Chinese state-backed threat group Salt Typhoon successfully compromised a U.S. state's Army National Guard network, accessing configuration data, administrative credentials, and intercepting inter-unit communications between March and December 2024. The Department of Defense report highlights the growing threat of Chinese cyber-espionage campaigns targeting U.S. military and critical infrastructure, escalating concerns among defense and intelligence communities.
Source: SecurityWeek
SonicWall SMA Devices Hacked by OVERSTEP Backdoor and Rootkit—Widespread Attacks on End-of-Life Hardware
A persistent and stealthy attack campaign is targeting fully patched, end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances. Google's Threat Intelligence Group links this activity to threat actor UNC6148, who deploys a custom rootkit called OVERSTEP, facilitating deep system compromise, data theft, and potentially extortion or ransomware operations. Organizations relying on legacy SonicWall hardware are at urgent risk and should prioritize upgrades or mitigations.
Source: Help Net Security
Global Operation Eastwood Takes Down Pro-Russian NoName057(16) DDoS Cybercrime Group
An international law enforcement campaign, codenamed Operation Eastwood and led by Europol and Eurojust, has dismantled the infrastructure of the notorious pro-Russian hacktivist group NoName057(16). Over 100 servers were seized and multiple suspects arrested across Europe and the US, delivering a decisive blow to DDoS operations targeting Ukraine and its allies and demonstrating increased global cooperation in cybercrime enforcement.
Source: SecurityWeek
Google Patches Actively Exploited Chrome Zero-Day (CVE-2025-6558)—Update Now
Google has released an urgent security update for Chrome to address CVE-2025-6558, a high-severity vulnerability under active exploitation. The flaw, rooted in incorrect input validation in Chrome's ANGLE and GPU components, allows attackers to escape the browser sandbox and execute code, marking the fifth exploited Chrome zero-day in 2025. Immediate patching is strongly advised to prevent compromise.
Source: Help Net Security
Former U.S. Soldier Pleads Guilty to Massive Telecom Hacks and Extortion Schemes
Cameron John Wagenius, a 21-year-old former U.S. Army soldier, has pleaded guilty to charges involving hacking into major telecom operators such as AT&T and Verizon and orchestrating crippling data extortion campaigns. His actions included leaking sensitive databases and demanding ransoms, demonstrating the persistent insider and external threats facing telecommunications infrastructure.
Source: Bleeping Computer
Amazon Issues Phishing Warning to 200 Million Prime Customers Amid Surge in Credential Theft Scams
Amazon has warned 200 million Prime members against a sophisticated phishing campaign actively seeking customer login credentials. This latest wave of social engineering emphasizes the ongoing risks to large-scale e-commerce platforms and the need for heightened security awareness and user education.
Source: MalwareBytes Blog
Clandestine Attacks Leverage SVG Images to Deliver Hidden Malware
Security researchers are warning of a notable spike in attacks using Scalable Vector Graphics (SVG) files to conceal malicious JavaScript for redirect and phishing campaigns. Utilities, SaaS providers, and B2B services are increasingly targeted, as attackers exploit trusted image formats to slip past conventional defenses, underscoring the need for advanced payload detection and user vigilance.
Source: SCMagazine
You May Also Be Interested In...