Arctic Wolf Labs reports that China‑nexus group UNC6384 is actively exploiting a Windows zero‑day to conduct espionage against diplomatic targets in Hungary, Belgium, and other EU nations. The campaign expands the group’s operations beyond earlier Southeast Asia targeting and underscores the urgency of applying temporary mitigations, tightening endpoint telemetry, and monitoring for suspicious lateral movement until a patch is available.
Source: Security Affairs
ASD Warns of BADCANDY Webshell on Unpatched Cisco IOS XE (CVE‑2023‑20198)
Australia’s Signals Directorate says attackers are exploiting the critical CVE‑2023‑20198 flaw on Cisco IOS XE, dropping a previously undocumented BADCANDY implant. Successful compromise can yield admin control of edge devices; defenders should patch immediately, audit for rogue users and unexpected web UI changes, and review device configs and logs for persistent implants.
Source: TheHackerNews
Active Windows Attacks With No Fix Available: CVE‑2025‑9491
Microsoft has confirmed in‑the‑wild exploitation of CVE‑2025‑9491 with no patch currently available. Organizations should apply Microsoft’s recommended mitigations, increase monitoring for related exploit indicators, and ensure rapid patch deployment once an update ships.
Source: Forbes Security
CISA: Ongoing Ransomware Attacks Target a Linux Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency warns that ransomware operators are actively exploiting a Linux vulnerability, dispelling myths that Linux is off attackers’ radar. Teams should prioritize patching, harden exposed services, deploy behavioral EDR on Linux workloads, and verify tested, offline backups.
Source: Forbes Security
Proton Confirms 300 Million Stolen Credentials Circulating on Dark Web
Proton has identified a massive trove of 300 million stolen credentials being traded on criminal marketplaces. Security teams should force password resets where appropriate, enable MFA across accounts, and advise users to monitor for reuse and enable breach alerts in their password managers.
Source: Forbes Security
Conti Case: Ukrainian Extradited to U.S. Over Ransomware Involvement
Irish authorities extradited Ukrainian national Oleksii Lytvynenko to the U.S. to face charges tied to the Conti ransomware enterprise. The action highlights sustained international cooperation against major ransomware operations and may yield further intelligence on Conti affiliates and infrastructure.
Source: Security Affairs
After Qantas Breach, Court Orders Raise Questions About Consumer Protection
Following a breach exposing frequent flyer data for 5 million Qantas customers, legal moves to restrict access to leaked data are drawing criticism. Experts argue such orders can shield brands more than consumers by limiting public verification and remediation, potentially benefiting scammers who already have the data.
Source: The Guardian
You May Also Be Interested In...
PayPal Attack Update: Another ‘Do Not Pay’ Warning Issued
New Kurdish Hacktivists Hezi Rash Behind 350 DDoS Attacks in 2 Months
‘Update And Shut Down’—Microsoft Confirms Windows Update Mistake