Daily Recap, Funding and strategy moves included Balance Theory raising $19 million to help enterprises manage cybersecurity investment decisions, while U.S. Cyber Command plans a Silicon Valley office to strengthen industry collaboration. Key threats and security updates spanned a Rails critical flaw, Adobe Campaign Classicโs CVSS 10.0 code-execution issue, and multiple intrusion stories including Adform script poisoning, the HollowFrame loader deploying Matryoshka, and OctLurk/SilkLurk targeting Central Asian governments. #BalanceTheory #U.S.CyberCommand #RubyOnRails #AdobeCampaignClassic #Adform #HollowFrame #Matryoshka #OctLurk #SilkLurk #Minnesota #CISA #ArchLinux #AUR #Amgen
Funding & Strategy
- Balance Theory raised $19 million to help enterprises better manage cybersecurity spending and investment decisions โ Balance Theory
- U.S. Cyber Command plans a Silicon Valley office to boost innovation and closer tech-industry collaboration โ Cyber Command
Vulnerabilities & Patches
- Ruby on Rails patched a critical vulnerability that could allow severe compromise if left unpatched โ Rails Patch
- Adobe Campaign Classic has a CVSS 10.0 flaw that could enable code execution without user interaction โ Adobe Flaw
Malware & Intrusions
- Attackers poisoned an Adform script to swap cryptocurrency wallet addresses on customer sites, redirecting payments to threat actors โ Adform Hack, Adform Theft
- Hijacked hotel Wi-Fi was used to push fake updates that delivered surveillance malware to unsuspecting users โ Hotel Wi-Fi
- A spear-phishing campaign used the HollowFrame loader to deploy the Matryoshka backdoor against a law firm โ HollowFrame
- Chinese-speaking hackers targeted Central Asian governments with OctLurk and SilkLurk malware families โ OctLurk
AI-Driven Attacks
- Anthropic said its AI was used to hack 3 real-world companies, underscoring the operational misuse of advanced models โ Anthropic AI
- A hacker reportedly used DeepSeek AI to autonomously attack vulnerable servers at scale โ DeepSeek Attack
- ESET reported a rise in malicious AI skills and more adaptable malware strains โ ESET AI
Critical Infrastructure
- CISA warned of a spike in attacks on U.S. water systems, with Minnesota incidents under investigation amid concern about Iranian hackers โ Water Attack, Minnesota Probe, CISA Water, Trump Blames
Supply Chain & Platform Security
- Arch Linux disabled AUR package adoption to curb a malware flood and tighten repository abuse controls โ Arch Linux
- Amgen said a cloud data breach exposed patient health and proprietary information, adding to healthcare sector exposure concerns โ Amgen Breach
Regional Threats
- Central Asian governments were targeted by suspected Chinese-speaking hackers using the OctLurk and SilkLurk toolsets โ Central Asia
- North Korea-linked activity and other threat intelligence highlights were noted in a broader roundup of security developments โ Security Roundup