact: contact@cyberthreat.zip
APT31's Arsenal: SharpADUserIP (Recon) SharpChrome (Password theft) StickyNotesExtract (Data theft) Tailscale VPN (Tunneling) CloudSorcerer/OneDriveDoor (Cloud C2) VtChatter (VirusTotal C2) LocalPlugX (Lateral movement) Various backdoors (Linux/Windows)
APT31 (China) targeted Russian gov't IT contractors in 2025 & earlier. The group operated undetected for extended periods, gathering intelligence through sophisticated cyber espionage campaigns.
APT31 (China) targeted Russian gov't IT contractors in 2025 & earlier. The group operated undetected for extended periods, gathering intelligence through sophisticated cyber espionage campaigns.
⚠️ 7-Zip RCE Vulnerability CVE-2025-11001: Critical vulnerability in 7-Zip! A malicious ZIP file can allow remote code execution on your computer. Simply opening the file is enough. ❕ Users are advised to update to 7-Zip version 25.00 or later.
⚠️ OpenVPN RCE Vulnerability CVE-2025-10680: High-severity flaw enabling authenticated VPN servers to execute OS commands on clients. Scope: OpenVPN Client (Linux, macOS) Requirement: --dns-updown enabled
⚠️ Fortinet FortiOS/FortiProxy Zero Day Vulnerability CVE-2024-55591: (CVSS score: 9.6) is an authentication bypass vulnerability in FortiOS and FortiProxy. It allows attackers to gain super admin privileges through specially crafted Node.js websocket requests.
✨🎉 A new year brings new opportunities and new goals! At CyberThreat.zip, we’re here to ensure your growth and security in 2025. 🛡️💻 Wishing everyone a happy, healthy, and safe New Year! 🎄🎆 #CyberThreatZip #HappyNewYear2025
CyberThreat.zip Error 404
cyberthreat.zip
⚠️ 7-Zip RCE Vulnerability CVE-2024-11477: CVE-2024-11477: An integer underflow vulnerability in 7-Zip’s Zstandard decompression function (CVSS 7.8) allows attackers to execute malicious code. ❕ Users are advised to update to 7-Zip version 24.07 or later.
⚠️ Palo Alto Networks Privilege escalation vulnerability CVE-2024-9474: A privilege escalation vulnerability affecting authorized users.
⚠️ Palo Alto Networks Authentication bypass vulnerability CVE-2024-0012: An authentication bypass vulnerability in PAN-OS allows attackers to gain administrator privileges.
⚠️ DragonRank Hits IIS Servers in Asia, Europe Over 35 IIS servers compromised using BadIIS malware and ASPXspy, exploiting web app vulnerabilities for SEO fraud.
❕Systems are not affected if IPv6 is disabled on the target machine.
⚠️ Windows TCP/IP 0-Click RCE Vulnerability CVE-2024-38063: Microsoft released an urgent update for a critical vulnerability. It allows remote code execution via specially crafted IPv6 packets. All Windows and Windows Server versions are affected.
⚠️ Windows TCP/IP 0-Click RCE Vulnerability CVE-2024-38063: Microsoft released an urgent update for a critical vulnerability. It allows remote code execution via specially crafted IPv6 packets. All Windows and Windows Server versions are affected.
Our Telegram Channel is Opened Our Telegram channel, where we make all announcements about cyber threats and security vulnerabilities, has been opened. t.me/cyberthreatzip
CyberThreat zip
Cyber Threat intelligence Alert contact@cyberthreat.zip
t.me
⚠️ Critical GeoServer RCE Flaw CVE-2024-36401: GeoServer versions before 2.24.4, 2.25.2, and 2.23.6 have a critical RCE vulnerability (CVSS 9.8). Users should upgrade to the latest versions to mitigate the threat.
⚠️VMware ESXi Authentication Bypass Vulnerability CVE-2024-37085: VMware ESXi Vulnerability On July 29, Microsoft announced that ransomware groups were exploiting a vulnerability identified as CVE-2024-37085.
🗣️ Microsoft confirmed that the nine-hour outage on Tuesday was caused by a DDoS attack. This attack affected many Microsoft 365 and Azure services worldwide.
⚠️ 10 billion passwords leaked. New RockYou2024 Password List. s3.timeweb.cloud/fd51ce25-6f9...
s3.timeweb.cloud
Oracle WebLogic Server Vulnerability CVE-2024-21007: Weblogic Server Remote Code Execution(RCE) Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0
🗣️Operation Endgame - New episode. S1E07: ODD ONE OUT Source: www.operation-endgame.com
Operation Endgame
Operation endgame
operation-endgame.com
Ollama Vulnerability CVE-2024-37032: Ollama Remote Code Execution(RCE) vulnerability. Exploitation involved overwriting /etc/ld.so.preload to load a malicious shared library, escalating from arbitrary file write to remote code execution.
New GitLab Vulnerability CVE-2024-5655: GitLab security updates fixing 14 vulnerabilities. GitLab Critical Patch Release: 17.1.1, 17.0.3, 16.11.5
New OpenSSH Vulnerability CVE-2024-6387: OpenSSH's server (sshd), allows unauthenticated remote code execution (RCE) as root on glibc-based Linux systems.