Qantas, Australia’s largest airline, has confirmed a cyberattack at a third-party provider, compromising the personal information of up to six million customers. The breach is linked to ongoing attacks in the aviation sector and reportedly involved sophisticated techniques typical of the Scattered Spider group, including the compromise of contact center platforms. The incident has raised fresh concerns about third-party risk management and data security in the travel industry, especially during peak travel season.
Source: SecurityWeek
Google Chrome Under Active Attack: Urgent Update Required for CVE-2025-6554
Google has released an urgent security patch for Chrome after disclosing CVE-2025-6554, a high-severity zero-day vulnerability under active exploitation. The flaw, involving type confusion in the V8 JavaScript engine, is the fourth Chrome zero-day addressed in 2025 and enables remote code execution if left unpatched. All users are urged to update immediately to avoid compromise, as exploits have already been observed in the wild targeting unsuspecting users.
Source: ZDNet
Phishing 2.0: AI Tools Supercharge Fake Login Pages that Fool Even Experts
Okta researchers have exposed a new generation of phishing attacks where threat actors leverage AI-driven platform v0.dev by Vercel to rapidly create convincing fake login pages for platforms like Okta and Microsoft 365. These advanced phishing sites are so realistic they can deceive even experienced cybersecurity professionals, illustrating how generative AI is accelerating cybercrime and heightening the difficulty of detection and response.
Source: Information Security Newspaper
French Government and Key Sectors Hit by Ivanti Zero-Day Attacks from Chinese Hackers
The French cyber agency ANSSI has confirmed a major cyberespionage campaign attributed to China-linked group UNC5174—Houken—which exploited several zero-day vulnerabilities (CVE-2024-8190, 8963, 9380) in Ivanti appliances. Governmental, telecom, media, finance, and transport organizations were affected, underlining the persistent threat of globally coordinated attacks using previously unknown flaws to breach even high-security environments.
Source: HackRead
US Sanctions Russian Hosting Provider Aeza Group Over Ransomware Support
The US Department of the Treasury has sanctioned Russian bulletproof hosting provider Aeza Group for facilitating ransomware, infostealer operations, and cyberattacks targeting US technology and defense entities. Aeza Group and its subsidiaries have been instrumental in enabling threat actors to evade detection and persist across global infrastructure, demonstrating growing international resolve to disrupt the cybercrime ecosystem via financial and legal measures.
Source: The Hacker News
Cisco Patches Maximum Severity Backdoor Flaw in Unified Communications Manager
Cisco has issued a patch for CVE-2025-20309, a critical vulnerability with a CVSS score of 10, in its Unified Communications Manager that allowed attackers to remotely access systems using hardcoded root SSH credentials. Organizations running affected builds are urged to update immediately, as exploitation could grant full control over voice and collaboration infrastructure, representing a significant risk to enterprise communications.
Source: The Hacker News
North Korean Hackers Target Crypto Firms with New Cross-Platform Nim-Based Malware
Security researchers have uncovered a campaign by North Korean threat actors deploying a novel macOS backdoor dubbed NimDoor, written in the rare Nim programming language. The malware targets web3 and cryptocurrency organizations and employs advanced evasion and persistence techniques, underscoring the evolving cross-platform sophistication of state-sponsored cyber attackers seeking financial gain through targeting next-generation digital assets.
Source: SentinelOne
You May Also Be Interested In...