Attackers are actively exploiting a zero-day vulnerability in Microsoft SharePoint (CVE-2025-53770), with the China-linked Storm-2603 group deploying Warlock ransomware across at least 400 government entities and businesses worldwide. Compromised targets include US federal agencies and the National Nuclear Security Administration, as Microsoft warns that its July 8 patch was insufficient, leaving many at risk. Exploitation continues despite partial mitigations, highlighting the persistent threat to on-premises SharePoint infrastructure.
Source: Bleeping Computer
Supply Chain on Alert: Major npm Package Compromised in Massive Phishing Campaign
A major supply chain attack targeted the npm JavaScript ecosystem when the widely used “is” package was infected with cross-platform malware following a targeted phishing campaign. Attackers used a typosquatted clone of the npm website to lure maintainers, compromising both cross-platform and Windows-only developer tools. The incident underscores the growing risks of package manager ecosystems and the sophistication of modern phishing campaigns against open-source communities.
Source: The Register
Amazon Q AI Coding Assistant Hit with Malicious Command — Exposes AI Supply Chain Risk
The official Amazon Q extension for Visual Studio Code was compromised, with a malicious prompt embedded to wipe user files and cloud resources. The tampered extension was available for two days before removal, illustrating the potential dangers as AI tools become a target for attackers. The incident has heightened concern over the security and oversight of AI-powered developer tools distributed via official channels.
Source: ZDNet
SonicWall Urges Emergency Patching After Critical Vulnerability Exploited in Ongoing Attacks
SonicWall has patched a critical flaw in its SMA 100 series appliances (CVE-2025-40599, CVSS 9.1), warning customers to urgently update and check for signs of compromise. Attackers are exploiting this vulnerability to deploy the OVERSTEP backdoor, particularly in out-of-support devices. Organizations are urged to review installations and take mitigation steps, as no active in-the-wild exploitation has been confirmed for patched devices, but ongoing campaigns are delivering malware to the unpatched and end-of-life systems.
Source: Bleeping Computer
BlackSuit Ransomware Gang’s Darknet Sites Seized in Global Police Operation
In a significant win for international law enforcement, authorities have dismantled the leak sites operated by the BlackSuit ransomware group, which has been responsible for attacks on hundreds of global organizations. Operation Checkmate resulted in the takedown of their dark web extortion platform — even as new groups like “Chaos” rise to fill the vacuum, highlighting the ongoing evolution of ransomware ecosystems.
Source: CyberNews
First-Ever Malware Uses Windows UI Automation to Steal Banking Credentials
The newly discovered Coyote malware leverages Microsoft’s UI Automation framework to harvest banking credentials, primarily targeting users in Brazil and focusing on more than 75 banks and crypto platforms. This marks the first instance of this accessibility technology being used in the wild for credential theft, potentially heralding a new trend of malware exploiting accessibility features to evade detection.
Source: The Register
Financial Services Unprepared for DORA Compliance, Survey Finds
Six months after the EU's Digital Operational Resilience Act (DORA) took effect, an overwhelming 96% of financial organizations in EMEA report that their data resilience efforts still fall short of regulatory requirements. The compliance gap highlights lagging preparedness and the complexity of building robust data resilience strategies among banks and financial service firms.
Source: HelpNet Security
You May Also Be Interested In... Clorox Sues Cognizant for $380 Million Over 2023 Hack
Chinese ‘Fire Ant’ Cyber Spies Exploit VMware and Virtualization Flaws
FBI Issues New Warning on Dangerous Apps