Mass theft of OAuth and session tokens from Salesloft has triggered an urgent scramble among enterprises to revoke access across integrated apps. Google warned the impact extends far beyond Salesforce, with valid tokens for Slack, Google Workspace, AWS, Azure, OpenAI and more, while downstream victims like Zscaler disclosed data exposure via the compromised integration—an object lesson in supply-chain blast radius and token hygiene.
Source: KrebsOnSecurity
WhatsApp patches zero‑click exploit used alongside Apple bug
WhatsApp fixed CVE-2025-55177, a flaw in linked-device sync message authorization that was abused in sophisticated, zero-click attacks. The exploit was reportedly chained with an Apple vulnerability, underscoring the need for rapid app updates and enabling phishing‑resistant protections like device locks and two-step verification.
Source: Malwarebytes
Amazon disrupts Russian APT29 watering-hole targeting Microsoft 365 auth
Amazon’s security team dismantled an APT29/Midnight Blizzard campaign that used compromised sites and malicious redirects to intercept Microsoft authentication flows and access M365 data. The operation highlights the continued targeting of identity providers and cloud SSO paths—defenders should review conditional access policies, token lifetimes, and sign-in anomalies.
Source: BleepingComputer
Signed driver abuse lets Silver Fox deploy ValleyRAT via BYOVD
Researchers attribute a Bring Your Own Vulnerable Driver (BYOVD) technique to Silver Fox, which abused a validly signed but vulnerable WatchDog Anti‑malware driver (amsdk.sys) to disable security products and drop ValleyRAT. The case reiterates the importance of kernel‑mode driver controls (e.g., Microsoft’s blocklist, HVCI/Memory Integrity) and vigilant EDR tamper protection.
Source: The Hacker News
Lazarus subgroup expands RAT arsenal against finance and crypto
Fox‑IT and NCC Group detail a Lazarus subgroup overlapping AppleJeus/Citrine Sleet/UNC4736/Gleaming Pisces using multiple RATs to compromise financial and cryptocurrency targets. The campaigns blend social engineering, supply-chain touchpoints, and bespoke implants—organizations should harden macOS/Windows developer workflows and enforce strict code‑signing and wallet segregation.
Source: Fox‑IT Blog
Frostbyte10 flaws threaten cold-chain: patch Copeland controllers now
Ten vulnerabilities in Copeland refrigeration controllers deployed across major grocers and cold storage sites could allow attackers to alter temperatures, risking mass spoilage of food and medicine. Operators should prioritize vendor updates, segment OT networks, and monitor for anomalous setpoint changes to protect critical supply chains.
Source: The Register
Sextortion at scale: 1,900 emails, 205 BTC addresses over four years
SANS ISC analyzed nearly 2,000 sextortion messages tied to 205 Bitcoin addresses, mapping operational patterns over multiple years. Findings can help defenders auto‑triage extortion spam, block recurrent wallet clusters, and educate users to reduce payment rates that keep these low‑effort scams profitable.
Source: SANS Internet Storm Center
You May Also Be Interested In...
Malicious npm package mimics Nodemailer to backdoor Atomic/Exodus wallet apps
Cisco finds 1,100+ Ollama AI servers exposed to the internet
NCSC UK: Adapting vulnerability disclosure models for AI safeguard bypasses