Cisco Talos is tracking UAT-8837, assessed with medium confidence to be a China-nexus APT targeting critical infrastructure sectors in North America. The activity underscores continued strategic interest in CI environments and the need for heightened monitoring and segmentation across IT/OT boundaries.
Source: Cisco Talos
Microsoft and law enforcement disrupt RedVDS cybercrime platform behind massive fraud
Authorities dismantled RedVDS, a virtual desktop infrastructure service used at scale for phishing, BEC, account takeovers, and other fraud, with losses exceeding $40 million in the U.S. alone. The takedown will likely trigger actor migration to alternate infrastructure—security teams should update blocks and detections using newly shared indicators and revisit controls on remote desktop access.
Source: SecurityWeek
Critical Node.js bug can crash “virtually every production app” via async_hooks DoS
Node.js released patches for a critical vulnerability where stack exhaustion tied to async_hooks can trigger denial-of-service conditions. Given the ubiquity of Node.js in backends and microservices, teams should fast-track updates and consider adding load and fuzz testing to catch crash conditions in request paths.
Source: The Hacker News
Fortinet fixes critical unauthenticated flaws in FortiSIEM and FortiFone
Two critical vulnerabilities— including an unauthenticated OS command injection in FortiSIEM enabling remote code execution—were patched alongside additional issues affecting FortiFone. Exposed management interfaces and SOC tooling are high-value targets; patch immediately and restrict access via network controls and MFA.
Source: SecurityWeek
VoidLink: new modular Linux malware framework targets cloud and containers
A newly identified framework, VoidLink, is designed for long-term access to cloud and containerized environments, featuring custom loaders, implants, and rootkits. Its cloud-native TTPs and stealthy plugins make compromise easy to miss—prioritize runtime telemetry, credential hygiene, and least-privilege for service accounts.
Source: SecurityWeek
Poland says it thwarted major cyberattack on power grid, blames Russia
Polish officials reported repelling the most serious cyberattack on the country’s energy infrastructure in years, narrowly avoiding a widespread outage. The incident highlights persistent OT targeting and the need for robust segmentation, incident response exercises, and coordinated defender-intel sharing across the energy sector.
Source: Recorded Future News
Magecart web skimming hits checkouts tied to major payment networks
A Magecart campaign is siphoning payment card data from e-commerce checkout pages associated with networks including AmEx, Diners Club, and Mastercard. Merchants should audit third-party scripts, enforce CSP and subresource integrity, and monitor for DOM tampering to curb skimmer injections.
Source: Malwarebytes
You May Also Be Interested In...
The NSA lays out the first steps for zero trust adoption
Palo Alto fixes GlobalProtect DoS flaw that can crash firewalls without login
Western cyber agencies warn about threats to industrial operational technology