Daily Recap, Fake OpenAI repositories on Hugging Face pushed an infostealer, while the TCLBANKER banking trojan spread through WhatsApp and Outlook alongside fake call-history apps that reportedly amassed 7.3 million Play Store downloads before stealing payments; PamDOORa also emerged as a new Linux backdoor. In other headlines, cPanel and WHM released fixes for three vulnerabilities, Braintrust urged API key rotation after a breach, NVIDIA confirmed a GeForce NOW breach affecting Armenian users, and ShinyHunters claimed a second attack against Instructure. #HuggingFace #OpenAI #Infostealer #TCLBANKER #WhatsApp #Outlook #PlayStore #PamDOORa #Linux #cPanel #WHM #Braintrust #NVIDIA #GeForceNOW #Armenian #ShinyHunters #Instructure #APIKey
Malware & Apps
- A fake OpenAI repository on Hugging Face delivered an infostealer, while the TCLBANKER banking trojan spread via WhatsApp and Outlook worms, and fake call-history apps racked up 7.3 million Play Store downloads before stealing payments β OpenAI Repo, TCLBANKER, Fake Apps
- A new PamDOORa Linux backdoor surfaced alongside other threat updates, including a train-hacker arrest and the latest CISA leadership race β PamDOORa
Vulnerabilities & Breaches
- cPanel and WHM released fixes for 3 new vulnerabilities, urging immediate patching β cPanel Fixes
- Braintrust disclosed a data breach and prompted API key rotation, while NVIDIA confirmed a GeForce NOW breach affecting Armenian users β Braintrust Breach, NVIDIA Breach
- ShinyHunters claimed a second attack against Instructure, extending its campaign of high-profile compromises β ShinyHunters Attack
Critical Infrastructure & Government
- Polandβs security agency reported ICS breaches at 5 water treatment plants, highlighting risks to essential services β Water Breaches
- A Virginia man was found guilty of deleting 96 government databases, underscoring insider-damage concerns β Gov Databases
- Sen. Schumer pressed the DHS for a plan to coordinate AI cyber efforts with state and local governments amid growing policy pressure β AI Coordination
Law Enforcement & Policy
- The Kingdom Market administrator received a 16-year sentence as authorities continued to target dark-web marketplaces β Kingdom Market
- GM agreed to pay over $12 million in a California privacy settlement tied to driver-data handling β GM Settlement