XStore Documentation

May 26, 2025 โ€“ Cyber Briefing

๐Ÿ‘‰ What are the latest cybersecurity alerts, incidents, and news?

D-Link flaw enables router hijack, TA-ShadowCricket runs decade-long espionage, and Killnet shifts to cybercrime. Philly schools and Naukri hacked, Qakbot leader indicted, AI aids CVE detection.

Listen to the full podcast


๐Ÿšจ Cyber Alerts

1. D-Link Routers Exposed by Weak Credentials

A significant security vulnerability, identified as CVE-2025โ€“46176, has been discovered in D-Linkโ€™s DIR-605L (firmware v2.13B01) and DIR-816L (firmware v2.06B01) routers. The flaw stems from hard-coded Telnet credentials, specifically the username โ€œAlphanetworksโ€ and a plaintext password like โ€œWj5eH%JC,โ€ which are stored directly in the firmware. This allows unauthenticated attackers to gain remote command execution capabilities, enabling them to modify settings, deploy malware, or access the internal network. While D-Link has acknowledged the medium-severity issue, no official patches are available as of May 2025. Users are strongly advised to disable Telnet and restrict WAN access to management ports to mitigate the immediate risk.

2. TA-ShadowCricke Unmasked via Backdoors

TA-ShadowCricket, a highly sophisticated APT group formerly known as Shadow Force, has conducted a decade-long cyber espionage campaign targeting over 2,000 systems in 72 countries, primarily in the Asia-Pacific region. Using a stealthy, multi-stage infection strategy that blends outdated IRC botnets with modern SQL-based backdoors, the group focuses on credential harvesting, data exfiltration, and cryptocurrency mining. While evidence links its infrastructure to Chinese IP addresses, attribution remains unclear due to overlapping indicators and tactics that suggest either state-sponsored operations or a hybrid cybercriminal model.

3. Killnet Resurfaces with New Identity

The notorious Russian hacker group Killnet has reemerged under new leadership after months of silence, shifting from pro-Kremlin hacktivism to profit-driven cybercrime. Analysts suggest the group is now focused on building reputation and revenue rather than ideology, operating more like a mercenary-for-hire service. The reappearance coincided with Russiaโ€™s Victory Day, prompting speculation of a renewed disinformation effort. Internal turmoil, leadership changes, and operational fragmentation have reshaped Killnetโ€™s structure, while offshoots continue pursuing politically motivated attacks under similar banners.

For more alerts, click here!

๐Ÿ’ฅ Cyber Incidents

For more incidents, click here!

Click to See Tools

๐Ÿ“ข Cyber News

For more news, click here

๐Ÿ“ˆCyber Stocks

On May 23, 2025, Zscaler rose 0.51%, CrowdStrike Holdings gained 2.59%, Palo Alto Networks increased 0.33%, Fortinet dipped 0.44%, and SentinelOne edged up 0.07%.

๐Ÿ’ก Cyber Tip

Click to Check Events

Copyright ยฉ 2025 CyberMaterial. All Rights Reserved.

Follow CyberMaterial on:

SubstackLinkedInTwitterRedditInstagramFacebookYouTube, and Medium.

Get Help

Online Scam Prevention & Recovery

Schedule a free consultation

 A free 15-min cybersecurity consultation