Daily Recap, North Korean-linked actors and a separate malicious-crate campaign were tied to a Rust supply-chain wave that injected build-time malware into crates with 245 million downloads, including poisoning the arrayref pathway to deliver an infostealer. Elsewhere, Microsoft warned of a max-severity Microsoft Entra ID flaw already exploited in attacks, while attackers abused Google OAuth and WhatsApp account linking and a passkey-enabled phishing toolkit to maintain access. #NorthKoreanHackers #Rust #arrayref #MicrosoftEntraID #GoogleOAuth #WhatsApp #Passkeys #EntraFlaw
Supply Chain
- North Korean hackers and a separate malicious-crate campaign are tied to a Rust supply-chain wave that injected build-time malware into crates with 245 million downloads and poisoned arrayref to deliver an infostealer – Rust Attack, Build Malware, Arrayref Poisoning
Cloud & Identity
- Microsoft warned of a max-severity Entra ID flaw already exploited in attacks, highlighting urgent patching needs for identity infrastructure – Entra Flaw
- Attackers are abusing Google OAuth and WhatsApp linking to hijack accounts, while a phishing toolkit now uses passkeys to keep access after password resets – OAuth Hijack, Passkey Phish
Vulnerabilities & Exploits
- A critical isolated-vm vulnerability can lead to RCE on the host, adding to a day packed with high-risk app and platform exposures – Isolated-vm RCE
- Citrix urged admins to patch new NetScaler flaws immediately as active exploitation continues across enterprise edge devices – NetScaler Flaws
- Zimbra servers are under active exploitation, and broader threat roundups flagged fresh Gogs RCE, n8n workflow-to-RCE, and a $10M reward tied to notable exploit activity – Zimbra Attack, ThreatsDay
Malware & Intrusions
- Hackers are using FTP server banners to deliver a new Windows malware strain, showing another stealthy infection route in the wild – FTP Malware
- Russian-suspected actors are targeting account access, while China’s SilkParasite operation is using AI-assisted malware for espionage in Central Asia – Russian Intrusion, SilkParasite
Data Breaches
- SickKids said a breach exposed employee and job applicant information, while CareCloud disclosed an incident affecting 3.7 million people – SickKids Breach, CareCloud Breach
Surveillance & Policy
- Lawmakers sought watchdog review of federal hacking of Americans as surveillance concerns grew around a retail-theft bill and broader monitoring powers – Watchdog Review, Retail Surveillance, Surveillance Primer
- Senators pressed TikTok over withholding safety features for some users amid growing scrutiny of platform protections – TikTok Safety
Physical Security
- A threat actor reportedly hacked 14,000 IP cameras across Ukraine and Russia, underscoring the scale of exposed connected devices – IP Cameras
Sentencing
- An early 764 member received a 77-year sentence, marking the longest prison term yet for a nihilistic violent extremist – 764 Sentence