intel
real-time security information stream
2025-04-17 14:32 UTC
new cve-2025-16988 exploit observed in the wild targeting unpatched nginx servers. requests contain malicious x-forwarded-for header triggering buffer overflow in request parsing module. exploit chain includes bypass for waf rules via malformed http version string.
45.142.212.89, user-agent: nginx-scanner/1.2
2025-04-17 11:15 UTC
stealer malware campaign using legitimate digital certificate for distribution. signed binary masquerades as system update utility from trusted vendor. actual payload steals browser credentials, crypto wallets, and ssh keys. certificate appears to be compromised from software build pipeline.
sha256: 7f8e2d3a1b4c5f6e7d8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1
2025-04-17 09:42 UTC
new yara rules released for apt29 activity patterns. rules detect custom cobalt strike profiles with specific beacon configurations, dns tunneling techniques, and lateral movement scripts. includes signatures for recently observed c2 infrastructure in eastern europe.
2025-04-16 23:08 UTC
potential 0-day exploit targeting popular vpn concentrator. targeted exploitation observed in multiple sectors including healthcare and finance. initial analysis suggests authentication bypass leading to pre-auth rce. vendor notified, patch timeline pending.
2025-04-16 18:45 UTC
lockbit 4.0 ransomware variant detected with new evasion techniques. uses process hollowing to inject into legitimate system processes, employs custom encryption with per-victim keys, and includes anti-forensics features to wipe event logs. c2 infrastructure rotates every 48 hours.
*.lockbit4[.]onion, sfx archive pattern: 7z-lzma
2025-04-16 14:20 UTC
sigma rules updated for credential dumping patterns. new rules detect lsass access via task manager, procdump, and custom tools. includes exceptions for authorized administrative tools and provides context for legitimate vs suspicious memory access.
2025-04-16 10:33 UTC
critical vulnerability in popular open-source logging library disclosed. deserialization flaw allows unauthenticated rce when processing specially crafted log entries. affects versions 2.0.0 through 2.4.7. upgrade to 2.4.8 recommended immediately.
cve: cve-2025-16721, cvss: 9.8 (critical)
2025-04-15 22:17 UTC
android banking trojan with overlay attack capabilities distributed via malicious app store clone. targets banking applications in eu region. implements accessibility service abuse to display fake login screens over legitimate apps. exfiltrates credentials and 2fa codes.
package: com.update.securitypatch, permissions: accessibility_service
2025-04-15 16:50 UTC
botnet infrastructure dismantled via coordinated takedown. dga-based botnet used for ddos-for-hire services. approximately 50,000 infected hosts worldwide. sinkholing efforts ongoing. threat actors believed to be operating from russia-aligned regions.
operation: operation-disrupt-botnet, partners: multiple
2025-04-15 11:28 UTC
exploit kit updated with 3 new browser exploits. targeting recent chromium and firefox vulnerabilities. distributed via compromised wordpress sites and malvertising campaigns. exploits used for initial access prior to ransomware deployment.
kit name: sunset-exploit-kit, landing pages: ~200 active