XStore Documentation

May 19, 2025 – Cyber Briefing

👉 What’s happening in cybersecurity today?

Firefox patches RCE flaws, ModiLoader targets Windows, and a glibc bug threatens Linux root access. Arla halts after a cyberattack, Poland’s Civic Platform hit by DDoS, and Harbin Clinic suffers a breach. Japan enacts active cyberdefense, Pwn2Own rewards $1M for zero-days, and UK faces a major cybersecurity skills gap.

Listen to the full podcast


🚨 Cyber Alerts

1. Mozilla Urgent Firefox Patch Fixes RCE Flaws

Mozilla released an emergency Firefox update to fix two critical JavaScript engine vulnerabilities. These severe out-of-bounds flaws could allow attackers to execute arbitrary code on users’ systems. The flaws impact multiple Firefox versions were shown at Pwn2Own and have a high risk score. Users are strongly urged to update Firefox immediately as active exploitation of these vulnerabilities is possible.

2. ModiLoader Malware Targets Windows Users

A malware strain called ModiLoader is spreading through phishing emails impersonating Turkish banks. Victims are tricked into opening RAR files that run encoded scripts installing the DBatLoader malware. It eventually deploys SnakeKeylogger, which steals sensitive data like keystrokes and stored credentials. The malware avoids detection using renamed files, misleading paths, DLL side-loading, and by disabling antivirus protections.

3. Glibc Flaw Gives Linux Root Access Risk

A critical glibc vulnerability (CVE-2025–4802) exposes many Linux systems to local privilege escalation attacks. This flaw in glibc 2.27–2.38 lets attackers manipulate LD_LIBRARY_PATH to execute arbitrary code. It affects statically linked setuid binaries calling dlopen and carries a critical 9.8 CVSS score. Experts advise updating glibc to 2.39+ applying patches and carefully auditing setuid binaries.

For more alerts, click here!

💥 Cyber Incidents

For more incidents, click here!

Click to See Tools

📢 Cyber News

For more news, click

📈Cyber Stocks

💡 Cyber Tip

📚 Cyber Book

Crypto Scams & Ponzi Schemes: Inside the Downfall by Nick C. Jackson

 

Click to Check Events

Copyright © 2025 CyberMaterial. All Rights Reserved.

Follow CyberMaterial on:

SubstackLinkedInTwitterRedditInstagramFacebookYouTube, and Medium.

Get Help

Online Scam Prevention & Recovery

Schedule a free consultation

A free 15-min cybersecurity consultation