CISA has refreshed its “Minimum Elements for a Software Bill of Materials (SBOM)” guidance and is requesting public comment. The update aims to improve transparency in software supply chains and help buyers and operators better assess component risk and patch exposure. Organizations that build or procure software should review the draft, test it against internal workflows, and provide feedback—this could shape future federal procurement and industry norms.
Source: SecurityWeek
APT36 targets Indian government with malicious Linux .desktop shortcuts
Pakistan-linked APT36 (Transparent Tribe) is abusing weaponized .desktop files to deliver custom malware against Indian government and defense entities. Initial access comes via spear-phishing, with both Windows and BOSS Linux systems in scope, enabling data theft and persistent espionage. Hardening mail gateways, restricting execution of .desktop files, and enforcing strict MIME handling can reduce risk.
Source: Security Affairs
Arch Linux Project battles week-long DDoS disrupting website, repos, and forums
The Arch Linux Project has been contending with a sustained DDoS attack that impacted its main site, package repository, and community forums. The incident underscores the fragility of open-source infrastructure and the downstream supply-chain risk when distribution channels are degraded. Enterprises relying on Arch-derived components should review mirror strategies and continuity plans.
Source: SecurityWeek
Android spyware masquerades as “FSB antivirus,” targets Russian business executives
Researchers detailed Android.Backdoor.916.origin, a multifunctional backdoor disguised as an antivirus app allegedly tied to Russia’s FSB. The spyware supports surveillance, keylogging, chat and browser data theft, and live audio/video capture, focusing on executives at Russian firms. Mobile fleet owners should enforce app provenance controls, enable mobile EDR, and audit devices for sideloaded APKs.
Source: Security Affairs
Mirai-based “Gayfemboy” botnet resurfaces, exploits router and IoT flaws
Fortinet tracked renewed activity from the Mirai-derivative “Gayfemboy” botnet, which now targets known vulnerabilities in DrayTek, TP-Link, Raisecom, and Cisco gear. The evolution highlights how low-cost, mass-exploitation of edge devices continues to feed DDoS capacity. Patch exposed devices, remove default credentials, and segment IoT networks to blunt recruitment attempts.
Source: Security Affairs
Critical vuln roundup: Apple zero-day exploited; Cisco FMC RCE; WinRAR, SharePoint, 7‑Zip bugs
Cyble flagged several high-impact issues, including Apple’s CVE-2025-43300 (exploited image-processing zero-day) and Cisco FMC CVE-2025-20265 (unauth RCE via RADIUS handling). Also trending: Trend Micro Apex One CVE-2025-54948 (KEV-listed), FortiSIEM CVE-2025-25256, WinRAR CVE-2025-8088 (path traversal), SharePoint CVE-2025-53770 (reported exploited), and 7‑Zip CVE-2025-55188. Prioritize patching per KEV/vendor advisories and review exposure of management consoles.
Source: Cyble
FTC warns Big Tech: don’t weaken U.S. data security
The FTC issued a public warning to major tech platforms—including Apple, Microsoft, Meta, Google, and Amazon—against actions that could erode consumer data protections or expose U.S. user data to undue risk. The message signals heightened scrutiny and potential enforcement if security practices are diluted amid product or policy shifts. CISOs should ensure privacy-by-design and robust cross-border data safeguards.
Source: CyberNews
You May Also Be Interested In...
Farmers Insurance Data Breach Impacts Over 1 Million People
Agentic AI Browsers Exploited by “PromptFix” Trick Technique