Britain has reportedly dropped its push to force Apple to provide blanket access to customers’ encrypted cloud data, a move U.S. officials framed as a win for end-to-end encryption. The climbdown eases immediate pressure on cloud providers but underscores that the policy fight over lawful access will continue in other venues and jurisdictions.
Source: SecurityWeek
Public exploit chains two critical SAP NetWeaver flaws for auth bypass and RCE
A newly released exploit combines CVE-2025-31324 (CVSS 10.0) and CVE-2025-42999 to bypass authentication in SAP NetWeaver Visual Composer and achieve remote code execution. Enterprises running unpatched instances face high risk of system compromise and data theft; urgent patching and exposure reduction (e.g., restricting internet access to affected components) are advised.
Source: SecurityWeek
Attackers exploit old Apache ActiveMQ bug, then patch it to keep rivals out
Researchers observed threat actors exploiting a nearly two‑year‑old ActiveMQ vulnerability to gain persistent access on cloud Linux systems and deploy “DripDropper” malware. In a twist, the intruders then “patched” the flaw on compromised hosts to lock out other attackers and lower detection, highlighting the need for rapid patching and thorough post‑compromise hunting.
Source: The Hacker News
700M+ downloads: Android VPN apps secretly linked and insecure
New research from ASU and Citizen Lab found three families of Android VPN apps with over 700 million installs are covertly connected and suffer from significant security weaknesses. The findings raise red flags for privacy and enterprise security; organizations should audit mobile VPN usage, enforce trusted providers via MDM, and review data permissions.
Source: Help Net Security
North Korea targets diplomats with spear‑phishing, leverages GitHub delivery
North Korean operators conducted a coordinated espionage campaign against diplomatic missions in South Korea, sending convincing meeting lures and abusing GitHub to host malicious content. The activity underscores ongoing APT innovation in using legitimate developer platforms to blend in and evade controls.
Source: The Hacker News
DOJ charges alleged RapperBot operator behind massive DDoS-for-hire service
A 22‑year‑old Oregon man was charged with operating the “RapperBot” botnet used in more than 370,000 DDoS attacks, including an outage that knocked X/Twitter offline in March 2025. The case illustrates the industrialization of botnet‑as‑a‑service and the continued exploitation of insecure IoT/embedded devices.
Source: KrebsOnSecurity
PyPI blocks “domain resurrection” attacks to curb package account takeovers
The Python Package Index introduced safeguards against domain resurrection attacks that abuse expired email domains to reset passwords and hijack maintainer accounts. The move strengthens software supply chain defenses; maintainers should also enable 2FA, rotate credentials, and verify project email domains remain under control.
Source: BleepingComputer
You May Also Be Interested In...
Microsoft releases emergency Windows updates to fix recovery/reset issues
Warlock ransomware exploits unpatched SharePoint to breach enterprises