A critical flaw in Docker Desktop for Windows and macOS (CVSS 9.3) allows a malicious container to break out and compromise the host, even when Enhanced Container Isolation is enabled. Admins should upgrade immediately to version 4.44.3 and avoid running untrusted images in developer environments where host credentials and secrets are often accessible.
Source: BleepingComputer
CISA adds exploited Git and Citrix bugs to KEV—patch now
US CISA added an exploited arbitrary file write in Git and a Citrix Session Recording vulnerability to its Known Exploited Vulnerabilities catalog, signaling active in-the-wild attacks. Federal agencies (and everyone else) should prioritize patching, inventory Git client/server usage across developer endpoints and CI systems, and mitigate Citrix exposure per vendor guidance.
Source: Security Affairs
PRC-nexus UNC6384 hijacks captive portals to deliver PlugX to diplomats
Google’s Threat Intelligence Group detailed a sophisticated espionage chain that hijacks captive-portal checks to redirect targets to a fake plugin page signed with a valid cert, then side-loads a DLL to deploy the SOGU.SEC (PlugX) backdoor. The campaign, aimed at diplomats in Southeast Asia, blends AitM tactics, code signing abuse, and memory-only payloads—defenders should monitor for captive-portal redirects, DLL sideloading, and associated IOCs.
Source: Google Cloud Threat Intelligence
77 malicious Android apps (19M installs) removed from Google Play
Researchers found 77 apps on Google Play with over 19 million installs distributing various malware families, including the Anatsa (TeaBot) banking trojan. Enterprises should audit managed Android fleets for the listed packages, enforce MDM policies to block risky categories, and enable Play Protect; consumers should remove unknown utilities and check app permissions.
Source: BleepingComputer
Global phishing wave uses UpCrypter to drop RATs via fake voicemail emails
FortiGuard Labs uncovered a campaign abusing convincing voicemail and purchase order lures to deliver UpCrypter, which then installs RATs like PureHVNC and DCRat across multiple industries. Block JavaScript attachments and HTA downloads at the email gateway, apply URL rewriting/sandboxing, and hunt for UpCrypter and RAT beacons in your EDR/NGFW telemetry.
Source: Fortinet
AI prompt injection via image scaling can exfiltrate data
New research shows attackers can hide malicious instructions inside images that trigger during downscaling, causing popular AI systems to follow injected prompts and leak sensitive data. Organizations deploying LLMs or AI assistants should treat all media as untrusted input, add image pre-processing/sanitization, and implement strict output filtering and allow-listing for tool use.
Source: SecurityWeek
Farmers Insurance breach hits 1.1M via third‑party Salesforce attacks
Farmers Insurance disclosed a data breach affecting 1.1 million customers after a third-party vendor tied to the recent wave of Salesforce compromises was attacked. The incident underscores SaaS and supply-chain risk; review partner access, rotate API keys/tokens, enforce SSO and scoped permissions for CRM integrations, and enable anomaly monitoring.
Source: BleepingComputer
You May Also Be Interested In...
Surge in coordinated scans targets Microsoft RDP auth servers