Tag: cybersecurity

Welcome New Member – Caroline Humer from US

Welcome New Member – Caroline Humer from US

Please welcome our newest member from the United States, Caroline Humer As an international digital safety advocate, Caroline Humer is dynamic and motivated, with a track record of successfully fostering cross-industry engagement. Growing up in numerous global settings has honed her ability to lead global 

Week-19 – A critical security vulnerability in the OpenCTI Platform

05 – 11 May 2025

A critical security vulnerability has been identified in the OpenCTI Platform which is designed to structure, store, organize and visualize technical and non-technical information about cyber threats. This vulnerability, tracked as CVE-2025-24977 is our new CVEofTheWeek with an assigned CVSS score of 9.1. It could allow attackers to execute commands on the hosting infrastructure and access secrets.

The security weakness is found in OpenCTI’s web-hook functionality. As outlined in the advisory, this feature enables users to tailor messages transmitted through web-hooks. It operates using JavaScript, which users can input into a web-hook template field.

The primary concern is that a malicious user could exploit this mechanism to execute commands within the hosting environment where OpenCTI runs. Although a protective layer has been implemented to block external modules in JavaScript code used for web-hooks, these safeguards can still be circumvented.

Furthermore, OpenCTI’s container-based deployments poses a security risk, as attackers could exploit web-hook JavaScript to access sensitive environment variables. Successful exploitation could lead to a wide range of malicious activities, including data breaches, system compromise, and lateral movement within the affected network.

The affected version of OpenCTI Platform is 6.4.8 and the patched version, which resolves this vulnerability, is 6.4.11.

Users of the OpenCTI Platform are strongly advised to upgrade OpenCTI Platform instance to version 6.4.11 or later to mitigate the risk posed by CVE-2025-24977.

Recommended Action:

  • Upgrade to OpenCTI latest version
  • Review user permissions, especially for the ‘manage customizations’ capability, and restrict them to trusted individuals.
  • Audit webhook configurations to ensure they are not susceptible to misuse

Official advisory: https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-mf88-g2wq-p7qm


White Hat IT Security is a Europe-based Managed Security Services Provider (MSSP) and proud Microsoft Solution Partner. Its Microsoft-verified managed security solutions (MXDR) reflect their deep expertise and commitment to excellence in cybersecurity. The company was awarded the Partner of the Year Hungary Award by Microsoft in 2024.

With the largest incident response capacity in the CEE region, they’re trusted by organizations to deliver fast, effective, and proactive protection. Their portfolio includes penetration testing, vulnerability assessments, managed Cyber Threat Intelligence, as well as Governance, Risk and Compliance (GRC) consulting and specialized security training.

They are committed to supporting professional initiatives that aim to raise cybersecurity awareness and maturity—both for individuals and organizations. They regularly contribute to the community through knowledge sharing, education, and outreach, helping to build a safer digital future for all.

CyAN Voices: Growing Careers Through Mentorship

CyAN Voices: Growing Careers Through Mentorship

In this mentorship story of 2025, Sumandeep Kaur shares her experience as a Web Developer and Cybersecurity Intern under the guidance of her CyAN mentor, Shantanu Bhattacharya. Empowering Early-Career Web Developer & Cybersecurity Professionals: My Journey with the CyAN Mentorship Program By Sumandeep Kaur Acknowledging 

Cyber (In)Securities – Issue 145

CyAN Voices: Growing Careers Through Mentorship

CyAN Voices: Growing Careers Through Mentorship

In this first mentorship story of 2025, Kuljit Kaur (Australia) shares her experience under the guidance of her CyAN mentor, Shakil Khan (UAE). My Mentoring Experience with CyAN Mentorship Program and Mr. Shakil Khan By Kuljit Kaur Starting a career journey in cybersecurity can be 

Week 18 – SAP NetWeaver’s Visual Composer component

Week 18 – SAP NetWeaver’s Visual Composer component

White Hat IT Security’s CVE Of The Week, CVE-2025-31324, is a critical zero-day vulnerability affecting SAP NetWeaver’s Visual Composer component

Cyber (In)Securities – Issue 144

News

  1. Quantum computer threat spurring quiet overhaul of internet security
    Cyberscoop – Greg Otto
  2. Pro-Russia hacktivists bombard Dutch public orgs with DDoS attacks
    BleepingComputer – Bill Toulas
  3. Dems look to close the barn door after top DOGE dog has bolted
    The Register – Brandon Vigliarolo
  4. Canadian Electric Utility Hit by Cyberattack
    SecurityWeek – Eduard Kovacs
  5. Putin’s Cyberattacks on Ukraine Rise 70%, With Little Effect
    Dark Reading – Nate Nelson
  6. Claude AI Exploited to Operate 100+ Fake Political Personas
    The Hacker News – Ravie Lakshmanan
  7. HIVE0117 Group Targets Russian Firms with DarkWatchman Malware
    Security Affairs – Pierluigi Paganini
  8. Ex-NSA cyber-boss: AI will soon be a great exploit coder
    The Register – Jessica Lyons
  9. AI talent heads to EU defence startups
    InnovationAus – Supantha Mukherjee & Michael Kahn
  10. WordPress plugin disguised as security tool injects backdoor
    BleepingComputer – Bill Toulas
  11. Nebulous Mantis targets NATO-linked entities
    The Hacker News – Ravie Lakshmanan
  12. Tariffs could slow replacement of telecom networks
    Cyberscoop – Tim Starks
  13. Ex-CISA chief decries cuts as Trump demands loyalty
    The Register – Jessica Lyons
  14. FBI shares massive list of 42,000 LabHost phishing domains
    BleepingComputer – Bill Toulas
  15. Phishers exploit Iberian blackout in real-time scams
    Dark Reading – Elizabeth Montalbano
  16. DOGE is building a surveillance state
    New York Times – Julia Angwin
  17. Tech Giants propose EOL security disclosure standard
    SecurityWeek – Ryan Naraine
  18. DARPA’s AI Cyber Challenge could upend patching
    Cyberscoop – Greg Otto
  19. Indian court orders Proton Mail block over deepfake claims
    The Hacker News – Ravie Lakshmanan
  20. Pushback against US cyber coordination shake-up
    Cyberscoop – Derek B. Johnson
  21. Fuel tank monitoring systems vulnerable to disruption
    Dark Reading – Jai Vijayan
  22. Hackers ramp up scans for leaked Git secrets
    BleepingComputer – Bill Toulas
  23. France attributes 12 cyberattacks to APT28
    BleepingComputer – Sergiu Gatlan
  24. Reports uncover jailbreaks and insecure AI code
    The Hacker News – Ravie Lakshmanan
  25. Apple ‘AirBorne’ flaws allow zero-click RCE
    BleepingComputer – Sergiu Gatlan
  26. Enterprise tech dominates zero-day exploits
    The Register – Connor Jones
  27. US critical infrastructure still struggles with OT security
    Dark Reading – Becky Bracken
  28. US House criminalizes nonconsensual deepfakes
    Cyberscoop – Derek B. Johnson
  29. Chinese espionage campaign targets SentinelOne
    The Hacker News – Ravie Lakshmanan
  30. Europol creates ‘Violence-as-a-Service’ taskforce
    Infosecurity Magazine – Phil Muncaster
  31. 76% of Australian orgs faced high-impact cyber events
    itWire – Gordon Peters
  32. France says Russian hackers targeted Macron in 2017
    The Guardian – Angelique Chrisafis

Analysis

  1. A Cybersecurity Paradox: Even Resilient Organizations Are Blind to AI Threats
    Dark Reading – Arielle Waldman
  2. New Research Reveals: 95% of AppSec Fixes Don’t Reduce Risk
    The Hacker News
  3. Debunking Security ‘Myths’ to Address Common Gaps
    Dark Reading – Arielle Waldman
  4. World Password Day 2025: Rethinking Security in the Age of MFA and Passkeys
    IT Security Guru – The Gurus
  5. ‘Source of data’: are electric cars vulnerable to cyber spies and hackers?
    The Guardian – Dan Milmo

Member Spotlights

  1. CRD #21: Security Blind Spots and Board-Level Leadership
    CyAN – Henry Röigas
  2. Online Safety for Kids and Teens: Global Platform Shifts
    CyAN – Vaishnavi J

🗓️ Upcoming CyAN (and CyAN Partner) Global Events:

GISEC Logo

📍 Dubai, UAE

GISEC
May 6–8

Read more
Cyber OSPAs Logo

📍 London, UK

Cyber OSPAs
May 8

Read more
CSG Awards Logo

📍 Dubai, UAE

CSG Awards 2025
May 7

Read more
World AI Expo Logo

📍 Dubai, UAE

World AI Technology Expo
May 14–15

Read more

🎉 Celebration

CyAN 10th Anniversary
(Details TBA)

GITEX Europe Logo

📍 Berlin, Germany

GITEX Europe Messe
May 21–23

Read more
MaTeCC Logo

📍 Rabat, Morocco

MaTeCC
June 7–9

Read more

🌐 Online

CyAN Q2 Call (APAC + Gulf)
June 11 – 12:00 GST / 16:00 SGT / 18:00 AEST

🌐 Online

CyAN Q2 Call (EMEA + Americas)
June 11 – 20:00 GST / 18:00 CET / 17:00 UTC / 12:00 EDT


Cyber (In)Securities – Issue 143

Cyber (In)Securities – Issue 143

News Cybersecurity CEO accused of running malware on hospital PC blabs about it on LinkedInThe Register – Brandon Vigliarolo Cybersecurity experts issue response to Trump order targeting Chris Krebs, SentinelOneCyberscoop – Greg Otto Marks & Spencer breach linked to Scattered Spider ransomware attackBleepingComputer – Lawrence