A self-replicating worm dubbed “Shai-Hulud” has compromised at least 187 npm packages, stealing developer credentials and automatically publishing those secrets to GitHub to fuel further spread. The incident briefly infected multiple code packages from a major security vendor, underscoring how quickly trust in software dependencies can be subverted and the risks to CI/CD pipelines and private repos.
Source: KrebsOnSecurity
Apple backports fix for actively exploited zero-day used in spyware attacks
Apple has shipped patches for CVE-2025-43300 to older devices—including models as old as iPhone 8—after confirming the bug was exploited in “extremely sophisticated” targeted attacks. The ImageIO out-of-bounds write flaw can be triggered with a malicious image, making rapid fleet updates critical for organizations with high‑risk users.
Source: The Register
Microsoft and Cloudflare disrupt RaccoonO365 phishing service, identify ringleader
Authorities seized 338 domains tied to the RaccoonO365 phishing-as-a-service, which Microsoft says stole over 5,000 Microsoft 365 credentials across 94 countries since mid‑2024. The operation identified an alleged leader and highlights the industrialization of credential theft, reinforcing the need for phishing-resistant MFA and conditional access.
Source: SecurityWeek
New “Phoenix” Rowhammer exploit cracks DDR5 protections in under 2 minutes
Researchers demonstrated a new Rowhammer variant (CVE-2025-6202) that bypasses advanced DDR5 defenses on certain AMD/SK Hynix configurations, achieving root in 109 seconds under lab conditions. While real-world constraints apply, the work shows hardware-level fault attacks remain viable, pressing vendors and operators to revisit memory protection assumptions.
Source: SecurityWeek
Criminals created fake account in Google’s law enforcement data portal
Google confirmed threat actors enrolled a fraudulent account in its Law Enforcement Request System (LERS), which agencies use to request user data, before the company disabled it. The incident raises concerns about verification processes for sensitive portals and the potential for forged legal requests or data exposure.
Source: The Register
GitHub adds post-quantum protection for SSH with hybrid keys
GitHub introduced hybrid SSH keys that combine classical and post‑quantum algorithms to mitigate harvest‑now‑decrypt‑later threats while maintaining compatibility. It’s a significant step in mainstreaming PQC for developer workflows, offering a practical migration path before quantum-capable adversaries emerge.
Source: Help Net Security
EFF releases Rayhunter, an open-source tool to detect Stingray-style cellular spying
The Electronic Frontier Foundation launched Rayhunter, which uses a low‑cost mobile hotspot to flag suspicious cell site simulator (IMSI catcher) activity. The project aims to equip researchers, journalists, and civil society with better visibility into mobile surveillance that often evades public scrutiny.
Source: Help Net Security
You May Also Be Interested In...