View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical Chrome flaws allow arbitrary code execution

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff — The Hacker News Russian authorities exploited Cellebrite UFED forensic tools to access the iPhone of detained activist Andrey Pivovarov in June 2021, three months after Cellebrite officially ceased sales to Russia and Belarus. Citizen Lab’s findings link forensic traces on the device with official Russian sources, highlighting ongoing unauthorized use of forensic tech despite sanctions.
  • $3 Million Reportedly Stolen in Polymarket Hack — SecurityWeek Decentralized prediction market Polymarket suffered a breach via a third-party vendor compromise, resulting in approximately $3 million stolen from user accounts. This incident underscores supply chain risk in DeFi platforms and the need for enhanced vendor security controls.

🔓 VULNERABILITIES & CVEs

🕵️ THREAT RESEARCH & DEEP DIVES

  • Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks — The Hacker News Google Threat Intelligence Group uncovered a new .NET backdoor named STOCKSTAY deployed by Russian APT Turla targeting Ukrainian government and military entities, as well as organizations linked to Italian foreign policy. The backdoor shows ongoing development and sophisticated espionage capabilities.
  • Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets — SecurityWeek Further analysis confirms Turla’s use of STOCKSTAY in active espionage campaigns against Ukraine. The backdoor’s modular design and stealth features represent a significant escalation in Turla’s toolkit, demanding enhanced detection and response measures.
  • New Enterprise-Ready MCP Specification Brings New Security Challenges — SecurityWeek The revamped Model Context Protocol (MCP) shifts critical security responsibilities from the protocol itself to developers and platform operators, increasing the risk of misconfigurations and vulnerabilities. Security teams should review MCP implementations closely to mitigate emerging risks.
  • Cyber Resilience Act – Part I — Compass Security The EU’s Cyber Resilience Act introduces mandatory cybersecurity requirements for digital products sold in the EU, covering IoT devices, OSes, and standalone software. This regulation will impact product security lifecycles and compliance strategies for vendors and integrators.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check