Security researchers have uncovered a critical escape vulnerability (CVE-2025-23266) in the NVIDIA Container Toolkit, potentially allowing attackers to achieve privilege escalation and gain full control of host machines in managed AI cloud services. With a CVSS score of 9.0, dubbed "NVIDIAScape," the flaw is particularly dangerous in multi-tenant environments, risking sensitive data and AI models. Security teams are urged to apply patches immediately and review cloud infrastructure for signs of compromise.
Source: TheHackerNews
Google Sues Operators of BADBOX 2.0 Botnet That Compromised 10 Million Android Devices
Google has filed a lawsuit against 25 unnamed individuals in China, accused of running the BADBOX 2.0 botnet which infected over 10 million uncertified Android devices worldwide. The botnet not only created a global residential proxy network for cybercriminals, but also facilitated various forms of digital fraud and cyberattacks, leading to Google's efforts to legally disrupt the operation. The incident underscores the growing risks from supply chain compromises in uncertified devices.
Source: TheHackerNews
VMware Issues Emergency Patches for Critical Vulnerabilities—CSA Alerts Global Organizations
The Cyber Security Agency of Singapore and Broadcom have released urgent security advisories addressing multiple critical VMware vulnerabilities (CVE-2025-41236, -41237, -41238, -41239) impacting ESXi, Workstation, Fusion, and related infrastructure. These flaws allow attackers with local admin rights on a VM to execute code on the host, leak data, or escalate privileges, creating major risks in enterprise and cloud environments. Organizations are strongly advised to patch immediately as no workarounds exist and public proof-of-concept code is available.
Source: Cyble
Japanese Police Release Free Decryptor for Phobos and 8Base Ransomware Victims
Victims of the Phobos and 8Base ransomware now have access to a free decryptor, thanks to a tool released by Japanese law enforcement in collaboration with the FBI and European agencies. The decryptor allows those affected to recover their files without paying a ransom, marking a significant blow to these active ransomware operations. Security experts urge victims to use the official tool rather than risk third-party services or attempts at self-decryption.
Source: BleepingComputer
APT28 Deploys AI-Powered ‘LameHug’ Malware in Targeted Attacks on Ukraine
Ukraine’s CERT has identified a new malware strain dubbed LameHug, attributed to Russia-linked APT28 (Fancy Bear), which leverages large language models (LLMs) to generate real-time operating system commands for data-theft on Windows systems. This marks a shift toward adversarial use of generative AI in crafting sophisticated, tailored attacks, raising alarms across the security community about the new frontier of AI-driven cyber-espionage.
Source: Security Affairs
CrushFTP Zero-Day Exploited in the Wild, Allowing Admin Access to Servers
CrushFTP has issued a warning regarding active exploitation of a zero-day vulnerability (CVE-2025-54309) in its secure file transfer software, which lets attackers gain administrative access via the web interface on unpatched servers. Threat actors are reported to be actively targeting this flaw, and organizations using CrushFTP are strongly encouraged to apply available patches and monitor for potential breaches immediately.
Source: BleepingComputer
UK Sanctions Russian GRU Cyber Spies Amid Civilian Targeting Allegations
The UK government has sanctioned 18 members of Russia’s GRU military intelligence for cyber operations contributing to military attacks, including deadly strikes on Ukrainian civilians. This marks a rare public attribution of cyber-enabled kinetic operations and escalates international pressures for accountability in state-sponsored cyberwarfare.
Source: RecordedFuture
You May Also Be Interested In...