Canadian and U.S. authorities have issued warnings after the China-linked Salt Typhoon APT group exploited a critical Cisco vulnerability (CVE-2023-20198) to breach Canadian telecommunications infrastructure. The campaign is part of broader, multi-year espionage operations targeting telecoms globally, leveraging router flaws and exploiting vendors’ delayed patching. Organizations are urged to examine their perimeter devices, apply recent updates promptly, and monitor for unusual router activity.
Source: The Hacker News
US, Allies Warn of Surge in Iranian Cyber Threats After Military Escalation
The U.S. Department of Homeland Security and multiple security agencies have warned of an increased risk of cyberattacks by Iranian state-sponsored threat groups and pro-Iranian hacktivists following recent U.S. airstrikes on Iranian nuclear sites. Potential targets include critical infrastructure and commercial entities, with anticipated attacks ranging from disruptive website defacement to more sophisticated attempts to breach vital systems. Organizations are advised to heighten vigilance and ensure resilience against state-aligned cyber aggression.
Source: BleepingComputer
SparkKitty Malware Discovered on Google Play and Apple App Store Stealing Photos and Crypto
Researchers have identified a new Trojan, SparkKitty, which made its way onto both Google Play and Apple’s App Store, stealing photos and cryptocurrency assets from infected Android and iOS devices. The malware spreads through malicious SDKs in seemingly benign apps and targets both images and wallet data, underscoring the need for increased scrutiny of app marketplaces and regular user security hygiene.
Source: BleepingComputer
China-Linked ‘LapDogs’ ORB Network Uses SOHO Devices as Espionage Infrastructure
SecurityScorecard analysts have revealed the “LapDogs” campaign, which repurposes compromised small office/home office (SOHO) routers and IoT devices using the ShortLeash backdoor and fake TLS certificates to evade detection. The operation, attributed to a Chinese APT group, targets U.S. and Asian organizations, creating stealthy relay networks for long-term espionage and data exfiltration.
Source: Help Net Security
Citrix Fixes Critical NetScaler Vulnerability Reminiscent of CitrixBleed (CVE-2025-5777)
Citrix has urgently patched a critical out-of-bounds read vulnerability (CVE-2025-5777) in NetScaler ADC and Gateway products, similar in risk to last year’s CitrixBleed flaw. While there is no widespread exploitation reported yet, organizations are strongly encouraged to upgrade immediately and terminate active sessions to prevent possible pre-authentication exploitation.
Source: Help Net Security
Echo Chamber Attack Bypasses AI Guardrails in Large Language Models
Security researchers have uncovered a novel technique dubbed the “Echo Chamber” jailbreak, which manipulates context in generative AI tools such as those from OpenAI and Google, allowing attackers to coax out harmful outputs without explicit prompts. This new class of indirect attacks highlights the ongoing cat-and-mouse game in AI security and the urgent need for robust contextual defenses in LLM deployments.
Source: SecurityWeek
Record-Breaking Data Breach Exposes 16 Billion Login Credentials
An unprecedented breach has exposed a massive trove of 16 billion login credentials, combining previously leaked datasets with newly exfiltrated credentials from malware-infected devices. Such password compilations dramatically increase the effectiveness of credential stuffing and phishing attacks, highlighting the necessity for multi-factor authentication and proactive password hygiene.
Source: McAfee Blog
You May Also Be Interested In... CoinMarketCap and Cointelegraph Compromised to Drain Crypto Wallets
Data of more than 740,000 stolen in ransomware attack on Michigan hospital network
Chrome 0-Day, 7.3 Tbps DDoS, MFA Bypass Tricks Weekly Recap