Cisco Talos reports a likely China-linked group, UAT-8837, has been targeting North American critical infrastructure since at least last year. The cluster’s tactics overlap with other known China-attributed activity, suggesting sustained reconnaissance and potential pre-positioning. Defenders should review telemetry for overlapping TTPs and tighten access controls across OT/IT environments.
Source: Security Affairs
Hundreds of Millions of Bluetooth Accessories Exposed by Fast Pair Hijack Flaw
A flaw in Google’s Fast Pair implementation could allow attackers to silently seize control of earbuds, headphones, and speakers without users pressing the pairing button. The Register warns that “hundreds of millions” of devices may be impacted due to sloppy implementations of the spec. Users should apply vendor firmware updates promptly and avoid pairing in hostile radio environments.
Source: The Register
Wireshark 4.6.3 Patches 4 Security Vulnerabilities
Wireshark released version 4.6.3 addressing four vulnerabilities and nine additional bugs. Given Wireshark’s exposure to untrusted traffic captures, administrators and analysts should update promptly to reduce the risk of crashes or potential code execution via crafted packets.
Source: SANS ISC
Microsoft Issues Emergency Fixes After Faulty Windows Security Update
Microsoft has pushed emergency updates to address widespread failures caused by a recent Windows security update. Organizations should review the out-of-band patches, validate system stability, and ensure vulnerable endpoints are remediated to maintain both security coverage and operational continuity.
Source: Forbes Security
Black Basta Leader Placed on EU Most Wanted; INTERPOL Issues Red Notice
Ukrainian and German authorities identified two Ukrainians tied to the Russia-linked Black Basta ransomware group and named an alleged Russian ringleader, now on the EU’s Most Wanted list with an INTERPOL Red Notice. The coordinated action signals sustained international pressure on major RaaS operations and may disrupt parts of Black Basta’s ecosystem.
Source: The Hacker News
145,000 Patients Exposed in Central Maine Healthcare Breach
Central Maine Healthcare disclosed a breach impacting 145,000 patients after attackers persisted in its systems for more than two months. Exposed data includes Social Security numbers, treatment details, and insurance information, underscoring continued risks to healthcare providers and the need for stronger lateral movement detection and data minimization.
Source: CyberNews
Report: US Hackers Allegedly Caused a Blackout in Venezuela
A Wired report claims US hackers were responsible for a power outage in Venezuela, raising legal and geopolitical questions around offensive cyber operations. The piece also touches on other policy-relevant incidents, highlighting the growing complexity at the intersection of national security, infrastructure, and cyber capabilities.
Source: Wired
You May Also Be Interested In...
"How many states are there in the United States?" (LLM API traffic observed in honeypots)New Chrome Update Deletes Google’s AI Data On Your Device
One developer’s tool strips AI and other junk from Chrome, Edge, and Firefox