A vulnerability in F5 BIG-IP Access Policy Manager initially labeled a high-severity DoS has been reclassified as a critical remote code execution issue, and attackers are now exploiting it. Organizations should patch immediately, restrict management interfaces, and monitor for signs of compromise on BIG-IP APM devices.
Source: SecurityWeek
Attackers begin exploiting new Citrix NetScaler memory overread (CVE-2026-3055)
Active exploitation has started against a critical Citrix NetScaler ADC/Gateway flaw that leaks application memory and can yield authenticated administrative session IDs. Immediate upgrades, session invalidation, and review of access logs are advised, especially for SAML IdP configurations that could be at heightened risk.
Source: SecurityWeek
Russia-linked TA446 targets iPhone users with “DarkSword” exploit via phishing
TA446 (aka SEABORGIUM/ColdRiver/Callisto/Star Blizzard) is using the DarkSword iOS exploit kit in targeted spear-phishing to compromise iPhones. The campaign underscores the growing sophistication of mobile-focused APT tradecraft and the need for rapid iOS patching and hardened email security controls.
Source: Security Affairs
Russian “CTRL” toolkit abuses LNK files to hijack RDP via FRP tunnels
Researchers uncovered a .NET-based remote access toolkit delivered via malicious Windows LNK files masquerading as private key folders. The toolkit enables credential phishing, keylogging, RDP session hijacking, and reverse tunneling over FRP, highlighting the need to block LNK attachments and monitor for unusual tunneling activity.
Source: The Hacker News
EvilTokens: Device code phishing-as-a-service supercharges BEC
Sekoia reports a widespread “EvilTokens” kit offering device code phishing-as-a-service with AI-augmented features, enabling attackers to harvest OAuth tokens and bypass MFA for business email compromise. Defenders should tighten conditional access, device compliance checks, and token hygiene to blunt device-code flow abuse.
Source: Sekoia
Three China-linked clusters ran a well-resourced 2025 campaign against a Southeast Asian government
Multiple China-aligned groups conducted concurrent operations deploying families such as HIUPAN, PUBLOAD, EggStreme variants, and MASOL, indicating shared tooling or coordinated tasking. The breadth of initial access vectors and payloads points to sustained, multi-pronged collection priorities in the region.
Source: The Hacker News
FBI confirms personal email hack of Director Kash Patel; US posts $10M reward
The FBI confirmed Iranian hackers compromised the director’s personal email account, noting the exposed information is old while emphasizing no breach of FBI networks. The incident spotlights ongoing targeting of senior officials’ personal accounts and the value of robust personal-identity and email protections.
Source: SecurityWeek
You May Also Be Interested In...
European Commission admits attackers broke into public web systems, but says little else