Daily Recap, Nation-state operations show Sandworm leveraging an LNK exploit and an OpenSSH over Tor obfs4 backdoor to target Belarus military, while China-linked groups deploy tools like Airstalk, UNC6384 exploiting CVE-2025-9491, and TICK leveraging Lanscope zero-day. The roundup also covers WSUS vulnerability exploits, Elementor King Addons flaws, and ongoing incidents, including UPenn investigations and Conti-related extradition, with regulatory and defense developments across FCC, CFPB, and password hygiene.
#Sandworm #Airstalk #UNC6384 #PlugX #Lanscope #BadCandy #GlassWorm #Meduza #WSUS #ElementorKing #UPenn #Conti #FCC #CFPB #Sling #ShadowAI #Aardvark
#Sandworm #Airstalk #UNC6384 #PlugX #Lanscope #BadCandy #GlassWorm #Meduza #WSUS #ElementorKing #UPenn #Conti #FCC #CFPB #Sling #ShadowAI #Aardvark
Nation-state operations
- Sandworm APT used an LNK exploit and an OpenSSH over Tor obfs4 backdoor to target the Belarus military β Sandworm Attack
- Nation-state actors deployed new Airstalk malware in a suspected supply-chain attack β Airstalk Deploy
- China-linked UNC6384 exploited an unpatched Windows LNK flaw (CVE-2025-9491) via spear-phishing to deliver PlugX to European diplomatic targets β PlugX Campaign
- China-linked TICK group exploited a Lanscope zeroβday to hijack corporate systems β Lanscope Zero-day
- Chinese actors are scanning/exploiting Cisco ASA firewalls used by governments while Australia warns of BadCandy infections on unpatched Cisco devices β Cisco Scans, BadCandy Alert
- GlassWorm supply-chain impact is downplayed by Open VSX even as alleged admins of the Meduza Stealer were arrested after hacking a Russian org β GlassWorm, Meduza Arrests
Exploits & vulnerabilities
- Attackers are exploiting the patched WSUS vulnerability (CVE-2025-59287) to drop the Skuld infostealer on unpatched Windows servers for credential harvesting β WSUS Exploit
- Critical flaws in Elementor King Addons affect roughly 10,000 sites and can enable site takeover or data exposure β Elementor Flaws
Incidents & arrests
- The University of Pennsylvania is investigating offensive βWe got hackedβ emails sent through its graduate school system amid a campus security incident β Penn Probe, Penn Emails
- A Ukrainian national was extradited from Ireland to the US on charges linked to Conti ransomware operations between 2020β2022 β Conti Extradition
Policy & regulation
- The FCC plans a vote to rescind Biden-era telecom cybersecurity mandates installed after the theft of Trump-related telecom info, moving to reverse telecom cyber obligations β FCC Vote, FCC Rollback
- The CFPB has ended its probe into Metaβs financial-data advertising practices, and Sling TV settled with California over alleged consumer-privacy violations β CFPB Closure, Sling Settlement
Scams & defenses
- A fake PayPal invoice impersonating Geek Squad is a tech-support scam that highlights common red flags and the need to verify contact channels β PayPal Scam
- Microsoft Edge adds a scareware sensor to speed up Defender SmartScreen detection and provide faster real-time scam warnings β Edge Sensor
- Security guidance reminder: robust password controls and hygiene remain critical defenses despite advances in authentication and AI-driven tools β Password Controls
AI & tooling
- Research finds about 1 in 4 employees use unapproved βshadow AIβ tools at work, raising data-loss and compliance risks β Shadow AI
- OpenAI unveiled Aardvark, a GPTβ5 agent designed to autonomously find and fix code flaws β Aardvark
Products & updates
- Windows 11 is testing shared Bluetooth audio support that will be available only on certified AI PCs, limiting the feature to select devices β Windows Bluetooth
- Daily roundup: WhatsApp passkey-encrypted backups, Kremlin targeting of Meduza malware, and a new Mastercard solution were highlighted in a multi-item news brief β In Other News