SANS ISC sensors observed a sharp rise in internet scans targeting TCP ports 8530 and 8531, likely tied to the newly disclosed WSUS vulnerability CVE-2025-59287. While some activity originates from research bodies like Shadowserver, a portion appears unrelated to known researchers, suggesting opportunistic threat actors are probing for exposed servers. WSUS admins should prioritize patching, restrict external exposure (especially 8530/HTTP), and inspect logs for anomalous sync requests.
Source: SANS ISC
Chinese APT Abuses AirWatch MDM APIs with ‘Airstalk’ Malware
A Chinese state-linked group is using PowerShell and .NET variants of a malware family dubbed “Airstalk” in supply chain attacks, SecurityWeek reports. The tooling abuses VMware AirWatch MDM APIs as a covert C2 channel, blending command-and-control traffic into legitimate device management operations. Enterprises should scrutinize MDM API usage, rotate tokens, and alert on unusual device enrollment or command patterns.
Source: Security Week
ASD: ‘BADCANDY’ Reinfects Unpatched Cisco IOS XE Devices After Removal
Australia’s Signals Directorate warns attackers are implanting “BADCANDY” on vulnerable Cisco IOS XE systems and can detect when defenders remove it—then reinstall. The advisory underscores continuing exploitation of unpatched devices and the limits of simple cleanup without full remediation. Organizations should urgently patch affected IOS XE versions, validate device integrity, and review edge device segmentation and monitoring.
Source: The Register
Conduent Breach Exposes PII of 10M+ Individuals
Conduent disclosed that a January 2025 intrusion exposed data on more than 10 million people, including names, addresses, dates of birth, Social Security numbers, and health/insurance information. The scale and sensitivity of the data highlight the cascading risk posed by large business services vendors. Impacted organizations should assess downstream exposure and prepare for identity fraud monitoring and notifications.
Source: Security Affairs
Europol: Caller ID Spoofing Fuels Europe’s Fraud Surge
Europol warns that caller ID spoofing is a major driver of cyber-enabled fraud across Europe, contributing to an estimated €850 million in global losses annually. Phone and text-based scams account for roughly two-thirds of reported cases, with manipulated identities complicating attribution and enforcement. The paper calls for stronger cross-border cooperation and better caller authentication to curb spoofed traffic.
Source: HelpNet Security
Kimsuky Deploys New ‘HttpTroy’ Backdoor via Invoice-Themed Phish
Gen Digital details a targeted spear-phishing operation in South Korea by North Korea–linked Kimsuky that delivered a previously unknown backdoor dubbed “HttpTroy.” The malware arrived as a ZIP attachment masquerading as a VPN invoice and establishes persistent remote access. Organizations in the region should harden email defenses, hunt for HttpTroy indicators, and reinforce executive phishing awareness.
Source: TheHackerNews
SOHO Printers Under Fire: Chained Bugs Enable Remote Takeover of Brother MFC-J1010DW
Researchers at Star Labs disclosed three flaws in Brother’s MFC-J1010DW (firmware ≤1.18) that chain to full remote compromise: SNMP-based authentication bypass to derive the default admin password, unauthenticated firmware rollback, and a buffer overflow via the HTTP Referer header. The findings spotlight office peripherals as viable ingress points if left unpatched and internet-exposed. Admins should update firmware, disable unnecessary services like SNMP, and restrict management access.
Source: Star Labs
You May Also Be Interested In...
Google Pays $100,000 in Rewards for Two Chrome Vulnerabilities
Alleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody
Norway discovers that its Chinese electric buses can be remotely disabled