Samsung has shipped fixes for a zero-day on Galaxy devices that was exploited in the wild to achieve remote code execution, according to reports from Meta and WhatsApp. The flaw appears to have been leveraged by a commercial spyware vendor. Enterprises should expedite the September 2025 update across managed fleets and consider limiting auto-processing of untrusted content until patching is complete.
Source: SecurityWeek
AI integration risk: Malicious MCP servers open new supply-chain attack paths
Kaspersky warns that the rapidly adopted Model Context Protocol (MCP) for wiring AI assistants into tools and data can be abused via rogue MCP servers. The research dissects MCP architecture, details vectors like malicious tool servers, token/session exfiltration, and prompt-injection pivots, and demonstrates a proof of concept. Security teams should authenticate and pin MCP endpoints, sandbox agent integrations, and treat MCP capabilities as code execution surfaces.
Source: SecureList
SEO poisoning and GitHub Pages abused to spread HiddenGh0st, Winos, kkRAT
Fortinet observed a campaign manipulating search rankings and using lookalike domains and GitHub Pages to deliver Chinese-language malware, including HiddenGh0st, Winos, and kkRAT. Fake software sites with subtle character swaps lure victims into multi-stage downloads. Defenders should restrict software acquisition to vendor domains, monitor for brand impersonation, and scrutinize GitHub-hosted binaries.
Source: TheHackerNews
ENISA to operate the EU Cybersecurity Reserve
The European Commission and ENISA signed a €36 million, three-year agreement tasking ENISA with administering and operating the EU Cybersecurity Reserve. The move formalizes the bloc’s emergency cyber response capabilities and has implications for cross-border incident coordination and MSSP participation. Providers aiming to support the Reserve should align services to EU readiness, procurement, and reporting expectations.
Source: Tripwire Blog
ShinyHunters hit Vietnam’s National Credit Information Center
Vietnam’s National Credit Information Center (CIC) was targeted by ShinyHunters, with VNCERT confirming indicators of unauthorized access intended to steal personal data. The investigation is ongoing and the scale of exposure remains unclear. Financial institutions relying on CIC data should reassess third-party risk, enable enhanced fraud monitoring, and ready customer notification plans.
Source: Security Affairs
Spike in probes for exposed backups like backup.zip and web.zip
SANS ISC reports a noticeable rise in automated requests for common archive filenames on web honeypots, suggesting broad reconnaissance for exposed site backups. Such archives often contain source code, credentials, and database dumps, making them high-value loot. Teams should audit web roots for stray archives, avoid predictable backup names, and store packages off-site or behind access controls.
Source: SANS ISC
UK Lords scrutinize Ofcom’s ‘child-protection’ plans under Online Safety Act
The House of Lords will examine whether Ofcom’s latest child-safety measures will effectively reduce harm or simply increase compliance burden. Outcomes could shape requirements around scanning, age verification, and platform risk assessments—areas with significant implications for encryption, privacy, and safety tech. Organizations should track potential changes that may impact product design and moderation workflows.
Source: The Register
You May Also Be Interested In...
AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns
Data destruction done wrong could cost your company millions