Cybersecurity News | Daily Recap [01 Nov 2025]

Cybersecurity News | Daily Recap [01 Nov 2025]

Daily Recap, Nation-state operations show Sandworm leveraging an LNK exploit and an OpenSSH over Tor obfs4 backdoor to target Belarus military, while China-linked groups deploy tools like Airstalk, UNC6384 exploiting CVE-2025-9491, and TICK leveraging Lanscope zero-day. The roundup also covers WSUS vulnerability exploits, Elementor King Addons flaws, and ongoing incidents, including UPenn investigations and Conti-related extradition, with regulatory and defense developments across FCC, CFPB, and password hygiene.
#Sandworm #Airstalk #UNC6384 #PlugX #Lanscope #BadCandy #GlassWorm #Meduza #WSUS #ElementorKing #UPenn #Conti #FCC #CFPB #Sling #ShadowAI #Aardvark

Nation-state operations

  • Sandworm APT used an LNK exploit and an OpenSSH over Tor obfs4 backdoor to target the Belarus military – Sandworm Attack
  • Nation-state actors deployed new Airstalk malware in a suspected supply-chain attack – Airstalk Deploy
  • China-linked UNC6384 exploited an unpatched Windows LNK flaw (CVE-2025-9491) via spear-phishing to deliver PlugX to European diplomatic targets – PlugX Campaign
  • China-linked TICK group exploited a Lanscope zero‑day to hijack corporate systems – Lanscope Zero-day
  • Chinese actors are scanning/exploiting Cisco ASA firewalls used by governments while Australia warns of BadCandy infections on unpatched Cisco devices – Cisco Scans, BadCandy Alert
  • GlassWorm supply-chain impact is downplayed by Open VSX even as alleged admins of the Meduza Stealer were arrested after hacking a Russian org – GlassWorm, Meduza Arrests

Exploits & vulnerabilities

  • Attackers are exploiting the patched WSUS vulnerability (CVE-2025-59287) to drop the Skuld infostealer on unpatched Windows servers for credential harvesting – WSUS Exploit
  • Critical flaws in Elementor King Addons affect roughly 10,000 sites and can enable site takeover or data exposure – Elementor Flaws

Incidents & arrests

  • The University of Pennsylvania is investigating offensive β€œWe got hacked” emails sent through its graduate school system amid a campus security incident – Penn Probe, Penn Emails
  • A Ukrainian national was extradited from Ireland to the US on charges linked to Conti ransomware operations between 2020–2022 – Conti Extradition

Policy & regulation

  • The FCC plans a vote to rescind Biden-era telecom cybersecurity mandates installed after the theft of Trump-related telecom info, moving to reverse telecom cyber obligations – FCC Vote, FCC Rollback
  • The CFPB has ended its probe into Metaβ€˜s financial-data advertising practices, and Sling TV settled with California over alleged consumer-privacy violations – CFPB Closure, Sling Settlement

Scams & defenses

  • A fake PayPal invoice impersonating Geek Squad is a tech-support scam that highlights common red flags and the need to verify contact channels – PayPal Scam
  • Microsoft Edge adds a scareware sensor to speed up Defender SmartScreen detection and provide faster real-time scam warnings – Edge Sensor
  • Security guidance reminder: robust password controls and hygiene remain critical defenses despite advances in authentication and AI-driven tools – Password Controls

AI & tooling

  • Research finds about 1 in 4 employees use unapproved β€œshadow AI” tools at work, raising data-loss and compliance risks – Shadow AI
  • OpenAI unveiled Aardvark, a GPT‑5 agent designed to autonomously find and fix code flaws – Aardvark

Products & updates

  • Windows 11 is testing shared Bluetooth audio support that will be available only on certified AI PCs, limiting the feature to select devices – Windows Bluetooth
  • Daily roundup: WhatsApp passkey-encrypted backups, Kremlin targeting of Meduza malware, and a new Mastercard solution were highlighted in a multi-item news brief – In Other News

Cybersecurity News | Daily Recap – hendryadrian.com