Sitecore “thumbnailsaccesstoken” Deserialization Scans (and some new reports) CVE-2025-27218, (Thu, Mar 27th)

On March 6th, Searchlight Cyber published a blog revealing details about a new deserialization vulnerability in Sitecore &#;x26;#;x5b;1&#;x26;#;x5d;. Sitecore calls itself a “Digital Experience Platform (CXP),” which is a fancy content management system&#;x26;#;xc2;&#;x26;#;xa0;(CMS). Sitecore itself is written in .Net and is often sold as part of a solution offered by Sitecore partners. Like other CMSs, it makes it easy to manage a website&#;x26;#;39;s content. It offers several attractive features to marketing professionals seeking more insight into user patterns.

Continue reading Sitecore “thumbnailsaccesstoken” Deserialization Scans (and some new reports) CVE-2025-27218, (Thu, Mar 27th)

Posted in Uncategorized

New Morphing Meerkat Phishing Kit Mimics 114 Brands Using Victims’ DNS Email Records

Cybersecurity researchers have shed light on a new phishing-as-a-service (PhaaS) platform that leverages the Domain Name System (DNS) mail exchange (MX) records to serve fake login pages that impersonate about 114 brands.
DNS intelligence firm Infoblox… Continue reading New Morphing Meerkat Phishing Kit Mimics 114 Brands Using Victims’ DNS Email Records

Posted in Uncategorized

Blacklock Ransomware: A Late Holiday Gift with Intrusion into the Threat Actor’s Infrastructure

As seen on Resecurity’s blog, and where they are entitled to take a victory lap: Dubbed “BlackLock” (aka “El Dorado” or “Eldorado“), the ransomware-as-a-service (RaaS) outfit has existed since March 2024. In Q4 of last yea… Continue reading Blacklock Ransomware: A Late Holiday Gift with Intrusion into the Threat Actor’s Infrastructure