Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
CVE-2025-10680

The OpenVPN 2.7_alpha1 through 2.7_beta1 releases are susceptible to noscript injection attacks when connecting to untrusted VPN services

https://community.openvpn.net/Security%20Announcements/CVE-2025-10680
BadBox 2.0 - Scale and Infection: The botnet secretly infected more than ten million connected devices, including streaming TV boxes, tablets, and projectors running a modified version of the Android Open Source Project (AOSP).

A legal complaint (claim for damages and injunctive relief) filed by Google LLC (Plaintiff) in the United States District Court for the Southern District of New York against unnamed cybercriminals (Defendants Does 1-25):

https://storage.courtlistener.com/recap/gov.uscourts.nysd.643466/gov.uscourts.nysd.643466.22.0.pdf
Shai-Hulud 2.0 kill chain highlights the pattern:
- 𝗣𝗿𝗲-𝗶𝗻𝘀𝘁𝗮𝗹𝗹 𝘀𝗰𝗿𝗶𝗽𝘁 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝗮𝘁𝗶𝗼𝗻:
-- Abuse of preinstall noscripts (npm install) as the initial worm entry.
- 𝗖𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹 𝗵𝗮𝗿𝘃𝗲𝘀𝘁𝗶𝗻𝗴 & 𝗲𝘅𝗳𝗶𝗹𝘁𝗿𝗮𝘁𝗶𝗼𝗻:
-- Automated credential harvesting (NPM tokens, PATs, cloud keys, env vars) and exfiltration to attacker-controlled repos.
- 𝗣𝗲𝗿𝘀𝗶𝘀𝘁𝗲𝗻𝗰𝗲 & 𝗹𝗮𝘁𝗲𝗿𝗮𝗹 𝗺𝗼𝘃𝗲𝗺𝗲𝗻𝘁:
-- Persistence and lateral movement via backdoored GitHub Actions runners, with RCE and even a wiper fail-safe.