Security Affairs newsletter Round 542 by Pierluigi Paganini – INTERNATIONAL EDITION

Wait 5 sec.

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.A cyberattack on Collins Aerospace disrupted operations at major European airportsCISA warns of malware deployed through Ivanti EPMM flawsFortra addressed a maximum severity flaw in GoAnywhere MFT softwareUK police arrested two teen Scattered Spider members linked to the 2024 attack on Transport for LondonShadowLeak: Radware Uncovers Zero-Click Attack on ChatGPTSonicWall warns customers to reset credentials after MySonicWall backups were exposedCVE-2025-10585 is the sixth actively exploited Chrome zero-day patched by Google in 2025Jaguar Land Rover will extend its production halt into a third week following a cyberattackChina-linked APT41 targets government, think tanks, and academics tied to US-China trade and policyMicrosoft and Cloudflare teamed up to dismantle the RaccoonO365 phishing serviceDoJ resentenced former BreachForums admin to three years in prisonApple backports fix for actively exploited CVE-2025-43300New supply chain attack hits npm registry, compromising 40+ packagesCybercrime group accessed Google Law Enforcement Request System (LERS)China-linked Mustang Panda deploys advanced SnakeDisk USB wormInsider breach at FinWise Bank exposes data of 689,000 AFF customersHackers steal millions of Gucci, Balenciaga, and Alexander McQueen customer recordsFairmont Federal Credit Union 2023 data breach impacted 187K peopleUK ICO finds students behind majority of school data breachesINC ransom group claimed the breach of Panama’s Ministry of Economy and FinanceShinyHunters Attack National Credit Information Center of VietnamInternational Press – NewsletterCybercrimeGucci, Balenciaga and Alexander McQueen private data ransomed by hackers Hackers claim access to law enforcement portals, but do they really have access?Founder of One of World’s Largest Hacker Forums Resentenced to Three Years in PrisonRaccoonO365: An Active Campaign and New Features  FileFix in the wild! New FileFix campaign goes beyond POC and leverages steganographyMicrosoft seizes 338 websites to disrupt rapidly growing ‘RaccoonO365’ phishing serviceUnited Kingdom National Charged in Connection with Multiple Cyber Attacks, Including on Critical InfrastructureTwo charged for TfL cyber attack     Inside the Lighthouse and Lucid PhaaS Campaigns Targeting 316 Global BrandsSystemBC – Bringing the Noise     Evolution Cybercrime—Key Trends, Cybersecurity Threats, and Mitigation Strategies from Historical DataMalwareSmokeLoader Rises From the Ashes Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages Satori Threat Intelligence Alert: SlopAds Covers Fraud with Layers of Obfuscation  Prompts as Code & Embedded Keys | The Hunt for LLM-Enabled MalwareLarge-Scale Attack Targeting Macs via GitHub Pages Impersonating Companies to Attempt to Deliver Stealer Malware      HackingA learning approach on exploiting CVE-2020-9273Rowhammer Attack Demonstrated Against DDR5  6 Browser-Based Attacks Security Teams Need to Prepare For Right NowGoogle Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens MillionsSonicWall Prompts Password Resets After Hackers Obtain Firewall Configurations ShadowLeak: A Zero-Click, Service-Side Attack Exfiltrating Sensitive Data Using ChatGPT’s Deep Research Agent CISA Releases Malware Analysis Report on Malicious Listener Targeting Ivanti Endpoint Manager Mobile SystemsIntelligence and Information WarfareAPT Down – The North Korea FilesHive0154, aka Mustang Panda, drops updated Toneshell backdoor and novel SnakeDisk USB worm  Israel announces seizure of $1.5M from crypto wallets tied to Iran Ukraine claims cyberattacks on Russian election systems; Moscow confirms disruptions THREE IRANIAN CYBER ACTORS SEC targets US firms tied to suspected Chinese ‘pump and dump’ scams   Minding the drone gap: Drone warfare and the EU  Gamaredon X Turla collab Modus Operandi of Subtle Snail  CybersecurityAI Agents are Eroding the Foundations of CybersecurityKids in the UK are hacking their own schools for dares and notoriety    Cloudflare participates in global operation to disrupt RaccoonO365   JLR could face disruption until November after hack Fortra Sheds Light on GoAnywhere MFT Zero-Day Exploit Used in Ransomware AttacksPalo Alto Networks Unit 42 Recognised by UK’s NCSC as an Enhanced Level Cyber Incident Response Assured Service Provider Germany approves new rules to protect critical infrastructurePassengers stranded at Heathrow, other European airports after cyberattack  Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, newsletter)