Security Affairs newsletter Round 544 by Pierluigi Paganini – INTERNATIONAL EDITION

Wait 5 sec.

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.GreyNoise detects 500% surge in scans targeting Palo Alto Networks portalsU.S. CISA adds Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities catalogShinyHunters Launches Data Leak Site: Trinity of Chaos Announces New Ransomware VictimsProSpy, ToSpy malware pose as Signal and ToTok to steal data in UAEGoogle warns of Cl0p extortion campaign against Oracle E-Business usersCERT-UA warns UAC-0245 targets Ukraine with CABINETRAT backdoorAllianz Life data breach impacted 1.5 Million peopleCybercrime group claims to have breached Red Hat ‘s private GitHub repositoriesChina-linked APT Phantom Taurus uses Net-Star malware in espionage campaigns against key sectorsOpenSSL patches 3 vulnerabilities, urging immediate updatesApple urges users to update iPhone and Mac to patch font bugWestJet confirms cyberattack exposed IDs, passports in June incidentBroadcom patches VMware Zero-Day actively exploited by UNC5174UK convicts Chinese national in £5.5B crypto fraud, marks world’s largest Bitcoin seizureU.S. CISA adds Adminer, Cisco IOS, Fortra GoAnywhere MFT, Libraesva ESG, and Sudo flaws to its Known Exploited Vulnerabilities catalogAsahi halts ordering, shipping, and customer service after cyberattackScattered Spider, ShinyHunters Restructure – New Attacks Underway UK grants £1.5B loan to Jaguar Land Rover after cyberattackHarrods alerts customers to new data breach linked to third-party providerAkira Ransomware bypasses MFA on SonicWall VPNsDespite Russian influence, Moldova votes Pro-EU, highlighting future election risksDutch teens arrested for spying on behalf of pro-Russian hackersCyberattack on Co-op leaves shelves empty, data stolen, and $275M in lost revenueInternational Press – NewsletterCybercrimeSmash and Grab: Aggressive Akira Campaign Targets SonicWall VPNs, Deploys Ransomware in an Hour or LessWoman convicted following world’s largest crypto seizure The Kids Aren’t AlrightTrinity of Chaos: The LAPSUS$, ShinyHunters, and Scattered Spider Alliance Embarks on Global Cybercrime Spree  ‘You’ll never need to work again’: Criminals offer reporter money to hack BBC  Red Hat confirms security incident after hackers claim GitHub breach Researchers Say They Flagged Cyber Flaws at Jaguar Ahead of Crippling Breach  Oracle Apps Exploited by Hackers in New Extortion Campaign Silent Smishing : The Hidden Abuse of Cellular Router APIs   MalwareFirst Malicious MCP in the Wild: The Postmark Backdoor That’s Stealing Your Emails  Klopatra: exposing a new Android banking trojan operation with roots in Turkey  Check Your Socks – A Deep Dive into soopsocks PyPI Package  New spyware campaigns target privacy-conscious Android users in the UAE  Rhadamanthys 0.9.x – walk through the updatesHackingAppSuite, OneStart & ManualFinder: The Nexus of Deception Apple fixes critical font processing bug. Update now! Why hackers are targeting the world’s shipping  HackerOne Report Finds 210% Spike in AI Vulnerability Reports Amid Rise of AI Autonomy  Palo Alto Scanning Surges ~500% in 48 Hours, Marking 90-Day High  WireTap: Breaking Server SGX via DRAM Bus InterpositionBattering RAM Low-Cost Interposer Attacks on Confidential ComputingOneLogin, Many Secrets: Clutch Uncovers Critical API Vulnerability Exposing Client Credentials        Intelligence and Information WarfareTwo Dutch teens arrested in rare Russian espionage case  Pro-EU party in Moldova set to win vote mired in claims of Russian interference You name it, VMware elevates it (CVE-2025-41244)  Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware SuiteSVG Phishing hits Ukraine with Amatera Stealer, PureMinerCABINETRAT backdoor used by UAC-0245 for targeted cyberattacks against SOU (CERT-UA#17479)  Cavalry Werewolf raids Russia’s public sector with trusted relationship attacksConfucius Espionage: From Stealer to Backdoor  CybersecurityHarrods warns customers their data may have been stolen in IT breach  Government backs Jaguar Land Rover with £1.5 billion loan guarantee  WestJet confirms recent breach exposed customers’ passportsAI Agents Are Eroding the Foundations of Cybersecurity    Feds cut funding to program that shared cyber threat info with local governments  California enacts AI safety law targeting tech giants  Package Maintainers Call for Improvements to GitHub’s New npm Security Plan Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, newsletter)