Microsoft shipped an out-of-band patch for a critical Windows Server Update Services flaw that allows remote, unauthenticated code execution, and exploitation has already been observed. A public proof-of-concept exists, raising the risk of rapid, widespread abuse against unpatched WSUS servers.
Source: SecurityWeek
Windows hardening: File Explorer previews disabled for downloaded files to stop NTLM hash leaks
Microsoft has disabled previews of files downloaded from the internet in File Explorer to block credential exposure. Researchers showed that HTML tags referencing external paths could trigger NTLM hash leaks during preview, prompting the change as a preventative mitigation.
Source: SecurityWeek
Google and Check Point dismantle massive YouTube “Ghost Network” pushing info-stealers
A large malware distribution operation abused legitimate YouTube accounts and tutorial videos for cracked software and game cheats to deliver information-stealing malware at scale. The takedown highlights how trusted content platforms are repeatedly weaponized for social engineering and payload delivery.
Source: SC Media
US to attend UN cybercrime treaty signing despite industry concerns
Officials will convene in Hanoi this weekend to sign a landmark UN cybercrime convention, with the United States set to attend. The move comes amid ongoing industry concerns about the treaty’s scope and safeguards, but signals continued US engagement on global cybercrime cooperation.
Source: The Record by Recorded Future
Lazarus targets Europe’s UAV sector with fake job lures
North Korea’s Lazarus Group is using Operation DreamJob tactics—fake job offers—to compromise companies developing unmanned aerial vehicle technology in Europe. The campaign focuses on information theft from sensitive aerospace R&D targets.
Source: SecurityWeek
Smishing Triad tied to 194,000 malicious domains in global SMS phishing operation
Palo Alto Networks’ Unit 42 linked the Smishing Triad to more than 194,000 malicious domains registered since January 2024. The infrastructure, registered via a Hong Kong-based registrar and using Chinese nameservers, supports large-scale SMS phishing against a wide range of services worldwide.
Source: The Hacker News
Report: Chinese UNC5221 used “Brickstorm” backdoor to infiltrate F5 for over a year
A Chinese state-backed operation (UNC5221) allegedly deployed a sophisticated Brickstorm backdoor to stealthily compromise US cybersecurity firm F5 for more than a year, exposing company source code. If confirmed, the incident underscores the persistence and depth of modern supply chain–adjacent intrusions.
Source: SC Media
You May Also Be Interested In...
Hackers Target Perplexity Comet Browser Users
Sneaky Mermaid attack in Microsoft 365 Copilot steals data
How Cloudflare’s client-side security made the npm supply chain attack a non-event