Cybersecurity News | Daily Recap [29 Oct 2025]

Cybersecurity News | Daily Recap [29 Oct 2025]

Daily Recap, Russian-linked actors used living-off-the-land techniques to breach Ukrainian organizations, while BlueNoroff leveraged AI-enhanced espionage on macOS to social-engineer victims. Major vulnerabilities and breaches, from Tomcat flaws to DELMIA alarms, underscore rapid attack surface expansion across industries. #RussianBreaches #BlueNoroffAI #TomcatFlaws #DELMIAWarning #ConduentBreach #DentsuMerkle #RavinAcademy #UKAfghanLeak

Nation‑state Activity

  • Russian-linked attackers used stealthy living‑off‑the‑land tactics to breach Ukrainian organizations this summer, exploiting legitimate tools rather than deploying heavy malware – Russian Breaches, Russian Breaches
  • BlueNoroff APT launched AI‑enhanced espionage on macOS using fake GhostCall/GhostHire meetings and GPT‑4o images to social‑engineer victims – BlueNoroff AI, BlueNoroff AI

Vulnerabilities & Active Exploits

  • Multiple production flaws are under active attack, including critical Apache Tomcat issues (9/10/11), two actively exploited Dassault vulnerabilities and XWiki flaws, and recent ASP.NET Core impact on QNAP NetBak – Tomcat Flaws, Dassault/XWiki, QNAP NetBak
  • Proof‑of‑concept code and disclosures surfaced for high‑risk bugs including BIND 9 (CVE‑2025‑40778), stored XSS reports and Struts2 framework issues — defenders should patch and monitor PoC activity – BIND PoC, Stored XSS, Struts2 Disclosure
  • CISA warns of exploited DELMIA Apriso/factory software vulnerabilities affecting industrial environments — patches and mitigations are urgently recommended – DELMIA Warning, DELMIA Warning

Hardware & Side‑Channel Research

  • Researchers disclosed TEE.Fail, a DDR5 side‑channel attack that can extract keys from Intel and AMD TEEs (SGX/TDX/SEV‑SNP) by observing DDR5 memory traffic, risking enclave secrecy and VM integrity – TEE.Fail DDR5, TEE.Fail DDR5

Ransomware & Malware

  • The Qilin ransomware gang has hit hundreds of organizations this year and now abuses WSL to run Linux encryptors on Windows hosts, complicating detection and response – Qilin Threat, Qilin Threat
  • Android threats surge: a new Herodotus banking trojan and other strains mimic human typing/delays to bypass anti‑fraud systems, while HyperRat is being sold as an off‑the‑shelf spy tool and infostealers hide in free video‑game cheats — users and banks targeted in multiple regions including Italy and Brazil – Herodotus Trojan, HyperRat, Android Evasion, Infostealers
  • New macOS and cross‑platform espionage chains (GhostCall/GhostHire) leverage AI imagery and social engineering to deliver advanced info‑stealers and implants – GhostCall Chains

Data Breaches & Leaks

  • Major breaches and data exposures announced this week: Conduent says the incident began in 2024, advertising giant Dentsu reported a Merkle subsidiary breach, and leaks exposed Capitol Hill applicants and other sensitive datasets — impacted parties urged to monitor notices – Conduent Breach, Dentsu/Merkle, DomeWatch Leak
  • An Iranian organization tied to MOIS (Ravin Academy) and a UK‑Afghan data leak linked to 49 deaths highlight risks from state‑linked breaches and exposed humanitarian records – Ravin Academy, UK Afghan Leak

Policy, Telecom & Fraud

  • European and US authorities spotlight caller‑ID spoofing and robocalls: Europol warns of rising spoofing threats and the FCC adopted new rules targeting robocalls as regulators press telecoms for fixes – Caller ID Spoofing, FCC Robocall Rule
  • Scammers increasingly target vulnerable groups, with campaigns threatening international students’ visa statuses and cross‑border scam‑center raids tied to criminal networks in Myanmar and Thailand — vigilance advised – Student Scams, Myanmar Scams

Industry, Standards & AI Risk

  • MITRE released ATT&CK v18 with updates improving detections and expanding coverage for Mobile and ICS, offering defenders refreshed mappings and controls – ATT&CK v18
  • AI safety and tooling headlines: Polygraf raised $9.5M to harden AI adoption, CyberRidge secured $26M for photonic encryption to resist quantum interception, and SimSpace raised $39M for cyber range training — funding signals growth in AI/security startups – Polygraf $9.5M, CyberRidge $26M, SimSpace $39M
  • AI product risks: OpenAI’s Atlas Browser was tripped by malformed URLs (prompt‑injection risk), while the Python core rejected a $1.5M U.S. grant over ethics concerns — oversight debates continue – Atlas Bug, Python Grant

Products & Updates

  • Microsoft pushed Windows 11 KB5067036 introducing an Administrator Protection feature, and also expanded Copilot to let users build apps and automate workflows amid a lawsuit alleging misleading Copilot M365 subscription practices – Win11 KB5067036, Copilot Build, Copilot Lawsuit

Events & Analysis

  • Security professionals can join a free webinar on practical AI tactics for GRC to learn adoption and risk mitigation strategies for governance, risk and compliance – AI GRC
  • Analysts warn of the coming 2026 digital battlefield — trends include ghost identities, poisoned accounts and rogue AI agents changing adversary tradecraft and defense priorities – Digital Battlefield

Cybersecurity News | Daily Recap – hendryadrian.com