Google's Threat Intelligence Group and Citizen Lab report an ongoing campaign by Russia-linked APT29 in which targets—including high-profile academics and researchers—are convinced to generate and surrender Google’s app-specific passwords. These passcodes, once shared, enable attackers to bypass two-factor authentication (2FA) and maintain long-term access to victims’ Gmail, demonstrating a sophisticated social engineering approach that exploits trusted authentication features.
Source: GoogleCloud Threat Intelligence
Critical Linux Flaws: Chaining CVEs Allows Easy Root on Most Distros
Two newly disclosed local privilege escalation vulnerabilities (CVE-2025-6018 and CVE-2025-6019) found by Qualys can be chained to achieve root access on most major Linux distributions with minimal effort. These flaws impact PAM and Udisks, representing severe risks for both enterprise and personal systems, and active exploitation has already prompted warnings from CISA and urgent patching recommendations.
Source: Help Net Security
Over 5.4 Million Impacted in Massive Healthcare Data Breach at Episource
Episource, a major healthcare technology and services provider, revealed that hackers compromised personal and health data of more than 5.4 million individuals earlier this year. This breach underscores the persistent threat targeting healthcare providers and the vast exposure risk posed by attacks on third-party tech vendors serving sensitive industries.
Source: SecurityWeek
Fake Minecraft Mods Infect Thousands With Multi-Stage Stealers
Security researchers at Check Point discovered a sophisticated multi-stage malware campaign targeting Minecraft players via malicious mods and cheats distributed on GitHub. The infection chain deploys downloaders and advanced stealers, harvesting credentials, crypto wallets, and browser data, and is believed to be operated by Russian-speaking threat actors. With Minecraft’s massive user base, the scope of exposure is substantial.
Source: Check Point Blog
CloudFlare Tunnels Abused to Deliver Stealthy Python-based Remote Access Trojans
A newly identified campaign named SERPENTINE#CLOUD leverages Cloudflare Tunnel subdomains to bypass perimeter defenses and deliver Python-based, memory-injected malware to victims. This approach enables attackers to establish persistent, covert remote access within corporate environments, highlighting growing attacker sophistication in abusing cloud infrastructure for command-and-control and payload delivery.
Source: The Hacker News
WormGPT Returns: Jailbroken AI Models Power Blackhat Phishing Tools
Security teams have identified two new variants of WormGPT, an uncensored AI tool, developed by jailbreaking mainstream commercial LLM APIs such as Grok and Mixtral. These AI-powered hacking tools are being sold on cybercrime forums, dramatically increasing the automation and sophistication of phishing, BEC, and malware campaigns conducted by less technical adversaries.
Source: HackRead
Threat Actors Exploit Critical Langflow Vulnerability (CVE-2025-3248) to Deploy Botnet
Trend Research and others have tracked ongoing exploitation of CVE-2025-3248 in Langflow servers to propagate the Flodrix botnet. Attackers run malicious scripts on unpatched servers, emphasizing the urgent need for organizations to address vulnerabilities in AI and ML application infrastructure.
Source: Security Affairs
You May Also Be Interested In... Cloudflare Launches Log Explorer for Security Visibility
Citrix Patches Critical NetScaler Vulnerabilities
North Korea’s ‘PylangGhost’ Python RAT Targets Crypto Job Seekers