Cybersecurity News | Daily Recap [04 Oct 2025]

Cybersecurity News | Daily Recap [04 Oct 2025]

Daily Recap, The article covers extortion and ransomware activities (Scattered Spider/LAPSUS$ threaten Salesforce, Toyota, Disney, Google; Cl0p-Oracle extortion linked to patched vulnerabilities and FIN11) alongside data breach incidents (Discord third-party breach; Renault UK; Shamir Medical Center). It also highlights actor activity and evolving malware campaigns (Detour Dog with Strela Stealer; Rhadamanthys MaaS; Confucius Group’s AnonDoor), plus notable vulnerabilities and privacy issues (Palo Alto Network scans; Splunk flaws; DrayTek CVE-2025-10547; ALPR surveillance debates) and industry responses (Signal SPQR; Oneleet funding). #ScatteredSpider #LAPSUS$ #Cl0p #FIN11 #DiscordData #RenaultUK #ShamirAttack #DetourDog #StrelaStealer #Rhadamanthys #AnonDoor #ConfuciusGroup #PaloAlto #Splunk #DrayTek #ALPR #FlockRaven #Signal #SPQR #Oneleet

Extortion & Ransomware

  • New dark‑web leak site by the Scattered Spider/LAPSUS$ group threatens to release data from firms including Salesforce, Toyota, Disney and Google unless ransoms are paid by October 10 – Scattered Site, Salesforce Probe
  • Cl0p-linked extortion targeting Oracle E‑Business Suite is tied to bugs patched in July and is under investigation with warnings of mass data theft and ties to FIN11 – Oracle Extortion, Cl0p Warning

Data Breaches

  • Hackers stole identifiable Discord user data from a compromised third‑party customer service provider, including ID documents and partial payment info with ransom demands – Discord Data
  • Renault UK confirms customer contact records exposed via a third‑party breach; no financial data reported and containment actions underway – Renault Breach
  • Cyberattack on Shamir Medical Center by the Russian‑speaking group Qilin exposed hospital emails and potentially patient data while core medical records remained intact – Shamir Attack

Threat Actors & Malware

  • Actor Detour Dog ran a DNS‑based malware infrastructure to distribute Strela Stealer, exploiting vulnerable WordPress sites and using botnets for spam and persistence – Detour Dog
  • The Rhadamanthys stealer added device fingerprinting, PNG steganography payloads and new proxy/crypt services as it professionalizes into a MaaS ecosystem – Rhadamanthys
  • Confucius threat actors shifted from document stealers to Python backdoors, weaponizing documents to deliver the AnonDoor backdoor in campaigns against South Asian targets – Confucius Group

Vulnerabilities & Scanning

  • Scanning against Palo Alto Networks login portals spiked by 500% in a day with over 1,300 IPs (predominantly U.S. and Europe), mirroring recent Cisco ASA reconnaissance activity – Palo Alto Scan
  • Splunk disclosed six critical flaws enabling remote JavaScript injection, SSRF and other server‑side issues across Enterprise and Cloud, with urgent upgrades and mitigations advised – Splunk Flaws
  • DrayTek patched an unauthenticated RCE in DrayOS tracked as CVE-2025-10547 via firmware updates; no active exploitation reported yet – DrayTek Patch

Surveillance & Privacy

  • California’s AG sued El Cajon for alleged illegal out‑of‑state searches of a license‑plate reader (ALPR) database, highlighting cross‑jurisdiction privacy risks for Californians – ALPR Lawsuit
  • Flock Safety unveiled Raven, a gunshot and human voice detection system that expands surveillance capabilities and rekindles civil‑liberties concerns – Flock Raven

Defenses & Industry

  • Signal introduced the SPQR (Sparse Post‑Quantum Ratchet) to harden messaging against quantum threats while maintaining post‑compromise confidentiality – Signal SPQR
  • Security startup Oneleet raised $33 million to scale its compliance and attack‑surface platform; separate roundup covers PQC adoption, new Android spyware and a FEMA data incident – Oneleet Funding, In Other News

Cybersecurity News | Daily Recap – hendryadrian.com