Apple released major platform updates across iPhone, iPad, Mac, watch, and TV that patch more than 50 vulnerabilities, including an exploited bug on older platforms. With Apple now aligning version numbers to “26,” enterprises should prioritize rapid testing and deployment, especially for WebKit and kernel fixes. Notably, VisionOS was not updated this cycle.
Source: SecurityWeek
FBI releases IoCs as criminals target Salesforce to steal data and extort victims
The FBI published indicators of compromise tied to campaigns by UNC6040 and UNC6395, warning that threat actors are breaching Salesforce instances to exfiltrate data and pressure organizations for payment. The advisory urges reviews of connected apps and OAuth scopes, tighter API and SSO configurations, and active monitoring of audit logs for suspicious access.
Source: SecurityWeek
‘Phoenix’ RowHammer bypasses DDR5 defenses in 109 seconds, enabling privilege escalation
Researchers from ETH Zürich and Google disclosed Phoenix (CVE-2025-6202), a new RowHammer technique that defeats enhanced Target Row Refresh (TRR) and in-DRAM protections on SK Hynix DDR5. The team demonstrated the first RowHammer-based privilege escalation on a production DDR5 system, highlighting gaps in current TRR/ECC mitigations and underscoring the need for stronger standards like PRAC.
Source: The Hacker News
Malicious VS Code, Cursor, and Windsurf extensions found abusing developer ecosystems
Researchers identified roughly two dozen nefarious extensions uploaded by “WhiteCobra” to the VS Code Marketplace and Open VSX, targeting users of VSCode, Cursor, and Windsurf. The add-ons can run arbitrary code and exfiltrate data, reinforcing the urgency for extension allowlists, publisher verification, and routine audits of IDE environments.
Source: SC Media
Phishing wave impersonates Rust Foundation to hijack crates.io maintainer accounts
Rust crate publishers are receiving convincing “breach notification” emails minutes after posting new packages, urging them to revalidate via credential-harvesting pages. The campaign mirrors recent npm phishing and aims to compromise maintainer accounts, enabling supply-chain tampering of popular crates.
Source: Help Net Security
Mustang Panda deploys ‘SnakeDisk’ USB worm to drop Yokai backdoor on Thailand IPs
China-linked APT Mustang Panda is using an updated TONESHELL backdoor alongside a previously undocumented USB worm, SnakeDisk, that only executes on devices with Thailand-based IP addresses. The campaign illustrates continued APT focus on region-specific targeting and removable-media tradecraft to establish persistence and exfiltrate data.
Source: The Hacker News
China mandates 1-hour reporting window for serious cyber incidents
Beijing’s new rule compels Chinese network operators to report major cyber incidents within one hour of detection or face penalties. The accelerated timeline will reshape incident response for firms operating in China, raising compliance pressure around detection, triage, and rapid regulatory disclosure.
Source: The Register
You May Also Be Interested In...
689,000 Affected by Insider Breach at FinWise Bank
Company that owns Gucci and Balenciaga confirms customer data breach
Uvalde, Texas school district closes for days after ransomware attack