The Aisuru IoT botnet behind this year’s 20+ Tbps DDoS attacks has been retooled to rent hundreds of thousands of infected devices to residential proxy services. Researchers say the proxy glut is fueling large-scale data harvesting and content scraping—often feeding AI projects—by masking activity as everyday home-user traffic. The shift trades noisy outages for a lucrative, stealthier business model that complicates takedown and attribution.
Source: KrebsOnSecurity
PoC released for high‑severity BIND 9 DNS cache poisoning flaw (CVE‑2025‑40778)
A newly published proof-of-concept exploit for CVE-2025-40778 allows remote, unauthenticated DNS cache poisoning against vulnerable BIND 9 resolvers, enabling traffic redirection, malware distribution, or interception. While no in-the-wild exploitation has been reported yet, internet-facing resolvers should be patched immediately and protected with defense-in-depth (e.g., limiting query sources, monitoring for anomaly spikes).
Source: Help Net Security
New TEE.fail attack targets DDR5 memory to steal keys from Intel and AMD enclaves
Academics disclosed “TEE.fail,” a side-channel technique against DDR5-era systems that can extract secrets from Intel SGX/TDX and AMD SEV-SNP trusted execution environments. Intel and AMD issued advisories and mitigations after researchers demonstrated key recovery from hardware-backed enclaves, underscoring that memory-era transitions can introduce fresh attack surfaces for protected workloads.
Source: SecurityWeek
CISA: Exploited DELMIA Apriso factory software bugs allow privileged access and RCE
Two flaws in Dassault Systèmes’ DELMIA Apriso can be chained to gain privileged access and execute code remotely, and are now under active exploitation. Manufacturers running Apriso should prioritize patching, restrict access to management interfaces, and watch for post-exploitation signs such as unexpected account creations or configuration changes.
Source: SecurityWeek
Chrome will warn on HTTP by default—HTTPS “Always Use Secure Connections” coming in 2026
Google will enable “Always Use Secure Connections” by default for public sites starting with Chrome 154 in October 2026, prompting users before first access to non-HTTPS sites. Enhanced Safe Browsing users will get the change earlier in April 2026; orgs should audit and migrate any lingering HTTP dependencies—especially redirects and local-network tooling—to avoid user friction and security risk.
Source: Google Online Security Blog
Commercial spyware “Dante” tied to Chrome zero‑day campaign delivering LeetAgent
Kaspersky linked exploitation of Chrome zero-day CVE-2025-2783 to delivery of LeetAgent and the Italian-made spyware Dante, with observed targeting of entities in Russia and Belarus. The finding highlights the continued abuse of browser 0‑days by commercial surveillance vendors and the need to rapidly deploy browser patches across enterprises.
Source: Help Net Security
Research: AI agents can exfiltrate company data via ordinary web searches
New research shows AI agents that browse the web and access internal resources can be tricked into leaking sensitive data without directly manipulating the model—simply by controlling what the agent reads during normal tasks. Teams should sandbox browsing, apply strict scope and consent controls, and instrument agent activity to detect indirect prompt injection and data exfiltration paths.
Source: Help Net Security
You May Also Be Interested In...
Researchers warn of Qilin ransomware gang after group hit hundreds of orgs this year
New Android Trojan ‘Herodotus’ mimics human typing to evade anti-fraud systems
Schneider Electric and Emerson named as victims in Oracle EBS supply-chain hack