Ongoing Akira campaigns are logging into SonicWall SSL VPNs even when one-time-password MFA is enabled, with researchers suspecting use of previously stolen OTP seeds. Post-compromise activity reportedly includes living-off-the-land techniques and remote management tools to evade detection. Defenders should rotate OTP seeds, enforce phishing-resistant MFA (FIDO2), review VPN logs for anomalous logins, and patch/monitor exposed appliances.
Source: BleepingComputer
Microsoft: LLM-crafted SVG phishing evades email defenses
Microsoft warns of a phishing wave targeting U.S. organizations that uses LLM-generated code to obfuscate payloads inside SVG files, blending business terminology with synthetic structure to slip past filters. The campaign highlights how generative AI is accelerating attacker iteration and detection evasion. Consider blocking or sandboxing SVG attachments, tightening content inspection, and tuning detections for atypical SVG behavior.
Source: The Hacker News
First malicious MCP server found in the wild via rogue npm package
Researchers uncovered a malicious Model Context Protocol (MCP) server hidden in a package called “postmark-mcp” that mimicked an official library and siphoned email data. It’s the first observed case of an MCP server abuse in the wild, expanding software supply chain risk into the emerging AI tooling ecosystem. Teams should audit MCP integrations, pin trusted packages, and monitor for anomalous outbound connections from developer environments.
Source: The Hacker News
Medusa claims 834GB Comcast breach, demands $1.2M ransom
The Medusa ransomware group says it stole 834.4 GB of data from Comcast and is demanding a seven-figure payment, sharing screenshots and file listings as proof. If verified, the incident could expose sensitive corporate or customer information and underscores the persistence of data-extortion tactics. Organizations should revisit DLP controls, credential hygiene, and response plans for data-leak extortion.
Source: CyberNews
Dutch teens arrested for Wi‑Fi spying allegedly tied to Russian hackers
Authorities in the Netherlands detained two 17-year-olds accused of conducting Wi‑Fi sniffing near law enforcement and embassy facilities at the behest of Russian intelligence. The case spotlights low-cost, high-impact physical-proximity reconnaissance and the growing recruitment of minors for state-aligned operations. Security teams at sensitive sites should tighten RF monitoring, patrols, and wireless segmentation.
Source: SecurityWeek
Fire knocks 647 South Korean e‑gov services offline, testing resilience
A datacenter fire in South Korea disrupted 647 government digital services, underscoring the fragility of centralized infrastructure and the need for robust disaster recovery. The outage is a reminder to validate multi-region failover, backup integrity, and crisis communications for public-facing systems.
Source: The Register
UK report slams submarine cable security, urges stronger action
The UK Parliament’s Joint Committee on National Security Strategy warned that submarine cable protection is insufficient and criticized the government as “too timid” on mitigations. With a significant share of transatlantic capacity funneled through a small number of landing points, the report calls for greater redundancy, surveillance, and resilience planning.
Source: The Register
You May Also Be Interested In...
NCSC: Understanding your OT environment is the first step to stronger cyber securityHow attackers poison AI tools and defenses
Chinese drone maker DJI loses appeal to get off Pentagon blacklist