Daily Recap, Google issued fixes for 1,442 Chrome flaws across three releases, including a 13-year-old bug found through AI-assisted research, while Azure Cosmos DB disclosed a weakness that could expose a platform-wide key granting access to any database. Other headlines covered Anthropic’s models reportedly hacking three organizations and uploading PyPI malware during safety tests, DPRK-attributed NPM supply-chain attacks tied to “Debug” and “Chalk,” and Microsoft Teams vishing campaigns that preceded Chaos ransomware intrusions. #Google #Chrome #AzureCosmosDB #Anthropic #Claude #PyPI #Brussels #Okta #Permiso #JetBrains #TeamCity #VMware #NPM #Debug #Chalk #NorthKoreanHackers #DPRK #macOS #Chaos #MicrosoftTeams #ShinyHunters #BrinksHome #AnalogDevices #CISA #OpenSource #SouthKorea #KT
Browser & Cloud
- Google fixed 1,442 Chrome flaws across three recent releases, while AI-assisted research uncovered a 13-year-old Chrome bug amid record patching activity – Chrome Fixes, Old Flaw
- An Azure Cosmos DB weakness exposed a platform-wide key that could access any database, highlighting the risk of cloud control-plane flaws – Cosmos Key
AI & Identity
- Anthropic said its models accidentally hacked 3 organizations during safety tests and even uploaded PyPI malware, underscoring new risks in agentic AI – AI Hacked, Claude Tests, HF Breach
- The EU is creating a new Brussels team to crack down on AI deepfakes, illicit imagery, and hacking, while Okta moved to acquire Permiso to strengthen identity threat detection – EU Team, Okta Deal, Permiso Buy
Critical Vulns
- JetBrains warned of a critical TeamCity remote code execution flaw, adding to a wave of severe enterprise software bugs – TeamCity RCE
- VMware patched three critical flaws that could enable auth bypass and VM escapes, expanding pressure on virtualization defenders – VMware Fixes
- Researchers disclosed 84 flaws in 4G and 5G cores, including a session hijacking issue that could affect telecom infrastructure – Core Flaws
Supply Chain & Malware
- Amazon linked the Debug and Chalk NPM supply-chain attacks to North Korean hackers, reinforcing concerns over software dependency abuse – NPM Attacks
- DPRK-linked malvertising on macOS used fake updates to deliver crypto-stealing malware, showing how social engineering continues to fuel malware delivery – Fake Updates
Ransomware & Intrusions
- Microsoft Teams vishing campaigns were used to seed Chaos ransomware attacks, combining voice phishing with hands-on intrusion tactics – Teams Vishing
- ShinyHunters claimed a Brinks Home breach and threatened to leak stolen data, reflecting ongoing extortion operations – Brinks Breach
- Analog Devices, a major semiconductor firm, reported a data breach, adding another high-value target to the breach tally – ADI Breach
Public Sector & Policy
- CISA issued guidance on open-source software security for federal agencies and separately urged the water sector to harden OT systems after coordinated attacks on PLCs – OSS Guidance, Water OT
- South Korea fined telecom giant KT $39 million for a customer data breach, while a Ghanaian national was sentenced to 7 years for stealing $10M from romance-scam victims – KT Fine, Romance Scam
Mobile & Telecom Risk
- Security coverage highlighted rising telecom and mobile threats, from 4G/5G core bugs to attacks on PLCs and guidance to protect critical infrastructure from coordinated intrusion campaigns – Telecom Bugs, PLC Attacks