Apple released emergency updates to fix CVE-2025-43300, a flaw in its image-processing framework that attackers exploited using booby-trapped images. The vulnerability was reportedly used in a sophisticated attack chain; users and enterprises should immediately update iPhones, iPads, and Macs and consider enabling Lockdown Mode for high-risk users.
Source: HackRead
China-linked Silk Typhoon ramps up attacks on North America
CrowdStrike warns that Silk Typhoon (aka Murky Panda) has intensified operations against North American organizations, exploiting both n-day and zero-day vulnerabilities to gain initial access. The group’s broad targeting and blend of cloud and on-prem techniques underscore the need for rapid patching, identity hardening, and vigilant cloud posture management.
Source: Security Affairs
DaVita ransomware breach exposes data of nearly 2.7 million individuals
Kidney dialysis giant DaVita confirmed a ransomware attack that compromised sensitive personal and health information impacting almost 2.7 million people. Healthcare data’s high value and the operational stakes in clinical environments make this a notable incident; expect downstream fraud attempts and ensure vendor risk and segmentation controls are in place.
Source: Security Affairs
SHAMOS: New Atomic macOS Stealer variant hits 300+ environments via malvertising
CrowdStrike reports a campaign distributing a variant of Atomic macOS Stealer (AMOS), dubbed SHAMOS, through malvertising between June and August. The infostealer targets Keychain credentials, browser data, and crypto wallets, highlighting the continued risk of search ads and the need for endpoint controls, DNS filtering, and least-privilege on macOS.
Source: Security Affairs
ClickFix phishing: Fake CAPTCHA prompts trick users into executing malicious commands
Microsoft is warning about “ClickFix,” a social engineering technique that impersonates CAPTCHA checks to get users to run harmful commands. Admins are advised to restrict command-line tools, consider disabling the Run dialog where appropriate, and tighten application control policies to blunt this growing class of UI-driven attacks.
Source: CyberNews
Redis flaw and multi-pronged abuse: From botnets to proxyware and crypto-mining
Researchers detail overlapping campaigns exploiting known vulnerabilities, including critical Redis bug CVE-2024-36401 (CVSS 9.8), to conscript devices into IoT botnets, residential proxy networks, or crypto-mining farms. Activity tied to GeoServer, PolarEdge, and Gayfemboy shows criminals maximizing monetization paths; prioritize patching, eliminate unnecessary internet exposure, and monitor for anomalous outbound traffic.
Source: The Hacker News
Crypto execs targeted by fake CoinMarketCap journalists in Zoom spear-phishing
Threat actors are impersonating CoinMarketCap reporters with convincing profiles to schedule Zoom interviews that ultimately deliver malware and attempt wallet theft. Crypto firms should verify media outreach via official channels, treat unsolicited interview files or links as suspicious, and enforce device isolation for high-risk roles.
Source: HackRead
You May Also Be Interested In...
IoT under siege: The return of the Mirai-based Gayfemboy botnet
Electronics supplier to tech giants suffers ransomware shutdown
Sneaking Invisible Instructions by Developers in Windsurf (prompt injection risk)