Home » Archives for admin


  • The U.S. Justice Department on Monday accused a 55-year-old cardiologist from Venezuela of being the mastermind behind Thanos ransomware, charging him with the use and sale of the malicious tool and entering into profit sharing arrangements. Moises Luis Zagala Gonzalez, also known by the monikers Nosophoros, Aesculapius, and Nebuchadnezzar, is alleged to have both developed and marketed the

  • US Critical Infrastructure Security Agency (CISA) adds critical CVE-2022-30525 RCE flaw in Zyxel Firewalls to its Known Exploited Vulnerabilities Catalog.

    The U.S. Cybersecurity and Infrastructure Security Agency added the recently disclosed remote code execution bug, tracked as CVE-2022-30525, affecting Zyxel firewalls, to its Known Exploited Vulnerabilities Catalog.

    According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

    Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

    Last week, Zyxel has addressed the critical CVE-2022-30525 (CVSS score: 9.8) affecting Zyxel firewall devices that enables unauthenticated and remote attackers to gain arbitrary code execution as the “nobody” user.

    The vulnerability was discovered by Rapid7 which reported it on April 13. Zyxel silently addressed the flaw by releasing security updates on April 28, 2022, Rapid7 pointed out that this choice leaves defenders in the dark and only advantages the attackers.

    “The affected models are vulnerable to unauthenticated and remote command injection via the administrative HTTP interface. Commands are executed as the nobody user.” reads the report published by Rapid7.

    Below is the list of vulnerable products and related patches:




    USG FLEX 100(W), 200, 500, 700

    ZLD V5.00 through ZLD V5.21 Patch 1

    ZLD V5.30

    USG FLEX 50(W) / USG20(W)-VPN

    ZLD V5.10 through ZLD V5.21 Patch 1

    ZLD V5.30

    ATP series

    ZLD V5.10 through ZLD V5.21 Patch 1

    ZLD V5.30

    VPN series

    ZLD V4.60 through ZLD V5.21 Patch 1

    ZLD V5.30

    According to Rapid 7, there are more than 15,000 internet-facing vulnerable systems tracked by the Shodan search engine. The researchers also developed a Metasploit module for this issue and published a video PoC of the attack:

    “Apply the vendor patch as soon as possible. If possible, enable automatic firmware updates. Disable WAN access to the administrative web interface of the system.” concludes the report.

    Researchers at Shadowserver Foundation reported they started observing exploitation attempts of CVE-2022-30525 starting on May 13th. The experts claim that at least 20 800 of the potentially affected Zyxel firewall models (by unique IP) are exposed online, the majority of the CVE-2022-30525 affected models are in the EU – France (4.5K) and Italy (4.4K) and the US (2.4K).

    We see at least 20 800 of the potentially affected Zyxel firewall models (by unique IP) accessible on the Internet. Most popular are USG20-VPN (10K IPs) and USG20W-VPN (5.7K IPs).
    Most of the CVE-2022-30525 affected models are in the EU – France (4.5K) and Italy (4.4K). pic.twitter.com/Wh7I8JCvVv
    — Shadowserver (@Shadowserver) May 15, 2022

    Cisa also added the CVE-2022-22947 code injection vulnerability in Spring Cloud Gateway to the catalog. A remote attacker could send specially-crafted requests to vulnerable systems to gain arbitrary code execution. Last week, Microsoft experts reported that the Sysrv-K botnet is exploiting this issue to take over the vulnerable web servers.

    Both issues have to be addressed by federal agencies by June 6.

    Please vote for Security Affairs as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
    Vote for me in the sections “The Underdogs – Best Personal (non-commercial) Security Blog” and “The Tech Whizz – Best Technical Blog” and others of your choice.
    To nominate, please visit: https://docs.google.com/forms/d/e/1FAIpQLSfxxrxICiMZ9QM9iiPuMQIC-IoM-NpQMOsFZnJXrBQRYJGCOw/viewform  

    Follow me on Twitter: @securityaffairs and Facebook

    Pierluigi Paganini

    (SecurityAffairs – hacking, domain name system)

    The post CISA adds CVE-2022-30525 flaw in Zyxel Firewalls to its Known Exploited Vulnerabilities Catalog appeared first on Security Affairs.

  • We’ve had this laptop now for two years, and I’ve noticed during these last few months that the performance has somewhat tanked. Like earlier today I only had a browser opened, and when I went to file explorer it took a few seconds to open. To add to that, whenever i right click on file explorer it hangs (it actually hangs) for a good half a minute.
    All of this led me to suspect that I may have inadvertently downloaded a malware. So I opened up Task Manager and looked at the memory used: 80…Read more

  • Ransomware

    The Cost of Ransomware

    by admin
    by admin

    The Cost of Ransomware Breaking down the state of ransomware economics and keys to effective ransomware defense Breaking down the state of…


Cybernonstop is created to bring news and knowledge through articles to visitors.

Do not forget to subscribe.

Laest News

@2021 – All Right Reserved. Designed and Developed by PenciDesign