Daily Recap, regulatory moves span India withdrawing the Sanchar Saathi mandate and the UKâs cookie-enforcement push, with broader state activity highlighting Russiaâs connected-car vulnerabilities and sanctions related to cyber espionage. The week also features critical RSC bugs in React/Next.js, LNK flaws, Elementor/King Addons WordPress exploits, a record AISURU DDoS with up to 4 million bots, Predator spyware activity, and data breaches at Freedom Mobile and Marquis alongside Rhysida ransomware pressure on local governments. #SancharSaathi #PredatorSpyware #AISURU #Rhysida #KingAddons #LNK #FreedomMobile #Marquis
News:
Privacy & Regulation
- India withdraws a mandate to pre-install the Sanchar Saathi cyberâsafety app after surveillance backlash, reversing a controversial phoneâpolicy â Sanchar Saathi, India Drops
- The UK ICOâs cookie enforcement campaign brings ~95% of top sites into compliance, leaving just 21 nonâcompliant sites and strengthening user tracking controls â UK Cookies
NationâState Activity
- Connectedâcar failures in Russia raise fears about automotive tracking vulnerabilities after unexplained Porsche shutdowns, highlighting risks to IoT vehicles â Porsche Shutdown
- Russian actors target Reporters Without Borders while the UK sanctions the GRU and linked cyber spies over a nerveâagent attack, underscoring escalating state cyber and diplomatic actions â Reporters Targeted, UK Sanctions
- Researchers report continued use of Predator spyware across countries including Iraq, and an exclusive analysis exposes a compromised North Korean APT machine tied to a major heist, showing persistent stateâgrade surveillance tooling â Predator Spyware, North Korea APT
- Russia blocks Roblox over alleged LGBT âpropagandaâ, illustrating censorship and platform control as part of broader state online measures â Roblox Block
Vulnerabilities & Patching
- Critical RSC bugs in React and Next.js allow unauthenticated remote code execution, posing severe risks to modern web apps â RSC Bugs
- Microsoft quietly patches a longâexploited Windows LNK flaw after years of active abuse, closing an often weaponized attack path â LNK Patch
- A Microsoft 365 licenseâcheck bug blocks desktop app downloads for affected users, disrupting productivity and licensing workflows â M365 Bug
- Critical WordPress plugin flawsâincluding an exploited Elementor addâon and active attacks exploiting King Addonsâare being used to create admin accounts and take over sites, urging immediate patching â Elementor Flaw, King Addons, King Addons
Malware & Botnets
- A record 29.7 Tbps DDoS attack was linked to the AISURU botnet with up to 4 Million infected hosts, marking a new volumetric high in internet disruption â Record DDoS
- New stealthy Linux malware combines Miraiâstyle DDoS capabilities with a cryptominer, expanding multifunction botnet threats on IoT and Linux hosts â Linux Malware
- Brazil is hit by a banking Trojan spread via a WhatsApp worm and RelayNFC relay fraud, demonstrating mobileâcentric banking malware evolution â Brazil Banking Trojan
- The socialâengineering ClickFix campaign uses a fake ChatGPT âAtlasâ browser to trick users into installing tools and executing commands to steal passwords and gain system control â ClickFix Attack
Data Breaches & Exposures
- Freedom Mobile discloses a data breach exposing customer personal information, with reporting across multiple outlets urging impacted user mitigation â Freedom Mobile, Freedom Mobile
- The Marquis breach affects over 74 US banks and credit unions, expanding the impact radius of thirdâparty data compromises in financial services â Marquis Breach
- French DIY giant Leroy Merlin and the University of Phoenix report data breaches tied to vendor/Oracle EBS issues, continuing the trend of supplyâchain and thirdâparty exposures â Leroy Merlin, UoP Breach
Ransomware & Supply Chain
- The Rhysida ransomware gang demanded ~9 bitcoin (almost $800,000) from the Cleveland County, OK sheriffâs office after compromising systems, reflecting rising pressure on local governments â Rhysida Ransom
- Analysts warn that ransomware and supplyâchain attacks are increasingly converging, amplifying downstream risk for organizations and partners â RansomâSupply Chain
Industry Trends & Guidance
- Global cyber agencies issue AI security guidance for protecting critical infrastructure OT, emphasizing secure AI deployment in industrial environments â AI OT Guidance
- Threat roundups highlight a surge in WiâFi hacks, npm worms, DeFi thefts and phishing blasts, while a yearâinâreview summarizes the 5 threats that reshaped web security in 2025 â ThreatsDay, Web Security
Surveillance & Policing
- A Canadian police department becomes the first to trial body cameras with embedded facial recognition, raising privacy and civilâliberty questions around law enforcement tech â Facial Cameras
Funding & Research
- Niobium raises $23 Million to accelerate hardware for fully homomorphic encryption, advancing practical privacyâpreserving computation capabilities â Niobium Funding
Privacy & Regulation
- India withdraws a mandate to pre-install the Sanchar Saathi cyberâsafety app after surveillance backlash, reversing a controversial phoneâpolicy â Sanchar Saathi, India Drops
- The UK ICOâs cookie enforcement campaign brings ~95% of top sites into compliance, leaving just 21 nonâcompliant sites and strengthening user tracking controls â UK Cookies
NationâState Activity
- Connectedâcar failures in Russia raise fears about automotive tracking vulnerabilities after unexplained Porsche shutdowns, highlighting risks to IoT vehicles â Porsche Shutdown
- Russian actors target Reporters Without Borders while the UK sanctions the GRU and linked cyber spies over a nerveâagent attack, underscoring escalating state cyber and diplomatic actions â Reporters Targeted, UK Sanctions
- Researchers report continued use of Predator spyware across countries including Iraq, and an exclusive analysis exposes a compromised North Korean APT machine tied to a major heist, showing persistent stateâgrade surveillance tooling â Predator Spyware, North Korea APT
- Russia blocks Roblox over alleged LGBT âpropagandaâ, illustrating censorship and platform control as part of broader state online measures â Roblox Block
Vulnerabilities & Patching
- Critical RSC bugs in React and Next.js allow unauthenticated remote code execution, posing severe risks to modern web apps â RSC Bugs
- Microsoft quietly patches a longâexploited Windows LNK flaw after years of active abuse, closing an often weaponized attack path â LNK Patch
- A Microsoft 365 licenseâcheck bug blocks desktop app downloads for affected users, disrupting productivity and licensing workflows â M365 Bug
- Critical WordPress plugin flawsâincluding an exploited Elementor addâon and active attacks exploiting King Addonsâare being used to create admin accounts and take over sites, urging immediate patching â Elementor Flaw, King Addons, King Addons
Malware & Botnets
- A record 29.7 Tbps DDoS attack was linked to the AISURU botnet with up to 4 Million infected hosts, marking a new volumetric high in internet disruption â Record DDoS
- New stealthy Linux malware combines Miraiâstyle DDoS capabilities with a cryptominer, expanding multifunction botnet threats on IoT and Linux hosts â Linux Malware
- Brazil is hit by a banking Trojan spread via a WhatsApp worm and RelayNFC relay fraud, demonstrating mobileâcentric banking malware evolution â Brazil Banking Trojan
- The socialâengineering ClickFix campaign uses a fake ChatGPT âAtlasâ browser to trick users into installing tools and executing commands to steal passwords and gain system control â ClickFix Attack
Data Breaches & Exposures
- Freedom Mobile discloses a data breach exposing customer personal information, with reporting across multiple outlets urging impacted user mitigation â Freedom Mobile, Freedom Mobile
- The Marquis breach affects over 74 US banks and credit unions, expanding the impact radius of thirdâparty data compromises in financial services â Marquis Breach
- French DIY giant Leroy Merlin and the University of Phoenix report data breaches tied to vendor/Oracle EBS issues, continuing the trend of supplyâchain and thirdâparty exposures â Leroy Merlin, UoP Breach
Ransomware & Supply Chain
- The Rhysida ransomware gang demanded ~9 bitcoin (almost $800,000) from the Cleveland County, OK sheriffâs office after compromising systems, reflecting rising pressure on local governments â Rhysida Ransom
- Analysts warn that ransomware and supplyâchain attacks are increasingly converging, amplifying downstream risk for organizations and partners â RansomâSupply Chain
Industry Trends & Guidance
- Global cyber agencies issue AI security guidance for protecting critical infrastructure OT, emphasizing secure AI deployment in industrial environments â AI OT Guidance
- Threat roundups highlight a surge in WiâFi hacks, npm worms, DeFi thefts and phishing blasts, while a yearâinâreview summarizes the 5 threats that reshaped web security in 2025 â ThreatsDay, Web Security
Surveillance & Policing
- A Canadian police department becomes the first to trial body cameras with embedded facial recognition, raising privacy and civilâliberty questions around law enforcement tech â Facial Cameras
Funding & Research
- Niobium raises $23 Million to accelerate hardware for fully homomorphic encryption, advancing practical privacyâpreserving computation capabilities â Niobium Funding