🚨 ACTIVE EXPLOITS & INCIDENTS
- Lantronix Serial-to-IP Converter Flaw (CVE-2025-67038) Actively Exploited — SecurityWeek Following an April disclosure via the BRIDGE:BREAK research project, attackers are exploiting CVE-2025-67038 in Lantronix devices used in OT environments. This vulnerability enables remote code execution and has been observed in active campaigns targeting industrial networks. Immediate patching is advised.
- Gaslight macOS Malware Uses Prompt Injection to Evade AI Analysis — The Hacker News A newly discovered Rust-based macOS implant embeds prompt injection payloads designed to confuse AI-driven malware analysis tools, causing them to abort or refuse analysis. This novel evasion technique complicates detection and forensic efforts, signaling a new wave of AI-targeted malware.
- Cal Water Investigates Iranian Hack Group Handala Claims — SecurityWeek Mandiant assisted Cal Water in investigating claims by Iranian threat actor Handala about disrupting water supply OT systems. No evidence of OT compromise was found, but the incident underscores ongoing targeting of critical infrastructure by nation-state actors.
🕵️ THREAT RESEARCH & DEEP DIVES
- Research: Prompt Injection Attacks Exploit LLM Role Confusion — Schneier on Security New academic work reveals that LLMs’ reliance on role tags as a security boundary is fundamentally flawed. Attackers exploit the continuous nature of role boundaries to subtly shift model states with innocuous text, making prompt injection a persistent threat without genuine role perception in LLMs.
- COM Usage by Windows Threats: A Technical Overview — Cisco Talos This deep dive explains how threat actors abuse Windows Component Object Model (COM) technology—originally designed for legitimate inter-process communication—to evade detection, execute code, and persist. Understanding COM abuse is critical for detecting sophisticated Windows malware.
- Surviving the Mythos Era: The Case for Network Detection and Response (NDR) — The Hacker News Richard Bejtlich discusses the limitations of alert-based triage and the need for context-rich NDR solutions to answer fundamental incident response questions. This approach is vital as attackers increasingly blend into normal telemetry and workflows.
📋 VENDOR BULLETINS & ADVISORIES
- GitLab Patches 13 Vulnerabilities Including Critical Code Execution Flaws — SecurityWeek GitLab CE/EE released updates addressing 13 vulnerabilities, with three rated high severity. Immediate patching is recommended to mitigate risks of remote code execution and sensitive data leaks.
- Curl Fixes 25-Year-Old Vulnerability Alongside 17 Other Medium/Low Issues — SecurityWeek The latest curl release patches a long-standing vulnerability along with multiple other flaws. Organizations using curl in critical infrastructure or development pipelines should upgrade to the newest version promptly.
- NIST Releases Updated IoT Security Guidelines for Federal Networks — SecurityWeek NIST’s draft guidance proposes enhanced cybersecurity requirements for IoT devices in federal environments, emphasizing secure development, authentication, and continuous monitoring. Public comments are open; agencies and vendors should prepare for compliance shifts.
💼 INDUSTRY NEWS, M&A & DEALS
- Runlayer Secures $30M Series A to Secure Enterprise AI Tools — SecurityWeek Runlayer, a startup offering a secure control layer for AI tools in enterprises, raised $30 million to accelerate development. Their platform aims to mitigate AI-specific risks as adoption grows across sectors.
📰 LESSER-KNOWN / UNDER-REPORTED
- Kaspersky: SMBs Face Rising Threats from Fake AI Tools and Phishing in 2026 — Securelist Kaspersky’s 2026 SMB threat report highlights an uptick in attacks leveraging fake AI tools to deceive users, alongside traditional phishing and data theft. SMBs remain a lucrative target with evolving tactics that require layered defenses.
- Imperva: No Single Tool Secures APIs—Layered Security Required — Imperva Blog A comprehensive overview of API security tools reveals gaps in coverage when relying on single solutions. Effective API defense requires combining secure coding, scanning, gateways, WAFs, bot management, and runtime protection.
- Risky Business Podcast: Five Eyes Warn on AI-Enabled Cyber Threats, Operation Endgame Update — Risky Business Discussion on Five Eyes agencies’ warnings about AI-enhanced offensive cyber capabilities, underscoring the futility of export controls on frontier AI models. Also covers the successes and challenges of Operation Endgame’s ongoing cybercrime disruption efforts.