Apple says it is sending new “Threat Notifications” to users it believes may be targeted by mercenary spyware. These notifications are designed to help affected individuals quickly verify suspicious activity and use built-in protections to reduce harm. For defenders, the key takeaway is that mercenary spyware campaigns are increasingly product-visible—telemetry and OS-level warning mechanisms are becoming part of the response playbook.
Source: MalwareBytes Blog
New Android banking malware (WindRelay) captures live card data via NFC relays
Researchers report WindRelay, an Android malware designed to harvest payment card information in real time by relaying NFC interactions to fraudsters. The campaign is paired with a remote access trojan (SpyNote), which helps maintain control of the infected device throughout the scam chain. The practical implication: incident response and mobile security teams should treat NFC-adjacent payment fraud as both social and technical—device compromise and attacker tooling are both in scope.
Source: Help Net Security
Unpatched GeoServer zero-day is already being probed—potential SQLi to RCE risk
A newly disclosed GeoServer zero-day is described as an SQL injection that may enable remote code execution, and security researchers note attackers are already probing exposed instances. Critically, there is reportedly no patch available yet, which shifts urgency to exposure reduction: verify whether GeoServer is internet-facing, enforce strict access controls, and monitor for suspicious request patterns. If your environment includes geospatial services, this is a reminder that “niche” infrastructure is still a high-value target when it becomes searchable and reproducible.
Source: Security Week
CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to the KEV exploited-vulnerabilities catalog
CISA updated its Known Exploited Vulnerabilities (KEV) catalog by adding multiple issues affecting widely used platforms. The batch includes a Metabase critical SQL injection flaw (CVE-2026-72898), a Windows use-after-free in a WinSock ancillary driver (CVE-2026-68820), and a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349). For security teams, KEV listings are operational signals: prioritize patching and compensating controls quickly, and validate if any asset inventory gaps could hide exposure.
Source: SC Media
Rapid7 ships Metasploit 6.5 with new exploit modules and HTTP profile improvements
Rapid7 released Metasploit Framework 6.5, bringing 13 new modules (including multiple RCE pathways across popular web applications and appliances) plus enhancements such as new “malleable” C2 HTTP(S) traffic shaping options. While Metasploit updates are not inherently malicious, they often accelerate defensive readiness gaps by making new attacker workflows easier to reproduce. Defenders should treat this as a signal to tighten perimeter and app controls, focus on patch compliance for commonly targeted CMS/portal software, and improve detection of exploit attempts against internet-facing services.
Source: Rapid7
US authorizes vetted private cyber firms to conduct offensive operations against transnational criminal networks
Multiple outlets report the US is formalizing a program allowing vetted private cybersecurity companies to conduct government-approved offensive cyber operations against transnational criminal organizations. This “privateering” approach could reshape how cyber enforcement happens—moving beyond traditional takedowns into disruption using offensive capabilities. For the policy and governance community, the immediate concern is oversight, authorization boundaries, and how outcomes and risks are managed to avoid collateral impact.
Source: Security Affairs
You May Also Be Interested In...
AWS Certificate Manager sets 2027 end date for email-validated certificate renewals
macOS screen sharing vulnerability actively exploited for crypto mining
Ukrainian police raid 94 fraudulent call centers, seize $2 million