Zum Hauptinhalt springen
Sicherheitslücken (CVE)CVE-2025-40646 | ViDay information disclosure (EUVD-2025-32669)(03.10.2026 um 01:07 Uhr)
•••••
Sichere ProgrammierungI Built My Dad a Local AI Translator for His Stock Research(03.10.2026 um 00:53 Uhr)
•
Sichere ProgrammierungTwo AI reviewers, one Fastify PR, and a 404 that quietly became a 414(03.10.2026 um 01:00 Uhr)
••
Sichere ProgrammierungAI quiz generators need tests, too(03.10.2026 um 01:02 Uhr)
•
Sichere ProgrammierungGet European job postings from an API in Python in 5 minutes(03.10.2026 um 01:05 Uhr)
•
Sicherheitslücken (CVE)CVE-2025-40646 | ViDay information disclosure (EUVD-2025-32669)(03.10.2026 um 01:07 Uhr)
•••••
Sichere ProgrammierungI Built My Dad a Local AI Translator for His Stock Research(03.10.2026 um 00:53 Uhr)
•
Sichere ProgrammierungTwo AI reviewers, one Fastify PR, and a 404 that quietly became a 414(03.10.2026 um 01:00 Uhr)
••
Sichere ProgrammierungAI quiz generators need tests, too(03.10.2026 um 01:02 Uhr)
•
Sichere ProgrammierungGet European job postings from an API in Python in 5 minutes(03.10.2026 um 01:05 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Security news weekly round-up - 28th March 2025

Malware, vulnerabilities, and phishing. These three threats are not going anywhere soon. We have to live with them and do our best that they don't affect us or…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

Malware, vulnerabilities, and phishing. These three threats are not going anywhere soon. We have to live with them and do our best that they don't affect us or any internet services that we care about.



Before we proceed, I apologize for missing last week's edition. It was beyond my control and I hope that you understand.



Now, back to our discussion. Based on the introductory paragraph, you should have guessed the articles that we'll review in this edition. Without saying too much at this stage, let's begin.









Medusa Ransomware Uses Malicious Driver to Disable Security Tools



Talk about killing the CCTV before a malicious action, this is similar. As defenders, this also proves that while attackers might not have what it takes to defeat a security solution, they might as well turn it off. Now, if a security tool is down, what's next? The system is ripe for exploitation.



From the article:




The driver was signed with an expired certificate and, to ensure that the driver would run successfully, the attackers used a .bat file to disable the Windows Time Service and set the system date to 2012.



Once up and running, the driver can perform requests for a broad range of operations, including process manipulation, file manipulation, process tampering, API loading, hook removal, driver termination, and system reboot.







Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication



First, there is more than one vulnerability. They are five and they are given a weird name to show their severity: IngressNightmare. What's more, it potentially affects over 6,500 publicly exposed clusters. The vulnerabilities, assigned CVE identifiers CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, and CVE-2025-1974, enable unauthenticated remote code execution.



This grants attackers unauthorized access to all secrets stored across all namespaces within a Kubernetes cluster. The result is unauthorized access that could lead to a complete takeover of the cluster.



From the article:




The vulnerability takes advantage of the fact that admission controllers, deployed within a Kubernetes pod, are accessible over the network without authentication.



Specifically, it involves injecting an arbitrary NGINX configuration remotely by sending a malicious ingress object (aka AdmissionReview requests) directly to the admission controller, resulting in code execution on the Ingress NGINX Controller's pod.







Critical Next.js Vulnerability in Hacker Crosshairs



Would you like to pause and update your Next.js versions to versions 15.2.3, 14.2.25, 13.5.9 or 12.3.5? Why? Here is why:




  • It's a critical vulnerability tracked as CVE-2025-29927

  • It has a CVSS score of 9.1.

  • This flaw allows attackers to bypass middleware-based security controls.

  • Threat actors are already probing the internet for servers impacted by the bug.



From the article:




The improper validation of the internal header, which has a predictable value, allows an attacker to send crafted requests mimicking the header and bypass authentication checks within a Next.js application. When the middleware is bypassed, the app does not perform its normal security routines, such as identity or role verification.







Top 3 MS Office Exploits Hackers Use in 2025 – Stay Alert!



It's an interesting read and one that you should not miss. A summary will be an injustice to what you will learn by reading the article.



So, have fun and happy reading!






Credits



Cover photo by Debby Hudson on Unsplash.






That's it for this week, and I'll see you next time.

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
IoC Intelligence
6 Indikatoren · Defanged · STIX 2.1
CVE-2025-24513CVE-2025-24514CVE-2025-1097CVE-2025-1098CVE-2025-1974CVE-2025-29927
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
3 Knoten · 2 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle
PoC · Ausnutzung · Patch-Stufen
CVE-2025-1974
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Aktive Angriffe beobachtet (CISA KEV / EPSS)
Patch & Schutzmaßnahmen
Noch kein offizieller Patch dokumentiert
Exploit Weaponization & PoC Radar
Nur belegte Faktoren · kein Score-Theater
CRITICAL WEAPONIZED · Index 100/100
Exploit-DB
EDB-52338
Interaktion
0-Click
Authentifizierung
Nicht erforderlich

Compliance, SLA & Vendor Adherence

Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Impact: 5.87 | Exploitability: 3.89
AVN
Netzwerk (Remote)
Aus der Ferne über das Internet ohne Vorbedingungen exploitbar.
ACL
Niedrig (Low)
Wiederholbar und deterministisch ohne spezielle Race Conditions ausnutzbar.
PRN
Keine (Unauthenticated)
Vollständig unauthentifiziert ohne Benutzerkonto exploitbar.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IH
Hoch (Volle Manipulation)
Vollständige Modifikation von Dateien, Parametern oder Ausführung von Code.
AH
Hoch (Totaler Ausfall / DoS)
Dienst oder Server wird komplett unbrauchbar (Denial of Service).
CISA-SSVC-Triage (vulnrichment)CVE-2025-24513
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2025-03-25T13:39:36.149148Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

In herstellerseitiger Prüfung
Handlungsempfehlung für Administratoren

Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
  • Upstream-Referenz (Code-Hosting, kein Advisory)
    github.com
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Security news weekly round-up - 28th March 2025

Thematisch verwandte Begriffe: Security, news, weekly, roundup · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag