A cyber-related incident at Collins Aerospace disrupted airline check-in and boarding systems, triggering delays and cancellations at major European hubs including London Heathrow, Brussels, and Berlin. The outage forced a switch to manual processes, highlighting the cascading operational risk when a critical third-party aviation IT provider is hit by cyberattacks.
Source: Politico Cyber
CISA details malware deployed via Ivanti EPMM exploitation
The U.S. Cybersecurity and Infrastructure Security Agency released technical analysis of two malware families discovered after attackers compromised an organization through Ivanti Endpoint Manager Mobile (EPMM) flaws. The advisory underscores the urgency of patching EPMM, auditing MDM infrastructure, and hunting for persistence and lateral movement tied to the published indicators of compromise.
Source: Security Affairs
Fake GitHub repos push Atomic macOS infostealer, LastPass warns
LastPass reported a widespread campaign targeting macOS users via fraudulent GitHub repositories that impersonate legitimate tools and redirect victims to malware-laced downloads. The payload delivers the Atomic (AMOS) infostealer, capable of harvesting credentials and sensitive data, emphasizing the need to verify repository provenance and code signatures before installing software.
Source: TheHackerNews
WarLock ransomware activity spikes, tied to recent SharePoint targeting
Sophos-tracked WarLock ransomware operations have surged in September, with the group linked to July’s Microsoft SharePoint attacks. Defenders should prioritize patching and hardening externally exposed collaboration platforms, enforce least privilege, and review backups and incident response playbooks amid the uptick.
Source: CyberNews
New worm highlights risks in software package ecosystems
A dangerous self-spreading threat moving through software packages is drawing attention to persistent supply chain weaknesses in open-source ecosystems. Wired’s roundup also notes arrests tied to the Scattered Spider group and fresh scrutiny of U.S. tech firms’ role in China’s surveillance apparatus—developments that collectively raise the stakes for software provenance and vendor risk management.
Source: Wired
White House: U.S. to control TikTok’s algorithm under proposed deal
The administration says a pending agreement would give the U.S. control over TikTok’s recommendation algorithm, amid ongoing negotiations and a congressionally mandated ban. If finalized, the deal would mark a significant policy shift on platform governance, data flows, and algorithmic oversight for a foreign-owned app with broad U.S. reach.
Source: Politico Cyber
Week in Review: Chrome 0‑day patched, npm supply-chain attack, AI data use
Help Net Security’s roundup highlights Google’s emergency patching of a Chrome zero-day, an npm ecosystem supply-chain incident, and concerns over enterprise AI activity occurring outside security’s line of sight. The mix underscores the breadth of current risk—from browser exploitation to package poisoning and shadow AI practices.
Source: HelpNet Security
You May Also Be Interested In... - Apple Warns All iPhone Users—Do Not Use Google Chrome - The Silent Threat: How Misconfigurations Fuel the Cyber Crime Economy - Weekly Update 470