A report reveals that over 3,000 malicious YouTube videos were used to spread infostealer malware. Check Point Research has named a major malware operation the “YouTube Ghost Network.” It uses fake YouTube accounts to spread infostealer malware like Rhadamanthys and Lumma. Game hacks and cheats and software cracks and piracy …
Read More »Check Point Research: "YouTube Ghost Network"
(CVE-2025-59287)
CIRT Alert RCE Vulnerability in Microsoft WSUS in Bangladesh
Bangladesh cyber security watchdog BGD e-GOV CIRT published an advisory (27.10.2025) regarding critical romote code execution vulnarability in Microsoft WSUS CVSS score 9.8 as per NVD, NIST. CIRT has detected a serious security flaw in Microsoft’s WSUS that could let an attacker fully control a WSUS server. This vulnerability not …
Read More »New CoPhish attack steals OAuth tokens Exploitng Copilot Studio agents
A phishing technique named CoPhish misuses Microsoft Copilot Studio to deceive users into giving hackers access to their Microsoft Entra ID accounts. Datadog Security Labs identified a method that uses customizable AI agents on legitimate Microsoft domains to disguise OAuth consent attacks, making them seem trustworthy and avoiding user suspicion. …
Read More »ALERT: APT Mysterious Elephant actively target Bangladesh
Mysterious Elephant is an active APT group identified by Kaspersky GReAT in 2023. It continually evolves its tactics to avoid detection. The group’s recent campaign, starting in early 2025, shows a notable change in their tactics, focusing more on new custom tools and open-source tools like BabShell and MemLoader. The …
Read More »MCP Server Flaw Exposes 3,000+ Servers and Thousands of API Keys
A critical vulnerability was discovered in Smithery.ai, a well-known registry for Model Context Protocol (MCP) servers. This flaw could have let hackers steal data from over 3,000 AI servers and access API keys of thousands of users. MCP connects AI apps to external tools and data, such as local files …
Read More »Oracle released 374 new security patches in its October 2025 Tuesday patch
Oracle’s October 2025 Critical Patch Update fixes 374 vulnerabilities in multiple products, making it one of the largest patches recently, covering databases, middleware, enterprise applications, and communication systems. As always, Oracle recommends that customers apply patches without delay, as many of the fixed vulnerabilities can be exploited remotely, even without …
Read More »Hackers Exploited 34 Zero-Day Vulns In Pwn2Own Ireland 2025
During the first day of the Pwn2Own Ireland 2025 hacking contest by Trend Micro’s Zero Day Initiative, participants earned $522,500 for their exploits. 34 new vulnerabilities have been used to hack printers, NAS devices, routers, and smart home products. The top prize of $100,000 was given in the ‘SOHO Smashup’ …
Read More »
(CVE-2025-6542, CVSS 9.3)
User Alert: TP-Link warns of critical command injection flaw in Omada gateways
TP-Link Systems has released a firmware update that fixes four serious vulnerabilities in its Omada gateway series, like ER605, ER7206, and ER8411, commonly used in businesses. These flaws—CVE-2025-6541, CVE-2025-6542, CVE-2025-7850, and CVE-2025-7851—can let attackers run arbitrary commands on the devices, sometimes without needing authentication. According to TP-Link’s advisory, “An arbitrary …
Read More »CISA Adds Oracle, Apple and Microsoft Vulns to KEV Catalog
CISA has added five new CVEs to its Known Exploited Vulnerabilities catalog, including issues from Microsoft, Apple, and Oracle. The vulnerabilities flagged by CISA include: CVE-2022-48503 is a critical vulnerability (8.8 severity) in several Apple products that allows for arbitrary code execution via web content. Apple fixed it with better …
Read More »71,000+ WatchGuard security devices vulnerable to critical RCE
About 76,000 WatchGuard Firebox security devices are publicly exposed and vulnerable to a serious issue (CVE-2025-9242) that could let remote attackers execute code without authentication. Firebox devices serve as a central hub to manage traffic between internal and external networks, offering protection with policy management, security services, VPN, and real-time …
Read More »
InfoSecBulletin Cybersecurity for mankind