Generated by All in One SEO v4.9.5.1, this is an llms.txt file, used by LLMs to index the site. # Rewterz Revolutionizing Cybersecurity ## Sitemaps - [XML Sitemap](https://rewterz.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [AI SOC vs Traditional SOC: Architectural Differences in Modern Security Operations](https://rewterz.com/blog/ai-soc-vs-traditional-soc-architecture) - Compare AI SOC vs traditional SOC architectures and see how AI improves threat detection, response speed, and security efficiency. - [Iran-Linked Botnet Exposed via Open Directory Leak - Active IOCs](https://rewterz.com/threat-advisory/iran-linked-botnet-exposed-via-open-directory-leak-active-iocs) - A threat actor with ties to Iran inadvertently exposed their entire working infrastructure after leaving an open directory on a staging server, - [Iranian Cyber Ops Exploit US Networks, Target Cameras - Active IOCs](https://rewterz.com/threat-advisory/iranian-cyber-ops-exploit-us-networks-target-cameras-active-iocs) - In early 2026, Iranian cyber operations intensified, with state-linked threat actors, including the APT group MuddyWater, - [Cisco Firewall 0-Day Powers Interlock Ransomware Attack - Active IOCs](https://rewterz.com/threat-advisory/cisco-firewall-0-day-powers-interlock-ransomware-attack-active-iocs) - The Interlock ransomware group is actively exploiting a critical zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC), - [Handala Hack Uses RDP and Wipers in MOIS-Linked Attacks - Active IOCs](https://rewterz.com/threat-advisory/handala-hack-uses-rdp-and-wipers-in-mois-linked-attacks-active-iocs) - The Iranian threat actor Handala Hack has conducted a series of highly destructive cyberattacks targeting organizations in Albania and the United States. - [Israel–Iran Conflict May Enable State-Backed Cyber Attacks](https://rewterz.com/threat-advisory/israel-iran-conflict-may-enable-state-backed-cyber-attacks) - Rising tensions between Israel and Iran are expected to spark a new wave of cyber threats, - [The AI-Powered SOC: Architecture, Capabilities, and the Future of Security Operations](https://rewterz.com/blog/ai-powered-soc-architecture-capabilities-future-security-operations) - Explore AI-powered SOC architecture, key capabilities, and how AI-driven security operations improve threat detection, investigation, and response. - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-56) - Google Chrome could allow a remote attacker to execute arbitrary code on the system, - [Splunk RCE Lets Attackers Run Arbitrary Shell Commands](https://rewterz.com/threat-advisory/splunk-rce-lets-attackers-run-arbitrary-shell-commands) - A critical security advisory has been released for Splunk, highlighting a high-severity Remote Command Execution (RCE) vulnerability - [Chrome Zero-Day Exploited in the Wild](https://rewterz.com/threat-advisory/chrome-zero-day-exploited-in-the-wild) - Google Chrome has released an urgent security update after confirming that two high-severity zero-day vulnerabilities are being actively exploited in the wild. - [Multiple Google Chrome Zero-Day Vulnerabilities Exploit in the Wild](https://rewterz.com/threat-advisory/multiple-google-chrome-zero-day-vulnerabilities-exploit-in-the-wild) - Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code - [Multiple Microsoft Office Excel Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-office-excel-vulnerabilities) - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-62) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Stealc Information Stealer Malware - Active IOCs](https://rewterz.com/threat-advisory/stealc-information-stealer-malware-active-iocs-15) - Stealc is a new malware that was first marketed by an actor named Plymouth on the XSS and BHF Russian-speaking underground forums on January 9, 2023. - [Iran-Linked Campaign Surge Targeting Middle East Governments - Active IOCs](https://rewterz.com/threat-advisory/iran-linked-campaign-surge-targeting-middle-east-governments-active-iocs) - Alongside Iranian activity, researchers observed a rise in phishing campaigns targeting Middle Eastern government - [Multiple Cisco IOS XR Vulnerabilities](https://rewterz.com/threat-advisory/multiple-cisco-ios-xr-vulnerabilities) - A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, - [Microsoft AD DS Vulnerability Allows Privilege Escalation](https://rewterz.com/threat-advisory/microsoft-ad-ds-vulnerability-allows-privilege-escalation) - On March 10, 2026, Microsoft released an “Important” security update addressing a high-severity vulnerability in Active Directory Domain Services (AD DS), - [Chrome Security Update Fixes 29 Bugs](https://rewterz.com/threat-advisory/chrome-security-update-fixes-29-bugs) - Google Chrome version 146 has been officially released to the stable channel, - [Multiple Microsoft Office Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-office-vulnerabilities-3) - Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. - [Wanna Cryptor aka WannaCry Ransomware - Active IOCs](https://rewterz.com/threat-advisory/wanna-cryptor-aka-wannacry-ransomware-active-iocs-3) - WannaCry, also known as WanaCrypt0r 2.0, remains a landmark example of the devastating potential of ransomware. - [FormBook Malware - Active IOCs](https://rewterz.com/threat-advisory/formbook-malware-active-iocs-32) - FormBook is an infostealer malware that was first identified in 2016. - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-55) - Google Chrome is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by WebCodecs. - [SideWinder APT Group aka Rattlesnake Targeting Pakistan – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-targeting-pakistan-active-iocs-23) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [FortiManager Vulnerability Enables Malicious Commands](https://rewterz.com/threat-advisory/fortimanager-vulnerability-enables-malicious-commands) - Fortinet has disclosed a high-severity stack-based buffer overflow vulnerability in its FortiManager platform, - [Microsoft .NET Zero-Day Enables DoS Attacks](https://rewterz.com/threat-advisory/microsoft-net-zero-day-enables-dos-attacks) - A critical vulnerability, CVE-2026-26127, has been disclosed in the .NET Framework, prompting an emergency security update from Microsoft. - [Multiple Microsoft Products Zero-Day Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-zero-day-vulnerabilities-4) - Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches. - [Gh0st RAT - Active IOCs](https://rewterz.com/threat-advisory/gh0st-rat-active-iocs-10) - Gh0st RAT is a remote access trojan (RAT) that was first discovered in 2008. - [NJRAT - Active IOCs](https://rewterz.com/threat-advisory/njrat-active-iocs-21) - NjRat is a Remote Access Trojan, which is found leveraging Pastebin to deliver a second-stage payload after initial infection. - [Multiple Apache Ranger Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apache-ranger-vulnerabilities) - Apache Ranger could allow a remote attacker to execute arbitrary code on the system, caused by a remote code execution Vulnerability in NashornScriptEngineCreator. - [Iran-Linked Hackers Target U.S. Critical Infrastructure - Active IOCs](https://rewterz.com/threat-advisory/iran-linked-hackers-target-u-s-critical-infrastructure-active-iocs) - Static Kitten, has been actively infiltrating multiple U.S. networks since early February 2026. - [AWS-LC Flaw Enables Certificate Verification Bypass](https://rewterz.com/threat-advisory/aws-lc-flaw-enables-certificate-verification-bypass) - on March 2, 2026, disclosed three vulnerabilities in AWS-LC, an open-source cryptographic library maintained by Amazon. - [China-Nexus APT Campaign Targeting Qatar Amid Middle East Escalation - Active IOCs](https://rewterz.com/threat-advisory/china-nexus-apt-campaign-targeting-qatar-amid-middle-east-escalation-active-iocs) - Following the escalation of tensions in the Middle East on March 1, 2026, researchers observed targeted cyber campaigns against organizations in Qatar. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-61) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [MassLogger Malware - Active IOCs](https://rewterz.com/threat-advisory/masslogger-malware-active-iocs-18) - MassLogger, a .NET credential stealer, is a keylogger and stealer malware. MassLogger's prime objective is data extraction or information theft, such as bank account and/or credit card details. - [Multiple D-Link DIR Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-dir-vulnerabilities) - D-Link DIR-513 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. - [Iranian APTs Target Critical Infrastructure Amid Conflict - Active IOCs](https://rewterz.com/threat-advisory/iranian-apts-target-critical-infrastructure-amid-conflict-active-iocs) - A new and highly dangerous chapter in Middle Eastern geopolitics has emerged following open conflict between Iran, Israel, and the United States. - [ICS: Multiple Johnson Controls Frick Controls Quantum HD Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-johnson-controls-frick-controls-quantum-hd-vulnerabilities) - Improper Control of Generation of Code Injection vulnerability in Johnson Controls Frick Controls Quantum HD. - [CISA Alerts on Exploited macOS and iOS Vulnerabilities](https://rewterz.com/threat-advisory/cisa-alerts-on-exploited-macos-and-ios-vulnerabilities) - The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding multiple actively exploited vulnerabilities in Apple products, - [Apache ActiveMQ Flaw Enables DoS Attacks](https://rewterz.com/threat-advisory/apache-activemq-flaw-enables-dos-attacks) - A medium-severity vulnerability in Apache ActiveMQ, tracked as CVE-2025-66168, - [CoinMiner Malware - Active IOCs](https://rewterz.com/threat-advisory/coinminer-malware-active-iocs-18) - CoinMiner is a malware designed to secretly mine cryptocurrencies, such as Bitcoin, on infected computers. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-58) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Iran-Linked Dust Specter Targets Government Entities in Espionage Campaign - Active IOCs](https://rewterz.com/threat-advisory/iran-linked-dust-specter-targets-government-entities-in-espionage-campaign-active-iocs) - The activity has been attributed with medium-to-high confidence to a suspected Iran-linked threat actor dubbed Dust Specter. - [MS-Agent Flaw Lets Hackers Take Full System Control](https://rewterz.com/threat-advisory/ms-agent-flaw-lets-hackers-take-full-system-control) - A critical security flaw, tracked as CVE-2026-2256, has been discovered in the ModelScope MS-Agent Framework, - [Azure Private Endpoint Flaw Exposes Resources to DoS](https://rewterz.com/threat-advisory/azure-private-endpoint-flaw-exposes-resources-to-dos) - A critical architectural weakness has been identified in Microsoft Azure’s Private Endpoint and Private Link implementation, - [SloppyLemming's Dual Malware Campaign Targets South Asia - Active IOCs](https://rewterz.com/threat-advisory/sloppylemmings-dual-malware-campaign-targets-south-asia-active-iocs) - Cybersecurity researchers at have detailed a year-long cyber espionage campaign attributed to the India-nexus threat actor SloppyLemming, also tracked as Outrider Tiger and Fishing Elephant. - [APT37 Targets Air-Gapped Systems via USB-Based Malware Campaign - Active IOCs](https://rewterz.com/threat-advisory/apt37-targets-air-gapped-systems-via-usb-based-malware-campaign-active-iocs) - A North Korea-linked threat group known as APT37, also tracked as ScarCruft, Ruby Sleet, and Velvet Chollima, - [Iran-Linked Cyber Activity Escalates Amid Regional Conflict Tensions](https://rewterz.com/threat-advisory/iran-linked-cyber-activity-escalates-amid-regional-conflict-tensions) - Iran maintains a mature cyber ecosystem, leveraging espionage, disruptive attacks, and influence operations to support strategic objectives. - [Critical BIG-IP and NGINX Vulnerabilities Patched by F5](https://rewterz.com/threat-advisory/critical-big-ip-and-nginx-vulnerabilities-patched-by-f5) - a security exposure affecting BIG-IP, NGINX, and container-based services. - [Cisco Meeting Management File Upload Vulnerability](https://rewterz.com/threat-advisory/cisco-meeting-management-file-upload-vulnerability) - A high-severity security vulnerability has been disclosed in Cisco Meeting Management software that allows authenticated remote attackers to gain full control of affected systems. - [Chrome Flaws Allow Code Execution and Crashes](https://rewterz.com/threat-advisory/chrome-flaws-allow-code-execution-and-crashes) - Google has rolled out a critical security update for the Chrome Stable channel to address two high-severity vulnerabilities - [Critical OpenSSL Flaws Enable RCE](https://rewterz.com/threat-advisory/critical-openssl-flaws-enable-rce) - OpenSSL released patches addressing 12 security vulnerabilities across versions 1.0.2 to 3.6. - [NVIDIA GPU Driver Exploits Lead to Privilege Escalation](https://rewterz.com/threat-advisory/nvidia-gpu-driver-exploits-lead-to-privilege-escalation) - NVIDIA has disclosed multiple high-severity vulnerabilities affecting its GPU display drivers, - [Automated Attacks Breach FortiGate Firewalls, Exposing Configuration Data - Active IOCs](https://rewterz.com/threat-advisory/automated-attacks-breach-fortigate-firewalls-exposing-configuration-data-active-iocs) - A newly observed wave of highly automated malicious activity is actively targeting FortiGate firewall devices, - [Zoom Command Injection Bug Enables Remote Code Execution](https://rewterz.com/threat-advisory/zoom-command-injection-bug-enables-remote-code-execution) - tracked as CVE-2026-22844, has been identified in Zoom Node Multimedia Routers (MMRs). - [Critical Oracle WebLogic Proxy Flaw Allows Server Compromise](https://rewterz.com/threat-advisory/critical-oracle-weblogic-proxy-flaw-allows-server-compromise) - Oracle has disclosed a critical security vulnerability affecting its Fusion Middleware suite, - [TP-Link Password Recovery Bug Enables Authentication Bypass](https://rewterz.com/threat-advisory/tp-link-password-recovery-bug-enables-authentication-bypass) - CVE-2026-0629 represents a critical security risk for any deployment of TP-Link VIGI cameras. - [5 Chrome Extensions Hijacking HR and ERP Systems](https://rewterz.com/threat-advisory/5-chrome-extensions-hijacking-hr-and-erp-systems) - A coordinated campaign involving five malicious Google Chrome extensions has emerged as a serious enterprise security threat, - [Windows Admin Center Bug Enables Full Azure Tenant Takeover](https://rewterz.com/threat-advisory/windows-admin-center-bug-enables-full-azure-tenant-takeover) - A high-severity vulnerability in Windows Admin Center (WAC) Azure Single Sign-On has exposed Azure virtual machines - [Palo Alto Firewall Flaw Lets Attackers Cause DoS](https://rewterz.com/threat-advisory/palo-alto-firewall-flaw-lets-attackers-cause-dos) - Palo Alto Networks released a patch for a critical denial-of-service vulnerability - [FortiSIEM RCE Flaw Exploited Through Crafted TCP Packets](https://rewterz.com/threat-advisory/fortisiem-rce-flaw-exploited-through-crafted-tcp-packets) - Fortinet has disclosed a critical OS command injection vulnerability in FortiSIEM - [Iranian APT MuddyWater Targets Middle East with RustyWater Malware - Active IOCs](https://rewterz.com/threat-advisory/iranian-apt-muddywater-targets-middle-east-with-rustywater-malware-active-iocs) - The Iranian state-linked threat actor MuddyWater has been attributed to a new spear-phishing campaign targeting diplomatic, - [Threat Actors Abuse Chrome Extensions to Steal AI Prompts - Active IOCs](https://rewterz.com/threat-advisory/threat-actors-abuse-chrome-extensions-to-steal-ai-prompts-active-iocs) - Two newly discovered malicious Chrome extensions were found exfiltrating conversations - [Tactical vs. Strategic Threat Intelligence: What SOCs Need Most](https://rewterz.com/blog/tactical-vs-strategic-threat-intelligence-what-socs-need-most) - Learn the differences between tactical and strategic threat intelligence and which approach SOC teams need most to improve detection and response. - [Trend Micro Apex Central RCE Vulnerability](https://rewterz.com/threat-advisory/trend-micro-apex-central-rce-vulnerability) - Trend Micro has released critical security patches to address three severe vulnerabilities - [CISA Warns of Microsoft PowerPoint Code Injection Flaw Actively Exploited](https://rewterz.com/threat-advisory/cisa-warns-of-microsoft-powerpoint-code-injection-flaw-actively-exploited) - a severe code-injection vulnerability in Microsoft PowerPoint, tracked as CVE-2009-0556, - [Chrome WebView Flaw Enables Security Bypass](https://rewterz.com/threat-advisory/chrome-webview-flaw-enables-security-bypass) - its Chrome browser to address a high-severity vulnerability in the WebView tag component - [Phishing Attack Impersonates Google Support to Steal Logins](https://rewterz.com/threat-advisory/phishing-attack-impersonates-google-support-to-steal-logins) - a sophisticated phishing campaign that impersonates Google support to steal user credentials, - [Critical IBM API Connect Flaw Enables Login Bypass](https://rewterz.com/threat-advisory/critical-ibm-api-connect-flaw-enables-login-bypass) - vulnerability has been identified in the IBM API Connect platform - [SAMA مقابل PDPL: تحليل مقارن لتنظيمات البيانات في المملكة العربية السعودية](https://rewterz.com/ar/articles/sama-مقابل-pdpl-تحليل-مقارن-لتنظيمات-البيانا) - Explore key differences between SAMA and PDPL regulations in Saudi Arabia to ensure compliance, data protection, and secure business operations. - [Red Team vs. APT Assessment: What’s the Difference?](https://rewterz.com/blog/red-team-vs-apt-assessment-whats-the-difference) - Learn the key differences between Red Team and APT assessments, their goals, methods, and when to use each for stronger cybersecurity defense. - [GlassWorm Malware Targets macOS via Trojanized VSCode Extensions - Active IOCs](https://rewterz.com/threat-advisory/glassworm-malware-targets-macos-via-trojanized-vscode-extensions-active-iocs) - a fourth wave of the GlassWorm malware campaign targeting macOS developers - [RondoDox Botnet Weaponize React2Shell to Infect IoT Devices and Web Apps](https://rewterz.com/threat-advisory/rondodox-botnet-weaponize-react2shell-to-infect-iot-devices-and-web-apps) - a nine-month-long malicious campaign that has targeted Internet of Things (IoT) devices and web applications to build a botnet known as RondoDox. - [APT Group Gamaredon aka Shuckworm - Active IOCs](https://rewterz.com/threat-advisory/apt-group-gamaredon-aka-shuckworm-active-iocs-23) - Shuckworm APT - aka Actinium, Armageddon, Primitive Bear, Gamaredon, and Trident Ursa - has been a Russia-backed advanced persistent threat (APT)... - [CISA Flags MongoDB MongoBleed Flaw as High Exposure Risk](https://rewterz.com/threat-advisory/cisa-flags-mongodb-mongobleed-flaw-as-high-exposure-risk) - a high-severity MongoDB vulnerability, actively exploited in the wild. - [جدل اختراق Oracle Cloud: بين النفي والابتزاز والمسؤولية الأخلاقية](https://rewterz.com/ar/articles/جدل-اختراق-oracle-cloud-بين-النفي-والابتزاز-والم) - Navigating Denials, Extortion, and Ethical Responsibility - [Stored XSS in Ivanti EPM Allows Admin Session Hijacking](https://rewterz.com/threat-advisory/stored-xss-in-ivanti-epm-allows-admin-session-hijacking) - A critical stored cross-site scripting (XSS) vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2024 SU4 and earlier, - [Copilot Studio Connected Agents Exploited by Hackers for Backdoor Access](https://rewterz.com/threat-advisory/copilot-studio-connected-agents-exploited-by-hackers-for-backdoor-access) - Microsoft’s newly introduced Connected Agents feature in Copilot Studio, announced at Build 2025, - [Windows Kernel Flaws Allow Privilege Escalation](https://rewterz.com/threat-advisory/windows-kernel-flaws-allow-privilege-escalation) - Security researchers are increasingly analyzing local privilege escalation (LPE) techniques in Windows, - [High-Severity Jenkins Flaw Enables Unauthenticated DoS](https://rewterz.com/threat-advisory/high-severity-jenkins-flaw-enables-unauthenticated-dos) - Jenkins, a widely used automation server for continuous integration and deployment, - [أهمية دمج مستجدات التهديدات في حلول SIEM الحديثة](https://rewterz.com/ar/articles/أهمية-دمج-مستجدات-التهديدات-في-حلول-siem-ا) - Integrating threat intelligence feeds into modern SIEM solutions boosts detection, improves response times, and strengthens your cybersecurity defense. - [Attackers Abuse Three-Year-Old FortiGate Flaw to Bypass Firewall 2FA](https://rewterz.com/threat-advisory/attackers-abuse-three-year-old-fortigate-flaw-to-bypass-firewall-2fa) - Cybercriminals are actively exploiting a long-patched Fortinet FortiGate vulnerability - [GitLab Fixes Multiple Flaws Allowing XSS and DoS Exploits](https://rewterz.com/threat-advisory/gitlab-fixes-multiple-flaws-allowing-xss-and-dos-exploits) - GitLab released critical security patches addressing ten vulnerabilities across its Community and Enterprise Edition platforms. - [SOC Threat Intelligence Explained: How It Enhances Detection and Response](https://rewterz.com/blog/soc-threat-intelligence-explained-how-it-enhances-detection-and-response) - Learn how SOC threat intelligence improves detection, speeds response, and reduces risk by turning insights into actionable security decisions. - [SideWinder APT Group aka Rattlesnake Targeting Pakistan – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-targeting-pakistan-active-iocs-22) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [PoC Released for Linux Kernel Use-After-Free Flaw](https://rewterz.com/threat-advisory/poc-released-for-linux-kernel-use-after-free-flaw) - a race condition vulnerability in the Linux kernel’s POSIX CPU timer implementation. - [BlackMoon Banking Trojan aka KrBanker - Active IOCs](https://rewterz.com/threat-advisory/blackmoon-banking-trojan-aka-krbanker-active-iocs-9) - BlackMoon, also known as KrBanker, is a banking Trojan that first emerged in September 2015, initially targeting South Korean bank s - [Multiple TP-Link Tapo Vulnerabilities](https://rewterz.com/threat-advisory/multiple-tp-link-tapo-vulnerabilities) - TP-Link Tapo C200 is vulnerable to a denial of service, caused by an integer overflow. - [كيف يمكن لمقدّمي خدمات الأمن المُدارة دعم المؤسسات في تطوير إستراتيجية للمرونة السيبرانية](https://rewterz.com/ar/articles/كيف-يمكن-لمقدّمي-خدمات-الأمن-المُدارة) - Learn how MSSPs help organizations boost cyber resilience through threat detection, response planning, and recovery support. - [Apache Log4j Flaw Lets Attackers Access Sensitive Logs](https://rewterz.com/threat-advisory/apache-log4j-flaw-lets-attackers-access-sensitive-logs) - Apache Logging Services has disclosed a critical vulnerability in Log4j Core, - [100 Cisco Secure Email Devices Exposed via Active Zero-Day](https://rewterz.com/threat-advisory/100-cisco-secure-email-devices-exposed-via-active-zero-day) - affecting Cisco Secure Email Gateway (SEG) and Cisco Secure Email and Web Manager (SEWM) devices. - [CVE-2025-14727 - F5 NGINX Ingress Controller Vulnerability](https://rewterz.com/threat-advisory/cve-2025-14727-f5-nginx-ingress-controller-vulnerability) - F5 NGINX Ingress Controller could allow a remote attacker to traverse directories on the system to unintended locations. - [Multiple Zoho ManageEngine Vulnerabilities](https://rewterz.com/threat-advisory/multiple-zoho-manageengine-vulnerabilities) - Zoho ManageEngine ADManager Plus could allow a remote authenticated attacker - [Multiple Mozilla Firefox Vulnerabilities](https://rewterz.com/threat-advisory/multiple-mozilla-firefox-vulnerabilities-16) - Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-47) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [NJRAT - Active IOCs](https://rewterz.com/threat-advisory/njrat-active-iocs-20) - NjRat is a Remote Access Trojan, which is found leveraging Pastebin to deliver a second-stage payload after initial infection. - [Apache Commons Text RCE Vulnerability](https://rewterz.com/threat-advisory/apache-commons-text-rce-vulnerability) - A newly disclosed vulnerability in Apache Commons Text, tracked as CVE-2025-46295, - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-57) - Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. - [Multiple NVIDIA Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-products-vulnerabilities-10) - NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, - [Remcos RAT - Active IOCs](https://rewterz.com/threat-advisory/remcos-rat-active-iocs-28) - Remcos malware has been operating since 2016. This RAT was originally promoted as genuine software for remote control of Microsoft Windows from XP onwards and is frequently found in phishing attempts due to its capacity to completely infect an afflicted machine. - [GCleaner Malware - Active IOCs](https://rewterz.com/threat-advisory/gcleaner-malware-active-iocs-6) - GCleaner is a type of malware that disguises itself as a legitimate software program called "GCleaner" or "G-Cleaner." - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-54) - Google Chrome could allow a remote attacker to execute arbitrary code on the system, - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-56) - Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. - [Multiple Elastic Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-elastic-products-vulnerabilities-3) - Refer to Elastic Security Advisory for patch, upgrade, or suggested workaround information. - [FormBook Malware - Active IOCs](https://rewterz.com/threat-advisory/formbook-malware-active-iocs-31) - FormBook is an infostealer malware that was first identified in 2016. - [Cobalt Strike Malware - Active IOCs](https://rewterz.com/threat-advisory/cobalt-strike-malware-active-iocs-26) - Cobalt Strike first appeared in 2012 in response to alleged flaws in the Metasploit Framework, an existing red team (penetration testing) tool. - [Multiple IBM UCD Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-ucd-vulnerabilities) - IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 Deploy transmits data in clear text that could allow an attacker - [Windows Admin Center Flaw Enables Privilege Escalation](https://rewterz.com/threat-advisory/windows-admin-center-flaw-enables-privilege-escalation) - A newly disclosed local privilege escalation vulnerability in Microsoft Windows Admin Center (WAC), - [STRRAT Malware - Active IOCs](https://rewterz.com/threat-advisory/strrat-malware-active-iocs-10) - STRRat is a Java-based Remote-Access Trojan (RAT) with a slew of malicious features, notably information theft and backdoor capabilities. - [Stealc Information Stealer Malware - Active IOCs](https://rewterz.com/threat-advisory/stealc-information-stealer-malware-active-iocs-14) - Stealc is a new malware that was first marketed by an actor named Plymouth on the XSS and BHF Russian-speaking underground forums on January 9, 2023. - [Multiple Apple macOS Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apple-macos-vulnerabilities-6) - Apple macOS Sonoma and Sequoia could allow a remote attacker to access protected user data, - [CISA Alerts on Google Chromium 0-Day Being Exploited](https://rewterz.com/threat-advisory/cisa-alerts-on-google-chromium-0-day-being-exploited) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical zero-day vulnerability in Google Chromium’s ANGLE graphics engine - [CVE-2025-14659 - D-Link DIR-860LB1/DIR-868LB1 Vulnerability](https://rewterz.com/threat-advisory/cve-2025-14659-d-link-dir-860lb1-dir-868lb1-vulnerability) - A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. - [Multiple Fortinet Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-fortinet-products-vulnerabilities-26) - Fortinet FortiExtender may allow an authenticated attacker to execute unauthorized code - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-57) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Hackers Abuse PuTTY for Lateral Movement and Data Exfiltration](https://rewterz.com/threat-advisory/hackers-abuse-putty-for-lateral-movement-and-data-exfiltration) - Attackers are increasingly leveraging the legitimate PuTTY SSH client to conduct stealthy lateral movement - [Cisco UCCX Vulnerabilities Allow Remote Code Execution](https://rewterz.com/threat-advisory/cisco-uccx-vulnerabilities-allow-remote-code-execution) - A critical security advisory has been issued for Cisco Unified Contact Center Express (Unified CCX), - [Integrating Threat Intelligence into SOC Workflows](https://rewterz.com/blog/integrating-threat-intelligence-into-soc-workflows) - Learn how integrating threat intelligence into SOC workflows improves detection, response speed, and overall cybersecurity operations. - [Cisco AsyncOS Zero-Day Exploited for RCE](https://rewterz.com/threat-advisory/cisco-asyncos-zero-day-exploited-for-rce) - A highly active cyber campaign has been exploiting a zero-day vulnerability in Cisco AsyncOS software, - [SonicWall SMA1000 Zero-Day Exploited for Privilege Escalation](https://rewterz.com/threat-advisory/sonicwall-sma1000-zero-day-exploited-for-privilege-escalation) - Security researchers have identified a critical privilege escalation vulnerability in SonicWall’s SMA1000 appliance, - [NVIDIA Isaac Lab Flaw Enables Remote Code Execution](https://rewterz.com/threat-advisory/nvidia-isaac-lab-flaw-enables-remote-code-execution) - A critical deserialization vulnerability has been identified in NVIDIA Isaac Lab, - [CISA Lists Actively Exploited Fortinet Vulnerability in KEV Catalog](https://rewterz.com/threat-advisory/cisa-lists-actively-exploited-fortinet-vulnerability-in-kev-catalog) - On December 16, 2025, CISA officially added CVE-2025-59718 to its Known Exploited Vulnerabilities (KEV) catalog, - [ما وراء جدار الحماية: فهم منهجية الحماية متعددة الطبقات](https://rewterz.com/ar/articles/ما-وراء-جدار-الحماية-فهم-منهجية-الحماي) - Businesses must engage in “defense in depth” or a multi layered approach to firewall security, to repel cyber attacks. - [ICS: Hitachi Vantara Pentaho Business Analytics Server Vulnerability](https://rewterz.com/threat-advisory/ics-hitachi-vantara-pentaho-business-analytics-server-vulnerability-2) - Pentaho data integration and analytics community dashboard editor plugin versions - [FortiWeb Flaw Actively Exploited for Full Admin Takeover](https://rewterz.com/threat-advisory/fortiweb-flaw-actively-exploited-for-full-admin-takeover) - A critical path-traversal vulnerability in Fortinet’s FortiWeb web application firewall, - [Multiple IBM Aspera Orchestrator Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-aspera-orchestrator-vulnerabilities) - IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. - [Multiple Fortinet Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-fortinet-products-vulnerabilities-25) - Fortinet FortiSOAR PaaS and FortiSOAR on-premise allow information disclosure to an authenticated attacker - [Bitter APT - Active IOCs](https://rewterz.com/threat-advisory/bitter-apt-active-iocs-32) - APT-17, also known as "Bitter APT" or "DeputyDog" is a state-sponsored cyber espionage group that is believed to operate out of China. - [DarkTortilla Malware - Active IOCs](https://rewterz.com/threat-advisory/darktortilla-malware-active-iocs-7) - DarkTortilla is a highly obfuscated, .NET-based malware crypter active since at least 2015. - [Multiple Microsoft Office Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-office-products-vulnerabilities-4) - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. - [Multiple Microsoft Office Excel and Word Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-office-excel-and-word-vulnerabilities) - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. - [Multiple Fortinet Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-fortinet-products-vulnerabilities-24) - Fortinet FortiWeb may allow an attacker to bypass the FortiCloud SSO login authentication via a specially crafted SAML response message, - [Multiple NVIDIA Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-products-vulnerabilities-9) - NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, - [CoinMiner Malware - Active IOCs](https://rewterz.com/threat-advisory/coinminer-malware-active-iocs-17) - CoinMiner is a malware designed to secretly mine cryptocurrencies, such as Bitcoin, on infected computers. - [GuLoader Malspam Campaign - Active IOCs](https://rewterz.com/threat-advisory/guloader-malspam-campaign-active-iocs-18) - Since 2019, Guloader has been in operation as a downloader. GuLoader spreads through spam campaigns with malicious archived attachments. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-60) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Apple Zero-Day Exploited in Attacks on iPhone Users](https://rewterz.com/threat-advisory/apple-zero-day-exploited-in-attacks-on-iphone-users) - Apple has released emergency security updates for iOS 26.2 - [Multiple Adobe Format Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-format-vulnerabilities-2) - Adobe Format Plugins is vulnerable to a denial of service, caused by a use-after-free error. - [Multiple Dell Encryption Vulnerabilities](https://rewterz.com/threat-advisory/multiple-dell-encryption-vulnerabilities) - Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access - [Multiple Microsoft Products Zero-Day Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-zero-day-vulnerabilities-3) - Microsoft Windows PowerShell allows an unauthorized attacker to execute code locally - [CVE-2025-62221 - Microsoft Windows Cloud Files Vulnerability Exploit in the Wild](https://rewterz.com/threat-advisory/cve-2025-62221-microsoft-windows-cloud-files-vulnerability-exploit-in-the-wild) - Microsoft Windows allows an authorized attacker to elevate privileges locally, caused by a use-after-free in the Cloud Files Mini Filter Driver. - [Quasar RAT aka CinaRAT - Active IOCs](https://rewterz.com/threat-advisory/quasar-rat-aka-cinarat-active-iocs-19) - Quasar malware is a Remote Access Trojan (RAT) that is often abused by cybercriminals to take remote control over users' computers for malicious purposes. - [Snake Keylogger Malware - Active IOCs](https://rewterz.com/threat-advisory/snake-keylogger-malware-active-iocs-22) - Snake is a modular .NET keylogger that was first spotted in late November 2020. Snake malware's main feature is keylogging, but it also has additional capabilities such as taking screenshots and extracting data from the clipboard. - [10 طرق لتجنّب هجمات الهندسة الاجتماعية](https://rewterz.com/ar/articles/10-طرق-لتجنّب-هجمات-الهندسة-الاجتماعية) - 10 طرق لتجنّب هجمات الهندسة الاجتماعية - [Multiple Intel Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-intel-products-vulnerabilities-42) - Intel QAT Software Drivers could allow a local authenticated attacker to obtain sensitive information, - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-57) - IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files. - [ModiLoader aka DBatLoader - Active IOCs](https://rewterz.com/threat-advisory/modiloader-aka-dbatloader-active-iocs-2) - ModiLoader - aka DBatLoader or NatsoLoader - was initially identified in June 2020. - [MassLogger Malware - Active IOCs](https://rewterz.com/threat-advisory/masslogger-malware-active-iocs-17) - MassLogger, a .NET credential stealer, is a keylogger and stealer malware. MassLogger's prime objective is data extraction or information theft, such as bank account and/or credit card details. - [Multiple Apple Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apple-products-vulnerabilities-35) - Apple Compressor could allow an adjacent attacker on the same network as a Compressor server - [Multiple Apache HTTP Server Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apache-http-server-vulnerabilities-2) - Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes - [CVE-2025-46603 - Dell CloudBoost Virtual Appliance Vulnerability](https://rewterz.com/threat-advisory/cve-2025-46603-dell-cloudboost-virtual-appliance-vulnerability) - Refer to Dell Security Advisory for patch, upgrade, or suggested workaround information. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-56) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Cobalt Strike Malware - Active IOCs](https://rewterz.com/threat-advisory/cobalt-strike-malware-active-iocs-25) - Cobalt Strike first appeared in 2012 in response to alleged flaws in the Metasploit Framework, an existing red team (penetration testing) tool. - [Windows Remote Access Manager Bugs Enable Privilege Escalation](https://rewterz.com/threat-advisory/windows-remote-access-manager-bugs-enable-privilege-escalation) - Two significant privilege escalation vulnerabilities CVE-2025-62472 and CVE-2025-62474 were disclosed on December 9, 2025, - [Adobe Acrobat Reader Bugs Enable Code Execution](https://rewterz.com/threat-advisory/adobe-acrobat-reader-bugs-enable-code-execution) - Adobe has released critical security updates for Acrobat and Reader to address multiple vulnerabilities - [Google Alerts on Actively Exploited Chrome 0-Day Flaw](https://rewterz.com/threat-advisory/google-alerts-on-actively-exploited-chrome-0-day-flaw) - Google has urgently released a security update for the Chrome browser - [Windows Defender Firewall Flaw Allows Sensitive Data Exposure](https://rewterz.com/threat-advisory/windows-defender-firewall-flaw-allows-sensitive-data-exposure) - A critical information disclosure vulnerability, tracked as CVE-2025-62468, has been identified in the Windows Defender Firewall Service, - [Virtual SOC vs. On-Premise SOC: Which Model Fits Your Organisation?](https://rewterz.com/blog/virtual-soc-vs-on-premise-soc-which-model-fits-your-organisation) - Compare virtual and on-premise SOC models to determine which best aligns with your organisation’s security needs. Explore key benefits, differences, and risks. - [تطوّر هجمات فيروس الفدية: كيف تغيّرت التهديدات وكيف تستعد لها المؤسسات
](https://rewterz.com/ar/articles/تطوّر-هجمات-فيروس-الفدية-كيف-تغيّرت-ال) - Discover how ransomware is evolving and learn practical strategies to adapt your cybersecurity defenses against emerging attack techniques. - [Windows PowerShell Zero-Day Allows Remote Code Execution](https://rewterz.com/threat-advisory/windows-powershell-zero-day-allows-remote-code-execution) - A newly disclosed Windows PowerShell 0-day vulnerability, tracked as CVE-2025-54100, - [Outlook Vulnerability Enables Remote Code Execution Attacks](https://rewterz.com/threat-advisory/outlook-vulnerability-enables-remote-code-execution-attacks) - A critical remote code execution (RCE) vulnerability in Microsoft Outlook, tracked as CVE-2025-62562, - [CISA Warns of D-Link Router Buffer Overflow Attacks](https://rewterz.com/threat-advisory/cisa-warns-of-d-link-router-buffer-overflow-attacks) - A critical buffer overflow vulnerability, CVE-2022-37055, affecting multiple D-Link routers, - [Zoom Rooms Flaws Allow Privilege Escalation and Data Leaks](https://rewterz.com/threat-advisory/zoom-rooms-flaws-allow-privilege-escalation-and-data-leaks) - Zoom has disclosed two critical security vulnerabilities in its Zoom Rooms software for Windows and macOS, - [Critical Apache Tika Core Exploited via Malicious PDF Uploads](https://rewterz.com/threat-advisory/critical-apache-tika-core-exploited-via-malicious-pdf-uploads) - A critical security flaw has been discovered in Apache Tika, a widely used open-source toolkit for extracting text and metadata from documents - [Critical RSC Flaw in React and Next.js Enables Code Execution](https://rewterz.com/threat-advisory/critical-rsc-flaw-in-react-and-next-js-enables-code-execution) - A critical security vulnerability has been identified in React and Next.js that allows unauthenticated remote attackers - [Multiple D-Link Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-products-vulnerabilities-23) - A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. - [NVIDIA Triton Bug Enables DoS Attacks](https://rewterz.com/threat-advisory/nvidia-triton-bug-enables-dos-attacks) - NVIDIA has released critical security patches addressing two high-severity vulnerabilities in the Triton Inference Server - [FormBook Malware - Active IOCs](https://rewterz.com/threat-advisory/formbook-malware-active-iocs-30) - FormBook is an infostealer malware that was first identified in 2016. - [MeterPreter Malware - Active IOCs](https://rewterz.com/threat-advisory/meterpreter-malware-active-iocs-9) - Meterpreter - a trojan-type program - enables attackers to take control of affected machines remotely. - [Patchwork APT Group - Active IOCs](https://rewterz.com/threat-advisory/patchwork-apt-group-active-iocs-12) - Patchwork is an Advanced Persistent Threat (APT) group active since at least 2014. - [Multiple NVIDIA Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-products-vulnerabilities-8) - NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check - [Gafgyt aka Bashlite Malware - Active IOCs](https://rewterz.com/threat-advisory/gafgyt-aka-bashlite-malware-active-iocs-20) - Gafgyt is a type of malware that is used to conduct Distributed Denial of Service (DDoS) attacks. - [DarkTortilla Malware - Active IOCs](https://rewterz.com/threat-advisory/darktortilla-malware-active-iocs-6) - DarkTortilla is a highly obfuscated, .NET-based malware crypter active since at least 2015. - [Multiple Adobe Format Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-format-vulnerabilities) - Adobe Format Plugins is vulnerable to a denial of service, caused by a use-after-free error. - [Critical Elementor Flaw Lets Attackers Take Over WordPress Admin](https://rewterz.com/threat-advisory/critical-elementor-flaw-lets-attackers-take-over-wordpress-admin) - A critical security flaw in the popular King Addons for Elementor WordPress plugin - [Chrome 143 Fixes 13 Code Execution Flaws](https://rewterz.com/threat-advisory/chrome-143-fixes-13-code-execution-flaws) - Google has released Chrome version 143 to the Stable channel for Windows, - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-53) - Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. - [CoinMiner Malware - Active IOCs](https://rewterz.com/threat-advisory/coinminer-malware-active-iocs-16) - CoinMiner is a malware designed to secretly mine cryptocurrencies, such as Bitcoin, on infected computers. - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-96) - The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. - [Lazarus aka Hidden Cobra APT Group - Active IOCs](https://rewterz.com/threat-advisory/lazarus-aka-hidden-cobra-apt-group-active-iocs-16) - Lazarus APT, one of North Korea’s most sophisticated and well-funded threat actors, has been active since at least 2009. - [ICS: Multiple Siemens Products Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-siemens-products-vulnerabilities-32) - Refer to Siemens Security Advisory for patch, upgrade, or suggested workaround information. - [Stealc Information Stealer Malware - Active IOCs](https://rewterz.com/threat-advisory/stealc-information-stealer-malware-active-iocs-13) - Stealc is a new malware that was first marketed by an actor named Plymouth on the XSS and BHF Russian-speaking underground forums on January 9, 2023. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-55) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Multiple Apache Kvrocks Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apache-kvrocks-vulnerabilities) - Apache Kvrocks could allow a remote authenticated attacker to obtain plaintext credentials information, caused by a flaw in the MONITOR command. - [Donot APT Group Targeting Pakistan - Active IOCs](https://rewterz.com/threat-advisory/donot-apt-group-targeting-pakistan-active-iocs-3) - APT-C-35 (also known as "Donot APT Group") is a cyber espionage group that has been active since at least 2013. - [ICS: Mitsubishi Electric MILCO.S Control System Vulnerability](https://rewterz.com/threat-advisory/ics-mitsubishi-electric-milco-s-control-system-vulnerability) - Malicious code execution vulnerability via DLL hijacking exists in setting and operation application for lighting control system MILCO.S. - [LokiBot Malware - Active IOCs](https://rewterz.com/threat-advisory/lokibot-malware-active-iocs-20) - In early 2016, LokiBot was originally made available on underground forums for cybercriminals to use against Microsoft Android phones. - [Tofsee Malware - Active IOCs](https://rewterz.com/threat-advisory/tofsee-malware-active-iocs-4) - Tofsee malware has been around since 2016. Once installed on a compromised computer, - [Multiple Cisco Splunk Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-cisco-splunk-products-vulnerabilities-2) - Splunk Universal Forwarder for Windows could allow a remote authenticated attacker to access the directory and all its contents, - [Microsoft Fixes Windows LNK 0-Day Exploit](https://rewterz.com/threat-advisory/microsoft-fixes-windows-lnk-0-day-exploit) - Microsoft has quietly patched a long-standing Windows shortcut vulnerability, - [Windows Vim Flaw Allows Arbitrary Code Execution](https://rewterz.com/threat-advisory/windows-vim-flaw-allows-arbitrary-code-execution) - A critical vulnerability has been discovered in Vim for Windows, identified as CVE-2025-66476, - [Hackers Exploit WordPress Plugin Flaw for Remote Code Execution](https://rewterz.com/threat-advisory/hackers-exploit-wordpress-plugin-flaw-for-remote-code-execution) - A critical remote code execution (RCE) vulnerability has been identified in the Sneeit Framework WordPress plugin, - [Building a Cybersecurity Culture: Training Employees to Be the First Line of Defence](https://rewterz.com/blog/building-a-cybersecurity-culture-training-employees-to-be-the-first-line-of-defence) - Empower your workforce with cybersecurity awareness. Discover how training employees as the first line of defence helps build a resilient, secure culture. - [APT Group Gamaredon aka Shuckworm - Active IOCs](https://rewterz.com/threat-advisory/apt-group-gamaredon-aka-shuckworm-active-iocs-22) - Shuckworm APT - aka Actinium, Armageddon, Primitive Bear, Gamaredon, and Trident Ursa - has been a Russia-backed advanced persistent threat (APT)... - [APT37 aka ScarCruft or RedEyes - Active IOCs](https://rewterz.com/threat-advisory/apt37-aka-scarcruft-or-redeyes-active-iocs-9) - APT37, also known as ScarCruft or Red Eyes, is a North Korean state-sponsored espionage group active since at least 2012. - [Apache Struts Bug Enables Disk Exhaustion Attacks](https://rewterz.com/threat-advisory/apache-struts-bug-enables-disk-exhaustion-attacks) - A critical vulnerability has been discovered in Apache Struts, tracked as CVE-2025-64775, - [Google Fixes Actively Exploited Android 0-Day Vulnerabilities](https://rewterz.com/threat-advisory/google-fixes-actively-exploited-android-0-day-vulnerabilities) - In December 2025, Google released critical security updates addressing multiple zero-day vulnerabilities affecting Android devices worldwide. - [PoC Released for Critical Outlook Zero-Click RCE Flaw](https://rewterz.com/threat-advisory/poc-released-for-critical-outlook-zero-click-rce-flaw) - A public Proof-of-Concept (PoC) exploit has been released for the critical Microsoft Outlook RCE vulnerability - [Critical Apache bRPC Framework Bug Lets Attackers Crash Servers](https://rewterz.com/threat-advisory/critical-apache-brpc-framework-bug-lets-attackers-crash-servers) - A critical vulnerability, CVE‑2025‑59789, has been identified in the Apache bRPC framework, - [Multiple Adobe Substance Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-substance-vulnerabilities-6) - Adobe Substance 3D Stager could allow a remote attacker to execute arbitrary code on the system, - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-40) - Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. - [Multiple D-Link Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-products-vulnerabilities-22) - A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-46) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-59) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [NVIDIA DGX Spark Flaws Enable RCE and DoS Attacks](https://rewterz.com/threat-advisory/nvidia-dgx-spark-flaws-enable-rce-and-dos-attacks) - NVIDIA has released an urgent security update for its DGX Spark AI workstation after uncovering 14 firmware vulnerabilities - [GitLab Fixes Flaws Allowing Auth Bypass and DoS](https://rewterz.com/threat-advisory/gitlab-fixes-flaws-allowing-auth-bypass-and-dos) - GitLab has issued critical security updates for both its Community Edition (CE) and Enterprise Edition (EE), - [AI-Powered Cyberattacks: How Generative Models Are Changing the Threat Landscape](https://rewterz.com/blog/ai-powered-cyberattacks-how-generative-models-are-changing-the-threat-landscape) - Discover how generative AI is reshaping cyberattacks, enabling advanced phishing, malware automation, and faster threat evolution in today’s digital landscape. - [Patchwork APT Group - Active IOCs](https://rewterz.com/threat-advisory/patchwork-apt-group-active-iocs-11) - Patchwork is an Advanced Persistent Threat (APT) group active since at least 2014. - [Azure Bastion Flaw Enables Auth Bypass and Privilege Escalation](https://rewterz.com/threat-advisory/azure-bastion-flaw-enables-auth-bypass-and-privilege-escalation) - A newly disclosed critical vulnerability in Azure Bastion, tracked as CVE-2025-49752, - [مستويات نضج مركز عمليات الأمن (SOC): خطوات لتحسين الخدمة باستمرار](https://rewterz.com/ar/articles/مستويات-نضج-مركز-عمليات-الأمن-soc-خطوات-ل) - Steps for Continual Service Improvement - [Apache Syncope Flaw Exposes Internal Database Data](https://rewterz.com/threat-advisory/apache-syncope-flaw-exposes-internal-database-data) - recently disclosed vulnerability in Apache Syncope exposes organizations to a serious security risk - [Oracle Identity Manager RCE Bug Under Active Attack](https://rewterz.com/threat-advisory/oracle-identity-manager-rce-bug-under-active-attack) - A critical vulnerability has been disclosed in Oracle Identity Manager, specifically affecting the Oracle Identity Governance Suite 12c - [Update Health Tools Flaw Allows Remote Code Execution](https://rewterz.com/threat-advisory/update-health-tools-flaw-allows-remote-code-execution) - A critical remote code execution (RCE) vulnerability was discovered in Microsoft’s Update Health Tools (KB4023057) - [NVIDIA Isaac-GROOT Flaw Enables Malicious Code Injection](https://rewterz.com/threat-advisory/nvidia-isaac-groot-flaw-enables-malicious-code-injection) - NVIDIA has disclosed two critical code injection vulnerabilities affecting its Isaac-GROOT robotics platform - [2.3 Million Attacks Target Palo Alto GlobalProtect VPN](https://rewterz.com/threat-advisory/2-3-million-attacks-target-palo-alto-globalprotect-vpn) - Since November 14, 2025, Palo Alto Networks’ GlobalProtect VPN portals have been targeted by over 2.3 million malicious sessions - [Windows Graphics Bug Enables Instant Takeover](https://rewterz.com/threat-advisory/windows-graphics-bug-enables-instant-takeover) - A critical remote code execution vulnerability (CVE-2025-50165) in Microsoft’s Windows Graphics Component allows attackers to compromise systems - [Threat Actor Claim to Sell a Microsoft Office 0-Day RCE Exploit](https://rewterz.com/threat-advisory/threat-actor-claim-to-sell-a-microsoft-office-0-day-rce-exploit) - threat actor known as Zeroplayer has reportedly advertised a dangerous zero-day remote code execution (RCE) exploit - [SonicOS SSLVPN Flaw Allows Remote Attackers to Crash Firewalls](https://rewterz.com/threat-advisory/sonicos-sslvpn-flaw-allows-remote-attackers-to-crash-firewalls) - SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service, - [Cloud Security Unification: Streamlining Protection Across Platforms](https://rewterz.com/blog/cloud-security-unification-streamlining-protection-across-platforms) - Enhance cloud protection with unified security, centralized visibility, and simplified management across multi-cloud environments. - [Massive WhatsApp Flaw Leaks Phone Numbers of 3.5 Billion Users](https://rewterz.com/threat-advisory/massive-whatsapp-flaw-leaks-phone-numbers-of-3-5-billion-users) - A newly uncovered critical flaw in WhatsApp’s contact discovery feature has exposed the phone numbers of 3.5 billion users - [D-Link EoL/EoS Routers Vulnerable to Remote Code Execution](https://rewterz.com/threat-advisory/d-link-eol-eos-routers-vulnerable-to-remote-code-execution) - D-Link DIR-878 routers are affected by multiple critical vulnerabilities across all models and firmware versions. - [Critical SolarWinds Serv-U Flaws Allow Remote Admin Code Execution](https://rewterz.com/threat-advisory/critical-solarwinds-serv-u-flaws-allow-remote-admin-code-execution) - SolarWinds has released security patches addressing three critical remote code execution (RCE) vulnerabilities in its Serv-U file transfer software, - [CISA Warns of Active FortiWeb Command Injection Exploit](https://rewterz.com/threat-advisory/cisa-warns-of-active-fortiweb-command-injection-exploit) - The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a critical vulnerability in Fortinet FortiWeb appliances - [Iranian SpearSpecter Deploys Targeted Social Engineering](https://rewterz.com/threat-advisory/iranian-spearspecter-deploys-targeted-social-engineering) - A highly sophisticated espionage operation known as SpearSpecter is actively targeting senior government and defense officials worldwide. - [Active Exploitation of Chrome Type Confusion Zero-Day Vulnerability](https://rewterz.com/threat-advisory/active-exploitation-of-chrome-type-confusion-zero-day-vulnerability) - Google has urgently released a critical security update for its Chrome browser after discovering a zero-day vulnerability actively exploited in the wild. - [FortiWeb WAF Admin Takeover Exploit Active in the Wild](https://rewterz.com/threat-advisory/fortiweb-waf-admin-takeover-exploit-active-in-the-wild) - Fortinet has issued an urgent advisory for a critical vulnerability (CVE-2025-64446) in its FortiWeb web application firewall (WAF) product, - [Severe RCE Bugs Hit Leading AI Engines](https://rewterz.com/threat-advisory/severe-rce-bugs-hit-leading-ai-engines) - researchers’ discovery of multiple high-severity Remote Code Execution (RCE) vulnerabilities across major AI frameworks from Meta, NVIDIA, Microsoft, - [Zoom Flaws Allow Access-Control Bypass](https://rewterz.com/threat-advisory/zoom-flaws-allow-access-control-bypass) - Zoom has released a new wave of security bulletins addressing multiple vulnerabilities across its Workplace applications for Android, Windows, macOS, and VDI clients. - [CVE-2025-7429 - Zohocorp ManageEngine Exchange Reporter Plus Vulnerability](https://rewterz.com/threat-advisory/cve-2025-7429-zohocorp-manageengine-exchange-reporter-plus-vulnerability) - Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report. - [CVE-2025-43723 - Dell PowerScale OneFS Vulnerability](https://rewterz.com/threat-advisory/cve-2025-43723-dell-powerscale-onefs-vulnerability) - Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, - [AsyncRAT - Active IOCs](https://rewterz.com/threat-advisory/asyncrat-active-iocs-25) - AsyncRAT is an open-source tool designed for remote monitoring via encrypted connections. - [MeterPreter Malware - Active IOCs](https://rewterz.com/threat-advisory/meterpreter-malware-active-iocs-8) - Meterpreter - a trojan-type program - enables attackers to take control of affected machines remotely. - [Multiple Adobe Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-products-vulnerabilities-41) - Adobe Experience Manager Screens is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-52) - Google Chrome could allow a remote attacker to bypass security restrictions, caused by inappropriate implementation in Permissions. - [An Emerging Ducktail Infostealer - Active IOCs](https://rewterz.com/threat-advisory/an-emerging-ducktail-infostealer-active-iocs-49) - Ducktail Infostealer is a malicious program designed by hackers to infiltrate computers and networks globally which is delivered through a spear-phishing email. - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-45) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-58) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [FortiWeb Auth Bypass Flaw Actively Exploited](https://rewterz.com/threat-advisory/fortiweb-auth-bypass-flaw-actively-exploited) - Threat actors are actively exploiting a critical authentication bypass vulnerability in Fortinet’s FortiWeb Web Application Firewall (CVE-2025-52970), - [Critical ASP.NET Core Vulnerability Patched by Microsoft](https://rewterz.com/threat-advisory/critical-asp-net-core-vulnerability-patched-by-microsoft) - Microsoft has released a critical security advisory addressing a high-severity vulnerability in ASP.NET Core, - [Apache OpenOffice Flaws Allow Memory Corruption and Content Loading](https://rewterz.com/threat-advisory/apache-openoffice-flaws-allow-memory-corruption-and-content-loading) - Apache OpenOffice has released version 4.1.16, addressing seven critical security vulnerabilities - [How MSSPs Can Strengthen Security Posture with Threat Hunting Services](https://rewterz.com/blog/how-mssps-can-strengthen-security-posture-with-threat-hunting-services) - Learn how MSSPs use proactive threat hunting to improve security posture, detect hidden threats, and reduce cyber risks effectively. - [Windows Remote Desktop Services Flaw Lets Attackers Escalate Privileges](https://rewterz.com/threat-advisory/windows-remote-desktop-services-flaw-lets-attackers-escalate-privileges) - Microsoft has disclosed a newly identified vulnerability in Windows Remote Desktop Services (RDS), tracked as CVE-2025-60703, - [Threat Actors Target Outlook and Google, Outsmarting Conventional Email Security](https://rewterz.com/threat-advisory/threat-actors-target-outlook-and-google-outsmarting-conventional-email-security) - Microsoft Outlook and Google Gmail. Analysis of 1.8 billion emails by Security researchers revealed a 13% year-over-year increase in malicious messages, - [نموذج نضج مركز العمليات الأمنية: أين تقف منظمتك؟](https://rewterz.com/ar/articles/نموذج-نضج-مركز-العمليات-الأمنية-أين-تق) - ولكن مع تنوّع الخيارات المتاحة، كيف يمكنك اختيار المنصة الأنسب لاستخبارات التهديدات التي تلبي احتياجاتك؟ في هذه المدونة، سنستعرض أهم الأسئلة التي يجب طرحها عند تقييم هذه المنصات. - [دور الذكاء الاصطناعي في الاستجابة التلقائية للحوادث الأمنية](https://rewterz.com/ar/articles/دور-الذكاء-الاصطناعي-في-الاستجابة-الت) - Discover how AI is transforming automated incident response by enhancing threat detection, reducing response time, and improving cybersecurity resilience. - [تحسين إدارة الثغرات عبر تكامل XDR](https://rewterz.com/ar/articles/تحسين-إدارة-الثغرات-عبر-تكامل-xdr) - Enhance your vulnerability management by integrating XDR for real-time threat detection, prioritization, and faster response. - [بناء مركز عمليات أمنية (SOC) فعّال من الصفر](https://rewterz.com/ar/articles/بناء-مركز-عمليات-أمنية-soc-فعّال-من-الصفر) - Learn how to build an effective SOC from the ground up. This guide covers planning, tools, staffing, and best practices for robust cybersecurity. - [كيف تحمي عبء العمل السحابي في عصر التهديدات المتزايدة.](https://rewterz.com/ar/articles/كيف-تحمي-عبء-العمل-السحابي-في-عصر-التهد) - Essential factors to consider when securing cloud workloads. From access control to compliance, explore best practices to strengthen cloud security posture. - [Multiple IBM Db2 Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-db2-vulnerabilities-4) - IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, - [Elastic Defend Vulnerability Allows Windows Privilege Escalation](https://rewterz.com/threat-advisory/elastic-defend-vulnerability-allows-windows-privilege-escalation) - Elastic has disclosed a high-severity vulnerability (CVE-2025-37735) in Elastic Defend for Windows, - [أفضل الممارسات لدمج XDR في عمليات الأمن السيبراني](https://rewterz.com/ar/articles/أفضل-الممارسات-لدمج-xdr-في-عمليات-الأمن-ا) - Discover expert-recommended best practices for integrating Extended Detection and Response (XDR) into your security operations. Learn how Rewterz helps streamline threat detection, response, and incident management. - [Multiple Adobe Substance Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-substance-vulnerabilities-5) - Adobe Substance 3D Modeler could allow a remote attacker to execute arbitrary code on the system, - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-39) - Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network. - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-51) - Google Chrome could allow a remote attacker to bypass security restrictions, caused by inappropriate implementation in V8. - [DarkTortilla Malware - Active IOCs](https://rewterz.com/threat-advisory/darktortilla-malware-active-iocs-5) - DarkTortilla is a highly obfuscated, .NET-based malware crypter active since at least 2015. - [Lumma Stealer Malware aka LummaC - Active IOCs](https://rewterz.com/threat-advisory/lumma-stealer-malware-aka-lummac-active-iocs-25) - Lumma is an information stealer that is sold as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums and Telegram. - [Multiple Dell Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-dell-products-vulnerabilities-16) - Dell CloudLink could allow a remote authenticated attacker to execute arbitrary commands on the system, - [Multiple NVIDIA Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-products-vulnerabilities-7) - NVIDIA NVApp could allow a local authenticated attacker to gain elevated privileges - [Qilin Ransomware: Rising Threat and HBZ Breach Claim - Active IOCs](https://rewterz.com/threat-advisory/qilin-ransomware-rising-threat-and-hbz-breach-claim-active-iocs) - Qilin ransomware, formerly known as Agenda, is a Russian-speaking ransomware-as-a-service (RaaS) operation that surfaced in July 2022. - [FormBook Malware - Active IOCs](https://rewterz.com/threat-advisory/formbook-malware-active-iocs-29) - FormBook is an infostealer malware that was first identified in 2016. - [CoinMiner Malware - Active IOCs](https://rewterz.com/threat-advisory/coinminer-malware-active-iocs-15) - CoinMiner is a malware designed to secretly mine cryptocurrencies, such as Bitcoin, on infected computers. - [خدمات الأمن المُدارة كحل لنقص مهارات الأمن السيبراني](https://rewterz.com/ar/articles/خدمات-الأمن-المُدارة-كحل-لنقص-مهارات-ا) - Learn how managed security services help solve the cybersecurity skills shortage by providing expert threat monitoring and response. - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-95) - The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation - [ICS: Multiple Fuji Electric Monitouch V-SFT-6 Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-fuji-electric-monitouch-v-sft-6-vulnerabilities) - Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted project file, - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-38) - Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-54) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [GuLoader Malspam Campaign - Active IOCs](https://rewterz.com/threat-advisory/guloader-malspam-campaign-active-iocs-17) - Since 2019, Guloader has been in operation as a downloader. GuLoader spreads through spam campaigns with malicious archived attachments. - [Multiple Adobe Illustrator Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-illustrator-vulnerabilities-2) - Adobe Illustrator could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write error. - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-37) - Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally. - [Gh0st RAT - Active IOCs](https://rewterz.com/threat-advisory/gh0st-rat-active-iocs-9) - Gh0st RAT is a remote access trojan (RAT) that was first discovered in 2008. - [Stealc Information Stealer Malware - Active IOCs](https://rewterz.com/threat-advisory/stealc-information-stealer-malware-active-iocs-12) - Stealc is a new malware that was first marketed by an actor named Plymouth on the XSS and BHF Russian-speaking underground forums on January 9, 2023. - [Multiple Adobe Substance Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-substance-vulnerabilities-4) - Adobe Substance 3D Modeler could allow a remote attacker to execute arbitrary code on the system, - [CVE-2025-40603 - SonicWall SMA100 Series Appliances Vulnerability](https://rewterz.com/threat-advisory/cve-2025-40603-sonicwall-sma100-series-appliances-vulnerability) - A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-36) - Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. - [Lumma Stealer Malware aka LummaC - Active IOCs](https://rewterz.com/threat-advisory/lumma-stealer-malware-aka-lummac-active-iocs-24) - Lumma is an information stealer that is sold as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums and Telegram. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-57) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [كيف يمكن للمؤسسات تقليل تكاليف الأمن السيبراني من خلال تحسين أنظمة SIEM](https://rewterz.com/ar/articles/كيف-يمكن-للمؤسسات-تقليل-تكاليف-الأمن-ا) - How Businesses Can Reduce Cybersecurity Costs Through SIEM Optimization - [Windows Cloud Files Mini-Filter Driver Flaw Used to Elevate Privileges](https://rewterz.com/threat-advisory/windows-cloud-files-mini-filter-driver-flaw-used-to-elevate-privileges) - A newly disclosed high-severity privilege-escalation bug (CVE-2025-55680, CVSS High) affects the Windows Cloud Files Mini Filter Driver (cldsync.sys). - [15 Malicious npm Packages Deliver Vidar Malware to Windows Systems - Active IOCs](https://rewterz.com/threat-advisory/15-malicious-npm-packages-deliver-vidar-malware-to-windows-systems-active-iocs) - A sophisticated supply-chain attack has surfaced targeting Windows systems through compromised npm packages, - [التطور الجوهري للكشف والاستجابة في بيئات السحابة](https://rewterz.com/ar/articles/التطور-الجوهري-للكشف-والاستجابة-في-بي) - Explore how cloud detection and response strategies have evolved to meet modern security challenges in dynamic, multi-cloud environments. - [The Role of MSSPs in Achieving Cybersecurity Compliance Across Industries](https://rewterz.com/blog/the-role-of-mssps-in-achieving-cybersecurity-compliance-across-industries) - Discover how MSSPs help industries meet cybersecurity compliance standards and protect against evolving threats effectively. - [Hackers Exploit Cisco ASA and FTD Zero-Day RCE flaw](https://rewterz.com/threat-advisory/hackers-exploit-cisco-asa-and-ftd-zero-day-rce-flaw) - Cisco has issued an urgent warning after confirming that threat actors are actively exploiting a critical remote code execution (RCE) vulnerability, - [Cl0p Exploits New Zero-Day Flaws - Active IOCs](https://rewterz.com/threat-advisory/cl0p-exploits-new-zero-day-flaws-active-iocs) - Cl0p, an infamous ransomware group active since early 2019, has cemented its reputation as one of the most formidable cyber threats worldwide. - [كيف يمكن لـ MDR تعزيز استثمارك في SIEM](https://rewterz.com/ar/articles/كيف-يمكن-لـ-mdr-تعزيز-استثمارك-في-siem) - Discover how MDR services enhance your SIEM investment by improving threat detection, response, and overall efficiency. - [تحسين أداء مراكز عمليات الأمن (SOC) من خلال الأتمتة المدعومة بتقنية XDR](https://rewterz.com/ar/articles/تحسين-أداء-مراكز-عمليات-الأمن-soc-من-خلال) - Discover how XDR-driven automation enhances SOC efficiency, streamlines threat detection, and reduces response times for stronger cybersecurity operations. - [WordPress Post SMTP Flaw Puts 400,000 Sites at Risk of Account Takeovers](https://rewterz.com/threat-advisory/wordpress-post-smtp-flaw-puts-400000-sites-at-risk-of-account-takeovers) - A critical flaw (CVE-2025-11833, CVSS high) in the popular Post SMTP WordPress plugin exposed email logs on more than 400,000 sites, - [Hackers Exploit OneDrive via DLL Sideloading to Run Malicious Code](https://rewterz.com/threat-advisory/hackers-exploit-onedrive-via-dll-sideloading-to-run-malicious-code) - A highly sophisticated DLL sideloading campaign targets Microsoft OneDrive by placing a weaponized version.dll alongside OneDrive.exe, - [Kimsuky and Lazarus Deploy New Backdoor and Remote-Access Toolkits - Active IOCs](https://rewterz.com/threat-advisory/kimsuky-and-lazarus-deploy-new-backdoor-and-remote-access-toolkits-active-iocs) - Two of the regime’s most prominent APT groups, Kimsuky and Lazarus, - [Apple Releases iOS 26.1 and iPadOS 26.1 Updates to Fix Critical Security Flaws](https://rewterz.com/threat-advisory/apple-releases-ios-26-1-and-ipados-26-1-updates-to-fix-critical-security-flaws) - Apple has released iOS 26.1 and iPadOS 26.1, addressing over 50 critical vulnerabilities that could lead to privacy breaches, - [Multiple Adobe Framemaker Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-framemaker-vulnerabilities-4) - Adobe Framemaker is vulnerable to a heap-based buffer overflow. - [Ubuntu Kernel Vulnerability Enables Privilege Escalation to Root](https://rewterz.com/threat-advisory/ubuntu-kernel-vulnerability-enables-privilege-escalation-to-root) - Researcher released a fix that brings the Ubuntu kernel fully in line with the upstream refcounting fixes; - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-35) - Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-56) - IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. - [GCleaner Malware - Active IOCs](https://rewterz.com/threat-advisory/gcleaner-malware-active-iocs-5) - GCleaner is a type of malware that disguises itself as a legitimate software program called "GCleaner" or "G-Cleaner." - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-44) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [CISA Warns of Linux Kernel Flaw Exploited for Ransomware Attacks](https://rewterz.com/threat-advisory/cisa-warns-of-linux-kernel-flaw-exploited-for-ransomware-attacks) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical use-after-free vulnerability in the Linux kernel, - [Windows Graphics Flaws Enable Remote Arbitrary Code Execution](https://rewterz.com/threat-advisory/windows-graphics-flaws-enable-remote-arbitrary-code-execution) - Multiple high-severity vulnerabilities have been uncovered in Microsoft’s Graphics Device Interface (GDI), - [Gunra Ransomware: Dual-Encryption Attacks on Windows and Linux - Active IOCs](https://rewterz.com/threat-advisory/gunra-ransomware-dual-encryption-attacks-on-windows-and-linux-active-iocs) - Gunra ransomware, first detected in April 2025, has rapidly evolved into a major global threat, - [Apache Tomcat RCE Flaws Expose Servers](https://rewterz.com/threat-advisory/apache-tomcat-rce-flaws-expose-servers) - The Apache Software Foundation has disclosed two critical vulnerabilities in Apache Tomcat, - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-34) - Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. - [STRRAT Malware - Active IOCs](https://rewterz.com/threat-advisory/strrat-malware-active-iocs-9) - STRRat is a Java-based Remote-Access Trojan (RAT) with a slew of malicious features, notably information theft and backdoor capabilities. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-53) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Multiple Adobe Dimension Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-dimension-vulnerabilities) - Adobe Dimension could allow a remote attacker to execute arbitrary code on the system, - [Major Adobe Magento RCE Flaw Being Exploited 60% of Stores at Risk](https://rewterz.com/threat-advisory/major-adobe-magento-rce-flaw-being-exploited-60-of-stores-at-risk) - Hackers are actively exploiting a critical remote code execution flaw in Adobe Commerce / Magento Open Source dubbed SessionReaper - [Multiple F5 Networks Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-f5-networks-products-vulnerabilities-3) - F5 BIG-IP is vulnerable to a denial of service, caused by a double free flaw. - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-33) - Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. - [DarkTortilla Malware - Active IOCs](https://rewterz.com/threat-advisory/darktortilla-malware-active-iocs-4) - DarkTortilla is a highly obfuscated, .NET-based malware crypter active since at least 2015. - [Gafgyt aka Bashlite Malware - Active IOCs](https://rewterz.com/threat-advisory/gafgyt-aka-bashlite-malware-active-iocs-19) - Gafgyt is a type of malware that is used to conduct Distributed Denial of Service (DDoS) attacks. - [Multiple Apache Tomcat Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apache-tomcat-vulnerabilities-3) - Apache Tomcat is vulnerable to a denial of service, caused by not clean up temporary copies of the uploaded parts written to disc immediately. - [Multiple IBM QRadar SIEM Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-qradar-siem-vulnerabilities-2) - IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-32) - Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally. - [Lumma Stealer Malware aka LummaC - Active IOCs](https://rewterz.com/threat-advisory/lumma-stealer-malware-aka-lummac-active-iocs-23) - Lumma is an information stealer that is sold as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums and Telegram. - [Snake Keylogger Malware - Active IOCs](https://rewterz.com/threat-advisory/snake-keylogger-malware-active-iocs-21) - Snake is a modular .NET keylogger that was first spotted in late November 2020. Snake malware's main feature is keylogging, but it also has additional capabilities such as taking screenshots and extracting data from the clipboard. - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-55) - Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. - [SideWinder APT Group aka Rattlesnake Targeting Pakistan – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-targeting-pakistan-active-iocs-21) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [CoinMiner Malware - Active IOCs](https://rewterz.com/threat-advisory/coinminer-malware-active-iocs-14) - CoinMiner is a malware designed to secretly mine cryptocurrencies, such as Bitcoin, on infected computers. - [AsyncRAT - Active IOCs](https://rewterz.com/threat-advisory/asyncrat-active-iocs-24) - AsyncRAT is an open-source tool designed for remote monitoring via encrypted connections. - [Critical Dell Storage Manager Flaws Allow Full System Compromise](https://rewterz.com/threat-advisory/critical-dell-storage-manager-flaws-allow-full-system-compromise) - Dell Technologies has disclosed three critical vulnerabilities in its Storage Manager (DSM) software that expose organizations to severe security risks, - [Windows Narrator DLL Hijack Enables Stealthy Persistence and Lateral Movement](https://rewterz.com/threat-advisory/windows-narrator-dll-hijack-enables-stealthy-persistence-and-lateral-movement) - A long-standing DLL-hijack vulnerability in Windows’ Narrator accessibility tool enables attackers to execute code stealthily by abusing how Narrator loads speech engine DLLs. - [Active Directory Compromise via Misconfigured Domain-Join Accounts](https://rewterz.com/threat-advisory/active-directory-compromise-via-misconfigured-domain-join-accounts) - Active Directory (AD) domain join accounts, used to add computers to a domain, have become a major source of enterprise compromise. - [Invisible-Character MIME Phishing Attack](https://rewterz.com/threat-advisory/invisible-character-mime-phishing-attack) - a highly sophisticated phishing technique that leverages invisible Unicode characters, - [The Importance of Continuous Network Monitoring: Why MSSPs Should Provide 24/7 Oversight](https://rewterz.com/blog/the-importance-of-continuous-network-monitoring-why-mssps-should-provide-24-7-oversight) - Learn why MSSPs must offer continuous 24/7 network monitoring to ensure security, uptime, and threat prevention. - [Oracle VirtualBox Zero-Days Enable Full Control of Host Machines](https://rewterz.com/threat-advisory/oracle-virtualbox-zero-days-enable-full-control-of-host-machines) - Oracle’s October 2025 Critical Patch Update has revealed nine critical vulnerabilities within Oracle VM VirtualBox’s Core component, - [CISA Warns of Active Exploitation of Windows Server Update Services RCE Flaw](https://rewterz.com/threat-advisory/cisa-warns-of-active-exploitation-of-windows-server-update-services-rce-flaw) - (CISA) has issued an urgent alert regarding a critical vulnerability, tracked as CVE-2022-48503, affecting multiple Apple products - [Agent Tesla Malware - Active IOCs](https://rewterz.com/threat-advisory/agent-tesla-malware-active-iocs-20) - Agent Tesla is a very popular spyware Trojan built for the .NET framework which has been deployed in many forms, most notably via phishing attempts. - [Multiple Mozilla Firefox Vulnerabilities](https://rewterz.com/threat-advisory/multiple-mozilla-firefox-vulnerabilities-15) - Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, - [Multiple Adobe Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-products-vulnerabilities-40) - Adobe Connect is vulnerable to a DOM-based cross-site scripting, caused by improper validation of user-supplied input. - [GitLab Flaws Allow Attackers to Cause DoS](https://rewterz.com/threat-advisory/gitlab-flaws-allow-attackers-to-cause-dos) - GitLab has urgently released security patches for its Community Edition (CE) and Enterprise Edition (EE) - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-54) - Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. - [Multiple F5 Networks Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-f5-networks-products-vulnerabilities-2) - F5 BIG-IP is vulnerable to a denial of service, caused by incorrect control flow scoping. - [Multiple NVIDIA Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-products-vulnerabilities-6) - NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-52) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-43) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [Multiple Oracle Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-oracle-products-vulnerabilities-23) - An unspecified vulnerability in Oracle WebLogic Server related to the Core component could allow a local attacker to cause high availability impact. - [Multiple Atlassian Jira Align Vulnerabilities](https://rewterz.com/threat-advisory/multiple-atlassian-jira-align-vulnerabilities) - Jira Align is vulnerable to an authorization issue. - [Multiple Microsoft Excel Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-excel-vulnerabilities-3) - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. - [Cobalt Strike Malware - Active IOCs](https://rewterz.com/threat-advisory/cobalt-strike-malware-active-iocs-24) - Cobalt Strike first appeared in 2012 in response to alleged flaws in the Metasploit Framework, an existing red team (penetration testing) tool. - [Rhadamanthys Stealer - Active IOCs](https://rewterz.com/threat-advisory/rhadamanthys-stealer-active-iocs-14) - Rhadamanthys is a type of malware known as a stealer, which is designed to steal sensitive information from infected computers. - [Multiple Adobe Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-products-vulnerabilities-39) - Adobe Bridge is vulnerable to a heap-based buffer overflow. - [Multiple GitLab Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-gitlab-products-vulnerabilities-21) - GitLab is vulnerable to a denial of service, caused by allocation of resources without limits or throttling. - [North Korea-Linked Konni APT Group - Active IOCs](https://rewterz.com/threat-advisory/north-korea-linked-konni-apt-group-active-iocs-18) - The Konni APT (Advanced Persistent Threat) group has been a cyber espionage group since at least 2014. - [Multiple F5 BIG-IP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-f5-big-ip-products-vulnerabilities-10) - F5 BIG-IP could allow a remote attacker to bypass security restrictions, caused by predictability problems. - [Multiple Zohocorp ManageEngine Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-zohocorp-manageengine-products-vulnerabilities) - Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. - [MeterPreter Malware - Active IOCs](https://rewterz.com/threat-advisory/meterpreter-malware-active-iocs-7) - Meterpreter - a trojan-type program - enables attackers to take control of affected machines remotely. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-56) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Multiple D-Link Nuclias Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-nuclias-vulnerabilities) - D-Link Nuclias Connect could allow a remote attacker to obtain sensitive information due to an observable response discrepancy vulnerability - [Multiple F5 BIG-IP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-f5-big-ip-products-vulnerabilities-9) - F5 BIG-IP is vulnerable to reflected cross-site scripting, caused by improper validation of user-supplied input - [Multiple Zyxel Networks Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-zyxel-networks-products-vulnerabilities) - A missing authorization vulnerability in Zyxel ATP series firmware versions - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-53) - Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network. - [CoinMiner Malware - Active IOCs](https://rewterz.com/threat-advisory/coinminer-malware-active-iocs-13) - CoinMiner is a malware designed to secretly mine cryptocurrencies, such as Bitcoin, on infected computers. - [MassLogger Malware - Active IOCs](https://rewterz.com/threat-advisory/masslogger-malware-active-iocs-16) - MassLogger, a .NET credential stealer, is a keylogger and stealer malware. MassLogger's prime objective is data extraction or information theft, such as bank account and/or credit card details. - [Multiple F5 BIG-IP Vulnerabilities](https://rewterz.com/threat-advisory/multiple-f5-big-ip-vulnerabilities) - F5 BIG-IP is vulnerable to a denial of service, caused by an unchecked return value flaw - [ICS: Multiple Rockwell Automation Products Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-rockwell-automation-products-vulnerabilities-7) - Rockwell Automation Comms - 1783-NATR is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-52) - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. - [Remcos RAT - Active IOCs](https://rewterz.com/threat-advisory/remcos-rat-active-iocs-27) - Remcos malware has been operating since 2016. This RAT was originally promoted as genuine software for remote control of Microsoft Windows from XP onwards and is frequently found in phishing attempts due to its capacity to completely infect an afflicted machine. - [DarkTortilla Malware - Active IOCs](https://rewterz.com/threat-advisory/darktortilla-malware-active-iocs-3) - DarkTortilla is a highly obfuscated, .NET-based malware crypter active since at least 2015. - [Chrome V8 Zero-Day Lets Attackers Run Remote Code](https://rewterz.com/threat-advisory/chrome-v8-zero-day-lets-attackers-run-remote-code) - Google has urgently patched a high-severity vulnerability in its Chrome browser, identified as CVE-2025-12036, impacting the V8 - [Oracle EBS Marketing Flaw Enables Full Attacker Access](https://rewterz.com/threat-advisory/oracle-ebs-marketing-flaw-enables-full-attacker-access) - Oracle has disclosed two critical vulnerabilities CVE-2025-53072 and CVE-2025-6248 affecting the Marketing Administration component of its E-Business Suite. - [Insider Threats: How MSSPs Can Help Identify and Prevent Employee-Based Security Risks](https://rewterz.com/blog/insider-threats-how-mssps-can-help-identify-and-prevent-employee-based-security-risks) - Learn how MSSPs help detect and stop insider threats. Protect your data and reduce employee-based security risks with Rewterz. - [تحقيق أقصى عائد من استثمارات ROI و XDR](https://rewterz.com/ar/articles/تحقيق-أقصى-عائد-من-استثمارات-roi-و-xdr) - Learn how managed security services help solve the cybersecurity skills shortage by providing expert threat monitoring and response. - [Azure Flaw Enables Fake Microsoft Teams Apps](https://rewterz.com/threat-advisory/azure-flaw-enables-fake-microsoft-teams-apps) - Security researchers uncovered critical flaws in Microsoft’s Azure ecosystem that allowed attackers to create deceptive applications - [CISA Warns of Actively Exploited Apple OS Vulnerabilities](https://rewterz.com/threat-advisory/cisa-warns-of-actively-exploited-apple-os-vulnerabilities) - (CISA) has issued an urgent alert regarding a critical vulnerability, tracked as CVE-2022-48503, affecting multiple Apple products - [Microsoft 365 Copilot Prompt Injection Flaw Enables Data Theft](https://rewterz.com/threat-advisory/microsoft-365-copilot-prompt-injection-flaw-enables-data-theft) - A sophisticated vulnerability in Microsoft 365 Copilot enabled attackers to stealthily exfiltrate sensitive tenant data including recent corporate emails - [Attackers Flood RDP Services with 30,000 New IPs Daily](https://rewterz.com/threat-advisory/attackers-flood-rdp-services-with-30000-new-ips-daily) - A large-scale and persistent cyber campaign is actively targeting Microsoft Remote Desktop Protocol (RDP) services, deploying over 30,000 new IP addresses daily - [131 Malicious WhatsApp Extensions Discovered on Chrome Web Store - Active IOCs](https://rewterz.com/threat-advisory/131-malicious-whatsapp-extensions-discovered-on-chrome-web-store-active-iocs) - The extensions work by injecting custom JavaScript into the WhatsApp Web interface to automate message delivery without user consent. - [Multiple Fortinet FortiOS Vulnerabilities](https://rewterz.com/threat-advisory/multiple-fortinet-fortios-vulnerabilities) - Fortinet FortiOS is vulnerable to a heap-based buffer overflow, caused by Null pointer dereference. - [Multiple Adobe Substance Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-substance-vulnerabilities-3) - Adobe Substance 3D Stager could allow a remote attacker to execute arbitrary code on the system - [Linux-PAM PoC Enables Root Escalation](https://rewterz.com/threat-advisory/linux-pam-poc-enables-root-escalation) - Cisco has issued a security advisory, published on October 15, 2025, warning of multiple vulnerabilities affecting its Desk Phone 9800 Series, - [Cisco Desk and IP Phones Exposed to Remote DoS and XSS Attacks](https://rewterz.com/threat-advisory/cisco-desk-and-ip-phones-exposed-to-remote-dos-and-xss-attacks) - Cisco has issued a security advisory, published on October 15, 2025, warning of multiple vulnerabilities affecting its Desk Phone 9800 Series, - [Cisco IOS and IOS XE Flaws Allow Remote Code Execution by Attackers](https://rewterz.com/threat-advisory/cisco-ios-and-ios-xe-flaws-allow-remote-code-execution-by-attackers) - Cisco has revealed a critical vulnerability in its IOS and IOS XE Software - [Multiple Microsoft Azure and Copilot Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-azure-and-copilot-vulnerabilities) - Azure Entra ID Elevation of Privilege Vulnerability - [ICS: Multiple Rockwell Automation Products Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-rockwell-automation-products-vulnerabilities-6) - Rockwell Automation PanelView Plus 7 Performance Series B could allow a remote authenticated attacker to bypass security restrictions, - [GuLoader Malspam Campaign - Active IOCs](https://rewterz.com/threat-advisory/guloader-malspam-campaign-active-iocs-16) - Since 2019, Guloader has been in operation as a downloader. GuLoader spreads through spam campaigns with malicious archived attachments. - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-42) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [Multiple F5 Networks Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-f5-networks-products-vulnerabilities) - F5 F5OS-A and F5OS-C could allow a local authenticated attacker to gain elevated privileges on the system, caused by an Eval injection flaw. - [Multiple Cisco Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-cisco-products-vulnerabilities-28) - Cisco IOS XE Software is vulnerable to a denial of service, caused by improper handling of crafted Ethernet frames. - [CVE-2025-11756 - Google Chrome Vulnerability](https://rewterz.com/threat-advisory/cve-2025-11756-google-chrome-vulnerability) - Google Chrome could allow a remote attacker to execute arbitrary code on the system, - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-55) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-51) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Windows Remote Access Connection Manager 0-day exploited](https://rewterz.com/threat-advisory/windows-remote-access-connection-manager-0-day-exploited) - Microsoft has confirmed active exploitation of a critical zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service - [Windows RDP Client RCE Vulnerability](https://rewterz.com/threat-advisory/windows-rdp-client-rce-vulnerability) - Microsoft has released a critical security patch for its Remote Desktop Client to address a severe vulnerability - [Windows Agere Modem Driver Zero-Day Escalates Privileges](https://rewterz.com/threat-advisory/windows-agere-modem-driver-zero-day-escalates-privileges) - Microsoft has disclosed two critical zero-day vulnerabilities in the Windows Agere Modem driver - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-94) - The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. - [New ChaosBot Leverages AD Credentials via Cisco VPN for Network Control - Active IOCs](https://rewterz.com/threat-advisory/new-chaosbot-leverages-ad-credentials-via-cisco-vpn-for-network-control-active-iocs) - ChaosBot is a modern, Rust-based backdoor that emerged in late September 2025 - [Multiple Oracle E-Business Vulnerabilities](https://rewterz.com/threat-advisory/multiple-oracle-e-business-vulnerabilities) - Oracle E-Business Suite could allow a remote attacker to obtain critical data information, - [Ivanti Patches 13 Endpoint Manager RCE Flaws](https://rewterz.com/threat-advisory/ivanti-patches-13-endpoint-manager-rce-flaws) - Ivanti has revealed 13 security vulnerabilities in its Endpoint Manager (EPM) software, - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-55) - IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, - [Multiple NVIDIA Display Driver Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-display-driver-vulnerabilities) - NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of service, - [FormBook Malware - Active IOCs](https://rewterz.com/threat-advisory/formbook-malware-active-iocs-28) - FormBook is an infostealer malware that was first identified in 2016. - [Quasar RAT aka CinaRAT - Active IOCs](https://rewterz.com/threat-advisory/quasar-rat-aka-cinarat-active-iocs-18) - Quasar malware is a Remote Access Trojan (RAT) that is often abused by cybercriminals to take remote control over users' computers for malicious purposes. - [Microsoft Defender Flaws Enable Malware Uploads](https://rewterz.com/threat-advisory/microsoft-defender-flaws-enable-malware-uploads) - A recent analysis by Researcher uncovered multiple critical vulnerabilities in Microsoft Defender for Endpoint (DFE) - [Multiple Juniper Networks Vulnerabilities](https://rewterz.com/threat-advisory/multiple-juniper-networks-vulnerabilities-2) - Juniper Networks Junos OS Evolved could allow a remote attacker to obtain sensitive information - [SonicWall SSLVPN Hit After Firewall Backup Breach](https://rewterz.com/threat-advisory/sonicwall-sslvpn-hit-after-firewall-backup-breach) - A wave of coordinated attacks is targeting SonicWall SSLVPN devices, - [Patchwork APT Group - Active IOCs](https://rewterz.com/threat-advisory/patchwork-apt-group-active-iocs-10) - Patchwork is an Advanced Persistent Threat (APT) group active since at least 2014. - [Multiple Elastic Beats Vulnerabilities](https://rewterz.com/threat-advisory/multiple-elastic-beats-vulnerabilities-2) - Refer to Elastic Security Advisory for patch, upgrade, or suggested workaround information. - [Stealc Information Stealer Malware - Active IOCs](https://rewterz.com/threat-advisory/stealc-information-stealer-malware-active-iocs-11) - Stealc is a new malware that was first marketed by an actor named Plymouth on the XSS and BHF Russian-speaking underground forums on January 9, 2023. - [Snake Keylogger Malware - Active IOCs](https://rewterz.com/threat-advisory/snake-keylogger-malware-active-iocs-20) - Snake is a modular .NET keylogger that was first spotted in late November 2020. Snake malware's main feature is keylogging, but it also has additional capabilities such as taking screenshots and extracting data from the clipboard. - [Windows GDI Bug Triggers Blue Screen Crash](https://rewterz.com/threat-advisory/windows-gdi-bug-triggers-blue-screen-crash) - Graphics Device Interface (GDI) exposes the challenges of integrating memory-safe languages into core Windows systems. - [TA585 Uses Unique Web Injection to Push MonsterV2 on Windows - Active IOCs](https://rewterz.com/threat-advisory/ta585-uses-unique-web-injection-to-push-monsterv2-on-windows-active-iocs) - TA585 is a newly identified, highly professionalized cybercriminal group that runs end-to-end operations - [Astaroth Banking Trojan Exploits GitHub to Stay Active After Takedowns - Active IOCs](https://rewterz.com/threat-advisory/astaroth-banking-trojan-exploits-github-to-stay-active-after-takedowns-active-iocs) - Astaroth is a stealthy, resilient banking trojan built to avoid analysis and interruption. - [Oracle E-Business Suite RCE Flaw Allows Unauthenticated Data Exposure](https://rewterz.com/threat-advisory/oracle-e-business-suite-rce-flaw-allows-unauthenticated-data-exposure) - Oracle has disclosed a critical vulnerability, CVE-2025-61884, - [Windows BitLocker Flaws Allow Security Bypass](https://rewterz.com/threat-advisory/windows-bitlocker-flaws-allow-security-bypass) - Microsoft’s October 2025 Patch Tuesday updates addressed two critical vulnerabilities in Windows BitLocker, - [SAP NetWeaver Bugs Allow Command Execution and Auth Bypass](https://rewterz.com/threat-advisory/sap-netweaver-bugs-allow-command-execution-and-auth-bypass) - with several critical flaws affecting SAP NetWeaver. - [How MSSPs Can Support Organizations in Developing a Cyber Resilience Strategy](https://rewterz.com/blog/how-mssps-can-support-organizations-in-developing-a-cyber-resilience-strategy) - Learn how MSSPs help organizations boost cyber resilience through threat detection, response planning, and recovery support. - [Critical GitHub Copilot Vulnerability Exposes Private Repositories](https://rewterz.com/threat-advisory/critical-github-copilot-vulnerability-exposes-private-repositories) - A researcher discovered a high-severity prompt-injection attack against GitHub Copilot Chat that chained clever misuse of GitHub’s own image proxy - [Massive Wave of Scans Targets Palo Alto Networks Login Interfaces](https://rewterz.com/threat-advisory/massive-wave-of-scans-targets-palo-alto-networks-login-interfaces) - Threat intelligence researchers reported a massive spike in scanning activity targeting Palo Alto Networks login portals, - [CISA Alerts on Actively Exploited Windows Privilege Escalation Vulnerability](https://rewterz.com/threat-advisory/cisa-alerts-on-actively-exploited-windows-privilege-escalation-vulnerability) - CISA added CVE-2021-43226 to its Known Exploited Vulnerabilities (KEV) catalog on October 6, 2025, - [Cl0p Ransomware Exploits Zero-Day in Oracle E-Business Suite](https://rewterz.com/threat-advisory/cl0p-ransomware-exploits-zero-day-in-oracle-e-business-suite) - The recent data theft and extortion campaign targeting Oracle E-Business Suite (EBS) customers has been confirmed to be the work of the Cl0p ransomware group, - [Microsoft Events Flaw Exposes User Data](https://rewterz.com/threat-advisory/microsoft-events-flaw-exposes-user-data) - Researcher discovered a serious OData injection vulnerability in Microsoft’s Events platform - [Vulnerabilities Disclosed in CrowdStrike Falcon Sensor for Windows](https://rewterz.com/threat-advisory/vulnerabilities-disclosed-in-crowdstrike-falcon-sensor-for-windows) - CrowdStrike Falcon Sensor for Windows has received fixes for two medium-severity vulnerabilities CVE-2025-42701 and CVE-2025-42706, - [Zero Trust Architecture: Why MSSPs Are Key to Implementing This Framework](https://rewterz.com/blog/zero-trust-architecture-why-mssps-are-key-to-implementing-this-framework) - Discover how MSSPs help implement Zero Trust Architecture, ensuring stronger cybersecurity, visibility, and threat resilience. - [Multiple Apache Kylin Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apache-kylin-vulnerabilities) - Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. - [Remote Code Execution via ksmbd Flaw in the Linux Kernel](https://rewterz.com/threat-advisory/remote-code-execution-via-ksmbd-flaw-in-the-linux-kernel) - A severe vulnerability has been identified in the Linux kernel’s ksmbd SMB server implementation, - [Over 48 Cisco Firewalls Exposed to Actively Exploited Zero-Day Vulnerability](https://rewterz.com/threat-advisory/over-48-cisco-firewalls-exposed-to-actively-exploited-zero-day-vulnerability) - A critical zero-day vulnerability in Cisco Secure Firewall ASA and FTD software, tracked as CVE-2025-20333, - [Hackers Claim Access to 28,000 Red Hat Internal Projects and Source Code](https://rewterz.com/threat-advisory/hackers-claim-access-to-28000-red-hat-internal-projects-and-source-code) - The Crimson Collective extortion group claims responsibility for breaching the private GitHub repositories of Red Hat, a leading U.S.-based open-source software provider. - [ICS: Hitachi Energy Asset Suite Vulnerability](https://rewterz.com/threat-advisory/ics-hitachi-energy-asset-suite-vulnerability) - A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in logfile - [VMware vCenter and NSX Flaws Allow Username Enumeration by Attackers](https://rewterz.com/threat-advisory/vmware-vcenter-and-nsx-flaws-allow-username-enumeration-by-attackers) - VMware has disclosed three critical security vulnerabilities in its vCenter Server and NSX platforms - [Building a Robust Incident Response Plan: Best Practices for MSSPs](https://rewterz.com/blog/building-a-robust-incident-response-plan-best-practices-for-mssps) - Discover top strategies MSSPs can use to build a robust incident response plan and effectively manage cybersecurity threats. - [Malicious Fonts Exploit Apple Font Parser](https://rewterz.com/threat-advisory/malicious-fonts-exploit-apple-font-parser) - Apple has released critical security updates to patch a newly disclosed vulnerability in its Font Parser component, - [Zero-Day in VMware Tools and Aria Enables Privilege Escalation to Root](https://rewterz.com/threat-advisory/zero-day-in-vmware-tools-and-aria-enables-privilege-escalation-to-root) - A critical zero-day local privilege escalation, tracked as CVE-2025-41244, has been disclosed in VMware Tools - [WhatsApp Flaw Lets Malicious DNG Execute Code Remotely](https://rewterz.com/threat-advisory/whatsapp-flaw-lets-malicious-dng-execute-code-remotely) - Researchers disclosed a dangerous zero-click remote code execution (RCE) vulnerability chain affecting WhatsApp on Apple’s iOS, macOS, and iPadOS. - [Apache Airflow Bug Exposes Data to Read-Only Users](https://rewterz.com/threat-advisory/apache-airflow-bug-exposes-data-to-read-only-users) - Apache Airflow 3.0.3 has been found vulnerable to a critical security flaw tracked as CVE-2025-54831, - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-50) - Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in V8. - [Cisco ASA Zero-Day Exploited to Deliver RayInitiator and LINE VIPER Malware](https://rewterz.com/threat-advisory/cisco-asa-zero-day-exploited-to-deliver-rayinitiator-and-line-viper-malware) - A newly disclosed espionage campaign has revealed that state-sponsored actors are actively exploiting a zero-day vulnerability - [Critical Cisco ASA Zero-Day RCE Actively Exploited in the Wild](https://rewterz.com/threat-advisory/critical-cisco-asa-zero-day-rce-actively-exploited-in-the-wild) - Cisco disclosed multiple zero-day vulnerabilities tied to its VPN/web services for Cisco Secure Firewall Adaptive Security Appliance (ASA) - [North Korea-Linked Konni APT Group - Active IOCs](https://rewterz.com/threat-advisory/north-korea-linked-konni-apt-group-active-iocs-17) - The Konni APT (Advanced Persistent Threat) group has been a cyber espionage group since at least 2014. - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-31) - Microsoft Windows could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper authentication in NTLM. - [Stealc Information Stealer Malware - Active IOCs](https://rewterz.com/threat-advisory/stealc-information-stealer-malware-active-iocs-10) - Stealc is a new malware that was first marketed by an actor named Plymouth on the XSS and BHF Russian-speaking underground forums on January 9, 2023. - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-93) - Update the WordPress plugin to the latest available version. - [Cisco IOS/XE Flaw Enables Remote Auth Bypass and Data Theft](https://rewterz.com/threat-advisory/cisco-ios-xe-flaw-enables-remote-auth-bypass-and-data-theft) - A critical flaw has been identified in the implementation of the TACACS+ protocol within Cisco IOS and IOS XE Software, - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-30) - Microsoft Windows could allow a remote attacker to bypass security restrictions, caused by protection mechanism failure in MapUrlToZone. - [Bitter APT - Active IOCs](https://rewterz.com/threat-advisory/bitter-apt-active-iocs-31) - APT-17, also known as "Bitter APT" or "DeputyDog" is a state-sponsored cyber espionage group that is believed to operate out of China. - [Rhadamanthys Stealer - Active IOCs](https://rewterz.com/threat-advisory/rhadamanthys-stealer-active-iocs-13) - Rhadamanthys is a type of malware known as a stealer, which is designed to steal sensitive information from infected computers. - [Amadey Botnet - Active IOCs](https://rewterz.com/threat-advisory/amadey-botnet-active-iocs-22) - Amadey botnet is a type of malicious software that infects computers and turns them into "bots" or "zombies" that can be controlled remotely by an attacker. - [Up to 2 Million Cisco Devices Hit by Actively Exploited Zero-Day](https://rewterz.com/threat-advisory/up-to-2-million-cisco-devices-hit-by-actively-exploited-zero-day) - Cisco has disclosed a critical zero-day vulnerability, tracked as CVE-2025-20352, affecting all supported versions of Cisco IOS and IOS XE. - [Multiple Apache Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apache-products-vulnerabilities-38) - Apache Fory is vulnerable to a denial of service, caused by an unsafe deserialization due to improper input validation. - [ICS: Multiple Siemens Products Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-siemens-products-vulnerabilities-31) - Siemens RUGGEDCOM RST2428P could allow a remote attacker to obtain sensitive information, caused by exposing certain non-critical information from the device. - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-29) - Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by use-after-free in BitLocker. - [Gh0st RAT - Active IOCs](https://rewterz.com/threat-advisory/gh0st-rat-active-iocs-8) - Gh0st RAT is a remote access trojan (RAT) that was first discovered in 2008. - [FormBook Malware - Active IOCs](https://rewterz.com/threat-advisory/formbook-malware-active-iocs-27) - FormBook is an infostealer malware that was first identified in 2016. - [Multiple Jenkins Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-jenkins-plugins-vulnerabilities-10) - Jenkins weekly and LTS could allow a remote attacker to insert forged log messages, - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-28) - Microsoft Windows could allow a remote attacker to obtain sensitive information, caused by buffer over-read in Routing and Remote Access Service (RRAS). - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-49) - Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in Dawn. - [GuLoader Malspam Campaign - Active IOCs](https://rewterz.com/threat-advisory/guloader-malspam-campaign-active-iocs-15) - Since 2019, Guloader has been in operation as a downloader. GuLoader spreads through spam campaigns with malicious archived attachments. - [Quasar RAT aka CinaRAT - Active IOCs](https://rewterz.com/threat-advisory/quasar-rat-aka-cinarat-active-iocs-17) - Quasar malware is a Remote Access Trojan (RAT) that is often abused by cybercriminals to take remote control over users' computers for malicious purposes. - [AI Malware ‘MalTerminal’ Uses GPT-4 for Ransomware - Active IOCs](https://rewterz.com/threat-advisory/ai-malware-malterminal-uses-gpt-4-for-ransomware-active-iocs) - Recent research has uncovered a new class of AI-powered malware, exemplified by MalTerminal, - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-27) - Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by integer overflow or wraparound in Kernel. - [Stealc Information Stealer Malware - Active IOCs](https://rewterz.com/threat-advisory/stealc-information-stealer-malware-active-iocs-9) - Stealc is a new malware that was first marketed by an actor named Plymouth on the XSS and BHF Russian-speaking underground forums on January 9, 2023. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-50) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [BlackMoon Banking Trojan aka KrBanker - Active IOCs](https://rewterz.com/threat-advisory/blackmoon-banking-trojan-aka-krbanker-active-iocs-8) - BlackMoon, also known as KrBanker, is a banking Trojan that first emerged in September 2015, initially targeting South Korean bank s - [NVIDIA Merlin Flaw Enables Remote Code Execution as Root](https://rewterz.com/threat-advisory/nvidia-merlin-flaw-enables-remote-code-execution-as-root) - A critical vulnerability (CVE-2025-23298) was discovered in NVIDIA’s Merlin Transformers4Rec library, - [Chrome Flaws Enable Data Theft and Crashes](https://rewterz.com/threat-advisory/chrome-flaws-enable-data-theft-and-crashes) - Google has rolled out an urgent security update for its Chrome browser to patch three high-severity vulnerabilities that pose risks of data exposure and system instability. - [CISA Warns of Shai-Hulud Worm Infecting 500 npm Packages](https://rewterz.com/threat-advisory/cisa-warns-of-shai-hulud-worm-infecting-500-npm-packages) - CISA has issued an urgent security alert regarding a large-scale software supply chain attack targeting npmjs.com, - [The Rise of Ransomware-as-a-Service: How MSSPs Can Protect Their Clients](https://rewterz.com/blog/the-rise-of-ransomware-as-a-service-how-mssps-can-protect-their-clients) - Explore how MSSPs can defend clients against Ransomware-as-a-Service threats with proactive security strategies and real-time threat detection. - [Unauthenticated RCE Flaw Found in SolarWinds Web Help Desk](https://rewterz.com/threat-advisory/unauthenticated-rce-flaw-found-in-solarwinds-web-help-desk) - SolarWinds has released an urgent advisory addressing a critical remote code execution (RCE) vulnerability in its Web Help Desk software, - [SonicWall Patches ‘OVERSTEP’ Rootkit Malware on SMA Devices - Active IOCs](https://rewterz.com/threat-advisory/sonicwall-patches-overstep-rootkit-malware-on-sma-devices-active-iocs) - SonicWall has released an urgent firmware update, version 10.2.2.2-92sv, for its SMA 100 series appliances - [Linux KSMBD Flaw Enables Remote Resource Exhaustion](https://rewterz.com/threat-advisory/linux-ksmbd-flaw-enables-remote-resource-exhaustion) - A newly disclosed denial-of-service vulnerability in the Linux kernel’s KSMBD (SMB Direct) subsystem, - [Threat Actor Claims Breach of American Income Life Insurance](https://rewterz.com/threat-advisory/threat-actor-claims-breach-of-american-income-life-insurance) - A threat actor has claimed responsibility for a data breach targeting American Income Life (AIL), a major U.S.-based provider of life, accident, - [CISA Alerts on Delta Electronics Flaws Enabling Auth Bypass](https://rewterz.com/threat-advisory/cisa-alerts-on-delta-electronics-flaws-enabling-auth-bypass) - CISA has issued a warning regarding two critical path traversal vulnerabilities in Delta Electronics’ DIALink industrial control system software - [Microsoft Entra ID Flaw Enables Full Admin Takeover](https://rewterz.com/threat-advisory/microsoft-entra-id-flaw-enables-full-admin-takeover) - A critical vulnerability in Microsoft’s Entra ID (CVE-2025-55241) was discovered in July 2025 that could have allowed attackers to gain complete administrative control - [Privacy Concerns Over Israeli AppCloud on Galaxy Devices](https://rewterz.com/threat-advisory/privacy-concerns-over-israeli-appcloud-on-galaxy-devices) - Samsung is facing growing backlash over the pre-installation of AppCloud, an application developed by Israeli firm IronSource, - [Chrome Zero-Day in V8 Engine Highlights Rising Exploit Activity](https://rewterz.com/threat-advisory/chrome-zero-day-in-v8-engine-highlights-rising-exploit-activity) - Google has released a new round of security updates for its Chrome browser, addressing four vulnerabilities - [TP-Link 0-Day RCE Exploited with ASLR Bypass, PoC Published](https://rewterz.com/threat-advisory/tp-link-0-day-rce-exploited-with-aslr-bypass-poc-published) - A newly discovered zero-day vulnerability, tracked as CVE-2025-9961, has been identified in TP-Link routers, posing a severe security risk to users. - [SAMA vs. PDPL: A Comparative Analysis of Saudi Arabia’s Data Regulations](https://rewterz.com/blog/sama-vs-pdpl-a-comparative-analysis-of-saudi-arabias-data-regulations) - Explore key differences between SAMA and PDPL regulations in Saudi Arabia to ensure compliance, data protection, and secure business operations. - [Apple Fixes 0-Days in Older iPhones And iPads](https://rewterz.com/threat-advisory/apple-fixes-0-days-in-older-iphones-and-ipads) - Apple has released iOS 16.7.12 and iPadOS 16.7.12 on September 15, 2025, addressing a critical zero-day vulnerability in the ImageIO framework. - [Bitpixie Bug Allows BitLocker Bypass and Privilege Escalation](https://rewterz.com/threat-advisory/bitpixie-bug-allows-bitlocker-bypass-and-privilege-escalation) - The BitPixie vulnerability, tracked as CVE-2023-21563, represents a critical flaw in the Windows Boot Manager - [Malicious npm Packages Allegedly Abused in Active Supply Chain Campaign - Active IOCs](https://rewterz.com/threat-advisory/malicious-npm-packages-allegedly-abused-in-active-supply-chain-campaign-active-iocs) - Cybersecurity researchers have uncovered a major software supply chain attack on the npm registry, - [Warlock Ransomware Group and Its Enterprise Disruption - Active IOCs](https://rewterz.com/threat-advisory/warlock-ransomware-group-and-its-enterprise-disruption-active-iocs) - The Warlock ransomware group emerged in June 2025 on the Russian-language RAMP forum with a bold advertisement, - [Multiple Adobe Substance Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-substance-vulnerabilities-2) - Adobe Substance 3D Modeler could allow a remote attacker to execute arbitrary code on the system, - [Linux CUPS Vulnerability Enables Remote DoS and Auth Bypass](https://rewterz.com/threat-advisory/linux-cups-vulnerability-enables-remote-dos-and-auth-bypass) - Two critical vulnerabilities have been uncovered in the Linux Common Unix Printing System (CUPS), - [Babuk Ransomware aka Babuk2 - Active IOCs](https://rewterz.com/threat-advisory/babuk-ransomware-aka-babuk2-active-iocs) - Babuk ransomware first emerged around early 2020 and became widely noticed in January 2021, - [IBM QRadar SIEM Vulnerability Enables Unauthorized Actions](https://rewterz.com/threat-advisory/ibm-qradar-siem-vulnerability-enables-unauthorized-actions) - IBM has disclosed a critical permission misconfiguration in its QRadar Security Information and Event Management (SIEM) platform, tracked as CVE-2025-0164. - [Patchwork APT Group - Active IOCs](https://rewterz.com/threat-advisory/patchwork-apt-group-active-iocs-9) - Patchwork is an Advanced Persistent Threat (APT) group active since at least 2014. - [New Kernel Address Leak Found in Windows 11 After Microsoft Patch](https://rewterz.com/threat-advisory/new-kernel-address-leak-found-in-windows-11-after-microsoft-patch) - A new Windows kernel information-disclosure flaw, CVE-2025-53136, has been uncovered in Windows 11 - [Windows Firewall Bug Enables Privilege Escalation](https://rewterz.com/threat-advisory/windows-firewall-bug-enables-privilege-escalation) - Three Windows Defender Firewall elevation-of-privilege flaws and a fourth related service EoP - [National CERT Alert: SideWinder APT Phishing Campaign Threatening Government and Military Targets - Active IOCs](https://rewterz.com/threat-advisory/national-cert-alert-sidewinder-apt-phishing-campaign-threatening-government-and-military-targets-active-iocs) - The National CERT has reported a surge in targeted phishing activity linked to the Sidewinder Advanced Persistent Threat (APT) group - [NVIDIA NVDebug Tool Flaw Enables Privilege Escalation](https://rewterz.com/threat-advisory/nvidia-nvdebug-tool-flaw-enables-privilege-escalation) - NVIDIA has issued a critical security update for its NVDebug tool, addressing three high-severity vulnerabilities that pose significant risks to affected systems. - [Palo Alto User-ID Agent Flaw Exposes Passwords](https://rewterz.com/threat-advisory/palo-alto-user-id-agent-flaw-exposes-passwords) - A newly disclosed vulnerability, tracked as CVE-2025-4235, has been identified in Palo Alto Networks’ User-ID Credential Agent for Windows, - [How to Integrate PDPL Compliance into Your Organization’s Data Governance Strategy](https://rewterz.com/blog/how-to-integrate-pdpl-compliance-into-your-organizations-data-governance-strategy) - Learn how to align your organization with PDPL compliance requirements. Discover best practices for secure, lawful, and effective data management. - [GitLab Patches DoS and SSRF Flaws](https://rewterz.com/threat-advisory/gitlab-patches-dos-and-ssrf-flaws) - GitLab has released urgent security patches for both its Community (CE) and Enterprise (EE) editions, - [Microsoft Warns of Active Directory Privilege Escalation Flaw](https://rewterz.com/threat-advisory/microsoft-warns-of-active-directory-privilege-escalation-flaw) - Microsoft has issued an updated warning regarding a critical vulnerability in Active Directory Domain Services - [Ivanti Endpoint Manager RCE Vulnerabilities](https://rewterz.com/threat-advisory/ivanti-endpoint-manager-rce-vulnerabilities) - Ivanti has released critical security updates addressing two high-severity vulnerabilities - [CVE-2025-43722 - Dell PowerScale OneFS Vulnerability](https://rewterz.com/threat-advisory/cve-2025-43722-dell-powerscale-onefs-vulnerability) - Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. - [MysteriousElephant APT Group aka APT-K-47 - Active IOCs](https://rewterz.com/threat-advisory/mysteriouselephant-apt-group-aka-apt-k-47-active-iocs) - MysteriousElephant, also tracked as APT-K-47, is a South Asia–linked advanced persistent threat group first publicly detailed by Kaspersky in 2023 - [Apache Jackrabbit RCE Vulnerability](https://rewterz.com/threat-advisory/apache-jackrabbit-rce-vulnerability) - A critical security vulnerability has been identified in Apache Jackrabbit, an open-source content repository - [Chrome Security Update Patches Critical RCE Vulnerabilities](https://rewterz.com/threat-advisory/chrome-security-update-patches-critical-rce-vulnerabilities) - Google has officially released Chrome 140 to the stable channel across all major platforms, including Windows, Mac, Linux, Android, and iOS. - [CISA Alerts on Linux Kernel Race Condition Exploit](https://rewterz.com/threat-advisory/cisa-alerts-on-linux-kernel-race-condition-exploit) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new high-severity Linux kernel vulnerability, - [Critical SAP S/4HANA Exploit Enables Full System Takeover](https://rewterz.com/threat-advisory/critical-sap-s-4hana-exploit-enables-full-system-takeover) - A critical vulnerability in SAP S/4HANA, tracked as CVE-2025-42957, is being actively exploited in the wild, - [Over Half of US Firms Face Insider Breaches With $2.7M Average Cost](https://rewterz.com/threat-advisory/over-half-of-us-firms-face-insider-breaches-with-2-7m-average-cost) - A new report, reveals that nearly two-thirds (61%) of US firms experienced insider-related data breaches in the past two years, averaging eight incidents per organization. - [Apache DolphinScheduler Permissions Flaw Fixed](https://rewterz.com/threat-advisory/apache-dolphinscheduler-permissions-flaw-fixed) - A critical vulnerability has been identified in Apache DolphinScheduler’s default permission system, - [APT28 Exploits Microsoft Outlook With Newly Discovered 'NotDoor' Backdoor - Active IOCs](https://rewterz.com/threat-advisory/apt28-exploits-microsoft-outlook-with-newly-discovered-notdoor-backdoor-active-iocs) - APT28, the Russian state-sponsored threat group linked to military intelligence, has been observed exploiting Microsoft Outlook with a new backdoor named “NotDoor.” - [BlackMoon Banking Trojan aka KrBanker - Active IOCs](https://rewterz.com/threat-advisory/blackmoon-banking-trojan-aka-krbanker-active-iocs-7) - BlackMoon, also known as KrBanker, is a banking Trojan that first emerged in September 2015, initially targeting South Korean bank s - [ICS: Multiple Mitsubishi Electric MELSEC iQ-F Series Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-mitsubishi-electric-melsec-iq-f-series-vulnerabilities) - Mitsubishi Electric MELSEC iQ-F Series CPU module could allow a remote attacker to obtain sensitive information, - [Iran-Linked Attack via Omani Mailbox - Active IOCs](https://rewterz.com/threat-advisory/iran-linked-attack-via-omani-mailbox-active-iocs) - First detected in August 2025, the operation leveraged a compromised Ministry of Foreign Affairs of Oman mailbox (@fm.gov.om) - [UNC6395 Supply Chain Attack on Salesloft Drift Hits Hundreds of Organizations - Active IOCs](https://rewterz.com/threat-advisory/unc6395-supply-chain-attack-on-salesloft-drift-hits-hundreds-of-organizations-active-iocs) - A major supply chain attack has compromised Salesloft ’s Drift application, leading to the theft of OAuth and refresh tokens and impacting hundreds of organizations worldwide. - [Multiple H3C Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-h3c-products-vulnerabilities) - H3C GR2200 is vulnerable to a denial of service, caused by a flaw in the USERLIMIT_GLOBAL option. - [macOS Security Features Exploited to Spread Malware](https://rewterz.com/threat-advisory/macos-security-features-exploited-to-spread-malware) - macOS has long been known for its layered security protections, but recent attacks demonstrate that adversaries are increasingly turning these very defenses into weapons. - [LokiBot Malware - Active IOCs](https://rewterz.com/threat-advisory/lokibot-malware-active-iocs-19) - In early 2016, LokiBot was originally made available on underground forums for cybercriminals to use against Microsoft Android phones. - [Azure AD Bug Lets Attackers Steal Credentials](https://rewterz.com/threat-advisory/azure-ad-bug-lets-attackers-steal-credentials) - A critical security vulnerability in Azure Active Directory (Azure AD) has been uncovered, - [IBM Watsonx SQL Injection Flaw](https://rewterz.com/threat-advisory/ibm-watsonx-sql-injection-flaw) - IBM has disclosed a serious Blind SQL injection vulnerability in its Watsonx Orchestrate Cartridge for IBM Cloud Pak for Data, tracked as CVE-2025-0165. - [Linux UDisks Daemon Flaw Exposes Privileged Files](https://rewterz.com/threat-advisory/linux-udisks-daemon-flaw-exposes-privileged-files) - A critical vulnerability, CVE-2025-8067, has been identified in the Linux UDisks daemon, impacting multiple versions of Red Hat Enterprise Linux - [Cisco IMC KVM Flaw Enables Malicious Redirects](https://rewterz.com/threat-advisory/cisco-imc-kvm-flaw-enables-malicious-redirects) - A newly disclosed vulnerability, tracked as CVE-2025-50154, exposes a critical flaw in Windows systems - [New Windows 0-Click NTLM Flaw Bypasses Patch](https://rewterz.com/threat-advisory/new-windows-0-click-ntlm-flaw-bypasses-patch) - A newly disclosed vulnerability, tracked as CVE-2025-50154, exposes a critical flaw in Windows systems - [Malvertising Campaign Delivers TamperedChef Stealer via Trojanized PDF Tools - Active IOCs](https://rewterz.com/threat-advisory/malvertising-campaign-delivers-tamperedchef-stealer-via-trojanized-pdf-tools-active-iocs) - Cybersecurity researchers have uncovered a malvertising campaign distributing a new information-stealing malware dubbed TamperedChef through trojanized PDF editors. - [CVE-2025-23307 - NVIDIA NeMo Curator Vulnerability](https://rewterz.com/threat-advisory/cve-2025-23307-nvidia-nemo-curator-vulnerability) - NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow code injection. - [Cisco Nexus Flaw Enables DoS Attacks](https://rewterz.com/threat-advisory/cisco-nexus-flaw-enables-dos-attacks) - Cisco has issued a high-severity advisory for a vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of NX-OS Software, - [Akira Ransomware - Active IOCs](https://rewterz.com/threat-advisory/akira-ransomware-active-iocs-13) - Akira ransomware is a sophisticated cyber threat that first emerged in March 2023 and operates under a Ransomware-as-a-Service (RaaS) model. - [An Emerging Ducktail Infostealer - Active IOCs](https://rewterz.com/threat-advisory/an-emerging-ducktail-infostealer-active-iocs-48) - Ducktail Infostealer is a malicious program designed by hackers to infiltrate computers and networks globally which is delivered through a spear-phishing email. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-54) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Critical Chrome Use-After-Free Bug Enables Code Execution](https://rewterz.com/threat-advisory/critical-chrome-use-after-free-bug-enables-code-execution) - Google has released an emergency security update for Chrome to fix a critical use-after-free vulnerability (CVE-2025-9478) discovered in the ANGLE graphics library. - [Unknown Threat Actors Targets Oman MOFA in Global Cyber Campaign - Active IOCs](https://rewterz.com/threat-advisory/unknown-threat-actors-targets-oman-mofa-in-global-cyber-campaign-active-iocs) - Researchers recently identified a cyber campaign in which unknown threat actors impersonated the Oman Ministry of Foreign Affairs to target multiple Ministries of Foreign Affairs. - [It Pays to Integrate Threat Intelligence Feeds in Modern SIEM Solutions](https://rewterz.com/blog/it-pays-to-integrate-threat-intelligence-feeds-in-modern-siem-solutions) - Integrating threat intelligence feeds into modern SIEM solutions boosts detection, improves response times, and strengthens your cybersecurity defense. - [Hackers Abuse PUP Ads to Spread Windows Malware - Active IOCs](https://rewterz.com/threat-advisory/hackers-abuse-pup-ads-to-spread-windows-malware-active-iocs) - Cybersecurity analysts have uncovered a stealthy malware campaign in which attackers distribute Windows malware - [Multiple NVIDIA Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-products-vulnerabilities-5) - NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/arguments.py component where an attacker - [Apple 0-Day Flaw Actively Exploited](https://rewterz.com/threat-advisory/apple-0-day-flaw-actively-exploited) - Apple has released emergency security updates for iOS 18.6.2 and iPadOS 18.6.2 to address a critical zero-day vulnerability, - [SHAMOS Malware Hits macOS via Fake Help Sites - Active IOCs](https://rewterz.com/threat-advisory/shamos-malware-hits-macos-via-fake-help-sites-active-iocs) - The operation involves SHAMOS, a new variant of the well-known Atomic macOS Stealer (AMOS), - [Apache Tika PDF Parser Flaw Exposes Data](https://rewterz.com/threat-advisory/apache-tika-pdf-parser-flaw-exposes-data) - A critical vulnerability, tracked as CVE-2025-54988, has been discovered in Apache Tika’s PDF parser module, - [Chrome VPN with 100K Installs Steals Data](https://rewterz.com/threat-advisory/chrome-vpn-with-100k-installs-steals-data) - A malicious Chrome VPN extension, FreeVPN.One, with over 100,000 installations and even a verified badge on the Chrome Web Store, - [Hacked Cisco, Linksys, Araknis Routers See Scan Spike](https://rewterz.com/threat-advisory/hacked-cisco-linksys-araknis-routers-see-scan-spike) - To mitigate the risks posed by this campaign, organizations are strongly urged to update firmware on affected routers, - [The Ransomware Evolution: How to Adapt Your Defense to New Techniques](https://rewterz.com/blog/ransomware-evolution-adapting-defense-new-techniques) - Discover how ransomware is evolving and learn practical strategies to adapt your cybersecurity defenses against emerging attack techniques. - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-51) - Microsoft Azure File Sync could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper access control. - [Microsoft IIS Web Deploy RCE Vulnerability](https://rewterz.com/threat-advisory/microsoft-iis-web-deploy-rce-vulnerability) - A high-severity vulnerability, tracked as CVE-2025-53772, has been discovered in Microsoft’s Web Deploy 4.0 tool - [Rockwell ControlLogix RCE Vulnerability](https://rewterz.com/threat-advisory/rockwell-controllogix-rce-vulnerability) - A critical vulnerability, tracked as CVE-2025-7353, has been identified in Rockwell Automation’s ControlLogix Ethernet communication modules, - [ICS: Siemens Mendix SAML Vulnerability](https://rewterz.com/threat-advisory/ics-siemens-mendix-saml-vulnerability) - Siemens Mendix SAML could allow a remote attacker to hijack an account in specific SSO configurations, caused by insufficiently enforce signature validation and binding checks. - [Zoom for Windows Privilege Escalation Flaw](https://rewterz.com/threat-advisory/zoom-for-windows-privilege-escalation-flaw) - Zoom has disclosed a critical vulnerability (CVE-2025-49457, CVSS high) affecting multiple Windows-based clients, - [How to Build an Effective Security Operations Center (SOC) from Scratch](https://rewterz.com/blog/how-to-build-an-effective-security-operations-center-soc-from-scratch) - Learn how to build an effective SOC from the ground up. This guide covers planning, tools, staffing, and best practices for robust cybersecurity. - [Ivanti Product Flaws Allow DoS Attacks](https://rewterz.com/threat-advisory/ivanti-product-flaws-allow-dos-attacks) - Ivanti has issued critical security updates for its Connect Secure, Policy Secure, and Zero Trust Access (ZTA) gateway products, - [Charon Ransomware Uses DLL Sideloading and Anti-EDR Tactics - Active IOCs](https://rewterz.com/threat-advisory/charon-ransomware-uses-dll-sideloading-and-anti-edr-tactics-active-iocs) - A newly discovered ransomware family named Charon is targeting organizations in the Middle East’s public sector and aviation industry, - [Critical Security Advisory: Heightened Alert Urged for Potential Cyberattacks Targeting Pakistan on Independence Day](https://rewterz.com/threat-advisory/critical-security-advisory-heightened-alert-urged-for-potential-cyberattacks-targeting-pakistan-on-independence-day) - As Pakistan’s Independence Day approaches in 2025, heightened vigilance is essential to safeguard our digital infrastructure from evolving cyber threats. - [Fortinet SSL VPN Hit by 780 IPs - Active IOCs](https://rewterz.com/threat-advisory/fortinet-ssl-vpn-hit-by-780-ips-active-iocs) - On August 3rd, security telemetry from Researcher recorded an unprecedented spike in brute-force attacks against Fortinet SSL VPN infrastructure, - [Apache bRPC Flaw Enables Remote Service Crash](https://rewterz.com/threat-advisory/apache-brpc-flaw-enables-remote-service-crash) - A severe vulnerability, tracked as CVE-2025-54472, has been identified in Apache bRPC versions - [Lazarus aka Hidden Cobra APT Group - Active IOCs](https://rewterz.com/threat-advisory/lazarus-aka-hidden-cobra-apt-group-active-iocs-15) - Lazarus APT, one of North Korea’s most sophisticated and well-funded threat actors, has been active since at least 2009. - [Multiple Linux Kernel Vulnerabilities](https://rewterz.com/threat-advisory/multiple-linux-kernel-vulnerabilities-17) - Linux Kernel is vulnerable to a denial of service, caused by an out-of-bounds read in usb: gadget: configfs. - [BitLocker Bypassed via Multiple 0-Days](https://rewterz.com/threat-advisory/bitlocker-bypassed-via-multiple-0-days) - These flaws—CVE-2025-48800, CVE-2025-48003, CVE-2025-48804, and CVE-2025-48818—undermine BitLocker’s core security model - [Zero-Day in WinRAR Actively Used to Deploy Malicious Files](https://rewterz.com/threat-advisory/zero-day-in-winrar-actively-used-to-deploy-malicious-files) - Security researchers have uncovered a zero-day path traversal vulnerability in the Windows version of WinRAR - [Ransomware Targets Pakistan Petroleum Limited](https://rewterz.com/threat-advisory/ransomware-targets-pakistan-petroleum-limited) - Pakistan Petroleum Limited (PPL), a leading state-run oil and gas company - [Linux Kernel Flaw Exploited via Chrome Sandbox](https://rewterz.com/threat-advisory/linux-kernel-flaw-exploited-via-chrome-sandbox) - A newly disclosed Linux kernel vulnerability, CVE-2025-38236, discovered by researcher - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-92) - The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads - [NVIDIA Triton Flaws Allow Attackers to Seize Control of AI Servers](https://rewterz.com/threat-advisory/nvidia-triton-flaws-allow-attackers-to-seize-control-of-ai-servers) - A critical vulnerability chain has been discovered in NVIDIA’s Triton Inference Server - [Multiple Dell Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-dell-products-vulnerabilities-15) - Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. - [Multiple Apache Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apache-products-vulnerabilities-37) - Apache Zeppelin could allow a remote attacker to read arbitrary files, caused by improper JDBC URL validation. - [NJRAT - Active IOCs](https://rewterz.com/threat-advisory/njrat-active-iocs-19) - NjRat is a Remote Access Trojan, which is found leveraging Pastebin to deliver a second-stage payload after initial infection. - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-41) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [Multiple Adobe Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-products-vulnerabilities-38) - Adobe Substance 3D Viewer could allow a remote attacker to obtain sensitive information, - [Multiple Apple Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apple-products-vulnerabilities-34) - This issue is fixed in Apple macOS Sequoia 15.6, iPadOS 17.7.9, macOS Ventura 13.7.7 - [Multiple NVIDIA Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-products-vulnerabilities-4) - NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-54) - IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. - [AsyncRAT - Active IOCs](https://rewterz.com/threat-advisory/asyncrat-active-iocs-23) - AsyncRAT is an open-source tool designed for remote monitoring via encrypted connections. - [Multiple Microsoft 365 Copilot Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-365-copilot-vulnerabilities) - Microsoft 365 Copilot Business Chat could allow a remote attacker to obtain sensitive information, caused by a command injection vulnerability. - [An Emerging Ducktail Infostealer - Active IOCs](https://rewterz.com/threat-advisory/an-emerging-ducktail-infostealer-active-iocs-47) - Ducktail Infostealer is a malicious program designed by hackers to infiltrate computers and networks globally which is delivered through a spear-phishing email. - [Earth Preta aka Mustang Panda APT Group - Active IOCs](https://rewterz.com/threat-advisory/earth-preta-aka-mustang-panda-apt-group-active-iocs-5) - Mustang Panda, aka Bronze President and TA416, has been active since at least 2012. - [New AD Lateral Movement Bypasses Authentication, Steals Data](https://rewterz.com/threat-advisory/new-ad-lateral-movement-bypasses-authentication-steals-data) - allowing threat actors with on-prem AD control to escalate privileges in Microsoft 365 environments stealthily and persistently. - [Windows UAC Bypassed via Character Map](https://rewterz.com/threat-advisory/windows-uac-bypassed-via-character-map) - A newly disclosed technique demonstrates how Windows’ built-in Private Character Editor - [The Role of Artificial Intelligence in Automated Incident Response](https://rewterz.com/blog/the-role-of-artificial-intelligence-in-automated-incident-response) - Discover how AI is transforming automated incident response by enhancing threat detection, reducing response time, and improving cybersecurity resilience. - [Iranian Hackers Target Finance, Government, and Media Orgs](https://rewterz.com/threat-advisory/iranian-hackers-target-finance-government-and-media-orgs) - During the 12-day conflict between Israel and Iran in June 2025, Iranian-linked cyber threat actors executed a highly coordinated digital campaign - [Lazarus Tricks Users with Device Warnings to Install RAT - Active IOCs](https://rewterz.com/threat-advisory/lazarus-tricks-users-with-device-warnings-to-install-rat-active-iocs) - In a newly uncovered social engineering campaign, North Korea’s Lazarus Group - [SideWinder APT Group aka Rattlesnake – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-active-iocs-25) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [New Exchange Exploit Enables Privilege Escalation](https://rewterz.com/threat-advisory/new-exchange-exploit-enables-privilege-escalation) - A newly disclosed critical vulnerability, CVE-2025-53786, impacts Microsoft Exchange Server hybrid deployments, - [Multiple Trend Micro Apex One Vulnerabilities](https://rewterz.com/threat-advisory/multiple-trend-micro-apex-one-vulnerabilities-2) - Trend Micro Apex One could allow a remote attacker to execute arbitrary commands on the system - [BumbleBee Malware - Active IOCs](https://rewterz.com/threat-advisory/bumblebee-malware-active-iocs-2) - The Bumblebee malware is malicious software that primarily targets enterprises. - [Dell Laptops Exposed to Hijacking and Persistent Malware](https://rewterz.com/threat-advisory/dell-laptops-exposed-to-hijacking-and-persistent-malware) - The recently disclosed "ReVault" vulnerability set affects millions of Dell laptops, - [CISA Warns of Active Exploitation of D-Link Devices](https://rewterz.com/threat-advisory/cisa-warns-of-active-exploitation-of-d-link-devices) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three old D-Link security vulnerabilities - [North Korean APT Kimsuky aka Black Banshee - Active IOCs](https://rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-55) - Kimsuky is a North Korean advanced persistent threat (APT) group, also known as "Black Banshee". - [Chaos Ransomware - Active IOCs](https://rewterz.com/threat-advisory/chaos-ransomware-active-iocs-2) - Chaos is a customizable ransomware builder that emerged on June 9, 2021 - [Multiple NVIDIA Triton Inference Server Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-triton-inference-server-vulnerabilities) - NVIDIA Triton Inference Server is vulnerable to a denial of service, caused by an integer overflow. - [SonicWall Warns of Gen 7 Firewall Attacks](https://rewterz.com/threat-advisory/sonicwall-warns-of-gen-7-firewall-attacks) - SonicWall has issued an urgent security advisory in response to a sharp rise in cyberattacks targeting its Gen 7 firewalls - [Interlock Ransomware Exploits ClickFix - Active IOCs](https://rewterz.com/threat-advisory/interlock-ransomware-exploits-clickfix-active-iocs) - Interlock ransomware has emerged as a formidable threat targeting organizations across North America and Europe since September 2024, - [Mozilla Warns of Add-on Developer Phishing](https://rewterz.com/threat-advisory/mozilla-warns-of-add-on-developer-phishing) - Mozilla has issued an urgent alert following the discovery of a sophisticated phishing campaign targeting developers - [BitLocker Registry Exploited via WMI for Code Execution](https://rewterz.com/threat-advisory/bitlocker-registry-exploited-via-wmi-for-code-execution) - BitLocker, Microsoft’s full disk encryption tool, is widely deployed for data protection. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-53) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [SideWinder APT Group aka Rattlesnake Targeting Pakistan – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-targeting-pakistan-active-iocs-20) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [Multiple D-Link Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-products-vulnerabilities-21) - D-Link DI-8400 is vulnerable to a denial of service, caused by a NULL pointer dereference in file usb_paswd.asp of the component jhttpd. - [Multiple Adobe Experience Manager Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-experience-manager-vulnerabilities-22) - Adobe Experience Manager is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. - [Multiple D-Link DIR-513 Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-dir-513-vulnerabilities) - A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. - [Multiple Mozilla Firefox Vulnerabilities](https://rewterz.com/threat-advisory/multiple-mozilla-firefox-vulnerabilities-14) - Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, - [Multiple IBM SmartCloud Analytics Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-smartcloud-analytics-vulnerabilities) - IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-26) - Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. - [Akira Exploits SonicWall 0-Day](https://rewterz.com/threat-advisory/akira-exploits-sonicwall-0-day) - A critical cybersecurity threat has emerged involving a suspected zero-day vulnerability in SonicWall firewall devices, - [Snake Keylogger Malware - Active IOCs](https://rewterz.com/threat-advisory/snake-keylogger-malware-active-iocs-19) - Snake is a modular .NET keylogger that was first spotted in late November 2020. Snake malware's main feature is keylogging, but it also has additional capabilities such as taking screenshots and extracting data from the clipboard. - [Patchwork APT Group - Active IOCs](https://rewterz.com/threat-advisory/patchwork-apt-group-active-iocs-8) - Patchwork is an Advanced Persistent Threat (APT) group active since at least 2014. - [Amadey Botnet - Active IOCs](https://rewterz.com/threat-advisory/amadey-botnet-active-iocs-21) - Amadey botnet is a type of malicious software that infects computers and turns them into "bots" or "zombies" that can be controlled remotely by an attacker. - [TeamViewer Windows Flaw Allows File Deletion as SYSTEM](https://rewterz.com/threat-advisory/teamviewer-windows-flaw-allows-file-deletion-as-system) - A critical vulnerability, CVE-2025-36537, has been identified in TeamViewer’s Remote Management solution for Windows, - [Silver Fox Exploits Google Translate for Malware Attacks - Active IOCs](https://rewterz.com/threat-advisory/silver-fox-exploits-google-translate-for-malware-attacks-active-iocs) - A newly uncovered malware campaign by the Silver Fox threat actors demonstrates a highly sophisticated use of social engineering, - [macOS 'Sploitlight' Bug Lets Hackers Bypass TCC](https://rewterz.com/threat-advisory/macos-sploitlight-bug-lets-hackers-bypass-tcc) - A critical vulnerability in macOS, dubbed “Sploitlight” and tracked as CVE-2025-31199, - [WordPress Theme RCE Bug Enables Full Site Takeover - Active IOCs](https://rewterz.com/threat-advisory/wordpress-theme-rce-bug-enables-full-site-takeover-active-iocs) - A critical Remote Code Execution (RCE) vulnerability tracked as CVE-2025-5394 has been discovered in the Alone WordPress theme, - [Qilin Ransomware aka Agenda - Active IOCs](https://rewterz.com/threat-advisory/qilin-ransomware-aka-agenda-active-iocs-3) - Qilin ransomware, formerly known as Agenda, is a Russian-speaking ransomware-as-a-service (RaaS) operation that emerged in July 2022. - [Multiple TP-Link TL-WR841N Vulnerabilities](https://rewterz.com/threat-advisory/multiple-tp-link-tl-wr841n-vulnerabilities) - A vulnerability has been found in TP-Link TL-WR841N V11. - [Wanna Cryptor aka WannaCry Ransomware - Active IOCs](https://rewterz.com/threat-advisory/wanna-cryptor-aka-wannacry-ransomware-active-iocs-2) - As of 2025, WannaCry, also known as WanaCrypt0r 2.0, remains a landmark example of the devastating potential of ransomware. - [What to Consider When Protecting Your Cloud Workloads](https://rewterz.com/blog/what-to-consider-when-protecting-your-cloud-workloads) - Essential factors to consider when securing cloud workloads. From access control to compliance, explore best practices to strengthen cloud security posture. - [Chrome Flaws Enable Memory Hacks and Code Execution](https://rewterz.com/threat-advisory/chrome-flaws-enable-memory-hacks-and-code-execution) - Google has released an urgent security update for its Chrome browser, - [SonicWall VPN Bug Enables Firewall DoS](https://rewterz.com/threat-advisory/sonicwall-vpn-bug-enables-firewall-dos) - A newly discovered medium-severity vulnerability, CVE-2025-40600, affects SonicWall Gen7 firewall products - [Multiple Elastic Beats Vulnerabilities](https://rewterz.com/threat-advisory/multiple-elastic-beats-vulnerabilities) - Refer to Elastic Security Advisory for patch, upgrade, or suggested workaround information. - [Black Basta Ransomware - Active IOCs](https://rewterz.com/threat-advisory/black-basta-ransomware-active-iocs) - Black Basta emerged in April 2022 (with indications of development starting as early as February) as a sophisticated ransomware-as-a-service (RaaS) operation. - [DarkComet RAT - Active IOCs](https://rewterz.com/threat-advisory/darkcomet-rat-active-iocs) - DarkComet is a widely used Remote Access Trojan (RAT) that originated in 2008, - [Fake Error Pages Spread Cross-Platform Malware - Active IOCs](https://rewterz.com/threat-advisory/fake-error-pages-spread-cross-platform-malware-active-iocs) - The technique allows them to infect both Linux and Windows systems, leveraging fake error pages hosted on domains like fastsoco. top to deliver malware - [Hackers Deploy .HTA Files to Spread Red Ransomware - Active IOCs](https://rewterz.com/threat-advisory/hackers-deploy-hta-files-to-spread-red-ransomware-active-iocs) - A new global wave of ransomware attacks in July 2025 has emerged, utilizing weaponized HTML Application (.HTA) files to deliver a refined version of the Epsilon Red ransomware. - [Hackers Target IIS Servers Using Advanced Web Shell for Full Remote Access](https://rewterz.com/threat-advisory/hackers-target-iis-servers-using-advanced-web-shell-for-full-remote-access) - Cybersecurity researchers have discovered a highly sophisticated web shell attack targeting Microsoft Internet Information Services (IIS) servers, - [Scattered Spider Actively Exploiting VMware vSphere Infrastructure](https://rewterz.com/threat-advisory/scattered-spider-actively-exploiting-vmware-vsphere-infrastructure) - Security firm has reported that the financially driven hacking group Scattered Spider also known as UNC3944, Muddled Libra, - [Oyster Malware Targets IT Admins via SEO Poisoning - Active IOCs](https://rewterz.com/threat-advisory/oyster-malware-targets-it-admins-via-seo-poisoning-active-iocs) - The resurfaced Oyster malware, also known as Broomstick or CleanupLoader, has re-emerged in July 2025 with a sophisticated SEO poisoning campaign, - [Microsoft AppLocker Flaw Enables Security Bypass](https://rewterz.com/threat-advisory/microsoft-applocker-flaw-enables-security-bypass) - A newly discovered configuration flaw in Microsoft’s AppLocker block list policy exposes a subtle yet critical security loophole. - [Vidar Malware - Active IOCs](https://rewterz.com/threat-advisory/vidar-malware-active-iocs-7) - Vidar, which first appeared in late 2018, is a malware family that primarily acts as an information stealer - [Patchwork APT Group - Active IOCs](https://rewterz.com/threat-advisory/patchwork-apt-group-active-iocs-7) - Patchwork is an Advanced Persistent Threat (APT) group active since at least 2014. - [Gh0st RAT - Active IOCs](https://rewterz.com/threat-advisory/gh0st-rat-active-iocs-7) - Gh0st RAT is a remote access trojan (RAT) that was first discovered in 2008. - [SharePoint 0-Day Exploited to Deploy Warlock Ransomware - Active IOCs](https://rewterz.com/threat-advisory/sharepoint-0-day-exploited-to-deploy-warlock-ransomware-active-iocs) - A critical security alert has been issued by Microsoft regarding active exploitation of zero-day vulnerabilities CVE-2025-53770 and CVE-2025-53771 in Microsoft SharePoint Server - [Multiple Apache Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apache-products-vulnerabilities-36) - Apache Seata (incubating) could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-25) - Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network. - [CVE-2025-27930 - Zoho ManageEngine Applications Manager Vulnerability](https://rewterz.com/threat-advisory/cve-2025-27930-zoho-manageengine-applications-manager-vulnerability) - Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-53) - IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-52) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-91) - The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation - [Multiple Adobe ColdFusion Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-coldfusion-vulnerabilities-4) - Adobe ColdFusion is vulnerable to a denial of service, caused by an improper access control vulnerability. - [CVE-2025-42947 - SAP FICA ODN Framework Vulnerability](https://rewterz.com/threat-advisory/cve-2025-42947-sap-fica-odn-framework-vulnerability) - SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. - [Multiple SonicWall SMA 100 Series Vulnerabilities](https://rewterz.com/threat-advisory/multiple-sonicwall-sma-100-series-vulnerabilities) - Sonicwall SMA 100 Series is vulnerable to a heap-based buffer overflow vulnerability in the web interface. - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-24) - Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. - [CVE-2024-38335 - IBM Security QRadar Network Vulnerability](https://rewterz.com/threat-advisory/cve-2024-38335-ibm-security-qradar-network-vulnerability) - IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of service due to improper allocation of resources. - [MeterPreter Malware - Active IOCs](https://rewterz.com/threat-advisory/meterpreter-malware-active-iocs-6) - Meterpreter - a trojan-type program - enables attackers to take control of affected machines remotely. - [FormBook Malware - Active IOCs](https://rewterz.com/threat-advisory/formbook-malware-active-iocs-26) - FormBook is an infostealer malware that was first identified in 2016. - [Multiple Adobe Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-products-vulnerabilities-37) - Adobe ColdFusion is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-48) - Google Chrome could allow a remote attacker to execute arbitrary code on the system, - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-50) - Microsoft SharePoint Server could allow a remote attacker to conduct spoofing attacks, - [CVE-2025-7945 - D-Link DIR-513 Vulnerability](https://rewterz.com/threat-advisory/cve-2025-7945-d-link-dir-513-vulnerability) - A vulnerability was found in D-Link DIR-513 up to 20190831. - [Multiple TP-Link VIGI Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-tp-link-vigi-products-vulnerabilities) - A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-23) - Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-40) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [NJRAT - Active IOCs](https://rewterz.com/threat-advisory/njrat-active-iocs-18) - NjRat is a Remote Access Trojan, which is found leveraging Pastebin to deliver a second-stage payload after initial infection. - [Multiple Adobe Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-products-vulnerabilities-36) - Adobe Framemaker is vulnerable to a stack-based buffer overflow. - [Multiple Dell Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-dell-products-vulnerabilities-14) - Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. - [North Korean APT Kimsuky aka Black Banshee - Active IOCs](https://rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-54) - Kimsuky is a North Korean advanced persistent threat (APT) group, also known as "Black Banshee". - [Multiple IBM Cognos Analytics Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-cognos-analytics-vulnerabilities-2) - IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of unencrypted network traffic. - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-22) - Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. - [Remcos RAT - Active IOCs](https://rewterz.com/threat-advisory/remcos-rat-active-iocs-26) - Remcos malware has been operating since 2016. This RAT was originally promoted as genuine software for remote control of Microsoft Windows from XP onwards and is frequently found in phishing attempts due to its capacity to completely infect an afflicted machine. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-51) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [CVE-2025-23270 - NVIDIA Jetson Linux Vulnerability](https://rewterz.com/threat-advisory/cve-2025-23270-nvidia-jetson-linux-vulnerability) - NVIDIA Jetson Linux could allow a physical attacker to execute arbitrary code on the system, caused by a vulnerability in UEFI Management mode. - [Multiple Adobe Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-products-vulnerabilities-35) - Adobe InDesign is vulnerable to a heap-based buffer overflow. - [CVE-2025-33014 - IBM Sterling Vulnerability](https://rewterz.com/threat-advisory/cve-2025-33014-ibm-sterling-vulnerability) - IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-49) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-21) - Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. - [STRRAT Malware - Active IOCs](https://rewterz.com/threat-advisory/strrat-malware-active-iocs-8) - STRRat is a Java-based Remote-Access Trojan (RAT) with a slew of malicious features, notably information theft and backdoor capabilities. - [CVE-2025-53770 - Microsoft SharePoint Zero-Day Vulnerability Exploit in the Wild](https://rewterz.com/threat-advisory/cve-2025-53770-microsoft-sharepoint-zero-day-vulnerability-exploit-in-the-wild) - Improper input validation in Microsoft SQL Server allows an unauthorized attacker to disclose information over a network. - [CISA Warns of Chromium 0-Day Exploited in Attacks](https://rewterz.com/threat-advisory/cisa-warns-of-chromium-0-day-exploited-in-attacks) - CISA has issued an urgent alert regarding a critical vulnerability in Google Chromium, - [TP-Link NVR Flaw Allows Remote Command Execution](https://rewterz.com/threat-advisory/tp-link-nvr-flaw-allows-remote-command-execution) - Two high-severity vulnerabilities have been discovered in TP-Link’s VIGI network video recorder (NVR) systems - [Gunra Ransomware Hits Windows, Deletes Backups - Active IOCs](https://rewterz.com/threat-advisory/gunra-ransomware-hits-windows-deletes-backups-active-iocs) - The Gunra ransomware campaign, first emerging in April 2025, represents a weaponized evolution of the leaked Conti source code, - [Stealc Information Stealer Malware - Active IOCs](https://rewterz.com/threat-advisory/stealc-information-stealer-malware-active-iocs-8) - Stealc is a new malware that was first marketed by an actor named Plymouth on the XSS and BHF Russian-speaking underground forums on January 9, 2023. - [APT32 SeaLotus aka OceanLotus Group - Active IOCs](https://rewterz.com/threat-advisory/apt32-sealotus-aka-oceanlotus-group-active-iocs-6) - A Vietnam-based threat group, APT32 (OceanLotus Group) has been active since 2014. - [SonicWall SMA 100 Flaws Allow Arbitrary JavaScript Execution](https://rewterz.com/threat-advisory/sonicwall-sma-100-flaws-allow-arbitrary-javascript-execution) - A set of critical vulnerabilities has been identified in SonicWall SMA 100 series SSL-VPN appliances, - [Stealth Backdoor in WordPress Plugins Grants Persistent Access - Active IOCs](https://rewterz.com/threat-advisory/stealth-backdoor-in-wordpress-plugins-grants-persistent-access-active-iocs) - A newly uncovered and highly sophisticated WordPress malware campaign is exploiting the “mu-plugins” (must-use plugins) directory, - [Storm-2603 Exploits SharePoint Vulnerability in Ransomware Campaign - Active IOCs](https://rewterz.com/threat-advisory/storm-2603-exploits-sharepoint-vulnerability-in-ransomware-campaign-active-iocs) - Microsoft has revealed that Storm-2603, a suspected China-based financially motivated threat actor, - [AWS Releases Fix for Windows Client VPN Local Privilege Escalation](https://rewterz.com/threat-advisory/aws-releases-fix-for-windows-client-vpn-local-privilege-escalation) - Amazon Web Services (AWS) has released a security patch addressing a high-severity local privilege escalation vulnerability - [Multiple Microsoft Office Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-office-products-vulnerabilities-3) - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. - [Multiple Microsoft Office Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-office-products-vulnerabilities-2) - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. - [The Essential Evolution of Cloud Detection and Response](https://rewterz.com/blog/the-essential-evolution-of-cloud-detection-and-response) - Explore how cloud detection and response strategies have evolved to meet modern security challenges in dynamic, multi-cloud environments. - [Hackers Breach US Nuclear Agency via SharePoint 0-Day](https://rewterz.com/threat-advisory/hackers-breach-us-nuclear-agency-via-sharepoint-0-day) - The recent cyberattack on the U.S. National Nuclear Security Administration (NNSA) marks one of the most severe breaches - [CISA Warns of SharePoint Code Injection Exploit](https://rewterz.com/threat-advisory/cisa-warns-of-sharepoint-code-injection-exploit) - CISA has issued an urgent alert for two actively exploited vulnerabilities in Microsoft SharePoint - [High-Severity Chrome Bugs Enable Arbitrary Code Execution](https://rewterz.com/threat-advisory/high-severity-chrome-bugs-enable-arbitrary-code-execution) - Google has issued an urgent security update for its Chrome browser to address three critical vulnerabilities, - [SideWinder APT Group aka Rattlesnake Targeting Pakistan – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-targeting-pakistan-active-iocs-19) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [APT UNG0002 Expands Cyber Espionage Campaigns Across Asia - Active IOCs](https://rewterz.com/threat-advisory/apt-ung0002-expands-cyber-espionage-campaigns-across-asia-active-iocs) - Cyber espionage in Asia is intensifying as researchers from a security firm have revealed new details on UNG0002, also known as Unknown Group 0002. - [Apache Jena Bug Enables File Access](https://rewterz.com/threat-advisory/apache-jena-bug-enables-file-access) - Apache Jena, a widely used framework for building Semantic Web and Linked Data applications, - [Sophos Firewall Bugs Enable Pre-Auth RCE](https://rewterz.com/threat-advisory/sophos-firewall-bugs-enable-pre-auth-rce) - Sophos has disclosed multiple high-impact vulnerabilities affecting Sophos Firewall versions 21.5 GA and earlier, - [Chaos Ransomware - Active IOCs](https://rewterz.com/threat-advisory/chaos-ransomware-active-iocs) - Chaos is a customizable ransomware builder that emerged on June 9, 2021 - [Multiple Microsoft Azure Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-azure-products-vulnerabilities) - Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. - [Dell Test Lab Breached by World Leaks Group](https://rewterz.com/threat-advisory/dell-test-lab-breached-by-world-leaks-group) - Dell Technologies has confirmed a targeted breach of its Customer Solution Centers by the World Leaks extortion group, - [SideWinder APT Group aka Rattlesnake – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-active-iocs-24) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [An Emerging Ducktail Infostealer - Active IOCs](https://rewterz.com/threat-advisory/an-emerging-ducktail-infostealer-active-iocs-46) - Ducktail Infostealer is a malicious program designed by hackers to infiltrate computers and networks globally which is delivered through a spear-phishing email. - [CISA Warns of Active SharePoint Zero-Day RCE Exploit](https://rewterz.com/threat-advisory/cisa-warns-of-active-sharepoint-zero-day-rce-exploit) - CISA has issued an urgent alert regarding CVE-2025-53770, a critical zero-day remote code execution (RCE) vulnerability - [Snake Keylogger Bypasses Defenses to Steal Credentials - Active IOCs](https://rewterz.com/threat-advisory/snake-keylogger-bypasses-defenses-to-steal-credentials-active-iocs) - According to the Researcher, Upon execution, the Snake Keylogger variant immediately initiates multiple layers of persistence - [Multiple NVIDIA Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-products-vulnerabilities-3) - NVIDIA Container Toolkit is vulnerable to a denial of service, caused by a vulnerability in the update-ldcache hook. - [Multiple Sophos Intercept X Vulnerabilities](https://rewterz.com/threat-advisory/multiple-sophos-intercept-x-vulnerabilities) - A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and older allows arbitrary code execution. - [Multiple Adobe ColdFusion Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-coldfusion-vulnerabilities-3) - Adobe ColdFusion could allow a remote attacker to bypass security restrictions, caused by an incorrect authorization vulnerability. - [CVE-2025-7673 - Zyxel VMG8825-T50K Firmware Vulnerability](https://rewterz.com/threat-advisory/cve-2025-7673-zyxel-vmg8825-t50k-firmware-vulnerability) - A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware - [Multiple Microsoft Windows Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-products-vulnerabilities-20) - Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. - [Rhadamanthys Stealer - Active IOCs](https://rewterz.com/threat-advisory/rhadamanthys-stealer-active-iocs-12) - Rhadamanthys is a type of malware known as a stealer, which is designed to steal sensitive information from infected computers. - [Stealc Information Stealer Malware - Active IOCs](https://rewterz.com/threat-advisory/stealc-information-stealer-malware-active-iocs-7) - Stealc is a new malware that was first marketed by an actor named Plymouth on the XSS and BHF Russian-speaking underground forums on January 9, 2023. - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-49) - Null pointer dereference in Microsoft Windows NTFS allows an authorized attacker to elevate privileges locally. - [Multiple Adobe Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-products-vulnerabilities-34) - Adobe Illustrator could allow a remote attacker to execute arbitrary code on the system, - [Multiple Oracle Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-oracle-products-vulnerabilities-22) - An unspecified vulnerability in Oracle VM VirtualBox related to the Core component could allow a local authenticated attacker - [CoinMiner Malware - Active IOCs](https://rewterz.com/threat-advisory/coinminer-malware-active-iocs-12) - CoinMiner is a malware designed to secretly mine cryptocurrencies, such as Bitcoin, on infected computers. - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-47) - Google Chrome could allow a remote attacker to execute arbitrary code on the system, - [Multiple VMware Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-vmware-products-vulnerabilities-4) - VMware ESXi, Workstation, and Fusion could allow a local attacker to execute arbitrary code on the system - [Cobalt Strike Malware - Active IOCs](https://rewterz.com/threat-advisory/cobalt-strike-malware-active-iocs-23) - Cobalt Strike first appeared in 2012 in response to alleged flaws in the Metasploit Framework, an existing red team (penetration testing) tool. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-50) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Multiple Oracle Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-oracle-products-vulnerabilities-21) - Vulnerability in the Oracle Database component of Oracle Database Server. - [Multiple Adobe Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-products-vulnerabilities-33) - Adobe Framemaker is vulnerable to a heap-based buffer overflow. - [North Korean APT Kimsuky aka Black Banshee - Active IOCs](https://rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-53) - Kimsuky is a North Korean advanced persistent threat (APT) group, also known as "Black Banshee". - [Multiple Jenkins Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-jenkins-plugins-vulnerabilities-9) - Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-90) - The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-48) - Microsoft Azure Monitor could allow a remote authenticated attacker to execute arbitrary code on the system, - [Multiple D-Link Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-products-vulnerabilities-20) - A vulnerability classified as critical has been found in D-Link DIR-818LW up to 20191215. - [NJRAT - Active IOCs](https://rewterz.com/threat-advisory/njrat-active-iocs-17) - NjRat is a Remote Access Trojan, which is found leveraging Pastebin to deliver a second-stage payload after initial infection. - [MassLogger Malware - Active IOCs](https://rewterz.com/threat-advisory/masslogger-malware-active-iocs-15) - MassLogger, a .NET credential stealer, is a keylogger and stealer malware. MassLogger's prime objective is data extraction or information theft, such as bank account and/or credit card details. - [Multiple Adobe Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-products-vulnerabilities-32) - Adobe InCopy could allow a remote attacker to execute arbitrary code on the system, - [CVE-2025-6265 - Zyxel NWA50AX PRO Firmware Vulnerability](https://rewterz.com/threat-advisory/cve-2025-6265-zyxel-nwa50ax-pro-firmware-vulnerability) - A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware - [Quasar RAT aka CinaRAT - Active IOCs](https://rewterz.com/threat-advisory/quasar-rat-aka-cinarat-active-iocs-16) - Quasar malware is a Remote Access Trojan (RAT) that is often abused by cybercriminals to take remote control over users' computers for malicious purposes. - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-47) - Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. - [Multiple SAP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-sap-products-vulnerabilities-27) - SAP SAPCAR could allow a local authenticated attacker to execute arbitrary code on the system, caused by a memory corruption flaw. - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-52) - An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it. - [Lumma Stealer Malware aka LummaC - Active IOCs](https://rewterz.com/threat-advisory/lumma-stealer-malware-aka-lummac-active-iocs-22) - Lumma is an information stealer that is sold as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums and Telegram. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-48) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [GuLoader Malspam Campaign - Active IOCs](https://rewterz.com/threat-advisory/guloader-malspam-campaign-active-iocs-14) - Since 2019, Guloader has been in operation as a downloader. GuLoader spreads through spam campaigns with malicious archived attachments. - [Multiple Jenkins Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-jenkins-plugins-vulnerabilities-8) - Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-51) - IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore Content. - [ICS: Multiple Rockwell Automation Arena Simulation Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-rockwell-automation-arena-simulation-vulnerabilities) - Rockwell Automation Arena Simulation could allow a remote attacker to execute arbitrary code on the system, - [Multiple SAP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-sap-products-vulnerabilities-26) - The GuiXT application, which is integrated with SAP GUI for Windows, - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-39) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [Cisco UI Center Remote File Upload Flaw](https://rewterz.com/threat-advisory/cisco-ui-center-remote-file-upload-flaw) - A critical vulnerability, tracked as CVE-2025-20274, has been identified in Cisco’s Unified Intelligence Center (CUIC) - [Hackers Exploit Ivanti ICS Flaws to Deliver MDifyLoader and Cobalt Strike - Active IOCs](https://rewterz.com/threat-advisory/hackers-exploit-ivanti-ics-flaws-to-deliver-mdifyloader-and-cobalt-strike-active-iocs) - Cybersecurity researchers have detailed a new malware called MDifyLoader, - [SharePoint RCE Exploited via XML Payload](https://rewterz.com/threat-advisory/sharepoint-rce-exploited-via-xml-payload) - A critical remote code execution (RCE) vulnerability has been discovered in Microsoft SharePoint, - [1-Click Oracle Cloud RCE Bug Allows Malicious File Upload](https://rewterz.com/threat-advisory/1-click-oracle-cloud-rce-bug-allows-malicious-file-upload) - A recently discovered critical Remote Code Execution (RCE) vulnerability in Oracle Cloud Infrastructure (OCI) Code Editor exposed a major security flaw - [Hackers Use DNS Blind Spots to Deliver Malware - Active IOCs](https://rewterz.com/threat-advisory/hackers-use-dns-blind-spots-to-deliver-malware-active-iocs) - A sophisticated cyberattack technique has emerged wherein threat actors are embedding malware within DNS TXT records, - [Cybercriminals Abuse GitHub for Amadey Malware Delivery and Data Theft - Active IOCs](https://rewterz.com/threat-advisory/cybercriminals-abuse-github-for-amadey-malware-delivery-and-data-theft-active-iocs) - Threat actors are leveraging public GitHub repositories to host malicious payloads distributed via Amadey malware - [NVIDIA Toolkit Bug Enables Code Execution](https://rewterz.com/threat-advisory/nvidia-toolkit-bug-enables-code-execution) - NVIDIA has released urgent security patches addressing two critical vulnerabilities - [Critical Cisco ISE Flaw Lets Attackers Gain Root Access Remotely](https://rewterz.com/threat-advisory/critical-cisco-ise-flaw-lets-attackers-gain-root-access-remotely) - Cisco has disclosed a maximum-severity vulnerability CVE-2025-20337 - [VMware ESXi and Workstation Bugs Enable Host Code Execution](https://rewterz.com/threat-advisory/vmware-esxi-and-workstation-bugs-enable-host-code-execution) - VMware has released urgent security patches addressing four high-severity vulnerabilities, - [KongTuke Targets Windows with Interlock RAT - Active IOCs](https://rewterz.com/threat-advisory/kongtuke-targets-windows-with-interlock-rat-active-iocs) - A sophisticated malware campaign attributed to the KongTuke threat cluster has been identified targeting Windows - [How MDR Can Optimize Your SIEM Investment](https://rewterz.com/blog/how-mdr-can-optimize-your-siem-investment) - Discover how MDR services enhance your SIEM investment by improving threat detection, response, and overall efficiency. - [FortiWeb SQL Injection Flaw Lets Attackers Run Malicious SQL Code](https://rewterz.com/threat-advisory/fortiweb-sql-injection-flaw-lets-attackers-run-malicious-sql-code) - A critical SQL injection vulnerability, tracked as CVE-2025-25257, has been discovered in multiple versions of Fortinet’s FortiWeb Web Application Firewall (WAF), - [Multiple Cisco Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-cisco-products-vulnerabilities-27) - A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, - [Multiple Cisco Splunk Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-cisco-splunk-products-vulnerabilities) - In Splunk Enterprise, and Splunk Cloud Platform the software potentially exposes the search head cluster key. - [Multiple SAP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-sap-products-vulnerabilities-25) - SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link - [SideWinder APT Group aka Rattlesnake – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-active-iocs-23) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [Remcos RAT - Active IOCs](https://rewterz.com/threat-advisory/remcos-rat-active-iocs-25) - Remcos malware has been operating since 2016. This RAT was originally promoted as genuine software for remote control of Microsoft Windows from XP onwards and is frequently found in phishing attempts due to its capacity to completely infect an afflicted machine. - [Microsoft SQL Server 0-Day Leaks Sensitive Data Over Network](https://rewterz.com/threat-advisory/microsoft-sql-server-0-day-leaks-sensitive-data-over-network) - A critical vulnerability in Microsoft SQL Server, tracked as CVE-2025-49719, - [Microsoft Fixes Wormable RCE Flaw in Windows and Server](https://rewterz.com/threat-advisory/microsoft-fixes-wormable-rce-flaw-in-windows-and-server) - Microsoft has released critical security patches addressing CVE-2025-47981, - [Zoom Windows Vulnerability Exposes Users to DoS Attacks](https://rewterz.com/threat-advisory/zoom-windows-vulnerability-exposes-users-to-dos-attacks) - Two medium-severity vulnerabilities, CVE-2025-49464 and CVE-2025-46789, have been discovered in specific Zoom Clients for Windows. - [Windows BitLocker Flaw Lets Attackers Bypass Security](https://rewterz.com/threat-advisory/windows-bitlocker-flaw-lets-attackers-bypass-security) - A critical vulnerability, CVE-2025-48818, has been discovered in Microsoft’s BitLocker Device Encryption, - [Multiple Adobe Framemaker Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-framemaker-vulnerabilities-3) - Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability - [Multiple SAP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-sap-products-vulnerabilities-24) - SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-49) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Multiple D-Link Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-products-vulnerabilities-19) - A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. - [FortiOS Buffer Overflow Enables Remote Code Execution](https://rewterz.com/threat-advisory/fortios-buffer-overflow-enables-remote-code-execution) - Fortinet has disclosed a heap-based buffer overflow vulnerability in its FortiOS operating system, - [macOS SMBClient Bug Enables RCE and Kernel Crash](https://rewterz.com/threat-advisory/macos-smbclient-bug-enables-rce-and-kernel-crash) - Apple has addressed three critical vulnerabilities in the macOS SMBClient - [Atomic Stealer Upgraded With Persistent Backdoor - Active IOCs](https://rewterz.com/threat-advisory/atomic-stealer-upgraded-with-persistent-backdoor-active-iocs) - The Atomic macOS Stealer (AMOS), a known Russia-affiliated malware, - [Hackers Abuse WordPress ClickFix to Drop RAT - Active IOCs](https://rewterz.com/threat-advisory/hackers-abuse-wordpress-clickfix-to-drop-rat-active-iocs) - Security researchers have uncovered a sophisticated cyberattack campaign in May 2025 that leverages compromised WordPress websites - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-47) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Signed Drivers Abused for Kernel Attacks on Windows](https://rewterz.com/threat-advisory/signed-drivers-abused-for-kernel-attacks-on-windows) - Cybercriminals are increasingly abusing Microsoft's Windows driver-signing processes to deploy stealthy kernel-level malware, - [Linux Boot Flaw Enables Secure Boot Bypass](https://rewterz.com/threat-advisory/linux-boot-flaw-enables-secure-boot-bypass) - A significant vulnerability affecting modern Linux distributions has been uncovered, - [XWorm RAT Uses New Loaders to Evade Detection - Active IOCs](https://rewterz.com/threat-advisory/xworm-rat-uses-new-loaders-to-evade-detection-active-iocs) - XWorm has solidified its place as one of the most dangerous and flexible remote access trojans (RATs) currently active in the threat landscape. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-48) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [SparkKitty Malware Targets iOS and Android to Steal Gallery Photos - Active IOCs](https://rewterz.com/threat-advisory/sparkkitty-malware-targets-ios-and-android-to-steal-gallery-photos-active-iocs) - SparkKitty is a highly sophisticated Trojan malware that has been actively targeting iOS and Android devices since early 2024. - [Veeam Patches Critical RCE Flaw in Backup and Replication Software](https://rewterz.com/threat-advisory/veeam-patches-critical-rce-flaw-in-backup-and-replication-software) - Veeam has released patches to fix a critical vulnerability in its Backup & Replication software that could enable remote code execution (RCE) by an authenticated domain user. - [ICS: Mitsubishi Electric MELSEC iQ-F Series Vulnerability](https://rewterz.com/threat-advisory/ics-mitsubishi-electric-melsec-iq-f-series-vulnerability-3) - Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series - [DoNot APT Targets European Ministry with Stealthy Espionage Campaign - Active IOCs](https://rewterz.com/threat-advisory/donot-apt-targets-european-ministry-with-stealthy-espionage-campaign-active-iocs) - In a newly uncovered campaign, the DoNot APT group—also known as APT-C-35, Mint Tempest, Origami Elephant, and Viceroy Tiger—has escalated its cyber-espionage activities - [Cobalt Strike Malware - Active IOCs](https://rewterz.com/threat-advisory/cobalt-strike-malware-active-iocs-22) - Cobalt Strike first appeared in 2012 in response to alleged flaws in the Metasploit Framework, an existing red team (penetration testing) tool. - [CVE-2025-49719 - Microsoft SQL Server Zero-Day Vulnerability](https://rewterz.com/threat-advisory/cve-2025-49719-microsoft-sql-server-zero-day-vulnerability) - Improper input validation in Microsoft SQL Server allows an unauthorized attacker to disclose information over a network. - [Multiple Cisco Splunk Enterprise Vulnerabilities](https://rewterz.com/threat-advisory/multiple-cisco-splunk-enterprise-vulnerabilities) - In Splunk Enterprise, and Splunk Cloud Platform an unauthenticated attacker can send a specially-crafted SPL search - [ICS: Multiple Siemens Products Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-siemens-products-vulnerabilities-30) - A vulnerability has been identified in Siemens SINEC NMS. - [Vidar Malware - Active IOCs](https://rewterz.com/threat-advisory/vidar-malware-active-iocs-6) - Vidar, which first appeared in late 2018, is a malware family that primarily acts as an information stealer - [Optimizing SOC Performance Through XDR-Driven Automation](https://rewterz.com/blog/optimizing-soc-performance-through-xdr-driven-automation) - Discover how XDR-driven automation enhances SOC efficiency, streamlines threat detection, and reduces response times for stronger cybersecurity operations. - [Multiple SAP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-sap-products-vulnerabilities-23) - SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content - [Bert Ransomware Strikes Worldwide Using Multiple Variants - Active IOCs](https://rewterz.com/threat-advisory/bert-ransomware-strikes-worldwide-using-multiple-variants-active-iocs) - Security researchers have identified the Bert ransomware group, also tracked as Water Pombero, actively targeting organizations - [An Emerging Ducktail Infostealer - Active IOCs](https://rewterz.com/threat-advisory/an-emerging-ducktail-infostealer-active-iocs-45) - Ducktail Infostealer is a malicious program designed by hackers to infiltrate computers and networks globally which is delivered through a spear-phishing email. - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-50) - IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory. - [AsyncRAT - Active IOCs](https://rewterz.com/threat-advisory/asyncrat-active-iocs-22) - AsyncRAT is an open-source tool designed for remote monitoring via encrypted connections. - [Firefox Extensions Malware Campaign Targets 40 Crypto Wallets - Active IOCs](https://rewterz.com/threat-advisory/firefox-extensions-malware-campaign-targets-40-crypto-wallets-active-iocs) - Security Experts have uncovered over 40 malicious Mozilla Firefox extensions designed to steal data from cryptocurrency wallets. - [BlackMoon Banking Trojan aka KrBanker - Active IOCs](https://rewterz.com/threat-advisory/blackmoon-banking-trojan-aka-krbanker-active-iocs-6) - BlackMoon, also known as KrBanker, is a banking Trojan that first emerged in September 2015, initially targeting South Korean bank s - [CVE-2025-46647 - Apache APISIX Vulnerability](https://rewterz.com/threat-advisory/cve-2025-46647-apache-apisix-vulnerability) - Apache APISIX could allow a remote attacker to bypass security restrictions, - [Gafgyt aka Bashlite Malware - Active IOCs](https://rewterz.com/threat-advisory/gafgyt-aka-bashlite-malware-active-iocs-18) - Gafgyt is a type of malware that is used to conduct Distributed Denial of Service (DDoS) attacks. - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-38) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [Microsoft and DocuSign Targeted in PDF Phishing Campaign](https://rewterz.com/threat-advisory/microsoft-and-docusign-targeted-in-pdf-phishing-campaign) - Cybersecurity researchers are warning about rising phishing campaigns that impersonate popular brands and use telephone-oriented attack delivery (TOAD), - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-89) - Update the WordPress plugin to the latest available version. - [Azure and Power Apps Flaws Allow Privilege Escalation Attacks](https://rewterz.com/threat-advisory/azure-and-power-apps-flaws-allow-privilege-escalation-attacks) - Microsoft disclosed four critical security vulnerabilities affecting key cloud services, including Azure DevOps, - [Amadey Botnet - Active IOCs](https://rewterz.com/threat-advisory/amadey-botnet-active-iocs-20) - Amadey botnet is a type of malicious software that infects computers and turns them into "bots" or "zombies" that can be controlled remotely by an attacker. - [Akira Ransomware - Active IOCs](https://rewterz.com/threat-advisory/akira-ransomware-active-iocs-12) - Akira ransomware is a sophisticated cyber threat that first emerged in March 2023 and operates under a Ransomware-as-a-Service (RaaS) model. - [Kimsuky Uses ClickFix to Execute Malicious Scripts - Active IOCs](https://rewterz.com/threat-advisory/kimsuky-uses-clickfix-to-execute-malicious-scripts-active-iocs) - The North Korean state-sponsored threat group Kimsuky has significantly advanced its social engineering tactics - [Critical Cisco Unified CM Flaw Allows Unauthorized Root Access](https://rewterz.com/threat-advisory/critical-cisco-unified-cm-flaw-allows-unauthorized-root-access) - Cisco has released security updates addressing a critical vulnerability (CVE-2025-20309) in its Unified Communications Manager - [Multiple Cisco Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-cisco-products-vulnerabilities-26) - Cisco BroadWorks Application Delivery Platform is vulnerable to cross-site scripting, - [GCleaner Malware - Active IOCs](https://rewterz.com/threat-advisory/gcleaner-malware-active-iocs-4) - GCleaner is a type of malware that disguises itself as a legitimate software program called "GCleaner" or "G-Cleaner." - [Snake Keyloggers Exploit Java Tools to Bypass Security - Active IOCs](https://rewterz.com/threat-advisory/snake-keyloggers-exploit-java-tools-to-bypass-security-active-iocs) - A highly sophisticated phishing campaign has been uncovered, distributing the Snake Keylogger malware - [North Korean APT Kimsuky aka Black Banshee - Active IOCs](https://rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-52) - Kimsuky is a North Korean advanced persistent threat (APT) group, also known as "Black Banshee". - [CVE-2025-49741 - Microsoft Edge Chromium-based Vulnerability](https://rewterz.com/threat-advisory/cve-2025-49741-microsoft-edge-chromium-based-vulnerability) - No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. - [DarkTortilla Malware - Active IOCs](https://rewterz.com/threat-advisory/darktortilla-malware-active-iocs-2) - DarkTortilla is a highly obfuscated, .NET-based malware crypter active since at least 2015. - [Maximizing the ROI of XDR and MDR Investments](https://rewterz.com/blog/maximizing-the-roi-of-xdr-and-mdr-investments) - Learn how managed security services help solve the cybersecurity skills shortage by providing expert threat monitoring and response. - [Local Privilege Escalation to Root via Sudo chroot in Linux](https://rewterz.com/threat-advisory/local-privilege-escalation-to-root-via-sudo-chroot-in-linux) - A critical vulnerability identified as CVE-2025-32463 has been disclosed in the widely used Linux Sudo utility, - [CoinMiner Malware - Active IOCs](https://rewterz.com/threat-advisory/coinminer-malware-active-iocs-11) - CoinMiner is a malware designed to secretly mine cryptocurrencies, such as Bitcoin, on infected computers. - [Google Warns of Active Exploits Targeting Chrome V8 Vulnerability](https://rewterz.com/threat-advisory/google-warns-of-active-exploits-targeting-chrome-v8-vulnerability) - Google has released security updates to patch a zero-day vulnerability (CVE-2025-6554) in its Chrome browser - [CVE-2025-6554 - Google Chrome Vulnerability](https://rewterz.com/threat-advisory/cve-2025-6554-google-chrome-vulnerability) - Google Chrome could allow a remote attacker to execute arbitrary code on the system, - [Scattered Spider Hits Tech Firms with Phishing and Social Engineering](https://rewterz.com/threat-advisory/scattered-spider-hits-tech-firms-with-phishing-and-social-engineering) - Scattered Spider has evolved rapidly from its roots as a SIM-swapping crew in 2022 to a highly capable, financially motivated threat group by 2025. - [Multiple D-Link Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-products-vulnerabilities-18) - A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. - [Multiple GitLab Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-gitlab-products-vulnerabilities-20) - An issue has been discovered in GitLab CE/EE affecting all versions - [CVE-2025-25012 - Elastic Kibana Vulnerability](https://rewterz.com/threat-advisory/cve-2025-25012-elastic-kibana-vulnerability) - URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-46) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [FormBook Malware - Active IOCs](https://rewterz.com/threat-advisory/formbook-malware-active-iocs-25) - FormBook is an infostealer malware that was first identified in 2016. - [PAN-OS Bug Enables Root Command Execution](https://rewterz.com/threat-advisory/pan-os-bug-enables-root-command-execution) - A recently disclosed vulnerability in Palo Alto Networks’ PAN-OS, identified as CVE-2025-4230, - [Gafgyt aka Bashlite Malware - Active IOCs](https://rewterz.com/threat-advisory/gafgyt-aka-bashlite-malware-active-iocs-17) - Gafgyt is a type of malware that is used to conduct Distributed Denial of Service (DDoS) attacks. - [Microsoft 365 Direct Send Abused for Internal Phishing - Active IOCs](https://rewterz.com/threat-advisory/microsoft-365-direct-send-abused-for-internal-phishing-active-iocs) - A newly discovered phishing campaign has targeted over 70 organizations by exploiting Microsoft 365’s Direct Send feature - [NVIDIA Megatron LM Flaw Enables Code Injection](https://rewterz.com/threat-advisory/nvidia-megatron-lm-flaw-enables-code-injection) - To mitigate the issue, NVIDIA has released version 0.12.1 of Megatron LM, which patches both CVEs. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-47) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Akira Ransomware - Active IOCs](https://rewterz.com/threat-advisory/akira-ransomware-active-iocs-11) - Akira ransomware is a sophisticated cyber threat that first emerged in March 2023 and operates under a Ransomware-as-a-Service (RaaS) model. - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-49) - IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-45) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Multiple D-Link Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-products-vulnerabilities-17) - A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. - [Multiple Intel Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-intel-products-vulnerabilities-41) - Intel Xeon 6 processor with E-cores could allow a local authenticated attacker to gain elevated privileges on the system - [Hacktivists Target U.S. Firms and Military After Iran Strikes](https://rewterz.com/threat-advisory/hacktivists-target-u-s-firms-and-military-after-iran-strikes) - The recent escalation in geopolitical tensions between the U.S., Iran, and Israel has triggered a significant surge in hacktivist activity targeting American infrastructure. - [Stealc Information Stealer Malware - Active IOCs](https://rewterz.com/threat-advisory/stealc-information-stealer-malware-active-iocs-6) - Stealc is a new malware that was first marketed by an actor named Plymouth on the XSS and BHF Russian-speaking underground forums on January 9, 2023. - [Multiple NVIDIA Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-nvidia-products-vulnerabilities-2) - NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access - [Lumma Stealer Malware aka LummaC - Active IOCs](https://rewterz.com/threat-advisory/lumma-stealer-malware-aka-lummac-active-iocs-21) - Lumma is an information stealer that is sold as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums and Telegram. - [Multiple GitLab Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-gitlab-products-vulnerabilities-19) - GitLab is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the Maven Dependency Proxy. - [DHS Alerts on Pro-Iranian Hacktivist Threats to U.S. Networks](https://rewterz.com/threat-advisory/dhs-alerts-on-pro-iranian-hacktivist-threats-to-u-s-networks) - The Department of Homeland Security has issued a high-level cyber threat advisory warning of imminent attacks from pro-Iranian hacktivist groups targeting the United States' infrastructure. - [UAC-0001 Hackers Target ICS Devices on Windows Servers - Active IOCs](https://rewterz.com/threat-advisory/uac-0001-hackers-target-ics-devices-on-windows-servers-active-iocs) - Ukrainian government agencies became the target of a highly sophisticated cyberattack campaign led by UAC-0001 (APT28), - [WinRAR Flaw Enables Code Execution](https://rewterz.com/threat-advisory/winrar-flaw-enables-code-execution) - A critical security vulnerability tracked as CVE-2025-6218 has been discovered in RARLAB’s widely used WinRAR utility. - [North Korean APT Kimsuky aka Black Banshee - Active IOCs](https://rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-51) - Kimsuky is a North Korean advanced persistent threat (APT) group, also known as "Black Banshee". - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-46) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [BlueNoroff Deepfake Zoom Call Deploys macOS Malware - Active IOCs](https://rewterz.com/threat-advisory/bluenoroff-deepfake-zoom-call-deploys-macos-malware-active-iocs) - In a sophisticated cyber operation linked to North Korea-aligned threat actor BlueNoroff (a sub-cluster of the Lazarus Group), - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-88) - Update the WordPress plugin to the latest available version. - [Multiple GitLab Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-gitlab-products-vulnerabilities-18) - An HTML injection/XSS vulnerability in GitLab CE/EE. Under certain conditions, malicious HTML can be injected into the search page, potentially hijacking user accounts. - [GuLoader Malspam Campaign - Active IOCs](https://rewterz.com/threat-advisory/guloader-malspam-campaign-active-iocs-13) - Since 2019, Guloader has been in operation as a downloader. GuLoader spreads through spam campaigns with malicious archived attachments. - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-48) - IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management. - [IBM i Flaw Enables Privilege Escalation by Attackers](https://rewterz.com/threat-advisory/ibm-i-flaw-enables-privilege-escalation-by-attackers) - IBM i could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i - [Multiple Zoho ManageEngine Exchange Reporter Vulnerabilities](https://rewterz.com/threat-advisory/multiple-zoho-manageengine-exchange-reporter-vulnerabilities) - Zoho ManageEngine Exchange reporter Plus is vulnerable to cross-site scripting, - [North Korean APT Deploys npm Supply Chain Malware for Crypto Theft - Active IOCs](https://rewterz.com/threat-advisory/north-korean-apt-deploys-npm-supply-chain-malware-for-crypto-theft-active-iocs) - Cybersecurity Researchers has uncovered a new wave of malicious npm packages - [CVE-2025-6565 - NETGEAR WNCE3001 Vulnerability](https://rewterz.com/threat-advisory/cve-2025-6565-netgear-wnce3001-vulnerability) - Netgear WNCE3001 is vulnerable to a stack-based buffer overflow, - [Amadey Botnet - Active IOCs](https://rewterz.com/threat-advisory/amadey-botnet-active-iocs-19) - Amadey botnet is a type of malicious software that infects computers and turns them into "bots" or "zombies" that can be controlled remotely by an attacker. - [Citrix Warns of Active Exploits on NetScaler Zero-Day Vulnerability](https://rewterz.com/threat-advisory/citrix-warns-of-active-exploits-on-netscaler-zero-day-vulnerability) - Citrix has issued security patches for a newly discovered, actively exploited critical vulnerability CVE-2025-6543 affecting NetScaler ADC and NetScaler Gateway. - [CVE-2025-6543 - Citrix NetScaler ADC and NetScaler Gateway Vulnerability](https://rewterz.com/threat-advisory/cve-2025-6543-citrix-netscaler-adc-and-netscaler-gateway-vulnerability) - Citrix NetScaler ADC and NetScaler Gateway is vulnerable to a buffer overflow, leading to unintended control flow and denial of service. - [Multiple D-Link DIR-619L Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-dir-619l-vulnerabilities-2) - A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. - [Snake Keylogger Malware - Active IOCs](https://rewterz.com/threat-advisory/snake-keylogger-malware-active-iocs-18) - Snake is a modular .NET keylogger that was first spotted in late November 2020. Snake malware's main feature is keylogging, but it also has additional capabilities such as taking screenshots and extracting data from the clipboard. - [LockBit Ransomware - Active IOCs](https://rewterz.com/threat-advisory/lockbit-ransomware-active-iocs-8) - LockBit ransomware takes as little as five minutes to deploy the encryption routine on target systems once it lands on the victim network. - [Critical RCE Vulnerabilities Discovered in Cisco ISE Platform](https://rewterz.com/threat-advisory/critical-rce-vulnerabilities-discovered-in-cisco-ise-platform) - Cisco has released security patches for two critical vulnerabilities - [Multiple Cisco Identity Services Engine Vulnerabilities](https://rewterz.com/threat-advisory/multiple-cisco-identity-services-engine-vulnerabilities-4) - Cisco Identity Services Engine could allow a remote attacker to execute arbitrary code on the system, - [Hacked SonicWall VPN Tool Used to Steal Data - Active IOCs](https://rewterz.com/threat-advisory/hacked-sonicwall-vpn-tool-used-to-steal-data-active-iocs) - Cybersecurity researchers have identified a highly sophisticated malware campaign specifically targeting users of SonicWall ’s SSL VPN NetExtender, - [APT Hackers Abuse Microsoft ClickOnce to Deliver Trusted Malware](https://rewterz.com/threat-advisory/apt-hackers-abuse-microsoft-clickonce-to-deliver-trusted-malware) - energy, oil, and gas sectors using an innovative exploitation of Microsoft ClickOnce technology. - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-46) - Google Chrome could allow a remote attacker to bypass security restrictions, caused by insufficient data validation in DevTools. - [Gh0st RAT - Active IOCs](https://rewterz.com/threat-advisory/gh0st-rat-active-iocs-6) - Gh0st RAT is a remote access trojan (RAT) that was first discovered in 2008. - [Managed Security Services as a Solution to the Cybersecurity Skills Shortage](https://rewterz.com/blog/managed-security-services-as-a-solution-to-the-cybersecurity-skills-shortage) - Learn how managed security services help solve the cybersecurity skills shortage by providing expert threat monitoring and response. - [Chinese APT Groups Weaponize Routers for Stealth Espionage Operations - Active IOCs](https://rewterz.com/threat-advisory/chinese-apt-groups-weaponize-routers-for-stealth-espionage-operations-active-iocs) - A China-linked advanced persistent threat (APT) group identified as UAT-5918 has been operating a covert espionage campaign named LapDogs, - [CVE-2025-48700 - Zimbra Collaboration Vulnerability](https://rewterz.com/threat-advisory/cve-2025-48700-zimbra-collaboration-vulnerability) - Zimbra Collaboration is vulnerable to cross-site scripting, caused by improper validation of user-supplied. - [Multiple NETGEAR Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-netgear-products-vulnerabilities-5) - A vulnerability classified as critical has been found in Netgear EX6150 1.0.0.46_1.0.76. - [NCSC Alerts on Fortinet Malware](https://rewterz.com/threat-advisory/ncsc-alerts-on-fortinet-malware) - UMBRELLA STAND is a sophisticated malware campaign identified by the Researcher, targeting internet-facing Fortinet FortiGate 100D firewalls. - [Confucius APT Resurfaces with Stealthy Anondoor Backdoor Framework - Active IOCs](https://rewterz.com/threat-advisory/confucius-apt-resurfaces-with-stealthy-anondoor-backdoor-framework-active-iocs) - The Confucius APT group, known for targeting government and military entities in South and East Asia, - [Apache CloudStack Privilege Escalation Flaw](https://rewterz.com/threat-advisory/apache-cloudstack-privilege-escalation-flaw) - Multiple critical vulnerabilities have been disclosed in Apache CloudStack, - [NJRAT - Active IOCs](https://rewterz.com/threat-advisory/njrat-active-iocs-16) - NjRat is a Remote Access Trojan, which is found leveraging Pastebin to deliver a second-stage payload after initial infection. - [SideWinder APT Group aka Rattlesnake Targeting Pakistan – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-targeting-pakistan-active-iocs-18) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [CISA Warns of Exploited Linux Kernel Flaw](https://rewterz.com/threat-advisory/cisa-warns-of-exploited-linux-kernel-flaw) - A critical Linux kernel vulnerability, tracked as CVE-2023-0386, has been added to CISA - Known Exploited Vulnerabilities (KEV) catalog, - [Amadey Botnet - Active IOCs](https://rewterz.com/threat-advisory/amadey-botnet-active-iocs-18) - Amadey botnet is a type of malicious software that infects computers and turns them into "bots" or "zombies" that can be controlled remotely by an attacker. - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-87) - Update the WordPress plugin to the latest available version. - [Multiple D-Link DIR-825 Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-dir-825-vulnerabilities) - A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. - [Prometei Botnet Hits Linux for Crypto Mining - Active IOCs](https://rewterz.com/threat-advisory/prometei-botnet-hits-linux-for-crypto-mining-active-iocs) - Cybersecurity researchers have detected a significant resurgence of the Prometei botnet, with a new campaign observed since March 2025. - [Cloudflare Tunnels Abused to Deliver Python Malware - Active IOCs](https://rewterz.com/threat-advisory/cloudflare-tunnels-abused-to-deliver-python-malware-active-iocs) - A sophisticated malware campaign dubbed SERPENTINE#CLOUD has emerged, exploiting Cloudflare’s tunneling service to stealthily deliver multi-stage Python-based malware. - [Apache SeaTunnel Bug Enables Deserialization Attack](https://rewterz.com/threat-advisory/apache-seatunnel-bug-enables-deserialization-attack) - A critical security vulnerability (CVE-2025-32896) has been identified in Apache SeaTunnel, - [CVE-2025-49715 - Microsoft Dynamics 365 Vulnerability](https://rewterz.com/threat-advisory/cve-2025-49715-microsoft-dynamics-365-vulnerability) - Exposure of private personal information to an unauthorized actor in Microsoft Dynamics 365 FastTrack Implementation Assets - [Lumma Stealer Malware aka LummaC - Active IOCs](https://rewterz.com/threat-advisory/lumma-stealer-malware-aka-lummac-active-iocs-20) - Lumma is an information stealer that is sold as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums and Telegram. - [Multiple Adobe Experience Manager Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-experience-manager-vulnerabilities-21) - Adobe Experience Manager versions are affected by a stored Cross-Site Scripting (XSS) vulnerability - [Apache Traffic Server DoS via Memory Exhaustion](https://rewterz.com/threat-advisory/apache-traffic-server-dos-via-memory-exhaustion) - A critical remote Denial-of-Service (DoS) vulnerability, tracked as CVE-2025-49763, has been discovered in Apache Traffic Server, - [100K WordPress Sites Vulnerable via MCP AI Engine Exploit](https://rewterz.com/threat-advisory/100k-wordpress-sites-vulnerable-via-mcp-ai-engine-exploit) - A critical vulnerability, CVE-2025-5071, has been discovered in the WordPress AI Engine plugin, - [60 GitHub Repos Used to Host Windows Malware - Active IOCs](https://rewterz.com/threat-advisory/60-github-repos-used-to-host-windows-malware-active-iocs) - A sophisticated software supply chain attack orchestrated by a threat actor known as Banana Squad has compromised over 60 GitHub repositories, - [Multiple IBM Sterling B2B Integrator and IBM Sterling File Gateway Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-sterling-b2b-integrator-and-ibm-sterling-file-gateway-vulnerabilities) - IBM Sterling B2B Integrator and IBM Sterling File Gateway could allow a local user to obtain sensitive information - [CVE-2025-6151 - TP-Link TL-WR940N Vulnerability](https://rewterz.com/threat-advisory/cve-2025-6151-tp-link-tl-wr940n-vulnerability) - A vulnerability, which was classified as critical, has been found in TP-Link TL-WR940N. - [Multiple D-Link Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-products-vulnerabilities-16) - A vulnerability classified as critical has been found in D-Link DIR-665. - [ICS: Multiple Siemens Products Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-siemens-products-vulnerabilities-29) - A vulnerability has been identified in Siemens RUGGEDCOM ROX. - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-37) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [Multiple Dell Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-dell-products-vulnerabilities-13) - Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-45) - A use-after-free vulnerability in the Profiler component of Google Chrome, - [Insecure GitHub Actions Expose Critical MITRE And Splunk Flaws](https://rewterz.com/threat-advisory/insecure-github-actions-expose-critical-mitre-and-splunk-flaws) - A comprehensive investigation has uncovered serious vulnerabilities in GitHub Actions workflows across a wide array of open-source repositories, - [Fake CAPTCHA Drops LightPerlGirl Malware - Active IOCs](https://rewterz.com/threat-advisory/fake-captcha-drops-lightperlgirl-malware-active-iocs) - Cybersecurity researchers have identified a sophisticated malware campaign named LightPerlGirl, - [CVE-2025-33122 - IBM i Vulnerability](https://rewterz.com/threat-advisory/cve-2025-33122-ibm-i-vulnerability) - IBM i could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i - [Multiple Adobe Experience Manager Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-experience-manager-vulnerabilities-20) - Adobe Experience Manager versions are affected by a stored Cross-Site Scripting (XSS) vulnerability - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-46) - Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. - [CVE-2025-23252 - NVIDIA NVDebug Tool Vulnerability](https://rewterz.com/threat-advisory/cve-2025-23252-nvidia-nvdebug-tool-vulnerability) - The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. - [Multiple Trend Micro Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-trend-micro-products-vulnerabilities-5) - Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-44) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-86) - Update the WordPress plugin to the latest available version. - [Multiple Apache Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apache-products-vulnerabilities-35) - Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. - [CISA Warns of iOS 0-Click Exploit](https://rewterz.com/threat-advisory/cisa-warns-of-ios-0-click-exploit) - A critical zero-click vulnerability, tracked as CVE-2025-43200, has been added by CISA to its Known Exploited Vulnerabilities (KEV) catalog - [CVE-2025-6121 - D-Link DIR-632 Vulnerability](https://rewterz.com/threat-advisory/cve-2025-6121-d-link-dir-632-vulnerability) - A vulnerability, which was classified as critical, has been found in D-Link DIR-632 FW103B08. - [MassLogger Malware - Active IOCs](https://rewterz.com/threat-advisory/masslogger-malware-active-iocs-14) - MassLogger, a .NET credential stealer, is a keylogger and stealer malware. MassLogger's prime objective is data extraction or information theft, such as bank account and/or credit card details. - [Multiple Dell Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-dell-products-vulnerabilities-12) - An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. - [Defender Spoofing Bug Allows Privilege Escalation ABD AD Access](https://rewterz.com/threat-advisory/defender-spoofing-bug-allows-privilege-escalation-abd-ad-access) - A critical spoofing vulnerability, tracked as CVE-2025-26685, affects Microsoft Defender for Identity (MDI) - [IBM Backup Services Flaw Allows Privilege Escalation](https://rewterz.com/threat-advisory/ibm-backup-services-flaw-allows-privilege-escalation) - A critical vulnerability, tracked as CVE-2025-33108, has been discovered in IBM Backup, Recovery, and Media Services (BRMS) for the i platform, - [VexTrio Hacks Hundreds of WordPress Sites for TDS Campaign - Active IOCs](https://rewterz.com/threat-advisory/vextrio-hacks-hundreds-of-wordpress-sites-for-tds-campaign-active-iocs) - VexTrio, a long-standing cybercriminal operation active since at least 2015, has executed one of the largest known compromise campaigns targeting WordPress websites, - [Multiple Adobe Experience Manager Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-experience-manager-vulnerabilities-19) - Adobe Experience Manager versions are affected by a stored Cross-Site Scripting (XSS) vulnerability - [CVE-2025-4613 - Trend Micro Maximum Security Vulnerability](https://rewterz.com/threat-advisory/cve-2025-4613-trend-micro-maximum-security-vulnerability) - This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Maximum Security. - [Multiple IBM Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-products-vulnerabilities-47) - IBM Cognos Analytics stores source code on the web server, which could aid in further attacks against the system. - [Qilin Ransomware aka Agenda - Active IOCs](https://rewterz.com/threat-advisory/qilin-ransomware-aka-agenda-active-iocs-2) - Qilin ransomware, formerly known as Agenda, is a Russian-speaking ransomware-as-a-service (RaaS) operation that emerged in July 2022. - [FormBook Malware - Active IOCs](https://rewterz.com/threat-advisory/formbook-malware-active-iocs-24) - FormBook is an infostealer malware that was first identified in 2016. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-45) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [IBM QRadar SIEM Bugs Enable Command Execution](https://rewterz.com/threat-advisory/ibm-qradar-siem-bugs-enable-command-execution) - IBM QRadar SIEM has been found vulnerable to multiple high-severity flaws, - [DragonForce Ransomware - Active IOCs](https://rewterz.com/threat-advisory/dragonforce-ransomware-active-iocs-3) - DragonForce Ransomware is a relatively new but highly disruptive ransomware strain that emerged in mid-2023 and gained prominence throughout 2024. - [Multiple IBM QRadar SIEM Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-qradar-siem-vulnerabilities) - IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user. - [EchoLeak: Zero-Click AI Exploit Exposes Microsoft 365 Copilot Data](https://rewterz.com/threat-advisory/echoleak-zero-click-ai-exploit-exposes-microsoft-365-copilot-data) - A critical zero-click vulnerability dubbed EchoLeak (CVE-2025-32711) has been discovered in Microsoft 365 Copilot, - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-45) - Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. - [MeterPreter Malware - Active IOCs](https://rewterz.com/threat-advisory/meterpreter-malware-active-iocs-5) - Meterpreter - a trojan-type program - enables attackers to take control of affected machines remotely. - [North Korean APT Kimsuky aka Black Banshee - Active IOCs](https://rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-50) - Kimsuky is a North Korean advanced persistent threat (APT) group, also known as "Black Banshee". - [Cisco VPN Bug Enables DoS Attack](https://rewterz.com/threat-advisory/cisco-vpn-bug-enables-dos-attack) - A newly disclosed critical vulnerability (CVE-2025-20271) affects Cisco Meraki MX and Z Series devices running AnyConnect VPN, - [STRRAT Malware - Active IOCs](https://rewterz.com/threat-advisory/strrat-malware-active-iocs-7) - STRRat is a Java-based Remote-Access Trojan (RAT) with a slew of malicious features, notably information theft and backdoor capabilities. - [Multiple Cisco Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-cisco-products-vulnerabilities-25) - A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway - [APT29 Bypasses Gmail 2FA Using App Passwords - Active IOCs](https://rewterz.com/threat-advisory/apt29-bypasses-gmail-2fa-using-app-passwords-active-iocs) - A Russian-linked hacking group, believed to be APT29 (also known as Cozy Bear), has been carrying out a sophisticated phishing campaign - [End-of-Life TP-Link Routers Become Gateway for Remote Attacks](https://rewterz.com/threat-advisory/end-of-life-tp-link-routers-become-gateway-for-remote-attacks) - Hackers are actively exploiting a critical vulnerability in outdated TP-Link routers, - [SideWinder APT Group aka Rattlesnake – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-active-iocs-22) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [Linux Bugs Let Attackers Gain Root Access](https://rewterz.com/threat-advisory/linux-bugs-let-attackers-gain-root-access) - The danger of this vulnerability chain lies in its exploitation of fundamental Linux system services - [Akira Ransomware - Active IOCs](https://rewterz.com/threat-advisory/akira-ransomware-active-iocs-10) - Akira ransomware is a sophisticated cyber threat that first emerged in March 2023 and operates under a Ransomware-as-a-Service (RaaS) model. - [Chrome Zero-Day Exploited by TaxOff for Trinper Attack](https://rewterz.com/threat-advisory/chrome-zero-day-exploited-by-taxoff-for-trinper-attack) - A serious security bug in Google Chrome was used by a hacking group called TaxOff to secretly install a backdoor named Trinper on victims' devices. - [Best Practices for Integrating XDR into Security Operations](https://rewterz.com/blog/best-practices-for-integrating-xdr-into-security-operations) - Discover expert-recommended best practices for integrating Extended Detection and Response (XDR) into your security operations. Learn how Rewterz helps streamline threat detection, response, and incident management. - [ICS: Multiple Fuji Electric Smart Editor Zero-Day Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-fuji-electric-smart-editor-zero-day-vulnerabilities) - Fuji Electric Smart Editor is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-44) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [New Chaos RAT Variants Target Windows and Linux - Active IOCs](https://rewterz.com/threat-advisory/new-chaos-rat-variants-target-windows-and-linux-active-iocs) - Cybersecurity researchers have uncovered advanced new variants of Chaos RAT, - [Qilin Ransomware aka Agenda - Active IOCs](https://rewterz.com/threat-advisory/qilin-ransomware-aka-agenda-active-iocs) - Qilin ransomware, formerly known as Agenda, is a Russian-speaking ransomware-as-a-service (RaaS) operation that emerged in July 2022. - [Kimsuky and Konni APT Groups Intensify Cyberattacks](https://rewterz.com/threat-advisory/kimsuky-and-konni-apt-groups-intensify-cyberattacks) - North Korean state-sponsored APT groups Kimsuky and Konni have recently intensified their cyber espionage campaigns, - [CVE-2025-43200 - Multiple Apple Products Vulnerability Exploit in the Wild](https://rewterz.com/threat-advisory/cve-2025-43200-multiple-apple-products-vulnerability-exploit-in-the-wild) - Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals. - [RedLine Stealer - Active IOCs](https://rewterz.com/threat-advisory/redline-stealer-active-iocs-36) - Redline Stealer is a type of malware that is used to steal sensitive information from infected systems. - [CVE-2025-33108 - IBM i Vulnerability](https://rewterz.com/threat-advisory/cve-2025-33108-ibm-i-vulnerability) - IBM Backup, Recovery and Media Services for i could allow a user with the capability to compile or restore a program to gain elevated privileges - [Patchwork APT Group - Active IOCs](https://rewterz.com/threat-advisory/patchwork-apt-group-active-iocs-6) - Patchwork is an Advanced Persistent Threat (APT) group active since at least 2014. - [Multiple Palo Alto Networks Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-palo-alto-networks-products-vulnerabilities-6) - An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma Access Browser enables users to bypass certain data control policies. - [Multiple Fortinet Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-fortinet-products-vulnerabilities-23) - A authorization bypass through user-controlled key in Fortinet FortiPortal versions may allow an authenticated attacker to view unauthorized device information - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-85) - Update the WordPress plugin to the latest available version. - [Multiple Microsoft Windows Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-windows-vulnerabilities-22) - Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. - [Windows SMB Zero-Day Exploited via Kerberos Relay](https://rewterz.com/threat-advisory/windows-smb-zero-day-exploited-via-kerberos-relay) - A newly discovered critical zero-day vulnerability tracked as CVE-2025-33073 affects multiple Windows systems - [Graphite Spyware Hits iOS Users - Active IOCs](https://rewterz.com/threat-advisory/graphite-spyware-hits-ios-users-active-iocs) - A highly advanced spyware known as Graphite, developed by the Israeli firm Paragon, - [Multiple Fortinet Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-fortinet-products-vulnerabilities-22) - Fortinet FortiOS and FortiProxy could allow a remote attacker to bypass security restrictions to add SSH key files on the system via crafted CLI requests, - [Multiple Mozilla Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-mozilla-products-vulnerabilities-7) - Mozilla Firefox could allow a remote attacker to obtain sensitive information, - [Multiple SAP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-sap-products-vulnerabilities-22) - SAP NetWeaver Visual Composer could allow a remote authenticated attacker to traverse directories on the system to read or modify arbitrary files. - [AsyncRAT - Active IOCs](https://rewterz.com/threat-advisory/asyncrat-active-iocs-21) - AsyncRAT is an open-source tool designed for remote monitoring via encrypted connections. - [Multiple Trend Micro Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-trend-micro-products-vulnerabilities-4) - This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Password Manager. - [Lumma Stealer Malware aka LummaC - Active IOCs](https://rewterz.com/threat-advisory/lumma-stealer-malware-aka-lummac-active-iocs-19) - Lumma is an information stealer that is sold as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums and Telegram. - [Hackers Target Apache Tomcat Manager From 400 IPs](https://rewterz.com/threat-advisory/hackers-target-apache-tomcat-manager-from-400-ips) - A massive, coordinated cyberattack campaign targeting Apache Tomcat Manager interfaces was detected, peaking on June 5, 2025. - [Multiple GitLab Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-gitlab-products-vulnerabilities-17) - An HTML injection/XSS vulnerability in GitLab CE/EE. Under certain conditions, malicious HTML can be injected into the search page, potentially hijacking user accounts. - [PAN-OS Flaw Lets Admin Execute Root Commands](https://rewterz.com/threat-advisory/pan-os-flaw-lets-admin-execute-root-commands) - A critical command injection vulnerability, tracked as CVE-2025-4231, has been discovered in Palo Alto Networks’ PAN-OS operating system, - [Task Scheduler Flaw Enables Privilege Escalation](https://rewterz.com/threat-advisory/task-scheduler-flaw-enables-privilege-escalation) - A critical elevation of privilege vulnerability, CVE-2025-33067, has been identified in the Windows Task Scheduler - [Akira Ransomware - Active IOCs](https://rewterz.com/threat-advisory/akira-ransomware-active-iocs-9) - Akira ransomware is a sophisticated cyber threat that first emerged in March 2023 and operates under a Ransomware-as-a-Service (RaaS) model. - [Multiple Trend Micro Endpoint Encryption Zero-Day Vulnerabilities](https://rewterz.com/threat-advisory/multiple-trend-micro-endpoint-encryption-zero-day-vulnerabilities) - This vulnerability allows remote malicious users to escalate privileges on affected installations of Trend Micro Endpoint Encryption. - [Multiple Trend Micro Products Zero-Day Vulnerabilities](https://rewterz.com/threat-advisory/multiple-trend-micro-products-zero-day-vulnerabilities) - This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex Central. - [Multiple Mozilla Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-mozilla-products-vulnerabilities-6) - Mozilla Thunderbird could allow a remote attacker to obtain sensitive information, - [Multiple Microsoft Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-microsoft-products-vulnerabilities-44) - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. - [Multiple SolarWinds SWOSH Vulnerabilities](https://rewterz.com/threat-advisory/multiple-solarwinds-swosh-vulnerabilities) - SolarWinds SWOSH is vulnerable to a stored cross-site scripting vulnerability due to an unsanitized field in the URL. - [Multiple SAP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-sap-products-vulnerabilities-21) - SAP NetWeaver (ABAP Keyword Documentation) is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-43) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Multiple Google Chrome Vulnerabilities](https://rewterz.com/threat-advisory/multiple-google-chrome-vulnerabilities-44) - Google Chrome could allow a remote attacker to execute arbitrary code on the system, - [Windows CLFS Driver Vulnerability Allows Privilege Escalation](https://rewterz.com/threat-advisory/windows-clfs-driver-vulnerability-allows-privilege-escalation) - A critical privilege escalation vulnerability, tracked as CVE-2025-32713, has been discovered in the Windows Common Log File System (CLFS) Driver. - [Windows RDP Vulnerability Enables Remote Code Execution](https://rewterz.com/threat-advisory/windows-rdp-vulnerability-enables-remote-code-execution) - On June 10, 2025, Microsoft disclosed CVE-2025-32710, a critical Remote Code Execution (RCE) vulnerability affecting multiple versions of Windows Server, - [Multiple Adobe Acrobat Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-acrobat-vulnerabilities) - Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability - [Bitter APT - Active IOCs](https://rewterz.com/threat-advisory/bitter-apt-active-iocs-30) - APT-17, also known as "Bitter APT" or "DeputyDog" is a state-sponsored cyber espionage group that is believed to operate out of China. - [ICS: Multiple Siemens Products Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-siemens-products-vulnerabilities-28) - Siemens Energy Services could allow a remote attacker to gain control of G5DFR component and tamper with outputs from the device, - [Multiple SAP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-sap-products-vulnerabilities-20) - SAP Business Objects Business Intelligence Platform is vulnerable to server-side request forgery, caused by improper validation of HTTP requests. - [Multiple Apache Cloudstack Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apache-cloudstack-vulnerabilities) - Apache CloudStack could allow a remote authenticated attacker to obtain the API key - [Multiple QNAP File Station 5 Vulnerabilities](https://rewterz.com/threat-advisory/multiple-qnap-file-station-5-vulnerabilities) - An out-of-bounds read vulnerability has been reported to affect File Station 5. - [Multiple Adobe Acrobat Reader Zero-Day Vulnerabilities](https://rewterz.com/threat-advisory/multiple-adobe-acrobat-reader-zero-day-vulnerabilities) - Acrobat Reader versions are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. - [ICS: Multiple Schneider Electric Products Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-schneider-electric-products-vulnerabilities-5) - Refer to Schneider Electric Security Advisory for patch, upgrade, or suggested workaround information. - [Gafgyt aka Bashlite Malware - Active IOCs](https://rewterz.com/threat-advisory/gafgyt-aka-bashlite-malware-active-iocs-16) - Gafgyt is a type of malware that is used to conduct Distributed Denial of Service (DDoS) attacks. - [GuLoader Malspam Campaign - Active IOCs](https://rewterz.com/threat-advisory/guloader-malspam-campaign-active-iocs-12) - Since 2019, Guloader has been in operation as a downloader. GuLoader spreads through spam campaigns with malicious archived attachments. - [Fog Ransomware Uses Pentest Tools - Active IOCs](https://rewterz.com/threat-advisory/fog-ransomware-uses-pentest-tools-active-iocs) - Fog ransomware represents a growing cyber threat where attackers misuse legitimate IT tools for malicious purposes. - [SideWinder APT Group aka Rattlesnake – Active IOCs](https://rewterz.com/threat-advisory/sidewinder-apt-group-aka-rattlesnake-active-iocs-21) - The SideWinder APT (Advanced Persistent Threat) Group is a sophisticated cyber espionage group active since at least 2012. - [Ivanti Vulnerabilities Expose SQL Credentials](https://rewterz.com/threat-advisory/ivanti-vulnerabilities-expose-sql-credentials) - Ivanti has released urgent security updates for its Workspace Control platform to address three high-severity vulnerabilities, - [FortiAnalyzer-Cloud RCE via OS Command Injection](https://rewterz.com/threat-advisory/fortianalyzer-cloud-rce-via-os-command-injection) - Fortinet, a global leader in cybersecurity, has addressed a high-severity OS command injection vulnerability, - [Critical DanaBot C2 Flaw Unmasks Threat Actors, Exposing Crypto Keys - Active IOCs](https://rewterz.com/threat-advisory/critical-danabot-c2-flaw-unmasks-threat-actors-exposing-crypto-keys-active-iocs) - DanaBot, which emerged in 2018 as a comprehensive Malware-as-a-Service (MaaS) platform, - [ICS: Multiple Schneider Electric Products Vulnerabilities](https://rewterz.com/threat-advisory/ics-multiple-schneider-electric-products-vulnerabilities-4) - Refer to Schneider Electric Security Advisory for patch, upgrade, or suggested workaround information. - [NJRAT - Active IOCs](https://rewterz.com/threat-advisory/njrat-active-iocs-15) - NjRat is a Remote Access Trojan, which is found leveraging Pastebin to deliver a second-stage payload after initial infection. - [Quasar RAT aka CinaRAT - Active IOCs](https://rewterz.com/threat-advisory/quasar-rat-aka-cinarat-active-iocs-15) - Quasar malware is a Remote Access Trojan (RAT) that is often abused by cybercriminals to take remote control over users' computers for malicious purposes. - [Akira Ransomware - Active IOCs](https://rewterz.com/threat-advisory/akira-ransomware-active-iocs-8) - Akira ransomware is a sophisticated cyber threat that first emerged in March 2023 and operates under a Ransomware-as-a-Service (RaaS) model. - [Multiple Apple macOS Vulnerabilities](https://rewterz.com/threat-advisory/multiple-apple-macos-vulnerabilities-5) - Apple macOS Sequoia could allow a local attacker to bypass Same Origin Policy, caused by an issue in the Safari component when using a specially crafted application. - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-84) - Update the WordPress plugin to the latest available version. - [Cisco Nexus Dashboard Flaw Allows Device Impersonation](https://rewterz.com/threat-advisory/cisco-nexus-dashboard-flaw-allows-device-impersonation) - A critical vulnerability CVE-2025-20163 affecting Cisco Nexus Dashboard Fabric Controller (NDFC) - [Jenkins Gatling Plugin Flaw Enables CSP Bypass](https://rewterz.com/threat-advisory/jenkins-gatling-plugin-flaw-enables-csp-bypass) - A critical Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2025-5806, has been identified in the Jenkins Gatling Plugin - [CVE-2025-3835 - Zoho ManageEngine Exchange Reporter Vulnerability](https://rewterz.com/threat-advisory/cve-2025-3835-zoho-manageengine-exchange-reporter-vulnerability) - Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. - [Remcos RAT - Active IOCs](https://rewterz.com/threat-advisory/remcos-rat-active-iocs-24) - Remcos malware has been operating since 2016. This RAT was originally promoted as genuine software for remote control of Microsoft Windows from XP onwards and is frequently found in phishing attempts due to its capacity to completely infect an afflicted machine. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-43) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Microsoft Office Flaws Allow Remote Code Execution by Attackers](https://rewterz.com/threat-advisory/microsoft-office-flaws-allow-remote-code-execution-by-attackers) - Multiple critical vulnerabilities have been discovered in Microsoft Office, posing significant security risks across Windows, macOS, and Android platforms. - [GitHub Phishing Targets Developers to Steal Tokens](https://rewterz.com/threat-advisory/github-phishing-targets-developers-to-steal-tokens) - A newly uncovered phishing campaign is exploiting GitHub’s OAuth2 device authorization flow to compromise developer accounts and steal authentication tokens. - [Unsubscribe Links Used in Phishing Attacks](https://rewterz.com/threat-advisory/unsubscribe-links-used-in-phishing-attacks) - When our inbox gets too full, the natural reaction is to click the “unsubscribe” link at the bottom of these emails to stop receiving them. - [North Korean APT Kimsuky aka Black Banshee - Active IOCs](https://rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-49) - Kimsuky is a North Korean advanced persistent threat (APT) group, also known as "Black Banshee". - [APT Hackers Exploit Windows WebDAV 0-Day to Deploy Malware - Active IOCs](https://rewterz.com/threat-advisory/apt-hackers-exploit-windows-webdav-0-day-to-deploy-malware-active-iocs) - The vulnerability allowed remote code execution (RCE) by manipulating the working directory used by legitimate Windows tools. - [FortiOS SSL-VPN Vulnerability Exposes Full VPN Settings](https://rewterz.com/threat-advisory/fortios-ssl-vpn-vulnerability-exposes-full-vpn-settings) - Fortinet has disclosed a newly discovered vulnerability, CVE-2025-25250, affecting its FortiOS SSL-VPN web-mode feature. - [CVE-2025-33053 - Microsoft WebDAV Zero-Day Vulnerability Exploit in the Wild](https://rewterz.com/threat-advisory/cve-2025-33053-microsoft-webdav-zero-day-vulnerability-exploit-in-the-wild) - External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network. - [Multiple QNAP Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-qnap-products-vulnerabilities-7) - A command injection vulnerability has been reported to affect several QNAP operating system versions. - [Akira Ransomware - Active IOCs](https://rewterz.com/threat-advisory/akira-ransomware-active-iocs-7) - Akira ransomware is a sophisticated cyber threat that first emerged in March 2023 and operates under a Ransomware-as-a-Service (RaaS) model. - [Cisco IMC Flaw Allows Attackers Elevated Access to Internal Services](https://rewterz.com/threat-advisory/cisco-imc-flaw-allows-attackers-elevated-access-to-internal-services) - The Cisco Integrated Management Controller (IMC) has been found to contain a critical privilege escalation vulnerability (CVE-2025-20261) - [Safari XSS Bug Exploits JS Error Handling for Code Execution](https://rewterz.com/threat-advisory/safari-xss-bug-exploits-js-error-handling-for-code-execution) - A newly discovered cross-site scripting (XSS) vulnerability in Safari highlights a critical flaw in the browser’s TypeError exception handling mechanism. - [Rhadamanthys Stealer - Active IOCs](https://rewterz.com/threat-advisory/rhadamanthys-stealer-active-iocs-11) - Rhadamanthys is a type of malware known as a stealer, which is designed to steal sensitive information from infected computers. - [CVE-2025-5806 - Jenkins Gatling Plugin Vulnerability](https://rewterz.com/threat-advisory/cve-2025-5806-jenkins-gatling-plugin-vulnerability) - Jenkins Gatling Plugin serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins, - [CVE-2025-27531 - Apache InLong Vulnerability](https://rewterz.com/threat-advisory/cve-2025-27531-apache-inlong-vulnerability) - Refer to Apache Security Advisory for patch, upgrade, or suggested workaround information. - [Gh0st RAT - Active IOCs](https://rewterz.com/threat-advisory/gh0st-rat-active-iocs-5) - Gh0st RAT is a remote access trojan (RAT) that was first discovered in 2008. - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-83) - Update the WordPress plugin to the latest available version. - [Dell PowerScale Bug Enables Unauthorized Access](https://rewterz.com/threat-advisory/dell-powerscale-bug-enables-unauthorized-access) - Two severe security vulnerabilities have been disclosed in Dell PowerScale OneFS, - [Lumma Stealer Malware aka LummaC - Active IOCs](https://rewterz.com/threat-advisory/lumma-stealer-malware-aka-lummac-active-iocs-18) - Lumma is an information stealer that is sold as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums and Telegram. - [MassLogger Malware - Active IOCs](https://rewterz.com/threat-advisory/masslogger-malware-active-iocs-13) - MassLogger, a .NET credential stealer, is a keylogger and stealer malware. MassLogger's prime objective is data extraction or information theft, such as bank account and/or credit card details. - [LokiBot Malware - Active IOCs](https://rewterz.com/threat-advisory/lokibot-malware-active-iocs-18) - In early 2016, LokiBot was originally made available on underground forums for cybercriminals to use against Microsoft Android phones. - [DarkCrystal RAT aka DCRat – Active IOCs](https://rewterz.com/threat-advisory/darkcrystal-rat-aka-dcrat-active-iocs-42) - DCRat, a Russian backdoor, was initially introduced in 2018 but rebuilt and relaunched a year later. - [Malicious Chrome Extensions Secretly Control User Browsers - Active IOCs](https://rewterz.com/threat-advisory/malicious-chrome-extensions-secretly-control-user-browsers-active-iocs) - A new browser-based cyber threat has come to light as a security firm exposes a covert network of malicious Chrome extensions operating as “sleeper agents.” - [VMware NSX XSS Flaw Enables Malicious Code Injection](https://rewterz.com/threat-advisory/vmware-nsx-xss-flaw-enables-malicious-code-injection) - VMware disclosed three critical stored Cross-Site Scripting (XSS) vulnerabilities affecting its NSX network virtualization platform, - [Apache Tomcat DoS Vulnerability PoC Released](https://rewterz.com/threat-advisory/apache-tomcat-dos-vulnerability-poc-released) - A newly disclosed vulnerability, CVE-2025-31650, presents a serious remote denial-of-service (DoS) threat to Apache Tomcat servers running versions 10.1.10 through 10.1.39. - [Chrome Extensions Vulnerability Exposes API Keys, Secrets, and Tokens](https://rewterz.com/threat-advisory/chrome-extensions-vulnerability-exposes-api-keys-secrets-and-tokens) - A critical security vulnerability has been uncovered in several widely used Chrome extensions, - [Multiple IBM Verify Identity Access Vulnerabilities](https://rewterz.com/threat-advisory/multiple-ibm-verify-identity-access-vulnerabilities) - IBM Verify Identity Access Digital Credentials could allow an authenticated user to crash the service with a specially crafted POST request. - [CVE-2025-47966 - Microsoft Power Automate Vulnerability](https://rewterz.com/threat-advisory/cve-2025-47966-microsoft-power-automate-vulnerability) - Exposure of sensitive information to an unauthorized actor in Microsoft Power Automate allows an unauthorized attacker to elevate privileges over a network. - [Akira Ransomware - Active IOCs](https://rewterz.com/threat-advisory/akira-ransomware-active-iocs-6) - Akira ransomware is a sophisticated cyber threat that first emerged in March 2023 and operates under a Ransomware-as-a-Service (RaaS) model. - [BlackMoon Banking Trojan aka KrBanker - Active IOCs](https://rewterz.com/threat-advisory/blackmoon-banking-trojan-aka-krbanker-active-iocs-5) - BlackMoon, also known as KrBanker, is a banking Trojan that first emerged in September 2015, initially targeting South Korean bank s - [CoinMiner Malware - Active IOCs](https://rewterz.com/threat-advisory/coinminer-malware-active-iocs-10) - CoinMiner is a malware designed to secretly mine cryptocurrencies, such as Bitcoin, on infected computers. - [Multiple WordPress Plugins Vulnerabilities](https://rewterz.com/threat-advisory/multiple-wordpress-plugins-vulnerabilities-82) - Update the WordPress plugin to the latest available version. - [New Phishing Attack Hides Malicious Link from Outlook Users](https://rewterz.com/threat-advisory/new-phishing-attack-hides-malicious-link-from-outlook-users) - A sophisticated phishing technique has been observed exploiting Microsoft Outlook's legacy HTML rendering engine - [NetSupport RAT Delivered Through Spoofed Verification Pages - Active IOCs](https://rewterz.com/threat-advisory/netsupport-rat-delivered-through-spoofed-verification-pages-active-iocs) - Security researchers have identified an ongoing and highly deceptive malware campaign that exploits user trust through spoofed websites - [Cisco ISE Vulnerability Allows Remote to Access Sensitive Data](https://rewterz.com/threat-advisory/cisco-ise-vulnerability-allows-remote-to-access-sensitive-data) - A critical vulnerability, tracked as CVE-2025-20286 with a CVSS score of high, has been discovered in Cisco Identity Services Engine (ISE) - [Multiple VMware Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-vmware-products-vulnerabilities-3) - VMware NSX Manager UI is vulnerable to a stored cross-site scripting (XSS) attack due to improper input validation. - [ViperSoftX Evolves: New PowerShell Malware - Active IOCs](https://rewterz.com/threat-advisory/vipersoftx-evolves-new-powershell-malware-active-iocs) - A newly discovered variant of the ViperSoftX malware family emerged in early 2025, - [Multiple D-Link DIR-816 Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-dir-816-vulnerabilities) - A vulnerability has been found in the D-Link DIR-816 and classified as critical. - [CVE-2025-36564 - Dell Encryption Admin Utilities Vulnerability](https://rewterz.com/threat-advisory/cve-2025-36564-dell-encryption-admin-utilities-vulnerability) - Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. - [Mirai Botnet aka Katana - Active IOCs](https://rewterz.com/threat-advisory/mirai-botnet-aka-katana-active-iocs-42) - The Mirai botnet is a type of malware that infectsIoT) devices, such as routers, security cameras, and other smart devices, to launch DDoS attacks. - [Google Flaw Exposed Phone Numbers of Any User to Attackers](https://rewterz.com/threat-advisory/google-flaw-exposed-phone-numbers-of-any-user-to-attackers) - A critical security vulnerability in Google’s legacy account recovery system allowed attackers to obtain the phone numbers of Google users through a highly efficient brute-force attack, - [Mirai Exploits Wazuh API Vulnerability in Latest Malware Campaign - Active IOCs](https://rewterz.com/threat-advisory/mirai-exploits-wazuh-api-vulnerability-in-latest-malware-campaign-active-iocs) - A critical remote code execution (RCE) vulnerability in Wazuh servers, - [Multiple Cisco Products Vulnerabilities](https://rewterz.com/threat-advisory/multiple-cisco-products-vulnerabilities-24) - A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker - [PumaBot Targets IoT Devices via SSH Brute-Force - Active IOCs](https://rewterz.com/threat-advisory/pumabot-targets-iot-devices-via-ssh-brute-force-active-iocs) - PumaBot is a newly discovered, sophisticated Linux-based botnet developed in the Go programming language, - [IBM QRadar Vulnerabilities Expose Config Files](https://rewterz.com/threat-advisory/ibm-qradar-vulnerabilities-expose-config-files) - IBM has disclosed multiple critical vulnerabilities in its QRadar Suite Software and Cloud Pak for Security, - [CVE-2025-5492 - D-Link DI-500WF-WT Vulnerability](https://rewterz.com/threat-advisory/cve-2025-5492-d-link-di-500wf-wt-vulnerability) - A vulnerability has been found in D-Link DI-500WF-WT and classified as critical. - [Multiple D-Link DCS-932L Vulnerabilities](https://rewterz.com/threat-advisory/multiple-d-link-dcs-932l-vulnerabilities) - A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. - [CVE-2025-5495 - NETGEAR WNR614 Firmware Vulnerability](https://rewterz.com/threat-advisory/cve-2025-5495-netgear-wnr614-firmware-vulnerability) - A vulnerability was found in Netgear WNR614. It has been classified as critical. - [GitHub Projects at Risk Due to Insecure Path Handling](https://rewterz.com/threat-advisory/github-projects-at-risk-due-to-insecure-path-handling) - A new security study has uncovered a serious vulnerability that affects more than 1,700 open-source GitHub projects. ## Pages - [AI-Powered MSSP & Managed SOC Services](https://rewterz.com/) - Transform security operations with Rewterz AI Powered SOC. Automate threat detection, prioritize risks, and accelerate response with AI-driven security. - [Request A Demo](https://rewterz.com/requestademo) - Request a demo to see how Rewterz AI Powered SOC enables autonomous security operations with AI-driven threat detection and faster response. - [Contact](https://rewterz.com/contact) - Contact Rewterz to learn more about our AI Powered SOC, cybersecurity services, and threat intelligence solutions for modern enterprises. - [Threat Advisories](https://rewterz.com/threat-advisories) - Stay updated with the latest cyber threat advisories, security alerts, and threat intelligence insights from Rewterz to respond to emerging threats. - [Blogs](https://rewterz.com/blogs) - Explore the Rewterz blog for insights on cybersecurity, security operations, and emerging cyber threats and industry trends. - [How SOC Works](https://rewterz.com/how-soc-works) - Learn how AI SOC works, including AI-driven threat detection, alert correlation, investigation, and automated response in modern security operations. - [مركز عمليات أمنية مُدار ومدعوم بالذكاء الاصطناعي للمؤسسات الحديثة.](https://rewterz.com/ar/عمليات-أمن-سيبراني-قابلة-للتوسع-فعليً) - تقدم ريوترز خدمات أمن مُدارة مدعومة بالذكاء الاصطناعي تقلل ضوضاء الإنذارات، وتسرّع عمليات التحقيق، وتمكّن الاستجابة بإشراف بشري ضمن بيئات مؤسسية معقدة في الشرق الأوسط. - [التقرير السنوي لاستخبارات التهديدات 2025](https://rewterz.com/ar/التقرير-السنوي-لاستخبارات-التهديدات-2025) - [Annual Intelligence Threat Report 2025](https://rewterz.com/annual-intelligence-threat-report-2025) - [عمليات أمن سيبراني قابلة للتوسع فعليًا](https://rewterz.com/ar/عمليات-أمن-سيبراني-قابلة-للتوسع-فعليً-2) - [Privacy Policy](https://rewterz.com/privacy-policy) - [Industries We Serve](https://rewterz.com/industries-we-serve) - [Security & Compliance](https://rewterz.com/security-compliance) - [آلية عمل مركز العمليات الأمنية (SOC)](https://rewterz.com/ar/آلية-عمل-مركز-العمليات-الأمنية-soc) - [اطلب عرضًا توضيحيًا](https://rewterz.com/ar/اطلب-عرضًا-توضيحيًا) - [New2026](https://rewterz.com/new2026) - [AI SOC](https://rewterz.com/ai-soc) ## Job Openings - [Sales Engineer – Cybersecurity](https://rewterz.com/jobs/sales-engineer-cybersecurity) - About Rewterz: Rewterz is a leading cybersecurity company committed to delivering cutting-edge solutions that help organizations secure their digital assets. With a strong portfolio of services including Threat Intelligence, Managed Security, and Incident Response, Rewterz serves clients across various industries and regions. We are looking for a Technical Proposal Writer to support our business development - [IT Support Specialist](https://rewterz.com/jobs/it-support-specialist) - Experience Level: Mid-Level (2–4 years) About the Role: We are looking for a proactive and technically skilled IT Support Specialist to join our team. The ideal candidate will have hands-on experience in troubleshooting and maintaining network infrastructure and server systems, ensuring smooth operations and minimal downtime. Key Responsibilities: Provide Tier 1 and Tier 2 IT support for hardware, software, networking, and - [Technical Proposal Writer](https://rewterz.com/jobs/technical-proposal-writer) - About Rewterz: Rewterz is a leading cybersecurity company committed to delivering cutting-edge solutions that help organizations secure their digital assets. With a strong portfolio of services including Threat Intelligence, Managed Security, and Incident Response, Rewterz serves clients across various industries and regions. We are looking for a Technical Proposal Writer to support our business development - [Financial Analyst / Accounts (US Accounting & Finance)](https://rewterz.com/jobs/financial-analyst-accounts-us-accounting-finance) - About Rewterz: Rewterz is a leading cybersecurity company specializing in managed security services, threat intelligence, and security consulting. We are seeking a detail-oriented and analytical Financial Analyst / Accounts specializing in US-based accounting and finance to join our team. The ideal candidate will have a strong understanding of US GAAP, financial reporting, and compliance requirements. - [SEO & PPC Executive](https://rewterz.com/jobs/seo-ppc-executive) - About the Role We are seeking a skilled and data-driven SEO & PPC Executive to join our team. The ideal candidate should have hands-on experience in Search Engine Optimization (SEO) and a basic understanding of Pay-Per-Click (PPC) advertising. This role requires expertise in Google Search Console, GA4, and guest post outreach, along with a strong - [Graphic Designer](https://rewterz.com/jobs/graphic-designer) - About the Role We are looking for a creative and detail-oriented Graphic Designer to join our team. The ideal candidate should have at least 1 year of experience in graphic design, with a strong understanding of composition, typography, and layout principles. Hands-on expertise in Adobe Photoshop and Illustrator is required, along with basic video editing - [Marketing Executive](https://rewterz.com/jobs/marketing-executive-2) - About the Role We are seeking a dynamic and results-driven Marketing Executive to join our team. The ideal candidate will have a strong passion for marketing, excellent communication skills, and a proven ability to execute campaigns that drive business growth. Key Responsibilities Develop and execute marketing strategies to enhance brand visibility and drive engagement. Manage - [Assistant Manager- Project Management](https://rewterz.com/jobs/assistant-manager-project-management) - Responsibilities: Coordinate internal resources and third parties/vendors for the flawless execution of projects. Ensure that all projects are delivered on time, within scope, and within budget. Manage changes to the project scope, project schedule, and project costs using appropriate verification techniques. Measure project performance using appropriate systems, tools, and techniques. Report and escalate to management - [Admin Officer](https://rewterz.com/jobs/admin-officer) - Description We are seeking a highly organized and proactive Administrative Officer to join our team. The ideal candidate will be responsible for overseeing and coordinating the day-to-day administrative functions of our office, ensuring smooth and efficient operations. This role requires excellent communication skills, attention to detail, and the ability to manage multiple tasks simultaneously. Qualifications: - [Operational Technology (OT) Security Consultant](https://rewterz.com/jobs/operational-technology-ot-security-consultant) - Description At Rewterz, we are at the forefront of cybersecurity, providing cutting-edge solutions to safeguard critical infrastructure. We are looking for a highly skilled and motivated Operational Technology (OT) Security Consultant to join our team. If you are passionate about cybersecurity and have a deep understanding of OT environments, we want to hear from you! - [Inside Sales Executive](https://rewterz.com/jobs/inside-sales-executive) - Job Description: As an Inside Sales Executive at Rewterz, you will play a key role in driving our sales efforts by identifying and pursuing new business opportunities. You will be responsible for engaging potential clients, understanding their needs, and presenting our cybersecurity solutions to help them achieve their security goals. Responsibilities: Identify and qualify new - [Senior Support Engineer](https://rewterz.com/jobs/senior-support-engineer) - Location: Karachi Experience Required: 5 to 7 years Education: Bachelor's degree in IT ## Templates - [رأس جديد-2026](https://rewterz.com/ar/template-item/رأس-جديد-2026) - [New-header-2026](https://rewterz.com/template-item/new-header-2026) - [Footer-new](https://rewterz.com/template-item/footer-new) - [Footer-new](https://rewterz.com/ar/template-item/footer-new) - [Post-new-2026](https://rewterz.com/template-item/post-new-2026) - [New-home-2026](https://rewterz.com/template-item/new-home-2026) - [Services megamenu Arabic](https://rewterz.com/ar/template-item/services-megamenu-arabic) - [platform Megamenu Arabic](https://rewterz.com/ar/template-item/platform-megamenu-arabic) - [About Megamenu Arabic](https://rewterz.com/ar/template-item/about-megamenu-arabic) - [fm-new-bars](https://rewterz.com/template-item/fm-new-bars) - [new-form-bottom](https://rewterz.com/template-item/new-form-bottom) - [services-oldStyle](https://rewterz.com/template-item/services-oldstyle) - [Resources-megamenu](https://rewterz.com/template-item/resources-megamenu) - [company-megamenu](https://rewterz.com/template-item/company-megamenu) - [platform-megamenu-new](https://rewterz.com/template-item/platform-megamenu-new) - [Services-megamenu](https://rewterz.com/template-item/services-megamenu) - [Resources-megamenu](https://rewterz.com/ar/template-item/resources-megamenu) - [](https://rewterz.com/template-item/14823) ## Categories - [Blog](https://rewterz.com/category/blog) - [Rewterz News](https://rewterz.com/category/rewterz-news) - [Articles](https://rewterz.com/category/articles) - [upcoming rewterz trainings/events](https://rewterz.com/category/upcoming-rewterz-trainingsevents) - [Uncategorized](https://rewterz.com/category/uncategorized) - [Data Leakage](https://rewterz.com/category/data-leakage) - [Data Loss](https://rewterz.com/category/data-loss) - [DLP](https://rewterz.com/category/dlp) - [PCI](https://rewterz.com/category/pci) - [Penetration Test](https://rewterz.com/category/pen-test) - [Vulnerability Management](https://rewterz.com/category/vulnerability-management) - [Endpoint Security](https://rewterz.com/category/endpoint-security) - [Threats](https://rewterz.com/category/threats) - [Worms](https://rewterz.com/category/worms) - [Privacy](https://rewterz.com/category/privacy) - [Vulnerabilities](https://rewterz.com/category/vulnerabilities) - [General](https://rewterz.com/category/general) - [home_box1](https://rewterz.com/category/home_box1) - [Threat Advisory](https://rewterz.com/category/threat-advisory) - [Press Release](https://rewterz.com/category/press-release) - [home_box](https://rewterz.com/category/home_box) - [Events](https://rewterz.com/category/events) - [Articles](https://rewterz.com/ar/category/articles) - [Blog](https://rewterz.com/ar/category/blog) ## Tags - [data loss prevention](https://rewterz.com/tag/data-loss-prevention) - [data loss protection](https://rewterz.com/tag/data-loss-protection) - [DLP](https://rewterz.com/tag/dlp) - [information security](https://rewterz.com/tag/information-security) - [common myths](https://rewterz.com/tag/common-myths) - [dss tools](https://rewterz.com/tag/dss-tools) - [financial gurus](https://rewterz.com/tag/financial-gurus) - [practical security](https://rewterz.com/tag/practical-security) - [strategy and focus](https://rewterz.com/tag/strategy-and-focus) - [Black box and White box](https://rewterz.com/tag/black-box-and-white-box) - [CEH](https://rewterz.com/tag/ceh) - [CISSP](https://rewterz.com/tag/cissp) - [CPTS](https://rewterz.com/tag/cpts) - [faiz ahmad shuja](https://rewterz.com/tag/faiz-ahmad-shuja) - [GCIA](https://rewterz.com/tag/gcia) - [GCIH](https://rewterz.com/tag/gcih) - [GSEC](https://rewterz.com/tag/gsec) - [infrastructure testing](https://rewterz.com/tag/infrastructure-testing) - [OSCP](https://rewterz.com/tag/oscp) - [Penetration Testing](https://rewterz.com/tag/penetration-testing) - [Rewterz](https://rewterz.com/tag/rewterz) - [security audit](https://rewterz.com/tag/security-audit) - [Data Leakage](https://rewterz.com/tag/data-leakage) - [Data Loss](https://rewterz.com/tag/data-loss) - [pk domains](https://rewterz.com/tag/pk-domains) - [Threats](https://rewterz.com/tag/threats) - [tillmann](https://rewterz.com/tag/tillmann) - [top level domains](https://rewterz.com/tag/top-level-domains) - [Worms](https://rewterz.com/tag/worms) - [compliant company](https://rewterz.com/tag/compliant-company) - [credit card payments](https://rewterz.com/tag/credit-card-payments) - [easy target](https://rewterz.com/tag/easy-target) - [pocket pickers](https://rewterz.com/tag/pocket-pickers) - [security parameters](https://rewterz.com/tag/security-parameters) - [corporate information security](https://rewterz.com/tag/corporate-information-security) - [information security issues](https://rewterz.com/tag/information-security-issues) - [security perspective](https://rewterz.com/tag/security-perspective) - [data leakage prevention](https://rewterz.com/tag/data-leakage-prevention) - [false alarms](https://rewterz.com/tag/false-alarms) - [guidelines](https://rewterz.com/tag/guidelines) - [policy](https://rewterz.com/tag/policy) - [firewalls](https://rewterz.com/tag/firewalls) - [corporate issues](https://rewterz.com/tag/corporate-issues) - [Employee](https://rewterz.com/tag/employee) - [Trust](https://rewterz.com/tag/trust) - [Guide to patching](https://rewterz.com/tag/guide-to-patching) - [Insight](https://rewterz.com/tag/insight) - [Patching](https://rewterz.com/tag/patching) - [Vulerability Management](https://rewterz.com/tag/vulerability-management) - [DLP and employees](https://rewterz.com/tag/dlp-and-employees) - [Vulnerablility Management](https://rewterz.com/tag/vulnerablility-management) - [zero day attacks](https://rewterz.com/tag/zero-day-attacks) - [Copyright infringement](https://rewterz.com/tag/copyright-infringement) - [Piracy](https://rewterz.com/tag/piracy) - [Godaddy](https://rewterz.com/tag/godaddy) - [Vulnerability](https://rewterz.com/tag/vulnerability) - [XSS](https://rewterz.com/tag/xss) - [APT](https://rewterz.com/tag/apt) - [Intelligence](https://rewterz.com/tag/intelligence) - [StrongerSecurity](https://rewterz.com/tag/strongersecurity) - [Penetration](https://rewterz.com/tag/penetration) - [Testing](https://rewterz.com/tag/testing) - [Essential](https://rewterz.com/tag/essential) - [Business](https://rewterz.com/tag/business) - [Oracle](https://rewterz.com/tag/oracle) - [Cloud](https://rewterz.com/tag/cloud) - [Breach Controversy](https://rewterz.com/tag/breach-controversy) - [Navigating Denials](https://rewterz.com/tag/navigating-denials) - [Extortion](https://rewterz.com/tag/extortion) - [Ethical Responsibility](https://rewterz.com/tag/ethical-responsibility) - [LevelsofSOC](https://rewterz.com/tag/levelsofsoc) - [Maturity](https://rewterz.com/tag/maturity) - [Steps](https://rewterz.com/tag/steps) - [for Continual](https://rewterz.com/tag/for-continual) - [Service](https://rewterz.com/tag/service) - [Improvement](https://rewterz.com/tag/improvement) - [cyrity](https://rewterz.com/tag/cyrity) - [KSA](https://rewterz.com/tag/ksa) - [Threat Intelligence](https://rewterz.com/tag/threat-intelligence) - [Key Cybersecurity](https://rewterz.com/tag/key-cybersecurity) - [mdr services](https://rewterz.com/tag/mdr-services) - [XDR](https://rewterz.com/tag/xdr) - [MDR](https://rewterz.com/tag/mdr) - [SOC](https://rewterz.com/tag/soc) - [AI](https://rewterz.com/tag/ai) - [automated response](https://rewterz.com/tag/automated-response) - [security operations centre](https://rewterz.com/tag/security-operations-centre) - [ransomware](https://rewterz.com/tag/ransomware) - [cybercrime](https://rewterz.com/tag/cybercrime) - [siem](https://rewterz.com/tag/siem) - [PDPL](https://rewterz.com/tag/pdpl) - [compliance](https://rewterz.com/tag/compliance) - [data regulation](https://rewterz.com/tag/data-regulation) - [SAMA](https://rewterz.com/tag/sama) - [mssp](https://rewterz.com/tag/mssp) - [incident response](https://rewterz.com/tag/incident-response) - [security](https://rewterz.com/tag/security) - [secure framework](https://rewterz.com/tag/secure-framework) - [firewalls](https://rewterz.com/ar/tag/firewalls) - [information security](https://rewterz.com/ar/tag/information-security) - [Key Cybersecurity](https://rewterz.com/ar/tag/key-cybersecurity) - [MDR](https://rewterz.com/ar/tag/mdr) - [practical security](https://rewterz.com/ar/tag/practical-security) - [StrongerSecurity](https://rewterz.com/ar/tag/strongersecurity) - [XDR](https://rewterz.com/ar/tag/xdr) - [mdr services](https://rewterz.com/ar/tag/mdr-services) - [SOC](https://rewterz.com/ar/tag/soc) - [APT](https://rewterz.com/ar/tag/apt) - [Intelligence](https://rewterz.com/ar/tag/intelligence) - [Rewterz](https://rewterz.com/ar/tag/rewterz) - [LevelsofSOC](https://rewterz.com/ar/tag/levelsofsoc) - [KSA](https://rewterz.com/ar/tag/ksa) - [AI](https://rewterz.com/ar/tag/ai) - [security operations centre](https://rewterz.com/ar/tag/security-operations-centre) - [Maturity](https://rewterz.com/ar/tag/maturity) - [Steps](https://rewterz.com/ar/tag/steps) - [for Continual](https://rewterz.com/ar/tag/for-continual) - [Service](https://rewterz.com/ar/tag/service) - [Improvement](https://rewterz.com/ar/tag/improvement) - [cyrity](https://rewterz.com/ar/tag/cyrity) - [automated response](https://rewterz.com/ar/tag/automated-response) - [ransomware](https://rewterz.com/ar/tag/ransomware) - [cybercrime](https://rewterz.com/ar/tag/cybercrime) - [Penetration](https://rewterz.com/ar/tag/penetration) - [Testing](https://rewterz.com/ar/tag/testing) - [Essential](https://rewterz.com/ar/tag/essential) - [Business](https://rewterz.com/ar/tag/business) - [WorkFlows](https://rewterz.com/tag/workflows) - [mssp](https://rewterz.com/ar/tag/mssp) - [security](https://rewterz.com/ar/tag/security) - [secure framework](https://rewterz.com/ar/tag/secure-framework) - [Threat Intelligence](https://rewterz.com/ar/tag/threat-intelligence) - [siem](https://rewterz.com/ar/tag/siem) - [Oracle](https://rewterz.com/ar/tag/oracle) - [Cloud](https://rewterz.com/ar/tag/cloud) - [Breach Controversy](https://rewterz.com/ar/tag/breach-controversy) - [Navigating Denials](https://rewterz.com/ar/tag/navigating-denials) - [Extortion](https://rewterz.com/ar/tag/extortion) - [Ethical Responsibility](https://rewterz.com/ar/tag/ethical-responsibility) - [Red Team](https://rewterz.com/tag/red-team) - [PDPL](https://rewterz.com/ar/tag/pdpl) - [compliance](https://rewterz.com/ar/tag/compliance) - [data regulation](https://rewterz.com/ar/tag/data-regulation) - [SAMA](https://rewterz.com/ar/tag/sama) - [ai powered soc](https://rewterz.com/tag/ai-powered-soc) - [ai soc](https://rewterz.com/tag/ai-soc) - [future of soc](https://rewterz.com/tag/future-of-soc) - [modern architecture](https://rewterz.com/tag/modern-architecture) - [ai driven soc](https://rewterz.com/tag/ai-driven-soc) ## Job Category - [Project Management](https://rewterz.com/job-category/project-management) - [Sales](https://rewterz.com/job-category/sales) - [Marketing](https://rewterz.com/job-category/marketing) - [IT](https://rewterz.com/job-category/it) - [administration](https://rewterz.com/job-category/administration) - [support](https://rewterz.com/job-category/support) - [seo](https://rewterz.com/job-category/seo) - [finance](https://rewterz.com/job-category/finance) ## Job Type - [Full Time](https://rewterz.com/job-type/full-time) ## Job Location - [Karachi](https://rewterz.com/job-location/karachi) ## Client categories - [newclients](https://rewterz.com/client-types/newclients) - [عملاء جدد](https://rewterz.com/ar/client-types/عملاء-جدد) ## Offer categories - [industries](https://rewterz.com/offer-types/industries)