Access Denied

0

Access Denied You don’t have permission to access “http://hindi.news18.com/news/ajab-gajab/viral-train-fact-rail-mileage-know-how-far-go-on-full-tank-unknown-fact-general-knowledge-hindi-news-trending-10294739.html” on this server.

Reference #18.4a200117.1774085089.3b6e239

https://errors.edgesuite.net/18.4a200117.1774085089.3b6e239

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026

0

Ravie LakshmananMar 21, 2026Vulnerability / Threat Intelligence

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them by April 3, 2026.

The vulnerabilities that have come under exploitation are listed below –

  • CVE-2025-31277 (CVSS score: 8.8) – A vulnerability in Apple WebKit that could result in memory corruption when processing maliciously crafted web content. (Fixed in July 2025)
  • CVE-2025-43510 (CVSS score: 7.8) – A memory corruption vulnerability in Apple’s kernel component that could allow a malicious application to cause unexpected changes in memory shared between processes. (Fixed in December 2025)
  • CVE-2025-43520 (CVSS score: 8.8) – A memory corruption vulnerability in Apple’s kernel component that could allow a malicious application to cause unexpected system termination or write kernel memory. (Fixed in December 2025)
  • CVE-2025-32432 (CVSS score: 10.0) – A code injection vulnerability in Craft CMS that could allow a remote attacker to execute arbitrary code. (Fixed in April 2025)
  • CVE-2025-54068 (CVSS score: 9.8) – A code injection vulnerability in Laravel Livewire that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. (Fixed in July 2025)

The addition of the three Apple vulnerabilities to the KEV catalog comes in the wake of reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout about an iOS exploit kit codenamed DarkSword that leverages these shortcomings, along with three bugs, to deploy various malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft.

CVE-2025-32432 is assessed to have been exploited as a zero-day by unknown threat actors since February 2025, per Orange Cyberdefense SensePost. Since then, an intrusion set tracked as Mimo (aka Hezb) has also been observed exploiting the vulnerability to deploy a cryptocurrency miner and residential proxyware.

Rounding off the list is CVE-2025-54068, whose exploitation was recently flagged by the Ctrl-Alt-Intel Threat Research team as part of attacks mounted by the Iranian state-sponsored hacking group, MuddyWater (aka Boggy Serpens).

In a report published earlier this week, Palo Alto Networks Unit 42 called out the adversary’s consistent targeting of diplomatic and critical infrastructure, including energy, maritime, and finance, across the Middle East and other strategic targets worldwide.

“While social engineering remains its defining trait, the group is also increasing its technological capabilities,” Unit 42 said. “Its diverse toolset includes AI-enhanced malware implants that incorporate anti-analysis techniques for long-term persistence. This combination of social engineering and rapidly developed tools creates a potent threat profile.”

“To support its large-scale social engineering campaigns, Boggy Serpens uses a custom-built, web-based orchestration platform,” Unit 42 said. “This tool enables operators to automate mass email delivery while maintaining granular control over sender identities and target lists.”

Attributed to the Iranian Ministry of Intelligence and Security (MOIS), the group is primarily focused on cyber espionage, although it has also been linked to disruptive operations targeting the Technion Israel Institute of Technology by adopting the DarkBit ransomware persona.

One of the defining hallmarks of MuddyWater’s tradecraft has been the use of hijacked accounts belonging to official government and corporate entities in its spear-phishing attacks, and abuse of trusted relationships to evade reputation-based blocking systems and deliver malware. 

In a sustained campaign targeting an unnamed national marine and energy company in the U.A.E. between August 16, 2025, and February 11, 2026, the threat actor is said to have conducted four distinct waves of attack, leading to the deployment of various malware families, including GhostBackDoor and Nuso (aka HTTP_VIP). Some of the other notable tools in the threat actor’s arsenal include UDPGangster and LampoRAT (aka CHAR).

“Boggy Serpens’ recent activity exemplifies a maturing threat profile, as the group integrates its established methodologies with refined mechanisms for operational persistence,” Unit 42 said. “By diversifying its development pipeline to include modern coding languages like Rust and AI-assisted workflows, the group creates parallel tracks that ensure the redundancy needed to sustain a high operational tempo.”



Source link

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.gadgets360.com/telecom/jio-cheapest-plan-2026-with-2gb-daily-unlimited-calling-free-jiohotstar-prime-video-12-ott-beat-airtel-vi-bsnl-news-11246301” on this server.

Reference #18.50200117.1774084385.7ed8455

https://errors.edgesuite.net/18.50200117.1774084385.7ed8455

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.news18.com/videos/ajab-gajab/blue-suit-didi-shook-her-waist-vigorously-boys-went-crazy-after-seeing-her-flexibility-video-viral-10294735.html” on this server.

Reference #18.4a200117.1774082881.3ae6c18

https://errors.edgesuite.net/18.4a200117.1774082881.3ae6c18

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.news18.com/videos/ajab-gajab/police-officers-in-kerala-give-cpr-to-peacock-and-bring-it-back-to-life-viral-video-10294714.html” on this server.

Reference #18.49200117.1774089359.3ea257c

https://errors.edgesuite.net/18.49200117.1774089359.3ea257c

Iran says it will allow Japanese ships to transit the Strait of Hormuz | US-Israel war on Iran News

0

Japan sources more than 90 percent of its crude oil imports from the Middle East and is heavily dependent on exports transiting the key waterway.

Iran says Japanese ships will be allowed to transit the Strait of Hormuz, in the latest sign that Tehran has started pursuing a selective blockade of the strategic waterway.

“We have not closed the strait. In our opinion, the strait is open. It is closed only to ships belonging to our enemies, countries that attack us. For other countries, ships can pass through the strait ,” Iranian Foreign Minister Abbas Araghchi told Japan’s Kyodo News late on Friday.

Recommended Stories

list of 4 itemsend of list

“We are talking to them to find a way to pass safely. We are ready to provide them with safe passage. All they need to do is contact us to discuss how this route will be,” Araghchi said, according to an English transcript of the interview shared on his Telegram account.

Japan sources more than 90 percent of its crude oil imports from the Middle East and is heavily dependent on exports transiting the strait, but the waterway has been de facto closed since the United States and Israel attacked Iran on February 28.

INTERACTIVE - Strait of Hormuz - March 2, 2026-1772714221

Iran’s Islamic Revolutionary Guard Corps (IRGC) warned in the early days of the war that its forces would set “ablaze” any ships trying to transit the waterway, bringing marine traffic to a near standstill.

Over the past week, however, Iran has toned down the rhetoric to say the strait is only closed to Tehran’s enemies.

Japan may soon join the small cohort of countries – mainly China, India, and Pakistan – whose vessels have been allowed to transit the waterway in recent days, with approval from Iranian authorities.

Lloyd’s List, a shipping and maritime information service, separately reported that 10 ships have transited the strait by sailing close to Iran’s coastline – a route that is emerging as a “safe corridor” for shipping.

The latest ship, a Greek bulk carrier, transited on Friday by passing close to Iran’s Larak island , Lloyd’s said, while broadcasting the message “Cargo Food for Iran”.

While ships have been transiting on a case-by-case basis, Lloyd’s List reported that the IRGC is developing a more coordinated vetting and registration system.

As the war on Iran hits three weeks, a handful of countries – among them US allies – have already started lobbying Tehran to reopen the strait or allow their ships safe passage.

Japan, France, Germany, Italy, the Netherlands, and the United Kingdom earlier this week issued a joint statement expressing their “readiness to contribute to appropriate efforts to ensure safe passage through the Strait”.

Iraq, Malaysia, China, India and Pakistan have all reportedly held direct talks with Tehran to discuss the matter, according to Lloyd’s.

Araghchi’s remarks to Kyodo follow a call with Japanese Foreign Minister Toshimitsu Motegi on Tuesday, during which Tokyo expressed concern about the large number of Japanese vessels currently stranded in the Gulf, according to a Japanese readout of the call.



Source link

Trump hints at ‘winding down’ Iran war as US deploys more troops to region | US-Israel war on Iran News

0

United States President Donald Trump says he is considering “winding down” the military operations in Iran even as his administration deploys 2,500 additional marines to the region and asks Congress for more money to fund the war.

In a social media post on Friday, Trump said the US was “getting very close to meeting our objectives as we consider winding down our great Military efforts in the Middle East”.

Recommended Stories

list of 4 itemsend of list

The mixed messages from Trump came after another climb in oil prices plunged the US stock markets. His administration also announced that it was lifting sanctions on Iranian oil already loaded on ships, a move aimed at wrangling the soaring fuel prices.

White House Press Secretary Karoline Leavitt, in a post on X shortly after Trump’s message, said “the President and the Pentagon predicted it would take approximately 4-6 weeks to achieve this mission.

“Tomorrow [Saturday] marks week 3 – and the US Armed Forces are doing an exceptional job,” Leavitt wrote. “Day by day, the Iranian Regime is being crippled, and their ability to threaten the United States and our allies is being significantly weakened.”

Al Jazeera’s Rosiland Jordan, reporting from Washington, said four to six weeks is “the new number coming from the Trump administration about when Operation Epic Fury could possibly end”.

“The White House has never been clear since the war began on February 28 about just how long the war was going to take, how many different platforms it would be fought on, and what would be the final metric for the US deciding to declare victory,” she said.

But the three-week-old war has shown no signs of abating, with the US-Israeli forces attacking the Iranian capital, Tehran, and nearby areas as the country welcomed the first day of the Persian new year, Nowruz. At least two people were killed by shelling on a residential area in the village of Dastak in northern Iran’s Kiashahr, Gilan province’s governor said.

Meanwhile, Iran fired ⁠two ⁠ballistic missiles at the Diego Garcia military base in the ⁠Indian Ocean, run jointly by the US and the United Kingdom, the semi-official Mehr news agency reported on Saturday.

Israel said Iranian forces continued to fire missiles at it early on Saturday, while Saudi Arabia said it downed 20 drones in just a couple of hours in the country’s eastern region – home to major oil installations.

US near completion of goals: Trump

The US and Israel have offered shifting rationales for the war at different times, from hoping to foment an uprising that topples Iran’s leadership to eliminating its nuclear and missile programmes.

While Trump claimed the US is “very close” to meeting the war’s objectives, his administration is moving to bolster its firepower in the region and request another $200bn from Congress to fund the war.

Earlier this week, the US redirected another group of amphibious assault ships carrying 2,500 marines from the Pacific to the Middle East. The marines will join more than 50,000 US troops already in the region.

Trump has said he has no plans to send ground forces into Iran, but has also asserted that he retains all options.

Iran’s Supreme Leader Mojtaba Khamenei on Friday said Iran has dealt “a dizzying blow” to its enemies and that the US-Israeli war on his country was a “gross miscalculation”.

In a written statement read on Iranian television to mark Nowruz, Khamenei praised the Iranians’ steadfastness in the face of war. Khamenei has not been seen in public since he became the supreme leader following the Israeli strikes that killed his father, Ayatollah Ali Khamenei, and reportedly wounded him.

More than 1,400 people have been killed in Iran during the war, according to the authorities, while Israeli bombing has killed more than 1,000 people in Lebanon. In Israel, at least 18 people have been killed by Iranian missiles, while at least 13 US soldiers have died so far, according to officials.



Source link

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.news18.com/videos/ajab-gajab/girl-troubled-by-march-her-reaction-viral-people-stop-laughing-after-hearing-watch-here-video-10294667.html” on this server.

Reference #18.49200117.1774096909.406e74d

https://errors.edgesuite.net/18.49200117.1774096909.406e74d

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.news18.com/cricket/sanju-samson-can-become-2nd-wicket-keeper-in-ipl-to-cross-5000-runs-mark-after-ms-dhoni-10294654.html” on this server.

Reference #18.6e560e17.1774082541.76d836e

https://errors.edgesuite.net/18.6e560e17.1774082541.76d836e

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

0

Ravie LakshmananMar 21, 2026Malware / Threat Intelligence

The threat actors behind the supply chain attack targeting the popular Trivy scanner are suspected to be conducting follow-on attacks that have led to the compromise of a large number of npm packages with a previously undocumented self-propagating worm dubbed CanisterWorm.

The name is a reference to the fact that the malware uses an ICP canister, which refers to tamperproof smart contracts on the Internet Computer blockchain, as a dead drop resolver. The development marks the first publicly documented abuse of an ICP canister for the explicit purpose of fetching the command-and-control (C2) server, Aikido Security researcher Charlie Eriksen said.

The list of affected packages is below –

  • 28 packages in the @EmilGroup scope
  • 16 packages in the @opengov scope
  • @teale.io/eslint-config
  • @airtm/uuid-base32
  • @pypestream/floating-ui-dom

The development comes within a day after threat actors leveraged a compromised credential to publish malicious trivy, trivy-action, and setup-trivy releases containing a credential stealer. A cloud-focused cybercriminal operation known as TeamPCP is suspected to be behind the attacks.

The infection chain involving the npm packages involves leveraging a postinstall hook to execute a loader, which then drops a Python backdoor that’s responsible for contacting the ICP canister dead drop to retrieve a URL pointing to the next-stage payload. The fact that the dead drop infrastructure is decentralized makes it resilient and resistant to takedown efforts.

“The canister controller can swap the URL at any time, pushing new binaries to all infected hosts without touching the implant,” Eriksen said.

Persistence is established by means of a systemd user service, which is configured to automatically start the Python backdoor after a 5-second delay if it gets terminated for some reason by using the “Restart=always” directive. The systemd service masquerades as PostgreSQL tooling (“pgmon”) in an attempt to fly under the radar.

The backdoor, as mentioned before, phones the ICP canister with a spoofed browser User-Agent every 50 minutes to fetch the URL in plaintext. The URL is subsequently parsed to fetch and run the executable.

“If the URL contains youtube[.]com, the script skips it,” Eriksen explained. “This is the canister’s dormant state. The attacker arms the implant by pointing the canister at a real binary, and disarms it by switching back to a YouTube link. If the attacker updates the canister to point to a new URL, every infected machine picks up the new binary on its next poll. The old binary keeps running in the background since the script never kills previous processes.”

It’s worth noting that a similar youtube[.]com-based kill switch has also been flagged by Wiz in connection with the trojanized Trivy binary (version 0.69.4), which also reaches out to the same ICP canister via a Python dropper (“sysmon.py”). As of writing, the URL returned by the C2 is a rickroll YouTube video.

The Hacker News found that the ICP canister supports three methods – get_latest_link, http_request, update_link – allowing the threat actor to modify the behavior at any time to serve an actual payload.

In tandem, the packages come with a “deploy.js” file that the attacker runs manually to spread the malicious payload to every package a stolen npm token provides access to in a programmatic fashion. The worm, assessed to be vibe-coded using an artificial intelligence (AI) tool, makes no attempt to conceal its functionality.

“This isn’t triggered by npm install,” Aikido said. “It’s a standalone tool the attacker runs with stolen tokens to maximize blast radius.”

To make matters worse, a subsequent iteration of CanisterWorm detected in “@teale.io/eslint-config” versions 1.8.11 and 1.8.12 has been found to self-propagate on its own without the need for manual intervention.

Unlike “deploy.js,” which was a self-contained script the attacker had to execute with the pilfered npm tokens to push a malicious version of the npm packages to the registry, the new variant incorporates this functionality in “index.js” within a findNpmTokens() function that’s run during the postinstall phase to collect npm authentication tokens from the victim’s machine.

The main difference here is that the postinstall script, after installing the persistent backdoor, attempts to locate every npm token from the developer’s environment and spawns the worm right away with those tokens by launching “deploy.js” as a fully detached background process.

Interestingly, the threat actor is said to have swapped out the ICP backdoor payload for a dummy test string (“hello123”), likely to ensure that the entire attack chain is working as intended before adding the malware.

“This is the point where the attack goes from ‘compromised account publishes malware’ to ‘malware compromises more accounts and publishes itself,'” Eriksen said. “Every developer or CI pipeline that installs this package and has an npm token accessible becomes an unwitting propagation vector. Their packages get infected, their downstream users install those, and if any of them have tokens, the cycle repeats.”

(This is a developing story. Please check back for more details.)



Source link