Google Threat Intelligence reports a shift from using AI for productivity to deploying AI-enabled malware during active operations. New families like PROMPTFLUX and PROMPTSTEAL call LLMs mid‑execution to rewrite code, generate one‑liner system commands, and evade detection, with APT28 observed using LLM APIs to drive data collection. Attackers are also social‑engineering AI guardrails and monetizing illicit AI tools on underground forums. Defenders should watch for anomalous calls to AI APIs and block outbound traffic to model endpoints.
Source: Google Cloud Blog
SonicWall: State‑sponsored attackers stole cloud firewall backups
SonicWall confirmed that a state‑sponsored actor accessed a specific cloud environment and exfiltrated firewall configuration backup files for customers using its cloud backup service. The data could help adversaries map networks, reuse credentials, or tailor exploits; SonicWall has blocked access and notified customers. Rotate credentials, review firewall rules and backup settings, and hunt for suspicious configuration changes.
Source: SecurityWeek
Actively exploited CWP bug allows unauthenticated RCE (CVE-2025-48703)
CISA warns that a critical flaw in Control Web Panel enables remote, unauthenticated command execution and is being exploited in the wild. The bug is now on the KEV list, raising urgency for organizations running CWP on CentOS/CentOS‑based systems to patch or apply mitigations immediately. Restrict panel access, monitor for webshells, and review logs for odd system commands.
Source: SecurityWeek
Russia‑linked actors abuse Hyper‑V to hide Linux VM and evade EDR
Researchers observed the Curly COMrades group enabling Windows Hyper‑V to deploy a minimal Alpine Linux VM, creating a covert execution environment for malware and long‑term persistence. Running payloads inside the hidden VM helps bypass Windows‑focused defenses and complicates forensics. Defenders should alert on unexpected Hyper‑V role activation, unknown VMs, and anomalous virtual switch activity.
Source: The Hacker News
Cisco patches critical Contact Center flaws enabling RCE to root
Cisco released fixes for critical vulnerabilities in its Contact Center appliance that allow remote code execution and privilege escalation to root on affected systems. These systems often sit in sensitive environments and handle high‑value customer data, making rapid patching essential. Inventory impacted appliances, apply updates without delay, and validate that internet‑facing management interfaces are locked down.
Source: SecurityWeek
WordPress ‘Post SMTP’ plugin under active attack; site takeover risk
A critical flaw in the Post SMTP plugin lets attackers read arbitrary emails, including password resets, enabling administrator account hijacking and full site compromise. Exploitation is ongoing, potentially affecting over 200,000 WordPress sites. Update the plugin to the latest fixed version, revoke reset emails for admin accounts, and enforce 2FA for site administrators.
Source: SecurityWeek
UK water utilities probed by hackers five times since 2024
New data shows repeated cyberattacks against UK water systems, underscoring growing risks to critical infrastructure worldwide. The activity highlights long‑standing OT/IT convergence gaps and the need for segmentation, asset visibility, and incident response readiness across utilities. Operators should prioritize patching exposed HMIs, enforcing MFA for remote access, and continuous monitoring of OT networks.
Source: Malwarebytes Blog
You May Also Be Interested In...
Cloudflare Scrubs Aisuru Botnet from Top Domains List
Apple patches 50 security flaws—update now
Microsoft finds backdoor using OpenAI Assistants API for C2 communications