Daily Recap, Microsoft, Fortinet, and Adobe Commerce rushed critical patches as attackers weaponized newly disclosed flaws, while SharePoint authentication bypass issues were exploited shortly after proof-of-concept release. Lazarus also leveraged a Windows zero-day to obtain SYSTEM access and deploy a backdoor, and multiple AI security concerns surfaced alongside fraud, mobile threats, and ongoing data-breach reporting from Trezor.
#Microsoft #Fortinet #AdobeCommerce #SharePoint #Lazarus #Windows #Trezor
#Microsoft #Fortinet #AdobeCommerce #SharePoint #Lazarus #Windows #Trezor
Critical Vulnerabilities
- Microsoft, Fortinet, and Adobe Commerce rushed out fixes as attackers quickly weaponized fresh flaws, while SharePoint authentication bypass issues were exploited soon after public PoC release. β Patch Roundup, Fortinet Fixes, SharePoint Attack, SharePoint PoC, Adobe Commerce, Windows 10 Update
- Lazarus abused a Windows zero-day to gain SYSTEM access and deploy a backdoor, underscoring ongoing North Korean targeting of defense-related victims. β Lazarus Zero-Day, Defense Targeting
AI Security
- Researchers warned that AI code ingestion at open-source scale is hard to vet, even as a LiteLLM supply-chain breach was said to impact thousands of enterprises. β AI Code Vetting, LiteLLM Breach
- A new API flaw affecting OpenAI, Anthropic, and Google reportedly let weaker models decode stronger modelsβ reasoning, while a near-autonomous AI attack was observed against a government target in Taiwan. β AI API Flaw, AI Attack
- Mindgard raised $30 million to expand protections for AI systems amid growing model and supply-chain risk. β Mindgard Funding
Threat Actor Activity
- DeadLock ransomware adopted blockchain to make infrastructure takedowns harder, showing continued innovation in ransomware resilience. β DeadLock Ransomware
- Hackers used social engineering to break into accounts and steal explicit content, prompting fresh warnings from the FBI about online account targeting. β FBI Warning, Account Theft
- The UK criminal records office had three intrusions go undetected for two years, highlighting serious lapses in visibility and detection. β UK Breaches
- Attackers used City-Forum data-theft campaigns against Salesforce and ServiceNow portals, while a fake-remote-worker scheme showed how hiring processes can be abused for access. β City-Forum Attacks, Fake Workers
Malware and Mobile Threats
- An Android malware combo was used to take out loans and relay victimsβ credit cards, showing how mobile fraud toolchains now blend banking theft and credit abuse. β Android Malware
- Plug and Pwn used fake USB devices to gain Windows SYSTEM access, demonstrating the danger of physical-device attack paths. β Plug and Pwn
Fraud and Scam Defense
- WhatsApp rolled out a feature that flags potential scam messages, while hundreds of fake Chrome VPN extensions were found routing traffic through attacker-controlled proxies. β WhatsApp Scam Flag, Fake VPN Extensions
Business and Policy
- The White House reportedly tapped private security firms for offensive hack-back operations, and Trump followed with a memo turning to the private sector for offensive hacking efforts. β Hack-Back Plan, Offensive Memo
- Trezor disclosed a data breach affecting nearly 14,000 customers, adding another high-profile loss of sensitive user data. β Trezor Breach
- Team8 secured an additional $365 million in funding, reflecting continued investor interest in cybersecurity ventures. β Team8 Funding