In this daily recap, multiple vulnerabilities and patches were issued for WhatsApp, TP-Link, FreePBX, MobSF, and Android, with active exploitation prompting immediate updates. The report also covers supply-chain-OAuth breaches, Lazarus Groupâs cross-platform tool expansion, and notable incidents affecting Cloudflare, Palo Alto Networks, Disney, and Jaguar Land Rover. #WhatsApp #TP-Link #FreePBX #MobSF #Android #Salesloft #Drift #LazarusGroup #PondRAT #ThemeForestRAT #RemotePE #APT29 #Disney #Cloudflare #PaloAltoNetworks #JaguarLandRover
Vulnerabilities & Patches
- U.S. cybersecurity agency adds critical flaws in WhatsApp and TP-Link devices to its Known Exploited Vulnerabilities catalog, warning of active exploitation that threatens users and agencies â CISA KEV, CISA KEV
- Sangoma issues emergency patches for a critical zero-day CVE-2025-57819 in FreePBX after active exploitation that enabled remote access and DB manipulation â FreePBX Patch
- Security flaws in the security-testing tool MobSF (v4.4.0) allowed path traversal and arbitrary file writes and have been fixed in v4.4.1âupdate immediately â MobSF Fix
- Googleâs September Android update patches 84 vulnerabilities, including two actively exploited flaws impacting Android 13â16 and chipset vendors like Qualcommâapply updates promptly â Android Patch
Supply-Chain & OAuth Attacks
- A widespread supply-chain campaign abusing OAuth tokens via the Salesloft/Drift compromise has impacted hundreds of organizations (including Palo Alto Networks, Zscaler, and Cloudflare), exposing support data and API tokens and forcing services offline as remediation continues â Salesloft Breach, Cloudflare Hit, Palo Alto Breach, Salesloft Breach
Malware & Threat Actors
- The North Korea-linked Lazarus Group expanded its toolkit with cross-platform implants like PondRAT, ThemeForestRAT, and RemotePE in a social-engineering campaign against a DeFi firmâhighlighting evolving attack chains and credential theft â Advanced Malware
- Researchers uncovered the stealthy MystRodX backdoor that uses DNS/ICMP triggers, encryption, and dynamic configs for covert control, likely tied to espionage groups such as Liminal Panda â MystRodX Backdoor
- Amazon disrupted a watering-hole campaign attributed to APT29 (Russia) that hijacked legitimate sites to inject malicious JavaScript targeting Microsoft authenticationâonly a small share of visitors were redirected to attacker-controlled domains â APT29 Hole
- Hackers breached a fintech supply chain in Brazil targeting Pix paymentsâan attempted $130M heist at Evertecâs Sinqia unit used stolen credentials and halted real-time transactions while recovery efforts continue â Bank Heist
Operational Disruptions & Ransomware
- The Pennsylvania Attorney General office is recovering after a ransomware attack that encrypted systems (refusing to pay ransom) and restored services amid ongoing investigations, mirroring broader government targeting trends â PA Recovery, PA Recovery
- Jaguar Land Rover reports a cyberattack that âseverely disruptedâ production and retail operations after core systems were shut down; customer data appears unaffected as restoration continues â JLR Outage
Regulatory & Privacy
- Disney agreed to pay a $10M settlement with the FTC for mislabeled YouTube content that enabled collection of childrenâs data without parental consent, prompting stronger compliance and labeling controls under COPPA â Disney COPPA, Disney COPPA, Disney COPPA
Account Security & Threats to Tech
- A new social-engineering scam abusing WhatsAppâs device-linking can fully hijack chats and propagate malicious linksâusers should enable two-step verification and monitor linked devices â WhatsApp Scam
- The hacker collective âScattered LapSus Huntersâ threatened Google staff and data leaks (no breach evidence disclosed), underscoring persistent targeting and extortion tactics against major tech firms â Google Threat
DDoS & Infrastructure
- Cloudflare mitigated the largest recorded volumetric DDoS attack peaking at 11.5 Tbps, largely sourced from Google Cloud infrastructure, highlighting escalating DDoS scale and mitigation challenges â Record DDoS
Leadership & Management
- CISA appointed Nicholas Andersen as Executive Assistant Director for Cybersecurity to help steer defenses for critical infrastructure amid agency growth and restructuring â CISA Hire, CISA Hire
Claims & Clarifications
- Google denied reports that it warned 2.5 billion Gmail users to reset passwords, clarifying there was no mass breach notification and reiterating protections like passkeysâavoid panic-driven resets unless directly instructed â Gmail False