This roundup covers major cybersecurity developments, including new malware and backdoors, critical vulnerabilities, phishing schemes, AI-agent abuse, and large-scale data breaches affecting organizations such as ZyXEL, Check Point, Elsevier, Google, and Microsoft. It also highlights growing risks from malicious bots, deepfakes, impersonation scams, and emerging security challenges tied to AI, cloud services, and critical infrastructure. #TASKSTOMP #ZyXEL #Elsevier #CheckPoint #EvilTokens #Gyazo #OpenAI #Google #Microsoft
Keypoints
- TASK#STOMP steals files, Wi-Fi passwords, screenshots, and clipboard data from Windows systems.
- Attackers exploited a ZyXEL switch flaw to exfiltrate data from nearly 1,000 devices worldwide.
- Microsoft disrupted the EvilTokens phishing service that compromised more than 12,000 inboxes.
- Check Point released emergency fixes after active exploitation of critical server and gateway vulnerabilities.
- Researchers and vendors warned about rising AI-agent abuse, deepfake scams, and bot activity across the web.