Palo Alto Networks has announced a definitive agreement to acquire identity security leader CyberArk in a cash-and-stock deal valued at approximately $25 billion. The acquisition—one of the largest in cybersecurity history—signals Palo Alto Networks' strategic push into the identity security and privileged access management domain, critical for securing both humans and AI-driven agents amid escalating threats.
Source: Help Net Security
Apple Patches Zero-Day Vulnerability Exploited Against Chrome, Urges Immediate Update
Apple has released urgent security updates for iOS and iPadOS addressing 29 vulnerabilities, including a high-severity zero-day flaw actively exploited to target Google Chrome users (CVE-2025-6558). This vulnerability allows attackers to escape browser sandboxes via GPU components, reinforcing the importance of prompt patching as sophisticated attacks increasingly exploit browser chains across platforms.
Source: MalwareBytes Blog
Critical SAP NetWeaver Flaw Exploited in Auto-Color Malware Attack
Threat actors exploited a critical vulnerability (CVE-2025-31324) in SAP NetWeaver to deliver an upgraded version of the Auto-Color Linux backdoor during a recent attack on a U.S. chemicals firm. The incident highlights the growing risks facing organizations that rely on ERP and critical infrastructure platforms, with attackers leveraging enterprise system flaws to access sensitive environments.
Source: TheHackerNews
SafePay Ransomware Gang Threatens to Leak 3.5TB of Ingram Micro Data
The SafePay ransomware group is threatening to publish 3.5TB of data allegedly stolen from IT distribution giant Ingram Micro, following an attack earlier this month. The incident underscores continued ransomware risks to supply chains, and the increasing trend of threat actors imposing strict deadlines for extortion while targeting massive repositories of business-critical information.
Source: Bleeping Computer
Hackers Plant 4G-Enabled Raspberry Pi in Physical ATM Attack, Bypass Security Controls
Hackers from group UNC2891 have demonstrated the feasibility of backdooring ATMs through physical implants, using a 4G-enabled Raspberry Pi to gain persistent network access and bypass security defenses. The attack, which involved anti-forensic techniques, highlights ongoing risks to ATM and banking infrastructure from advanced cybercriminal operations blending physical and digital methods.
Source: ArsTechnica
PyPI-Targeted Phishing Surge Entangles Python Developers
Pythons Package Index (PyPI) users have been hit with a targeted phishing wave, with attackers sending convincing verification emails that redirect developers to malicious fake PyPI websites aimed at credential theft. The ongoing campaign signals persistent threats to software supply chains and highlights the developer ecosystem’s growing attractiveness for credential harvesting attacks.
Source: Bleeping Computer
AI Drives Surge in vCISO Adoption, Cutting Workload and Redefining Security Operations
A new report indicates that adoption of virtual CISO (vCISO) services has tripled in the past year as AI-driven platforms reduce workloads for MSPs and MSSPs by up to 68%. This transformation is allowing security teams to scale their protection against threats more efficiently, marking a significant shift in how organizations—especially SMBs—manage and operationalize cybersecurity leadership.
Source: Help Net Security
You May Also Be Interested In...