🚨 ACTIVE EXPLOITS & INCIDENTS
- CISA sets urgent deadline to fix Cisco flaw exploited in attacks — BleepingComputer CISA mandates federal agencies patch a critical vulnerability in Cisco Unified Communications Manager Server by Sunday. The flaw is actively exploited in the wild, posing risks of remote code execution and system takeover. Immediate patching is critical.
- Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories — SecurityWeek AWS patched a vulnerability that allowed attackers to steal cloud credentials by injecting malicious code into repositories. This flaw enabled unauthorized access to sensitive AWS credentials, increasing risk of lateral movement in cloud environments.
- Polymarket customers lose $3 million in supply-chain attack — BleepingComputer Hackers injected malicious scripts into Polymarket’s frontend via a compromised third-party vendor, resulting in $3M customer losses. Polymarket plans full reimbursement but this highlights ongoing risks in supply chain security for web platforms.
- FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys — The Hacker News Russian APTs have enhanced phishing campaigns targeting Signal users by coercing victims to hand over their Signal Backup Recovery Keys. This enables attackers persistent access to private and group chats, bypassing typical account protections.
🔓 VULNERABILITIES & CVEs
- More Klue Breach Victims Identified as Hackers Get Hacked — SecurityWeek Following the Klue-Salesforce breach, ~24 companies disclosed impacts to customers. The breach involves credential theft and lateral movement, underscoring risks from third-party SaaS integrations and the need for enhanced supply chain vigilance.
🕵️ THREAT RESEARCH & DEEP DIVES
- Threat Brief: Mitigating Large-Scale Credential Attacks — Palo Alto Unit 42 Unit 42 details recent large-scale credential stuffing and brute-force campaigns targeting security vendors’ devices. The brief offers mitigation strategies including multi-factor authentication enforcement, anomaly detection, and credential hygiene best practices.
- New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks — The Hacker News Kaspersky tracks a new malware family, SharkLoader, used to deploy Cobalt Strike Beacons in targeted attacks against diplomatic and government entities in Indonesia and Taiwan. This loader represents a stealthy initial access vector with modular payload delivery.
- Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign — The Hacker News APT group CL-STA-1062 is deploying a custom TinyRCT backdoor targeting government and critical infrastructure in Southeast Asia, focusing on energy and state-owned enterprises. The malware features stealthy persistence and remote control capabilities.
- Cybersecurity firms targeted by fraudulent OpenAI organization invites — BleepingComputer Threat actors impersonate OpenAI tenants to trick cybersecurity employees into joining fake organizations, aiming to harvest sensitive company info via chat and project collaboration tools. This social engineering tactic leverages trust in AI brands.
📋 VENDOR BULLETINS & ADVISORIES
- FCC requires emergency-alert distributors to secure their systems — Cybersecurity Dive The FCC moves from recommending to mandating cybersecurity protocols for emergency-alert distributors following a decade-old hacking campaign. This regulatory shift demands enhanced security controls to protect critical public safety communications infrastructure.
📰 LESSER-KNOWN / UNDER-REPORTED
- In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs — SecurityWeek Highlights include Russia’s use of Cellebrite to hack activist phones, Five Eyes’ urgent AI threat warning, a macOS Gaslight backdoor discovery, and Scattered Spider group guilty pleas. These developments indicate evolving espionage tactics and persistent supply chain risks.