Researchers say Russia-linked Sandworm likely orchestrated a late-2025 cyberattack against Poland’s energy sector, deploying data-wiping malware and tactics reminiscent of its historic Ukraine operations. The incident underscores escalating threats to European critical infrastructure and the need to stress-test OT segmentation, backups, and incident response playbooks.
Source: SecurityWeek
Critical VMware bug from 2024 now actively targeted for remote code execution
A critical-severity VMware vulnerability disclosed in 2024 is drawing fresh attacker interest, with exploits relying on crafted network packets to achieve RCE. Organizations should urgently patch, restrict management interfaces, and increase telemetry around anomalous service behavior to spot exploitation attempts.
Source: SecurityWeek
Reports of fully patched FortiGate compromises and probing of Cisco RCE put edge gear on notice
A weekly roundup highlights mounting evidence that fully patched FortiGate firewalls are being compromised, alongside attacker reconnaissance against a Cisco remote code execution flaw. The trend points to continued pressure on perimeter devices and the importance of threat hunting, configuration hardening, and exposure reduction on internet-facing appliances.
Source: Help Net Security
New MaaS toolkit "Stanley" enables website spoofing and extension-based phishing
Threat actors are marketing a phishing toolkit priced between $2,000 and $6,000 that promises website spoofing capabilities and even publication on the Chrome Web Store. If successful, this lowers the barrier to extension-based social engineering, reinforcing the need for strict browser extension governance and enterprise allowlists.
Source: SecurityWeek
PeckBirdy: China-aligned APTs abuse LOLBins via JScript C2 framework
Trend Micro details PeckBirdy, a JScript-based command-and-control framework leveraged by China-aligned threat groups to exploit living-off-the-land binaries across diverse environments. The framework has delivered advanced backdoors against gambling organizations and Asian government targets, complicating detection through native tool abuse.
Source: Trend Micro Research
Konni uses AI-generated PowerShell backdoor to hit blockchain developers
The North Korea-linked Konni group is deploying PowerShell malware generated with AI tools, targeting developer and engineering teams in the blockchain sector. Campaigns observed in Japan, Australia, and India illustrate both an expanded target set and the growing use of AI to rapidly produce evasive code.
Source: The Hacker News
Microsoft Entra ID to auto-enable passkey profiles and roll out synced passkeys in March
Microsoft will begin automatically enabling passkey profiles in Entra ID and introducing synced passkeys into general availability, with group-based configuration support. Identity teams should prepare communications, policy scoping, and device readiness to capitalize on phishing-resistant authentication at scale.
Source: Help Net Security
You May Also Be Interested In...
Unusual scanners hit web servers with /$(pwd)/ as the starting path
Nike investigates breach after hackers leak purported years of design and factory data