A newly disclosed high-severity vulnerability dubbed “MongoBleed” allows unauthenticated, remote attackers to leak sensitive information from MongoDB servers. Active exploitation has been observed in the wild, making rapid patching and exposure reduction urgent for organizations running internet-facing instances.
Source: SecurityWeek
EmEditor supply chain attack delivers infostealer via official download
The official EmEditor website’s “download” button briefly served a malicious installer that delivered infostealer malware, underscoring the persistent risk of supply chain compromises. Organizations should verify hashes, review recent installs, and monitor endpoints for anomalous connections tied to post-install activity.
Source: SecurityWeek
HoneyMyte APT unveils kernel-mode rootkit to hide ToneShell backdoor
Kaspersky reports a 2025 HoneyMyte (aka Mustang Panda/Bronze President) campaign using a kernel-mode rootkit to deploy and shield the ToneShell backdoor. The rootkit-based approach boosts stealth and persistence, signaling continued escalation in APT tradecraft at the kernel level.
Source: SecureList
Evasive Panda uses DNS poisoning to install MgBot backdoor in regional targets
Researchers observed China-linked Evasive Panda leveraging DNS poisoning to deliver its MgBot backdoor to victims in Türkiye, China, and India. The technique enables covert initial access via tampered name resolution, bypassing traditional perimeter defenses and content filtering.
Source: Security Affairs
Aflac breach exposes data of 22 million, including SSNs and medical info
Aflac disclosed a major breach affecting 22 million individuals, with attackers obtaining names, addresses, Social Security numbers, identification numbers, and medical/health insurance information. The scope and sensitivity of the stolen data elevate risks of identity theft and fraud across impacted populations.
Source: SecurityWeek
WIRED subscriber data leak hits 2.3M; hacker claims 40M more from Condé Nast
A hacker known as “Lovely” leaked 2.3 million WIRED subscriber records and claims to possess up to 40 million additional Condé Nast records. While the broader claim remains unverified, the confirmed exposure highlights ongoing threats to media subscribers and the data brokers who value their details.
Source: SecurityWeek
LLMs now power the “human” in romance-baiting scams
New research shows romance-baiting scams are increasingly automated with large language models that mimic human conversation over weeks to build trust. The automated scripts eventually push victims toward fraudulent crypto investments, scaling social engineering with convincing, low-cost interactions.
Source: Help Net Security
You May Also Be Interested In...
Stolen LastPass backups enable crypto theft through 2025
Superagent: Open-source framework for guardrails around agentic AI
27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials