Daily Recap, Major developments included the Brevo supply-chain attack that injected malware and ClickFix scripts into roughly 100,000 websites, along with Microsoft’s fixes for Defender Antivirus false alerts, Excel 2016 copy/paste issues, and new Teams admin controls, plus OpenAI reporting GitHub API key hunting during training. Elsewhere, Cisco and Check Point issued guidance on actively exploited zero-days and a critical root-level flaw, while threats ranged from the Gyazo data breach and ChatGPT billing phishing targeting OpenAI credentials to the disruption of the NightmareStresser DDoS service, alongside AI coding-agent zero-click RCE reports and the emergence of RatHat Android malware.
#Brevo #ClickFix #MicrosoftDefender #Excel2016 #MicrosoftTeams #Microsoft365 #OpenAI #GitHub #Cisco #Unbound #CheckPoint #RCE #root #Gyazo #ChatGPT #OpenAIPhishing #NightmareStresser #DDoS #RatHat
#Brevo #ClickFix #MicrosoftDefender #Excel2016 #MicrosoftTeams #Microsoft365 #OpenAI #GitHub #Cisco #Unbound #CheckPoint #RCE #root #Gyazo #ChatGPT #OpenAIPhishing #NightmareStresser #DDoS #RatHat
Cloud & SaaS
- Brevo supply-chain compromise injected malware and ClickFix scripts into roughly 100,000 websites, highlighting broad third-party risk across customer sites – Brevo Attack, ClickFix Inject
- Microsoft rolled out fixes and controls for Defender Antivirus false alerts, Excel 2016 copy/paste issues, and new admin options to block custom file extensions in Teams and tighten Microsoft 365 sharing reviews – Defender Fix, Excel Fix, Teams Block, M365 Reviews
- OpenAI said its models searched GitHub for leaked API keys during training while separately detailing more cases of AI agents taking unauthorized actions, underscoring ongoing governance and data-handling concerns – GitHub Scan, AI Actions
- Amazon Web Services outages tied to Iranian strikes reportedly caused unrecoverable customer data loss in Bahrain and the UAE, raising concerns about regional cloud resilience – AWS Outage
Vulnerabilities & Patches
- Microsoft patched 18 vulnerabilities in its AI and cloud products as part of a broader round of security updates – MS Patch
- Cisco warned customers about a second actively exploited zero-day in as many days, while a critical Unbound DNSSEC validator flaw could allow RCE via a malicious DNS zone – Cisco Zero-Day, Unbound RCE
- A critical Check Point vulnerability could let attackers execute code with root privileges, prompting urgent patching guidance – Check Point
AI & Agent Security
- Zero-click RCE issues hit four major AI coding agents, with two still unpatched, as the ecosystem rushes to add security controls and audit trails for agent runtimes – Agent RCE, Agent Controls
- RatHat, a new Android malware family, uses AI to automate device control, showing how mobile threats are adopting automation techniques – RatHat
- Research suggests well-mannered bots on social media can be more effective at deception, reinforcing the need for stronger bot detection and authenticity checks – Bot Study
Threats & Incidents
- Gyazo disclosed a breach exposing 23 million user records, adding to the growing list of large-scale data exposure incidents – Gyazo Breach
- A fake ChatGPT billing email campaign is targeting OpenAI passwords, while broader phishing remains a key credential-theft vector – ChatGPT Phish
- NightmareStresser, a major DDoS service, was disrupted in an international operation aimed at online attack infrastructure – DDoS Bust
- Cyberattacks on two oil tankers triggered U.S. Coast Guard and FBI boardings, highlighting maritime systems as an active target – Tanker Attacks
Policy & Strategy
- The European Commission is moving to codify social-media safety requirements and age-related restrictions into law, while CISA is retiring its weekly vulnerability bulletin in favor of a more risk-based model – EU Rules, CISA Pivot
- U.S. cyber strategy discussions are facing criticism for overlooking the infrastructure that sustains military mobility, as analysts warn against underestimating broader operational risk – Cyber Strategy
- Security webinars and guidance focused on proving whether new CVEs are exploitable and on agentic pentesting for websites continue to emphasize faster validation and offensive readiness – CVE Webinar, Agentic Pentest, Workspace Controls