Cybersecurity News | Daily Recap [14 Nov 2025]

Cybersecurity News | Daily Recap [14 Nov 2025]

Daily Recap, Akira ransomware funds and CISA warnings highlight an imminent threat to Nutanix VMs, while the ransomware ecosystem shows fragmentation with LockBit and Kraken enhancing encryption strategies. The batch of breaches, exploits, phishing, and policy shifts underscores a widening threat landscape across data breaches, DDoS, auth-bypass flaws, and AI-assisted espionage. #Akira #CISA #Nutanix #LockBit #Kraken #Checkout.com #WashingtonPost #Oracle #DoorDash #DDoS #FortiWeb #Imunify360 #ImunifyAV #CiscoISE #CitrixBleed #ASUS #ChatGPT #Claude #Lighthouse #ANY.RUN #Zimbra #Rhadamanthys #VenomRAT #Elysium

Ransomware & Extortion

  • Akira operators have siphoned off roughly $244M–$250M in ransoms and are flagged by CISA as an β€œimminent threat” targeting Nutanix VMs – Akira Funds, Akira CISA, Akira FBI
  • The ransomware scene is fragmenting as LockBit resurfaces, Kraken adds system-benchmarking to optimize encryption, and attacks jumped 30% in October – Ransomware Shift, Kraken Benchmarks, Ransomware Rise

Major Breaches & Disruption

  • Payment processor Checkout.com disclosed a data breach after an extortion attempt and says it refused the ransom despite exposure of old merchant files – Checkout Breach, Checkout Refusal
  • The Washington Post reports nearly 10,000 employees and contractors were impacted by an Oracle-related hack affecting internal data – WP Oracle, WP Impact
  • DoorDash disclosed a new October breach via social engineering that exposed customer, Dasher and merchant data, marking another incident for the platform – DoorDash Breach
  • A DDoS attack disrupted multiple Danish government and defense websites, causing service outages for public portals – Denmark DDoS

Vulnerabilities & Exploits

  • Critical path-traversal and auth-bypass flaws in Fortinet FortiWeb are being actively exploited to create admin users; users should update and audit management interfaces – FortiWeb Flaw, FortiWeb PoC
  • Flaws in Imunify360 and ImunifyAV could enable remote code execution and full-system compromise on millions of Linux-hosted sites, prompting urgent patches – Imunify360 Flaw, ImunifyAV RCE
  • <liAn advanced APT leveraging simultaneous zero-days in Cisco ISE (RCE) and Citrix Bleed was exposed, and CISA updated guidance for patching Cisco devices amid China-linked targeting – Amazon APT, CISA Cisco Guidance

  • ASUS warns of a critical auth-bypass flaw in its DSL-series routers that could allow unauthenticated access to device management – ASUS DSL Flaw
  • A vulnerability in ChatGPT implementations exposed underlying cloud infrastructure, highlighting risks from model integrations – ChatGPT Flaw

AI Abuse & Phishing Kits

  • China-linked actors automated espionage using Anthropic’s Claude (reportedly powering 90% of the campaign), demonstrating AI-assisted intrusion at scale – Claude Abuse, AI-Powered Espionage
  • Google says the Chinese β€œLighthouse” phishing kit was disrupted following legal action, limiting a major phishing infrastructure – Lighthouse Disrupted

Phishing, Malware & Takedowns

  • Russian-speaking actors created over 4,300 fake travel booking sites to steal hotel guests’ payment data in a large-scale, multilingual phishing campaign – Fake Travel Sites
  • Researchers using ANY.RUN dissected a multi-domain Indonesian phishing operation exposing cloned Zimbra login pages and GH0STnet hosting, mapping TLS/SNI and second-stage infrastructure – Indonesian Phish
  • Phishing targeting customers of a major Italian web-hosting provider was observed, highlighting supply-chain credential risks – Italian Hosting Phish
  • A fake Chrome extension named β€œSafery” steals Ethereum wallet seed phrases via a Sui-based trick, and an IndonesianFoods worm flooded npm with ~100,000 malicious packages; law enforcement also took down >1,000 servers linked to Rhadamanthys, VenomRAT and Elysium – Safery Extension, IndonesianFoods Worm, Mass Takedown

Policy, Guidance & Industry

  • A list of the top 100 U.S. cybersecurity leaders shaping industry strategy was published – Top 100 Leaders
  • Two key cyber laws (including CISA-related state/local grants) were reinstated as the president signed a bill to end the shutdown, restoring program funding – Cyber Laws Return
  • Kazakhstan enacted an online ban on alleged β€œLGBT propaganda,” expanding digital content restrictions in the region – Kazakhstan Ban
  • Practical defenses: updated guidance on Kerberoasting in 2025 outlines steps to protect service accounts and reduce ticket-based credential theft risk – Kerberoasting Guide
  • Android reports a major drop in memory-safety bugs as Rust adoption accelerates, improving platform memory safety and developer productivity – Android Rust

Cybersecurity News | Daily Recap – hendryadrian.com