Daily Recap, The latest cyber threats span Android banking trojans like Sturnus hijacking devices across Europe, PhaaS kits such as Sneaky2FA, and HijackOnChat/Eternidade Worm targeting WhatsApp. Vulnerabilities from 7-Zip CVE-2025-11001 to W3 Total Cache PHP injections are being actively exploited, while ASUS WrtHug hijacks over 50,000 routers and sanctions hit Russian bulletproof hosting providers. #Sturnus #TamperedChef #Sneaky2FA #HijackOnChat #EternidadeWorm #7Zippercve #WrtHug #HostingSanctions #Photocall #ARCDataSale
Malware & Mobile
- The new Android banking trojan Sturnus can intercept encrypted chats, steal credentials and fully hijack devices across Europe â Sturnus Trojan, Sturnus Trojan
- Ongoing global campaigns deploy fake installers and stealthy loaders including TamperedChef and advancing PhaaS kits like Sneaky2FA using BrowserâinâtheâBrowser tricks â TamperedChef, Sneaky2FA Kit
- WhatsApp-targeting campaigns including the socialâengineering HijackOnChat wave and a Python worm spreading the Eternidade stealer are rapidly infecting devices and distributing infoâstealers â HackOnChat, Eternidade Worm
Vulnerabilities & Exploits
- Attackers are actively exploiting the CVE-2025-11001 7âZip symbolicâlink RCE flaw, prompting NHS and other alerts â patch or mitigate now â 7-Zip RCE, 7-Zip RCE
- Recent disclosures and patches cover critical enterprise and web components, from SolarWinds ServâU fixes to a PHP command injection in W3 Total Cache and an exploited twoâyearâold Ray AI framework flaw â SolarWinds Fixes, W3TC Flaw, Ray Flaw
Routers & IoT
- The WrtHug campaign exploited six ASUS WRT flaws to hijack over 50,000 endâofâlife routers worldwide, enabling persistent access and network abuse â ASUS WrtHug, ASUS WrtHug
Sanctions & Takedowns
- The US, UK, Australia and allies sanctioned multiple Russian bulletproof hosting providers tied to ransomware and illicit services, and operatorsâ domains have been disrupted â Hosting Sanctions, Hosting Sanctions, Hosting Sanctions, Hosting Sanctions
Piracy & Crypto Enforcement
- Law enforcement and industry operations disrupted major piracy networks, seized domains like Photocall (â26M yearly visits) and traced roughly $55 million in crypto to fund takedowns â Photocall Shutdown, Crypto Trace, Crypto Trace
- Separately, founders of a prominent crypto mixer were sentenced for laundering over $237 million, underscoring intensified antiâmoneyâlaundering enforcement â Crypto Mixer
Threat Intelligence
- Weekly bulletins highlight active 0âdays, new malware waves, crypto crime trends and IoT flaws that defenders should prioritize â read the roundup for indicators and mitigations â ThreatsDay
Policy & Governance
- The EU is centralizing CVE governance as ENISA becomes a CVE root, while national and industry agreements like the CybleâBotswana BOCRA MoU aim to shore up regional cyber frameworks â ENISA CVE Root, Botswana MoU
- Regulatory and legislative moves include a reintroduced bill to beef up SEC cybersecurity oversight, Canadian privacy regulators blaming schools after the PowerSchool breach, and an EU proposal that critics say could weaken GDPR/AI safeguards â SEC Bill, PowerSchool Ruling, GDPR Proposal
- An ARC dataâsale scandal revealed airlinesâ travel records used for warrantless surveillance, raising fresh privacy and dataâsharing concerns â ARC Data Sale
Corporate Deals & Funding
- Cyber startups and vendors raised and closed major deals this week, including $70M for Doppel, a $3.35B Palo Alto acquisition of Chronosphere, and seed rounds for Secure.com ($4.5M) and Mate ($15.5M) â Doppel Funding, Palo Alto Deal, Secure.com Funding, Mate Funding
CyberâPhysical Incidents
- Investigations link Iranianâlinked hackers to AIS mapping of ships days before a missile strike attempt and vendors like Amazon documented cyberâenabled kinetic attacks tying espionage to physical strikes â AIS Mapping, Amazon Report
- A major Russian insurer experienced widespread outages after a cyberattack, impacting services and claims processing amid ongoing investigation â Insurer Outage
Consumer Fraud & Scams
- Seasonal shopping scams hit record levels with fake deals and storefronts driving increased consumer losses during Black Friday promotions â prioritise phishing and fraud controls â Black Friday Scams
Events & Research
- Webinar: practical guidance on protecting what WAFs and gateways canât see â register for defensive strategies and demo material â WAF Webinar