Law enforcement from Europe, the US, UK, Australia and Canada seized over 1,000 servers and arrested suspects tied to three major crimeware platforms powering credential theft, RAT access and botnet operations. The takedown will disrupt many ransomware affiliates’ tooling, but defenders should expect rebrands and rapid rebuilding; use this window to hunt for residual implants and C2 beacons linked to these families.
Source: SecurityWeek
Zero-days in Cisco ISE and CitrixBleed 2 exploited in the wild
Amazon researchers observed an advanced actor chaining critical flaws in Cisco Identity Services Engine (CVE-2025-20337) and Citrix NetScaler ADC/Gateway (CitrixBleed 2, CVE-2025-5777) as zero-days to deploy custom malware. Patch immediately, rotate credentials/tokens tied to affected systems, and review device logs for anomalous config changes and unexpected outbound connections.
Source: SecurityWeek
Chinese espionage campaign leveraged Anthropic’s Claude to automate attacks
Anthropic reported a state-backed actor used Claude Code to orchestrate roughly 90% of a cyber-espionage operation against about 30 global organizations, successfully compromising a small number. The “agentic AI” workflow executed reconnaissance and exploitation steps, underscoring the need for monitoring AI-tool usage, enforcing guardrails, and tightening code/tool access policies.
Source: SecurityWeek
150,000+ malicious npm packages flood registry in worm-powered campaign
Amazon detected a massive open-source supply-chain event: more than 150,000 npm packages published as part of an automated token-farming operation linked to tea.xyz incentives. The scale exceeds past floods and highlights the need for strict dependency controls (pinning, allowlists), automated package vetting, and rapid provenance checks in CI/CD.
Source: SecurityWeek
Fortinet FortiWeb authentication bypass actively exploited ahead of disclosure
Researchers warn of in-the-wild exploitation of an authentication bypass in FortiWeb WAF, reportedly patched silently by Fortinet prior to public notice. Admins should apply the latest FortiWeb updates, audit admin access logs for suspicious sessions, and review WAF policies and upstream load balancer traffic for indicators of compromise.
Source: The Hacker News
CISA: “Patched” but still exposed—US agencies must re-remediate Cisco ASA/FTD
CISA ordered federal agencies to re-verify fixes for two actively exploited Cisco ASA/Firepower flaws (CVE-2025-20333, CVE-2025-20362) after finding devices marked “patched” were still on vulnerable versions. Organizations beyond government should validate exact fixed builds, confirm mitigation coverage, and check for post-exploitation artifacts.
Source: Help Net Security
Google sues operators of China-based Lighthouse SMS phishing-as-a-service
Google filed suit against more than two dozen individuals behind a prolific mobile phishing service that spoofed hundreds of brands, blasted SMS lures, and laundered stolen cards into mobile wallets. The legal move aims to disrupt PhaaS infrastructure at scale; enterprises should continue hardening against smishing with sender validation, URL filtering, and rapid takedowns.
Source: KrebsOnSecurity
You May Also Be Interested In...
FBI: Akira gang has received nearly $250 million in ransoms
The State of Ransomware in Q3 2025
Imunify360 Vulnerability Could Expose Millions of Sites to Hacking