BeyondMachines :verified:

Simple, automated security tools and guidance for individuals and companies of all sizes.
Good cybersecurity shouldn't be an enterprise feature.

Sometimes a bot, sometimes not.

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

Coordinated cyberattacks target two years old Zyxel firewall flaw

A coordinated global cyberattack campaign on June 16, 2025, involved 244 unique IP addresses exploiting a critical command injection vulnerability (CVE-2023-28771) in Zyxel firewall and VPN devices that allows unauthenticated remote code execution via a single malicious packet to UDP port 500. Even though patches are available for over two years since the vulnerability's original disclosure in April 2023, organizations worldwide remain vulnerable.

**If you still haven't patched your ZyXel firewall, and it's exposed on UDP port 500 to the internet, time to act NOW! Isolate the UDP port 500 from the internet, and start patching your firewalls. And check for any indicators of compromise, if possible even do a factory reset and load a trusted configuration.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

Another flaw in ASUS Armoury Crate mainboard update system enables System-level privilege escalation

ASUS has patched a high-severity authorization bypass vulnerability (CVE-2025-3464) in its Armoury Crate system management software that allows attackers with existing system access to manipulate hard links and bypass driver security controls, potentially gaining complete operating system compromise through extensive low-level privileges.

**If you are running an ASUS mainboard on your computer, update the Armory Crate software. The exploit chain is complicated, but hackers have found a way to abuse it before, so they will find a way to abuse it again.**
#cybersecurity #infosec #advisory #ransomware
beyondmachines.net/event_detai

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@ilsk 👌

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@patrickcmiller Here's a crazy idea: Turn off the all the servers running AI slop. More available energy and water. Less excess heat.

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@wcbdata as we affectionally call it, the bubble

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

Some people will understand

Guys this is why the internet isn't working.
Some idiot broke all the lava lamps @ cloudflare
office

Photo of a wall with a bunch of broken lava lamps, with multi-colored liquid splashed on the wall and streaming to the floor. Puddles of multi-colored liquid on the floor.
BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@wcbdata also known as a...

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

Virginia Radford School District hit by cyberattack

Radford City Public Schools in Virginia experienced a cybersecurity incident that disrupted parts of their computer network and internal systems. The district has not disclosed details about the nature of the attack or any data exposure. The timing during summer break when schools are closed minimized operational impact.

****
#cybersecurity #infosec #incident #ransomware
beyondmachines.net/event_detai

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

Four images, one answer.
Can you solve it?

photo of tulipsphoto of AIG buildingimage of a Bored Apediagram of an Large Language Model
BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@CauseOfBSOD Iterative improvement.

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

State of (in)security - Week 24, 2025

During the week of June 9-16, 2025, there were 31 total cybersecurity events (10 vulnerabilities and 21 incidents/breaches) affecting over 3.3 million individuals. Malware and ransomware attacks are the primary cause (9 incidents) and IT, government, healthcare, and insurance sectors being most heavily targeted.

**Attackers are hiding malicious AI commands in messages to people, hoping people will use AI to parse messages. Read your messages! Before an AI does that! Be very careful about messages with content that looks like AI prompt instructions to do something which makes little sense to you. If not needed, fully delete such messages and content and report it to your admins so it's possibly not loaded into the AI.**
#cybersecurity #infosec #knowledge #weeklyreport
beyondmachines.net/event_detai

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@CauseOfBSOD why not path:/(^|\/)\.env$/ /^.*KEY=0x[0-9a-fA-F]{64}$/

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

World Leaks gang claims cyberattack and are extorting Freedman HealthCare

Massachusetts-based health data management company Freedman HealthCare was hit by a data theft and extortion attack by the World Leaks cybercriminal group, who claim to have stolen 52.4 GB of sensitive data including healthcare claims, insurance information, and protected health information with a threat to release it by June 17th. The breach could potentially expose financial and health data of millions of Americans given Freedman's partnerships with dozens of US state health departments.

****
#cybersecurity #infosec #incident #databreach
beyondmachines.net/event_detai

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

Mitel reports critical path traversal flaw in Mitel MiCollab

Mitel has disclosed a critical path traversal vulnerability (CVE-2025-23092) in its MiCollab platform that allows remote, unauthenticated attackers to access provisioning information and perform unauthorized administrative actions. This flaw bypasses a previous security patch and similar vulnerabilities have already been exploited in the wild.

**If you have Mitel MiCollab systems running version 9.8 SP2 or earlier, immediately upgrade to version 9.8 SP3 or apply the available patch to fix CVE-2025-23092. Hackers love the Mitel platform since it's a messaging platform exposed to the world by it's very design. Don't ignore this one.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@oneiros @kae_bytheocean seemed like a great idea at development debug time 🤷

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@leckse We are beyond UX. We are in the realm of HX (Hacker eXperience)

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

Car-sharing Zoomcar reports data breach exposing 8.4 M users

Zoomcar Holdings, an Indian car-sharing marketplace, reports a data breach affecting 8.4 million users that was discovered on June 9, 2025, when employees received communications from a threat actor. The breach exposed personal information including names, phone numbers, addresses, and car registration data. This marks the second major breach for the company, following a 2018 incident that compromised 3.6 million customer records.

****
#cybersecurity #infosec #incident #databreach
beyondmachines.net/event_detai

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@Datterich @nixCraft so it must be good

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@inthehands @adamshostack @rk Damn, this is so scary. And I need to think about it

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-17

@rk @adamshostack @inthehands Whatever AI generates is something they have been trained on.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst