Salesforce says customer-managed Gainsight-published apps were abused to access Salesforce instances, with ShinyHunters linked to the campaign. The company revoked all access and refresh tokens for affected apps and temporarily removed them from the AppExchange, underscoring the risk of third-party OAuth integrations. Security teams should audit connected apps, rotate tokens, and review logs for anomalous API activity tied to Gainsight connectors.
Source: SecurityWeek
Chinese APT24 pushes ‘BadAudio’ malware through supply chain compromises
Researchers detail how PRC-nexus APT24 is deploying the BadAudio downloader via supply chain intrusions and watering-hole attacks to deliver additional payloads. The campaign shows a sustained pivot toward compromising trusted third-party code and distribution channels, heightening enterprise exposure through indirect dependencies. Defenders should tighten third-party script governance, monitor for unexpected DLL sideloading, and validate software provenance.
Source: SecurityWeek
50,000+ Asus routers hijacked in ‘Operation WrtHug’
A Chinese threat actor compromised more than 50,000 discontinued Asus routers by exploiting known vulnerabilities, conscripting them into an Operational Relay Box (ORB) proxy network. The campaign highlights the long tail risk of end-of-life network gear left unpatched and reachable from the internet. Organizations should inventory and replace unsupported devices, lock down management interfaces, and segment untrusted hardware.
Source: SecurityWeek
7-Zip RCE flaw actively exploited in the wild
A high-severity 7-Zip remote code execution vulnerability (CVE-2025-11001) is being exploited, with a proof-of-concept widely available. Opening a crafted archive can trigger code execution, making developer and analyst workstations prime targets. Patch 7-Zip immediately and consider sandboxing untrusted archives to reduce blast radius.
Source: SecurityWeek
WhatsApp enumeration bug allowed scraping of 3.5 billion accounts
Researchers demonstrated a now-patched enumeration flaw that could be used to scrape the entire WhatsApp user base, exposing account presence and profile metadata at massive scale. While message content remained protected, the dataset is a boon for targeted phishing, SIM swap reconnaissance, and cross-platform identity matching. Users and orgs should expect increased, personalized fraud leveraging phone-based identifiers.
Source: SecurityWeek
‘Sturnus’ Android banking trojan captures content from encrypted chats
The new Sturnus malware targets European users, enabling credential theft, full device takeover, and screen-capture of messages from WhatsApp, Telegram, and Signal after decryption on-device. It abuses accessibility and overlay permissions to hide activity and orchestrate fraud in real time. Enterprises should harden MDM policies against sideloading and enforce least-privilege app permissions.
Source: SecurityWeek
US, UK, and Australia sanction Russian bulletproof hosting providers
Coordinated sanctions hit Media Land, Hypercore, and associated personnel for supporting criminal marketplaces and ransomware operations such as LockBit and BlackSuit. The move aims to disrupt resilient command-and-control and hosting services favored by top-tier cybercrime groups, and raises compliance risk for intermediaries. Providers and resellers should rapidly assess exposure and cease any direct or indirect dealings with designated entities.
Source: SecurityWeek
You May Also Be Interested In...
SquareX and Perplexity quarrel over alleged Comet browser vulnerability
Palo Alto GlobalProtect portals see 40x surge in malicious traffic
Black Friday cybercrime spikes: domain fraud and e-commerce scams