The UK's Information Commissioner's Office has fined DNA testing company 23andMe £2.31 million ($3.1 million) for “serious security failings” that led to a major data breach in 2023. The attack, which compromised the genetic and personal data of millions worldwide, highlights growing regulatory scrutiny over the protection of sensitive biometric information.
Source: Bleeping ComputerScattered Spider Ransomware Group Shifts Targets to US Insurance Firms
Google’s Threat Intelligence Group and multiple sources warn that the notorious Scattered Spider threat actor has pivoted from the retail to insurance sectors, successfully breaching several major US insurance companies. The group, known for sophisticated social engineering and ransomware attacks, poses a growing threat to critical financial services infrastructure.
Source: SecurityWeekCritical Flaws in Sitecore CMS Allow Pre-Auth Remote Code Execution
Security researchers have revealed a pre-authentication remote code execution chain in the widely-used Sitecore Experience Platform, triggered by vulnerabilities including a hardcoded “b” password. The flaw—impacting major enterprise deployments—permits attackers to fully compromise systems running unpatched instances, underlining the urgent need for updates and monitoring CMS environments.
Source: Bleeping ComputerTP-Link Routers & Apple Devices Added to CISA’s Known Exploited Vulnerabilities
CISA has issued immediate alerts on a critical remote code execution bug (CVE-2023-33538) impacting discontinued TP-Link router models and further vulnerabilities affecting Apple products. These flaws are actively exploited in the wild, leaving legacy devices especially exposed as attackers seek to compromise home and small business networks.
Source: TheHackerNewsLangflow AI Server Vulnerability Exploited to Deploy Flodrix Botnet
A critical vulnerability in Langflow (CVE-2025-3248) is being exploited in active campaigns, with attackers installing the Flodrix botnet on unpatched servers. This threat not only enables complete system compromise but also allows botnet-driven DDoS attacks and data exfiltration, underscoring the risk posed by flaws in popular open source AI tools.
Source: SecurityWeekResearchers Find Keyloggers on Outlook Login Pages after Exchange Server Compromises
Multiple organizations, including government agencies, fell victim to attackers who compromised Microsoft Exchange servers and injected browser-based keyloggers into Outlook Web Access login pages. The malicious JavaScript harvested user credentials directly, though the initial compromise vector—possibly via unpatched vulnerabilities—remains unidentified.
Source: Help Net SecurityMeta to Display Targeted Ads in WhatsApp App, Sparking Privacy Concerns
After years of delay, Meta has started rolling out targeted ads within WhatsApp. The move raises fresh privacy concerns, as ads will appear in the app’s Updates tab, even as Meta claims the system was “built with privacy in mind.” Privacy advocates and regulators are expected to scrutinize the development, given WhatsApp’s previous privacy assurances.
Source: MalwareBytes BlogYou May Also Be Interested In... Critical Windows Privilege Escalation — Patch Now
New ClickFix Malware Variant 'LightPerlGirl' Spotted in the Wild
CISA Urges Users to Ditch Vulnerable TP-Link Routers