WatchGuard shipped fixes for a critical vulnerability in Fireware OS’s iked process that allows unauthenticated remote code execution, and it’s already being exploited. Edge appliances remain prime targets for rapid mass exploitation, so admins should prioritize patching, audit exposure of VPN/IKE services, and monitor for anomalous iked activity. Consider temporarily restricting management and VPN endpoints to trusted IPs until updates are fully deployed.
Source: SecurityWeek
Kimwolf Android botnet infects 1.8 million+ devices, unleashes massive DDoS
Researchers report the newly discovered Kimwolf Android botnet has compromised more than 1.8 million devices and issued over 1.7 billion DDoS commands, with links to the Aisuru botnet. Mobile devices are increasingly being weaponized for large-scale traffic floods; organizations should expand DDoS defenses to consider mobile-origin traffic and users should avoid sideloaded apps and keep devices updated.
Source: Security Affairs
Session token theft is surging, giving attackers a shortcut around MFA
Web apps commonly store session tokens in cookies or browser storage that are accessible to in-page scripts, including third-party tags—making theft easier than credential phishing. Stolen tokens let attackers bypass MFA and move quickly; mitigate with HttpOnly/Secure/SameSite cookies, short token lifetimes, token binding/DPoP where possible, strict CSP and tag governance, and continuous session anomaly detection.
Source: Help Net Security
NIST issues guidance to secure smart speakers in telehealth
As smart speakers and IoT assistants enter home health settings, NIST highlights risks from prescription tampering to medical data theft and patient impersonation. The new guidance outlines controls for device hardening, identity verification, data minimization, and secure connectivity to protect patients and providers in “virtual care” environments.
Source: Help Net Security
Europol-led operation nets 574 arrests in Africa-wide cybercrime crackdown
Operation Sentinel, spanning 19 countries over a month, targeted business email compromise, digital extortion, and ransomware, resulting in 574 arrests and roughly $3 million recovered. The takedown underscores BEC’s dominance and the value of coordinated international action; businesses should reinforce invoice/payment verification and tighten email security controls.
Source: Help Net Security
UK government probes “cyber incident” after reports of China-linked access to documents
Britain’s government confirmed it is investigating a cyber incident following media reports that China-linked hackers accessed thousands of confidential files. Details remain limited, but the case highlights ongoing state-aligned targeting of government data and the need for robust segmentation, access controls, and incident response readiness across the public sector.
Source: SecurityWeek
Docker makes hardened, open-source container images free for all
Docker released more than 1,000 Hardened Images—based on Debian and Alpine—at no cost under Apache 2.0, aiming to improve baseline security early in the software supply chain. Transparent, maintained base images help reduce image drift and vulnerability noise, enabling teams to focus on application-layer risks and consistent CI/CD trust policies.
Source: Help Net Security
You May Also Be Interested In... - Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale - Browser agents don’t always respect your privacy choices - University of Sydney discloses data breach impacting 27,000 people