THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts

Europol has disrupted a sophisticated cybercrime-as-a-service platform that operated a massive SIM farm used to enable crimes ranging from phishing to investment fraud. The coordinated Operation SIMCARTEL involved 26 searches, led to seven arrests, and seized key infrastructure. The takedown underscores how industrialized SIM operations fuel large-scale fraud and account abuse.

Source: The Hacker News


Everest Gang Claims Collins Aerospace Breach Tied to EU Airport Disruptions

The Everest ransomware group claimed responsibility for hacking Collins Aerospace, an incident previously linked to check-in and boarding disruptions at several major European airports, including Heathrow, Brussels, and Berlin. Shortly after the claim, the gang’s leak site vanished, prompting speculation about a takedown or internal turmoil. The episode highlights the cascading risks of supply chain attacks on critical transport operations.

Source: Security Affairs


New .NET “CAPI Backdoor” Targets Russian Auto and E‑Commerce Firms via Phishing ZIPs

Researchers at Seqrite Labs uncovered a campaign delivering a previously undocumented .NET malware dubbed CAPI Backdoor. The attackers use phishing emails with ZIP archives to trigger infections, with targeting focused on Russia’s automobile and e-commerce sectors. The discovery adds another stealthy backdoor to defenders’ watchlists.

Source: The Hacker News


Winos 4.0 Actors Expand to Japan and Malaysia Using Fake Ministry PDFs

The threat actors behind Winos 4.0 (ValleyRAT) have broadened operations from China and Taiwan to Japan and Malaysia. Lures masquerade as Finance Ministry documents in PDF form and deliver the HoldingHands remote access trojan, alongside another RAT. The expansion signals persistent, regionally adaptive targeting across Asia.

Source: Security Affairs


Court Permanently Blocks NSO Group From Targeting WhatsApp Users

A federal judge granted Meta-owned WhatsApp a permanent injunction barring Israeli cyberintelligence firm NSO Group from targeting the messaging app’s users. While the injunction stands, the court dramatically reduced the monetary penalties NSO must pay. The ruling marks a significant legal milestone in curbing mercenary spyware operations against mainstream platforms.

Source: TechCrunch


Week in Review: F5 Data Breach, Microsoft Patches Three Actively Exploited Zero‑Days

Help Net Security’s roundup spotlights a reported F5 data breach and Microsoft updates that fix three zero-day vulnerabilities already exploited in the wild. The week underscores the dual pressure on infrastructure vendors and enterprise endpoints, reinforcing the need for rapid patching and vigilant exposure management. Teams should prioritize Microsoft’s latest security updates and review F5-related risk.

Source: Help Net Security


Malware Spreads via TikTok “Activation” Videos Urging PowerShell Commands

Cybercriminals are leveraging viral TikTok videos that pose as software activation tutorials to trick viewers into running malicious PowerShell commands. Thousands have reportedly followed the instructions, inadvertently installing malware. The campaign highlights how social media virality can turbocharge malware distribution and social engineering.

Source: CyberNews


You May Also Be Interested In...

Hackers Dox ICE, DHS, DOJ, and FBI Officials

1 little known secret of wsreset.exe

Locked out of your Google account? Now a friend can help

Cybersecurity — October 19, 2025 | Briefing24