Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access

A critical authentication bypass vulnerability (CVE-2026-24061) in the GNU InetUtils telnet daemon (telnetd), affecting versions 1.9.3 through 2.7, allows remote attackers to gain root by supplying a crafted USER environment value. The flaw, introduced in 2015 and reported in January 2026, is being actively probed in the wild and should be…

Read More
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack

Researchers disclosed a new ransomware family called Osiris that struck a major food service franchisee in Southeast Asia in November 2025, leveraging a custom driver named POORTRY in a BYOVD-style attack to disable security and exfiltrate data to Wasabi cloud buckets. Osiris uses hybrid per-file encryption, can stop services and kill…

Read More
Old Attack, New Speed: Researchers Optimize Page Cache Exploits

TU Graz researchers have revived Linux page cache attacks and demonstrated they are far more practical and dramatically faster than prior work, affecting kernel versions from 2003 to the present. The techniques enable precise password-prompt detection, synchronized phishing overlays, inter-keystroke timing, cross-container spying in Docker, and site-identification via Firefox resources, and…

Read More
The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity

The article compares Stranger Things’ Upside Down to modern enterprise attack surfaces, warning that unmanaged IT, OT, IoT, and cloud assets act as unseen portals for threats like the Mind Flayer and Demogorgon. It calls for continuous visibility, remediation prioritization, IT/OT segmentation, and cross-functional teamwork to detect and stop threats before…

Read More
Fortinet Admins Report Active Exploits on “Fixed” FortiOS 7.4.9 Firmware

A critical Fortinet SSO vulnerability, CVE-2025-59718, is being actively exploited against systems believed to be patched, with breaches reported on FortiOS 7.4.9. Administrators are urged to disable FortiCloud SSO via CLI and audit for unauthorized forticloud-sso logins, new admin accounts, and configuration exports to mitigate the persistent “Zombie” vulnerability. #CVE-2025-59718 #FortiOS…

Read More
The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time

This article describes a novel AI-augmented attack where a benign webpage requests code from trusted LLM APIs, assembles malicious JavaScript in-browser at runtime, and renders personalized phishing pages that evade network-based detection. The report demonstrates a proof-of-concept that leverages prompt engineering and polymorphic LLM-generated code to bypass guardrails and recommends runtime…

Read More
Osiris: New Ransomware, Experienced Attackers?

A new, distinct ransomware family called Osiris was used in a November 2025 attack against a major food service franchisee in Southeast Asia, employing hybrid ECC+AES-128-CTR encryption, VSS deletion, and a variety of living-off-the-land and dual-use tools. The intrusion included data exfiltration to Wasabi buckets, use of a Mimikatz build named kaz.exe, and deployment of a malicious signed driver (Poortry/Abyssworker) consistent with a BYOVD defense‑impairment tactic. #Osiris #Poortry

Read More
Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations

Arctic Wolf warns of a new cluster of automated malicious activity beginning January 15, 2026, that involves unauthorized configuration changes on Fortinet FortiGate devices. Threat actors exploited CVE-2025-59718 and CVE-2025-59719 to bypass FortiCloud SSO, create persistent admin accounts, export firewall configurations, and grant VPN access; operators are advised to disable admin-forticloud-sso-login….

Read More
The APT35 Dump Episode 4: Leaking The Backstage Pass To An Iranian Intelligence Operation

Episode 4 of the Charming Kitten / APT35 leaks exposes not sophisticated zero-day exploits but the bureaucratic infrastructure—spreadsheets, invoices, crypto receipts, hosting accounts, and one-time ProtonMail identities—that fund, procure, and maintain Iranian cyber operations. The documents tie APT35’s procurement and payment chains to Moses Staff’s leak domains and operational tooling, showing micro-crypto payments via Cryptomus, recurring European VPS providers (EDIS, Impreza), and repeatable, auditable workflows that convert state intent into persistent infrastructure. #APT35 #MosesStaff

Read More