Hackers exploited critical GeoServer RCE flaw to breach US federal agency
The intruders moved laterally across the agency's network, targeting and infiltrating a web server and an SQL server.
The intruders moved laterally across the agency's network, targeting and infiltrating a web server and an SQL server.
The flaw, tracked as CVE-2025-59689, impacts ESG versions 4.5 through 5.5.x, up to but not including 5.5.7.
The network included over 300 SIM servers and 100,000 SIM cards.
The technique exploits legitimate Windows components to force EDR and antivirus processes into a suspended or ‘coma’ state.
The media company in question was part of a wider disinformation network financed through a complex money-laundering scheme.
The company plans to introduce new security measures aimed at reducing the risks posed by token abuse, credential theft, and malware propagation.
The threat actor sends highly targeted phishing emails that look like job offers from HR recruiters.
The attackers are using SEO poisoning to manipulate Google and Bing search results.
The SIM cards were used to enhance the communication and navigation systems of combat UAVs.
The cyberattack targeted software systems provided by US defense and aviation firm Collins Aerospace.
Showing elements 511 - 520