A ransomware attack on the CodeRED emergency alert platform caused outages and triggered warnings across the U.S., raising alarms about the resilience of public-notification infrastructure. The incident highlights third‑party risk in crisis communications and the need for vendor access hardening, redundancy, and joint incident response exercises with municipalities and 911/EMA stakeholders.
Source: Malwarebytes Blog
OpenAI cuts off Mixpanel after analytics breach exposes API user data
OpenAI said API users may have been affected by a breach at its former analytics provider, Mixpanel, and it has severed ties with the vendor while reviewing others. The episode underscores supply‑chain risk from telemetry tools and the importance of limiting data shared with third‑party analytics.
Source: The Register
Critical auth bypass in ASUS AiCloud routers patched—update now
ASUS released new firmware addressing nine flaws, including CVE‑2025‑59366 (CVSS 9.2), a critical authentication bypass in routers with AiCloud enabled. Admins should prioritize patching affected models and disable unneeded cloud features to reduce exposure.
Source: Security Affairs
Teams guest access can sidestep Defender protections across tenants
Researchers warn that when users join external tenants as Teams guests, their protections are governed by the host environment—potentially bypassing Microsoft Defender for Office 365 safeguards from their home organization. Adversaries can abuse this cross‑tenant blind spot for phishing and malware delivery; tighten guest policies, apply Conditional Access, and monitor cross‑tenant activity.
Source: The Hacker News
Asahi confirms data on nearly 2M people stolen before ransomware attack
Asahi said hackers exfiltrated personal information on about 2 million customers and employees prior to deploying ransomware that disrupted its operations in Japan. The disclosure illustrates the continuing convergence of data theft and encryption, and the long recovery tail for large manufacturers.
Source: SecurityWeek
Thousands of secrets exposed on JSONFormatter and CodeBeautify
WatchTowr researchers found widespread leakage of credentials, API tokens, and private keys on developer formatting sites including JSONFormatter and CodeBeautify. Organizations should prohibit pasting sensitive payloads into public tools, use local/offline formatters, and enforce secret-scanning and key rotation.
Source: Security Affairs
New Mirai variant ‘ShadowV2’ probed IoT exploits during AWS outage
FortiGuard Labs observed a Mirai‑based botnet dubbed ShadowV2 targeting vulnerable IoT devices across multiple countries while October’s AWS disruption unfolded, then going quiet—likely a test run. The timing suggests actors are using major cloud outages to cloak live-fire trials and validate exploit chains.
Source: Security Affairs
You May Also Be Interested In...
Tomiris wreaks Havoc: New tools and techniques of the APT group
FCC sounds alarm after emergency tones turned into profanity-laced radio takeover
Microsoft to block unauthorized scripts in Entra ID logins with 2026 CSP update