The Inc Ransom group hit the OnSolve CodeRED platform, disrupting local emergency notifications for state and local governments and exposing data in the process. The outage underscores third‑party risk to critical communications and the need for contingency channels, incident response runbooks, and rapid credential/token rotation for connected services.
Source: SecurityWeek
New “HashJack” prompt injection hijacks AI browsers and assistants
Researchers detailed “HashJack,” an indirect prompt injection that hides malicious instructions in a URL’s fragment (#) to manipulate AI assistants into exfiltrating data, delivering phishing, or pushing risky actions. The attack affects popular AI-enabled browsing tools and highlights the need to strip fragments from fetched content, restrict tool use, and add robust content provenance and allowlists.
Source: Help Net Security
Mirai variant “ShadowV2” surfaced during AWS outage to conscript IoT for DDoS
FortiGuard Labs analyzed ShadowV2, a Mirai-based botnet that emerged amid a recent AWS disruption, targeting exposed IoT gear to build DDoS firepower. The campaign’s timing and propagation techniques reinforce the need to harden and segment IoT, disable UPnP and default services, and maintain continuous monitoring for anomalous outbound traffic.
Source: Fortinet
Salesforce issues IoCs and timeline after Gainsight-connected breach
Salesforce shared indicators of compromise and a likely attack window tied to the Gainsight incident, noting reconnaissance from November 8 and intrusions between November 16–23. Organizations should audit connected apps, revoke and reissue tokens, review access logs for the provided IPs/User Agents, and hunt for suspicious API activity.
Source: Help Net Security
ASUS patches critical AiCloud router auth bypass (CVE-2025-59366)
ASUS released firmware updates fixing nine flaws, including a critical authentication bypass (CVSS 9.2) affecting routers with AiCloud enabled. Admins should patch immediately, disable AiCloud if updates can’t be applied promptly, and restrict WAN access to management interfaces.
Source: Security Affairs
Shai‑hulud 2.0 targets cloud and developer ecosystems, backdoors victim packages
Trend Micro warns of a campaign stealing credentials and secrets from major cloud and developer platforms and automating backdoors into npm packages maintained by compromised developers. The supply chain risk to downstream users calls for token rotation, hardened CI/CD, package publishing protections (2FA, code signing), and vigilant dependency monitoring.
Source: Trend Micro Research
Thousands of secrets leaked via popular code formatting websites
Security researchers found JSONFormatter and CodeBeautify users inadvertently exposed more than 80,000 files containing sensitive data like passwords, API keys, and private configs across critical sectors. Teams should prohibit uploading sensitive data to third‑party tools, deploy DLP and secret scanning, and offer secure, internal alternatives for code formatting and sharing.
Source: SecurityWeek
You May Also Be Interested In...
Fake LinkedIn jobs trick Mac users into downloading Flexible Ferret malwareLondon councils probe cyber incident as shared IT systems knocked offline
Malicious Chrome extension injects hidden Solana transfer fees