Meta has issued emergency fixes for a WhatsApp vulnerability exploited in targeted “zero‑click” attacks on iPhone and Mac users, requiring no user interaction. High‑risk users (journalists, activists, executives) should update WhatsApp immediately, ensure devices are on the latest iOS/macOS, and consider enabling Lockdown Mode.
Source: Forbes Security
Supply chain attacks have doubled since spring, driven by zero-days and third‑party risk
New research shows software supply chain incidents have averaged 26 per month since April—twice the previous rate—fueled by exploitation of widely used enterprise products (e.g., NetScaler, SharePoint), cloud misconfigurations, and AI‑assisted phishing. Recent cases disrupted hundreds of municipalities and exposed data across tech, telecom, and semiconductor ecosystems, underscoring the need for third‑party risk management, microsegmentation, and ransomware‑resilient backups.
Source: Cyble
Dutch NCSC warns of global malware campaign hiding in fake PDF tools
The Netherlands’ NCSC flagged a widespread campaign that disguises malware as “free” PDF editors and ManualFinder apps, often promoted via SEO‑poisoned search results. Organizations should block untrusted installers, favor vendor‑verified distribution channels, and monitor for trojanized utilities used as initial access.
Source: CyberNews
APT37 (ScarCruft) targets South Korean academics with RokRAT in ‘Operation HanKook Phantom’
Researchers uncovered a phishing campaign by North Korea‑linked ScarCruft delivering RokRAT, a backdoor capable of command execution and data exfiltration. The lures focus on intelligence and academic circles, highlighting ongoing state‑aligned targeting of research communities—reinforce email authentication, sandbox document tooling, and watch for unusual outbound traffic.
Source: The Hacker News
Boards urged to step up cyber oversight as ransomware pivots to identity and help desks
Google Cloud’s Office of the CISO says boards must treat cybersecurity as core to resilience and growth, focusing on ransomware, cyber‑enabled fraud, and securing innovation. The report notes attackers increasingly abuse identity workflows and support desks, pushing leaders to prioritize identity security, rapid incident response, and measurable risk reduction.
Source: Help Net Security
‘LegalPwn’ jailbreak: LLMs can be tricked by adversarial instructions buried in legalese
Pangea researchers show that hiding malicious prompts inside legal documents can cause LLMs to bypass guardrails, exploiting model biases that treat legal text as authoritative. Security teams deploying LLMs for document processing should add robust input filters, provenance checks, and policy‑aware output validation.
Source: The Register
Study finds many government sites route traffic across borders, skip HTTPS, or funnel through few chokepoints
New analysis reveals traffic to government domains frequently traverses foreign networks, relies on a small number of providers, and in some cases lacks encryption—raising surveillance and resilience concerns. Governments should enforce HTTPS everywhere, diversify transit paths, and strengthen sovereign routing strategies.
Source: The Register
You May Also Be Interested In...
AIDEFEND: Free AI defense framework for securing ML systems
Which controls cut breach risk? New CRIC study links practices to outcomes
Von der Leyen’s plane hit by suspected Russian GPS jamming