⤷ Title: CVE-2025-42599: Critical Buffer Overflow in Active! mail Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 21 Apr 2025 00:20:39 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active! mail #buffer overflow #CVE_2025_42599 #JPCERT #rce #security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 21 Apr 2025 00:20:39 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active! mail #buffer overflow #CVE_2025_42599 #JPCERT #rce #security
Daily CyberSecurity
CVE-2025-42599: Critical Buffer Overflow in Active! mail Exploited in the Wild
Critical vulnerability (CVE-2025-42599) in Active! mail allows remote code execution. Update to the latest version immediately to protect your systems.
⤷ Title: DslogdRAT Malware Targets Ivanti Connect Secure via CVE-2025-0282 Zero-Day Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 26 Apr 2025 00:16:04 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #CVE_2025_0282 #cybersecurity #DslogdRAT #Ivanti #JPCERT #Remote Access Trojan #UNC5221 #Web Shell #Zero_Day Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 26 Apr 2025 00:16:04 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #CVE_2025_0282 #cybersecurity #DslogdRAT #Ivanti #JPCERT #Remote Access Trojan #UNC5221 #Web Shell #Zero_Day Exploit
Daily CyberSecurity
DslogdRAT Malware Targets Ivanti Connect Secure via CVE-2025-0282 Zero-Day Exploit
DslogdRAT malware exploited Ivanti Connect Secure via CVE-2025-0282, using web shells and C2 channels to evade detection and persist in networks.
⤷ Title: High-Risk Flaws in a-blog cms: CVE-2025-36560 Scores Critical 9.2 on CVSS Scale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 15 May 2025 08:52:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #a_blog cms #CMS vulnerability #CVE_2025_36560 #CVSS 9.2 #JPCERT #Path Traversal #ssrf #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 15 May 2025 08:52:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #a_blog cms #CMS vulnerability #CVE_2025_36560 #CVSS 9.2 #JPCERT #Path Traversal #ssrf #XSS
Daily CyberSecurity
High-Risk Flaws in a-blog cms: CVE-2025-36560 Scores Critical 9.2 on CVSS Scale
JPCERT reports critical flaws in a-blog cms, including CVE-2025-36560 (CVSS 9.2). Attackers could hijack sessions and access sensitive data.
⤷ Title: Critical Vulnerabilities Found in Nimesa Backup and Recovery Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:13:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS #CVE_2025_48501 #CVE_2025_53473 #cybersecurity #Disaster Recovery #JPCERT/CC #Nimesa Backup #rce #Remote Code Execution #Server_Side Request Forgery #ssrf #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:13:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS #CVE_2025_48501 #CVE_2025_53473 #cybersecurity #Disaster Recovery #JPCERT/CC #Nimesa Backup #rce #Remote Code Execution #Server_Side Request Forgery #ssrf #Vulnerability
Daily CyberSecurity
Critical Vulnerabilities Found in Nimesa Backup and Recovery Software
JPCERT/CC warns of critical flaws in Nimesa Backup and Recovery (CVE-2025-48501, CVSS 9.8 RCE; CVE-2025-53473 SSRF). Unsupported versions pose severe risk to AWS data.
⤷ Title: From MDifyLoader to Fscan: JPCERT Uncovers Deep Exploitation of Ivanti VPN Flaws in Advanced Malware Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cobalt Strike #cyberattack #Fscan #Ivanti Connect Secure #JPCERT/CC #malware #MDifyLoader #VShell #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cobalt Strike #cyberattack #Fscan #Ivanti Connect Secure #JPCERT/CC #malware #MDifyLoader #VShell #Vulnerability
Daily CyberSecurity
From MDifyLoader to Fscan: JPCERT Uncovers Deep Exploitation of Ivanti VPN Flaws in Advanced Malware Campaign
JPCERT/CC details a sophisticated, ongoing malware campaign exploiting Ivanti Connect Secure (CVE-2025-0282, -22457) using MDifyLoader, Cobalt Strike, vshell, and Fscan for stealthy persistent access.
⤷ Title: Beyond Windows: How Attackers Are Using CrossC2 to Infiltrate Linux Networks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 17 Aug 2025 23:10:54 +0000
════════════════════════
⌗ Tags: #Malware #BlackBasta #Cobalt Strike #CrossC2 #cybersecurity #JPCERT/CC #Linux #malware #ReadNimeLoader #windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 17 Aug 2025 23:10:54 +0000
════════════════════════
⌗ Tags: #Malware #BlackBasta #Cobalt Strike #CrossC2 #cybersecurity #JPCERT/CC #Linux #malware #ReadNimeLoader #windows
Penetration Testing Tools
Beyond Windows: How Attackers Are Using CrossC2 to Infiltrate Linux Networks
A new report from JPCERT/CC reveals a sophisticated attack campaign using CrossC2 and a custom loader to compromise both Linux and Windows systems.
⤷ Title: CrossC2 and ReadNimeLoader: Inside the Multi-Stage Intrusions Targeting Linux and Windows Environments
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 18 Aug 2025 00:34:34 +0000
════════════════════════
⌗ Tags: #Malware #BlackBasta #Cobalt Strike #CrossC2 #cybersecurity #JPCERT/CC #Linux #malware #ReadNimeLoader #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 18 Aug 2025 00:34:34 +0000
════════════════════════
⌗ Tags: #Malware #BlackBasta #Cobalt Strike #CrossC2 #cybersecurity #JPCERT/CC #Linux #malware #ReadNimeLoader #windows
Daily CyberSecurity
CrossC2 and ReadNimeLoader: Inside the Multi-Stage Intrusions Targeting Linux and Windows Environments
A JPCERT/CC report reveals a new attack campaign using CrossC2 and a custom loader to compromise both Linux and Windows systems.
⤷ Title: Urgent Patch: Critical Lanscope Endpoint Manager RCE (CVE-2025-61932, CVSS 9.8) Under Active Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Oct 2025 03:42:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Critical Vulnerability #CVE_2025_61932 #Endpoint Manager #JPCERT #Lanscope #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Oct 2025 03:42:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Critical Vulnerability #CVE_2025_61932 #Endpoint Manager #JPCERT #Lanscope #rce
Daily CyberSecurity
Urgent Patch: Critical Lanscope Endpoint Manager RCE (CVE-2025-61932, CVSS 9.8) Under Active Exploitation
A Critical RCE flaw (CVE-2025-61932, CVSS 9.8) in Lanscope Endpoint Manager (v9.4.7.1 and earlier) is actively exploited via malicious packets.
⤷ Title: APT-C-60 Returns: New SpyGlace Malware Hides in Fake Résumé VHDX Attachments
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:09:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT_C_60 #Cyberespionage #GitHubAbuse #HRPersonnel #JPCERT #phishing #SpyGlace #VHDX
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:09:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT_C_60 #Cyberespionage #GitHubAbuse #HRPersonnel #JPCERT #phishing #SpyGlace #VHDX
Penetration Testing Tools
APT-C-60 Returns: New SpyGlace Malware Hides in Fake Résumé VHDX Attachments
APT-C-60 targets HR staff with fake resumes attached as VHDX files. The new SpyGlace malware variants use Git, COM hijacking, and GitHub for control.
⤷ Title: APT-C-60 Returns: New SpyGlace Malware Hides in Fake Resume VHDX Attachments
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:09:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT_C_60 #Cyberespionage #GitHubAbuse #HRPersonnel #JPCERT #phishing #SpyGlace #VHDX
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:09:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT_C_60 #Cyberespionage #GitHubAbuse #HRPersonnel #JPCERT #phishing #SpyGlace #VHDX
Penetration Testing Tools
APT-C-60 Returns: New SpyGlace Malware Hides in Fake Résumé VHDX Attachments
APT-C-60 targets HR staff with fake resumes attached as VHDX files. The new SpyGlace malware variants use Git, COM hijacking, and GitHub for control.
⤷ Title: Covert Backdoor: Array AG Gateway Exploit Allows Command Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:18:22 +0000
════════════════════════
⌗ Tags: #Vulnerability #Array AG Series #Backdoor #Command Execution #Corporate Gateway #Corporate VPN #DesktopDirect #JPCERT #Security Advisory
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:18:22 +0000
════════════════════════
⌗ Tags: #Vulnerability #Array AG Series #Backdoor #Command Execution #Corporate Gateway #Corporate VPN #DesktopDirect #JPCERT #Security Advisory
Penetration Testing Tools
Covert Backdoor: Array AG Gateway Exploit Allows Command Execution
Hacker groups have exploited a security gap in Array AG Series corporate gateways, implanting covert management micro-programs and
⤷ Title: JPCERT/CC Warns of Active Exploits Targeting Critical FileZen Command Injection Flaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 00:17:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Antivirus Evasion #CVE_2026_25108 #File Transfer #FileZen #JPCERT/CC #os command injection #Patch Alert #Soliton Systems #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 00:17:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Antivirus Evasion #CVE_2026_25108 #File Transfer #FileZen #JPCERT/CC #os command injection #Patch Alert #Soliton Systems #zero_day
Daily CyberSecurity
JPCERT/CC Warns of Active Exploits Targeting Critical FileZen Command Injection Flaw
Critical FileZen flaw CVE-2026-25108 is under active attack. Antivirus feature allows command injection. Update to V5.0.11 immediately to secure data.
⤷ Title: Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:19:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Canon Marketing Japan #CVE_2026_32661 #Exploit in the Wild #GUARDIANWALL MailSuite #infosec #JPCERT/CC #Mail Security #Patch Alert #rce #stack_based buffer overflow #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:19:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Canon Marketing Japan #CVE_2026_32661 #Exploit in the Wild #GUARDIANWALL MailSuite #infosec #JPCERT/CC #Mail Security #Patch Alert #rce #stack_based buffer overflow #zero_day
Daily CyberSecurity
Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
CVE-2026-32661 exploited in the wild. A 9.8 CVSS flaw in GUARDIANWALL MailSuite allows unauthenticated RCE. Apply Canon's official patches immediately.
⤷ Title: APT-C-60 Attacks Target Japan With SpyGlace Malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 01:00:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT_C_60 #Japan #JPCERT #living_off_the_land #LNK malware #spear_phishing #SpyGlace
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 01:00:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT_C_60 #Japan #JPCERT #living_off_the_land #LNK malware #spear_phishing #SpyGlace
Daily CyberSecurity
APT-C-60 Attacks Target Japan With SpyGlace Malware
At a glance Actor / group APT-C-60 (threat group) Activity Spear-phishing, LNK loader, SpyGlace backdoor Targets / victims Organizations in Japan Scale Ongoing campaign; victim count not disclosed…