CISA added CVE-2021-26829, a cross-site scripting vulnerability in OpenPLC ScadaBR for Windows and Linux, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation tied to a hacktivist attack on industrial control systems. OT operators should audit any external exposure of ScadaBR, apply available fixes, and monitor for suspicious web interactions targeting system_settings.shtm.
Source: SecurityWeek
APT “Tomiris” pivots to Telegram/Discord-based implants for stealthy C2
Researchers report Tomiris is targeting foreign ministries and intergovernmental bodies with implants that use public services like Telegram and Discord for command-and-control. The shift reduces infrastructure risk and blends malicious traffic with normal cloud service use, complicating detection and takedown.
Source: The Hacker News
New Albiriox Android MaaS enables on‑device fraud against 400+ apps
“Albiriox” is a malware-as-a-service for Android offering screen control, real-time device interaction, and on‑device fraud, with a hard-coded target list spanning 400+ banking, fintech, payment, and crypto apps. Its capabilities can bypass out-of-band checks by operating on compromised devices, elevating risk for mobile financial services.
Source: The Hacker News
Swiss data watchdogs urge public sector to avoid M365 and SaaS lacking end‑to‑end encryption
Switzerland’s Conference of Data Protection Officers (Privatim) issued a resolution advising public bodies to steer clear of hyperscale clouds and SaaS—including Microsoft 365—because they lack end‑to‑end encryption and raise sovereignty and confidentiality concerns. The guidance could reshape procurement, pushing requirements for stronger encryption, data residency, and contractual control.
Source: The Register
Coupang breach exposes data of 33 million users in South Korea
E‑commerce giant Coupang disclosed a massive breach affecting 33 million customers, the country’s largest data leak in a decade. Authorities are probing a suspected insider angle involving a former employee in China, as investigators assess the scope of exposed personal information.
Source: CyberNews
Ransomware loves weekends: identity changes and org shake-ups heighten risk
Over half of ransomware incidents in the past year struck during weekends or holidays, according to Semperis, when staffing is thin and detection lags. Notably, 60% of incidents followed M&A, restructuring, or similar changes, with identity system shifts cited as a common trigger—underscoring the need for change‑control, MFA, and continuous monitoring around high‑risk periods.
Source: Help Net Security
Hackers leak sensitive Sorbonne Université staff data
A threat actor on the dark web is distributing files allegedly stolen from Sorbonne Université, including banking details, salary records, and social security numbers. If verified, the exposure poses significant risks of fraud and identity theft for staff while the university investigates.
Source: CyberNews
You May Also Be Interested In...
Offensive cyber power is spreading fast and changing global security
Singapore orders Apple and Google to curb fake government texts
Over 2,000 fake shopping sites spotted ahead of Cyber Monday