The Cybersecurity and Infrastructure Security Agency added CVE-2025-43300 to its Known Exploited Vulnerabilities catalog and gave civilian federal agencies until September 11 to patch. The flaw affects recent iPhones, iPads, and Macs and has been used in targeted attacks, underscoring the need for rapid updates across both public and private fleets.
Source: Recorded Future News (The Record)
Murky Panda exploits cloud trust to reach downstream customers
A China-linked group known as Murky Panda (aka Silk Typhoon) is abusing trusted cloud relationships to pivot into downstream customers’ environments. Researchers warn of lateral movement via cloud identity and app trust, urging rigorous review of third-party connections, OAuth consents, and federated identity configurations.
Source: BleepingComputer
Interpol’s Serengeti 2.0 nets 1,209 arrests, $97.4M seized, and 11,432 infrastructures dismantled
An Africa-wide cybercrime crackdown led by Interpol dismantled major ransomware, BEC, and fraud operations over three months. The operation recovered $97.4 million, aided 88,000 victims, and disrupted 11,432 malicious infrastructures—highlighting both the reach of organized cybercrime and the impact of coordinated law enforcement.
Source: SecurityWeek
New ‘Salty’ phishing framework bypasses SMS, voice, and app-based 2FA
Researchers spotlight “Salty,” an evasive phishing framework capable of defeating multiple two-factor authentication methods, including SMS, voice, and companion apps. Organizations should prioritize phishing-resistant authentication (FIDO2/passkeys), strengthen user education, and add real-time detection for adversary-in-the-middle kits.
Source: SC Media
AWS Trusted Advisor bug could falsely mark exposed S3 buckets as secure
A now-fixed issue allowed attackers to trick AWS Trusted Advisor into reporting unsecured S3 buckets as compliant. The incident is a reminder not to rely on a single control: enable S3 Block Public Access by default, enforce guardrails with SCPs/CloudFormation, and use independent posture checks to verify storage policies.
Source: SecurityWeek
SHAMOS macOS stealer hits 300+ targets via malvertising
Between June and August, more than 300 entities were targeted with a new variant of the Atomic macOS Stealer delivered through deceptive ads. The malware focuses on credential and data theft, reinforcing the need for macOS EDR coverage, blocking ad-based downloads, and restricting installation sources.
Source: SecurityWeek
Ransomware shuts down electronics supplier Data I/O, raising supply-chain risk
Data I/O disclosed a ransomware incident that continues to disrupt operations; its customer list includes Amazon, Apple, Google, and Microsoft. The attack underscores third-party and upstream manufacturing risk, pressing buyers to validate vendors’ incident response, resilience, and recovery timelines.
Source: The Register
You May Also Be Interested In...