Canada’s cyber agency and the RCMP confirmed multiple incidents where hacktivists compromised internet-exposed ICS at a water facility and an oil and gas firm, manipulating controls in ways that could have caused unsafe conditions. The advisory underscores a surge in activist-driven intrusions against OT, urging operators to remove public exposure, enforce MFA, segment networks, and harden remote access and HMIs.
Source: SecurityWeek
Major US telecom backbone firm breached by suspected nation-state actors
Ribbon Communications disclosed a prolonged intrusion attributed to nation-state hackers, raising supply chain concerns given its role powering networks for the US government and major carriers. Details on data access remain limited, but the campaign highlights persistent, stealthy targeting of telecom infrastructure and the potential for downstream impact to customers.
Source: SecurityWeek
Chinese APT exploits unpatched Windows shortcut flaw to spy on European diplomats
Researchers report a China-linked group leveraging an unpatched Windows .LNK vulnerability to deliver PlugX malware in recent campaigns against diplomatic entities in Belgium and Hungary. With no Microsoft fix yet, defenders should block or sandbox LNK files from untrusted sources, tighten email and endpoint controls, and monitor for PlugX and related loader activity.
Source: SecurityWeek
WSUS zero-day (CVE-2025-59287) actively exploited to drop Skuld infostealer
Attackers are weaponizing a recently patched WSUS RCE to deploy the Skuld infostealer on unpatched Windows servers, aided by a public PoC. Organizations should apply the out-of-band update immediately, audit WSUS for unauthorized tasks or binaries, remove unnecessary internet exposure, and review credentials and tokens that may have been harvested.
Source: Help Net Security
Supply-chain alert: 136 npm packages stole tokens and credentials, with 100,000+ downloads
A large campaign pushed malicious npm packages that exfiltrated developer system info, GitHub tokens, API keys, and other secrets during install and runtime. Teams should quarantine affected builds, rotate all exposed credentials, enforce lockfiles and provenance checks, and tighten developer workstation EDR and egress monitoring.
Source: SecurityWeek
IR trend: stolen credentials and valid account abuse drive financially motivated intrusions
Fortinet’s H1 2025 incident response review finds attackers increasingly using legitimate accounts and remote management tools to blend in and bypass detection. The report emphasizes identity-first defenses: strong MFA, continuous session monitoring, least privilege, rigorous offboarding, and detections tuned for “living off the land” activity.
Source: Fortinet
OpenAI debuts ‘Aardvark,’ an autonomous agent to scan, validate, and patch code
Now in private beta, Aardvark continuously analyzes repositories, models threats, validates exploitability in a sandbox, and proposes human-auditable patches via pull requests. Early deployments surfaced previously unknown issues, signaling how agentic AI could augment AppSec teams and integrate security deeper into CI/CD workflows.
Source: CyberScoop
You May Also Be Interested In...
CISA, NSA offer guidance to better protect Microsoft Exchange ServersWhatsApp now lets you secure chat backups with passkeys
Open-source AdaptixC2 red-teaming tool has fans in Russian cybercrime underground