GitLab RCE PoC, Certighost AD Exploit, AgentForger Flaw and Cl0p Targets Windchill

THN Daily Updates
Newsletter
cover

Zero Knowledge, Infinite Trust: The Evolution and Revolution of Blockchain Technology ($30.00 Value) FREE for a Limited Time

An eye-opening discussion of how to apply new blockchain technologies to realize our digital potential

Download Now Sponsored
LATEST NEWS Jul 25, 2026

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has ...

Read More
Twitter Facebook LinkedIn

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised l...

Read More
Twitter Facebook LinkedIn

One platform for human risk management? Yes, it exists!

Our AI-powered platform builds an Emotional Susceptibility Profile for each user that directs their personalized training and phishing plan and helps identify the social engineering tactics most likely to trick them. See it in action!

Read More
Twitter Facebook LinkedIn

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data ex...

Read More
Twitter Facebook LinkedIn

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to vi...

Read More
Twitter Facebook LinkedIn

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platfor...

Read More
Twitter Facebook LinkedIn

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed t...

Read More
Twitter Facebook LinkedIn

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial i...

Read More
Twitter Facebook LinkedIn
cover

Zero Knowledge, Infinite Trust: The Evolution and Revolution of Blockchain Technology ($30.00 Value) FREE for a Limited Time

An eye-opening discussion of how to apply new blockchain technologies to realize our digital potential

Download Now Sponsored

This email was sent to sikubaycom.s3cr3tz@blogger.com. You are receiving this newsletter because you opted-in to receive relevant communications from THN. To manage your email newsletter preferences, please click here.

Contact THN: info@thehackernews.com
Unsubscribe

THN | K.P BLock, Pitampura, Delhi