The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2018-4063 in Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities catalog after reports of in-the-wild attacks. The unrestricted file upload bug can lead to remote code execution, putting distributed fleets and IoT deployments at risk. Organizations should urgently update ALEOS firmware, restrict remote administration, and monitor for anomalous uploads and unexpected reboots.
Source: TheHackerNews
Apple Confirms iPhone Attacks—Update to iOS 26.2 Now
Apple has released iOS 26.2 to fix 26 vulnerabilities, including two already exploited in the wild. The update closes critical holes that could enable code execution and device compromise, making prompt patching essential for personal and corporate iPhones alike. Enable automatic updates and verify that high-risk devices are on the latest build.
Source: Forbes Security
Microsoft Warns of ‘Shai-Hulud’ Cloud Worm Attacks—Rotate Passwords and Tokens Now
Microsoft is urging rapid password changes as the “Shai-Hulud/Dune Worm” campaign targets cloud environments using compromised credentials and lateral movement. The ongoing activity highlights weaknesses in identity hygiene and cross-tenant access controls. Security teams should revoke active tokens, enforce phishing-resistant MFA, review conditional access policies, and audit workload identities and service principals.
Source: Forbes Security
Open 16TB Database Exposes 4.3B Professional Records, Supercharging Social Engineering
Researchers discovered an unsecured 16TB MongoDB holding 4.3 billion professional records—primarily LinkedIn-style data—before it was taken offline. The trove enables highly tailored phishing, AI-driven impersonation, and recruitment fraud at scale. Organizations should strengthen email authentication, train staff to detect hyper-personalized lures, and monitor for identity abuse in BEC and vendor fraud scenarios.
Source: Security Affairs
FBI Finds 630 Million Stolen Passwords on Single Hacker’s Devices
The FBI confirmed it recovered 630 million stolen passwords from a lone threat actor, underscoring the industrial scale of credential theft. The cache fuels credential-stuffing and account takeover, particularly where password reuse persists. Enforce password managers and MFA, rotate high-risk credentials, and use breach notification services to assess exposure.
Source: Forbes Security
Germany Summons Russian Ambassador Over ATC Hack and Disinformation Claims
Germany says it has “clear evidence” linking August attacks on its air traffic control authority and a concurrent disinformation campaign to Russian actors, escalating tensions ahead of February elections. The incident illustrates how cyber operations against critical infrastructure can be paired with influence operations. Aviation and OT defenders should review segmentation, incident playbooks, and coordinated comms strategies.
Source: Security Affairs
Stanford’s ARTEMIS AI Agent Outperforms Human Pentesters at Lower Cost
Stanford’s ARTEMIS AI system reportedly beat nine of ten human cybersecurity professionals in a hacking test while operating at a fraction of the cost. The result signals accelerating offensive and defensive automation, compressing attacker timelines and lowering barriers. Security programs should invest in secure-by-design practices and incorporate AI-aware red/blue teaming.
Source: CyberNews
You May Also Be Interested In...
Google Issues Critical ‘No Password Required’ Attack WarningCISA adds Google Chromium and Sierra Wireless AirLink ALEOS flaws to KEV
How to Protect Your WordPress Site From a Phishing Attack