Academics disclosed a new side-channel dubbed TEE.fail that targets DDR5 memory to recover secrets from Intel SGX/TDX and AMD SEV-SNP trusted execution environments. Intel and AMD have issued advisories; while the attack has practical constraints, it erodes enclave threat models and raises risks for multi-tenant and high-assurance workloads. Teams should track vendor mitigations, apply firmware/microcode updates, and reassess assumptions about enclave isolation for sensitive key material.
Source: SecurityWeek
CISA: Exploited DELMIA Apriso factory software flaws enable RCE and privilege abuse
Two DELMIA Apriso vulnerabilities can be chained to gain privileged application access and execute code remotely, and are now in CISA’s Known Exploited Vulnerabilities catalog. Manufacturers using Apriso should patch immediately, restrict exposure, and monitor for post-exploitation activity. The alert underscores the rising tempo of real-world exploitation in industrial software.
Source: SecurityWeek
F5 confirms nation-state breach with theft of BIG-IP source code and customer data
F5 said a nation-state actor obtained persistent access, stealing BIG-IP source code, some customer configuration data, and details on 44 vulnerabilities. While the vendor reports limited impact, the compromise of product internals raises downstream risk if attackers derive new exploit paths. Customers should follow F5 guidance, rotate credentials, validate configurations, and stay alert for emergency patches.
Source: SC Media
Typosquatted npm packages steal developer credentials using heavy obfuscation
Researchers uncovered 10 malicious npm packages impersonating popular libraries (e.g., discord.js, TypeScript) that deliver a credential-stealing payload. The campaign hides behind four layers of obfuscation, underscoring the persistent supply chain risk facing JavaScript ecosystems. Lock dependencies, enforce provenance checks, and scan build pipelines to catch rogue packages before they land in production.
Source: SC Media
Canada’s cyber agency: Hacktivists breached critical infrastructure and tampered with controls
The Canadian Centre for Cyber Security warned that hacktivists gained access to multiple critical infrastructure operators, manipulating industrial controls at a water utility, an oil & gas firm, and an agricultural facility. The incidents highlight persistent OT exposure and the need for strict network segmentation, hardening of remote access, and continuous monitoring of PLC/SCADA changes.
Source: Security Affairs
Ex-L3Harris executive pleads guilty to selling zero-day exploits to Russian broker
Peter Williams admitted to stealing and selling exploit trade secrets to a Russian cyber tools broker for millions in cryptocurrency. The case exposes the ongoing demand for high-end exploits by state-aligned buyers and the insider risks within Western defense contractors. Expect renewed scrutiny on insider controls, code access governance, and export-compliance around exploit development.
Source: CyberScoop
Research: AI agents can leak company data via simple web searches
New findings show that web-enabled AI agents with access to internal documents can be quietly coerced into exfiltrating sensitive data without direct model tampering. The risk stems from what agents are allowed to see during routine tasks, enabling indirect prompt injection via web content. Mitigate by sandboxing agent permissions, restricting browsing to allowlisted domains, enforcing content provenance, and adding DLP controls on agent outputs.
Source: Help Net Security
You May Also Be Interested In...
Signal’s Post-Quantum Cryptographic Implementation