Tag: cybersecurity
Welcome New Member – Caroline Humer from US
Please welcome our newest member from the United States, Caroline Humer As an international digital safety advocate, Caroline Humer is dynamic and motivated, with a track record of successfully fostering cross-industry engagement. Growing up in numerous global settings has honed her ability to lead global …
Week-19 – A critical security vulnerability in the OpenCTI Platform

05 – 11 May 2025
A critical security vulnerability has been identified in the OpenCTI Platform which is designed to structure, store, organize and visualize technical and non-technical information about cyber threats. This vulnerability, tracked as CVE-2025-24977 is our new CVEofTheWeek with an assigned CVSS score of 9.1. It could allow attackers to execute commands on the hosting infrastructure and access secrets.
The security weakness is found in OpenCTI’s web-hook functionality. As outlined in the advisory, this feature enables users to tailor messages transmitted through web-hooks. It operates using JavaScript, which users can input into a web-hook template field.
The primary concern is that a malicious user could exploit this mechanism to execute commands within the hosting environment where OpenCTI runs. Although a protective layer has been implemented to block external modules in JavaScript code used for web-hooks, these safeguards can still be circumvented.
Furthermore, OpenCTI’s container-based deployments poses a security risk, as attackers could exploit web-hook JavaScript to access sensitive environment variables. Successful exploitation could lead to a wide range of malicious activities, including data breaches, system compromise, and lateral movement within the affected network.
The affected version of OpenCTI Platform is 6.4.8 and the patched version, which resolves this vulnerability, is 6.4.11.
Users of the OpenCTI Platform are strongly advised to upgrade OpenCTI Platform instance to version 6.4.11 or later to mitigate the risk posed by CVE-2025-24977.
Recommended Action:
- Upgrade to OpenCTI latest version
- Review user permissions, especially for the ‘manage customizations’ capability, and restrict them to trusted individuals.
- Audit webhook configurations to ensure they are not susceptible to misuse
Official advisory: https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-mf88-g2wq-p7qm

White Hat IT Security is a Europe-based Managed Security Services Provider (MSSP) and proud Microsoft Solution Partner. Its Microsoft-verified managed security solutions (MXDR) reflect their deep expertise and commitment to excellence in cybersecurity. The company was awarded the Partner of the Year Hungary Award by Microsoft in 2024.
With the largest incident response capacity in the CEE region, they’re trusted by organizations to deliver fast, effective, and proactive protection. Their portfolio includes penetration testing, vulnerability assessments, managed Cyber Threat Intelligence, as well as Governance, Risk and Compliance (GRC) consulting and specialized security training.
They are committed to supporting professional initiatives that aim to raise cybersecurity awareness and maturity—both for individuals and organizations. They regularly contribute to the community through knowledge sharing, education, and outreach, helping to build a safer digital future for all.
CyAN Voices: Growing Careers Through Mentorship
In this mentorship story of 2025, Sumandeep Kaur shares her experience as a Web Developer and Cybersecurity Intern under the guidance of her CyAN mentor, Shantanu Bhattacharya. Empowering Early-Career Web Developer & Cybersecurity Professionals: My Journey with the CyAN Mentorship Program By Sumandeep Kaur Acknowledging …
CyAN Voices: Growing Careers Through Mentorship
In this first mentorship story of 2025, Kuljit Kaur (Australia) shares her experience under the guidance of her CyAN mentor, Shakil Khan (UAE). My Mentoring Experience with CyAN Mentorship Program and Mr. Shakil Khan By Kuljit Kaur Starting a career journey in cybersecurity can be …
Cyber (In)Securities – Issue 144
News
-
Quantum computer threat spurring quiet overhaul of internet security
Cyberscoop – Greg Otto -
Pro-Russia hacktivists bombard Dutch public orgs with DDoS attacks
BleepingComputer – Bill Toulas -
Dems look to close the barn door after top DOGE dog has bolted
The Register – Brandon Vigliarolo -
Canadian Electric Utility Hit by Cyberattack
SecurityWeek – Eduard Kovacs -
Putin’s Cyberattacks on Ukraine Rise 70%, With Little Effect
Dark Reading – Nate Nelson -
Claude AI Exploited to Operate 100+ Fake Political Personas
The Hacker News – Ravie Lakshmanan -
HIVE0117 Group Targets Russian Firms with DarkWatchman Malware
Security Affairs – Pierluigi Paganini -
Ex-NSA cyber-boss: AI will soon be a great exploit coder
The Register – Jessica Lyons -
AI talent heads to EU defence startups
InnovationAus – Supantha Mukherjee & Michael Kahn -
WordPress plugin disguised as security tool injects backdoor
BleepingComputer – Bill Toulas -
Nebulous Mantis targets NATO-linked entities
The Hacker News – Ravie Lakshmanan -
Tariffs could slow replacement of telecom networks
Cyberscoop – Tim Starks -
Ex-CISA chief decries cuts as Trump demands loyalty
The Register – Jessica Lyons -
FBI shares massive list of 42,000 LabHost phishing domains
BleepingComputer – Bill Toulas -
Phishers exploit Iberian blackout in real-time scams
Dark Reading – Elizabeth Montalbano -
DOGE is building a surveillance state
New York Times – Julia Angwin -
Tech Giants propose EOL security disclosure standard
SecurityWeek – Ryan Naraine -
DARPA’s AI Cyber Challenge could upend patching
Cyberscoop – Greg Otto -
Indian court orders Proton Mail block over deepfake claims
The Hacker News – Ravie Lakshmanan -
Pushback against US cyber coordination shake-up
Cyberscoop – Derek B. Johnson -
Fuel tank monitoring systems vulnerable to disruption
Dark Reading – Jai Vijayan -
Hackers ramp up scans for leaked Git secrets
BleepingComputer – Bill Toulas -
France attributes 12 cyberattacks to APT28
BleepingComputer – Sergiu Gatlan -
Reports uncover jailbreaks and insecure AI code
The Hacker News – Ravie Lakshmanan -
Apple ‘AirBorne’ flaws allow zero-click RCE
BleepingComputer – Sergiu Gatlan -
Enterprise tech dominates zero-day exploits
The Register – Connor Jones -
US critical infrastructure still struggles with OT security
Dark Reading – Becky Bracken -
US House criminalizes nonconsensual deepfakes
Cyberscoop – Derek B. Johnson -
Chinese espionage campaign targets SentinelOne
The Hacker News – Ravie Lakshmanan -
Europol creates ‘Violence-as-a-Service’ taskforce
Infosecurity Magazine – Phil Muncaster -
76% of Australian orgs faced high-impact cyber events
itWire – Gordon Peters -
France says Russian hackers targeted Macron in 2017
The Guardian – Angelique Chrisafis
Analysis
-
A Cybersecurity Paradox: Even Resilient Organizations Are Blind to AI Threats
Dark Reading – Arielle Waldman -
New Research Reveals: 95% of AppSec Fixes Don’t Reduce Risk
The Hacker News -
Debunking Security ‘Myths’ to Address Common Gaps
Dark Reading – Arielle Waldman -
World Password Day 2025: Rethinking Security in the Age of MFA and Passkeys
IT Security Guru – The Gurus -
‘Source of data’: are electric cars vulnerable to cyber spies and hackers?
The Guardian – Dan Milmo
Member Spotlights
-
CRD #21: Security Blind Spots and Board-Level Leadership
CyAN – Henry Röigas -
Online Safety for Kids and Teens: Global Platform Shifts
CyAN – Vaishnavi J
🗓️ Upcoming CyAN (and CyAN Partner) Global Events:
🎉 Celebration
CyAN 10th Anniversary
(Details TBA)
🌐 Online
CyAN Q2 Call (APAC + Gulf)
June 11 – 12:00 GST / 16:00 SGT / 18:00 AEST
🌐 Online
CyAN Q2 Call (EMEA + Americas)
June 11 – 20:00 GST / 18:00 CET / 17:00 UTC / 12:00 EDT
Cyber (In)Securities – Issue 143
News Cybersecurity CEO accused of running malware on hospital PC blabs about it on LinkedInThe Register – Brandon Vigliarolo Cybersecurity experts issue response to Trump order targeting Chris Krebs, SentinelOneCyberscoop – Greg Otto Marks & Spencer breach linked to Scattered Spider ransomware attackBleepingComputer – Lawrence …