Cl0p names nearly 30 alleged victims of Oracle E‑Business Suite hack
The Cl0p ransomware site has posted an alleged victim list tied to an Oracle EBS intrusion campaign, naming major organizations including Logitech, The Washington Post, Cox Enterprises, Pan American Silver, LKQ, and Copeland. The claims highlight the risk to ERP platforms and data exfiltration at scale. Oracle EBS users should urgently review internet exposure, apply the latest patches, and hunt for anomalous access and data movement.
Source: SecurityWeek
QNAP patches multiple vulnerabilities exploited at Pwn2Own Ireland
QNAP released fixes for multiple flaws across QTS, QuTS hero and several apps that could enable remote code execution, information disclosure, and DoS conditions. The issues were demonstrated in live exploits during Pwn2Own Ireland, underscoring the risk to widely deployed NAS gear. Admins should update firmware and affected apps immediately, minimize internet exposure, and review backup/sync and admin access policies.
Source: SecurityWeek
Microsoft details ‘Whisper Leak’ side‑channel exposing AI chat topics despite encryption
Microsoft researchers disclosed Whisper Leak, a side‑channel that allows network observers to infer what users discuss with remote LLMs even when traffic is encrypted. The finding highlights metadata leakage risks as organizations adopt AI assistants over the network. Mitigations include traffic shaping/padding, gateway proxies, and treating LLM egress like other sensitive SaaS with zero‑trust monitoring.
Source: Security Affairs
Malicious ‘GlassWorm’ resurfaces via three VS Code extensions with thousands of installs
Researchers identified three Visual Studio Code extensions tied to the GlassWorm campaign that remain available for download, collectively tallying thousands of installs. Malicious extensions can exfiltrate data or execute attacker code in developer environments, turning the dev toolchain into an intrusion vector. Teams should inventory and restrict extensions via allowlists, verify publishers, and monitor developer workstation egress.
Source: TheHackerNews
New ‘Landfall’ zero‑click spyware targets Samsung Galaxy devices
A commercial‑grade Android spyware dubbed Landfall has been discovered exploiting zero‑day vulnerabilities in Samsung Galaxy devices. The campaign appears tailored for targeted surveillance with no user interaction. Galaxy users and enterprise MDM teams should apply the latest security updates as soon as they land, enforce mobile threat defense, and minimize attack surface by disabling unneeded services/features.
Source: CyberNews
Time‑bombed NuGet packages aim to disrupt databases and industrial systems
Socket’s Threat Research Team uncovered nine malicious NuGet packages from “shanhai666” that include time‑delayed payloads set to trigger in 2027 and 2028, targeting databases and industrial control environments. The long‑dwell supply‑chain tactic seeks to evade detection and maximize operational impact. Developers should remove the affected packages, pin dependencies with lockfiles, use private registries with provenance checks, and scan builds for malicious code.
Source: Security Affairs
U.S. reportedly preparing TP‑Link sales ban amid supply‑chain and security concerns
KrebsOnSecurity reports the U.S. government is considering a ban on TP‑Link networking gear, a vendor with an estimated 50% market share among home and SMB users. While tied to China concerns rather than a specific CVE, the move spotlights persistent “insecure‑by‑default” issues across low‑cost routers. Organizations should review procurement dependencies, harden consumer‑grade gear where used, and plan lifecycle replacements with devices supporting strong default security and patch cadence.
Source: KrebsOnSecurity
You May Also Be Interested In...
Multi‑brand phishing campaign harvests credentials via Telegram Bot API
ClickFix phishing wave targets hotels, delivers PureRAT
Data breach at Chinese infosec firm reportedly exposes cyber‑weapons and targeting