The European Commission is investigating suspicious activity in its mobile device management backend after CERT-EU flagged an intrusion. While the scope is still being assessed, a compromise of MDM infrastructure could expose device policies, app push channels, and authentication tokens, enabling deeper access. Organizations should review MDM access controls, rotate credentials/tokens, and increase logging on management endpoints.
Source: The Register
Critical pre-auth RCE in BeyondTrust Remote Support and PRA — patch now
BeyondTrust released fixes for a critical pre-authentication remote code execution vulnerability affecting Remote Support (RS) and older versions of Privileged Remote Access (PRA). Internet-exposed instances are at particular risk of takeover before authentication. Admins should upgrade immediately and restrict access to management interfaces behind VPN or allowlists.
Source: The Hacker News
TeamPCP worm targets cloud-native stacks via exposed Docker, Kubernetes, Ray, and Redis
Researchers warn of a massive, worm-driven campaign that since late December has compromised cloud-native environments by abusing exposed Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers, plus a recently disclosed flaw. The operators leverage the access to build criminal infrastructure for follow-on attacks. Lock down management endpoints, disable unauthenticated APIs, and enforce network policies to contain lateral movement.
Source: The Hacker News
“DKnife” toolkit hijacks routers to spy and deliver malware since 2019
Cisco Talos uncovered DKnife, a Linux-based toolkit used to commandeer routers and edge devices for adversary-in-the-middle operations and downstream malware delivery. Active since 2019 and linked to cyber-espionage, it inspects and alters in-transit traffic and pushes payloads to PCs and mobile devices. Defenders should update router firmware, disable unused services, and monitor for anomalous traffic redirection and persistence on edge gear.
Source: Security Affairs
Cyberattack disrupts Romania’s national oil pipeline operator Conpet
Conpet, Romania’s state-controlled crude pipeline operator, reported a cyber incident that disrupted business systems and temporarily took its website offline. While the investigation continues, the event underscores the exposure of energy-sector IT environments and their potential as stepping stones toward OT. Segmentation between IT/OT and robust incident response planning remain critical.
Source: Security Affairs
Flickr warns users after third-party email provider exposes customer data
Flickr disclosed that a flaw in a third-party email provider may have exposed users’ names, email addresses, IP addresses, and account activity. The company cautioned that the data could fuel targeted phishing and social engineering. Users should be alert to unsolicited messages, verify sender domains, and enable two-factor authentication.
Source: Security Affairs
CSA: Autonomous AI agents act like users—but security and governance lag
A new Cloud Security Alliance report highlights that autonomous AI agents are being deployed across production and test environments using static credentials, inconsistent controls, and with limited visibility. The guidance urges treating agents as first-class identities with traceability, least-privilege access, policy enforcement, and auditable actions to match their growing business impact.
Source: Help Net Security
You May Also Be Interested In...
Malicious RTF lures resurge amid reports of APT28 exploiting a recent Microsoft Office flaw
DDoS campaign by NoName057(16) hammers Italy and Germany
NetSupport RAT spear‑phishing hits Uzbekistan and Russia