Organizations are being warned about a trojanized version of SonicWall's SSL-VPN NetExtender application, used to exfiltrate VPN credentials from unsuspecting users. Threat actors are distributing the compromised installer via lookalike websites, highlighting the persistent risk of downloading software from unofficial sources. If your organization relies on SonicWall VPN, ensure every installation came directly from SonicWall and review credential security immediately.
Source: Help Net Security
Critical WinRAR Vulnerability Patched—Users Urged to Update Quickly (CVE-2025-6218)
A high-risk directory traversal vulnerability in WinRAR (CVE-2025-6218) could allow remote attackers to execute arbitrary code on affected machines. The flaw has been patched in WinRAR 7.12 beta 1, and users are strongly encouraged to update immediately, as attackers can exploit this flaw to compromise Windows systems by simply tricking users into opening malicious archive files.
Source: Help Net Security
Chinese APT ‘Salt Typhoon’ Campaign Hits Canadian Telecom in Espionage Operation
A joint US-Canadian advisory confirms that the Chinese state-sponsored Salt Typhoon (also known as APT) compromised a major Canadian telecom provider in February. The campaign, active for up to two years, targets telecom and internet infrastructure, leveraging compromised devices—including SOHO routers—to build a global espionage network. This incident highlights escalating China-backed threat activity against North American infrastructure and the urgent need for robust segmentation and device hardening.
Source: SCMagazine
Sophisticated Spyware Found in Apple App Store and Google Play, Stealing Photos and Possibly Crypto Data
Researchers uncovered "SparkKitty" spyware on both the Apple App Store and Google Play, capable of stealing all photos from infected mobile devices and potentially targeting stored cryptocurrency wallet information. The campaign, active since early 2024, underlines the persistent risks of malicious apps slipping through official store reviews and the vital need for organizations to carefully review employee device management and mobile security policies.
Source: HackRead
Russia's APT28 Deploys New Malware via Signal Chats Against Ukraine
Ukraine’s CERT and global researchers report that Russian state-sponsored group APT28 (aka Fancy Bear/Forest Blizzard) used Signal encrypted chats to deliver new malware variants (BeardShell and SlimAgent) in targeted attacks on government officials. While Signal itself remains uncompromised, this novel social engineering technique demonstrates how secure messaging platforms can be exploited as delivery channels in advanced persistent threat scenarios.
Source: SecurityWeek
US House Bans WhatsApp on Staff Devices Citing Security Concerns
The US House of Representatives has formally banned the use of WhatsApp on government-issued devices, citing security gaps in how the messaging app handles and encrypts data. The move reflects growing concern about third-party communication tools in government, following similar restrictions on generative AI apps and software with unclear data protection practices.
Source: Bleeping Computer
New WordPress Malware Campaign Imitates Cloudflare to Skim Credit Cards
A sophisticated malware operation has been uncovered targeting WordPress websites, hiding malicious code on checkout pages via a rogue Core plugin that masquerades as a Cloudflare component. This campaign, active since 2023, specializes in stealing credit cards and credentials using advanced anti-detection tactics—sending a clear signal to ecommerce platforms to review plugin authenticity, monitor file integrity, and implement strong endpoint protection.
Source: HackRead
You May Also Be Interested In...