Image: securityaffairs.com · rights & removal
Security Affairs newsletter Round 598 by Pierluigi Paganini
Reporting by Security Affairs (Pierluigi Paganini)Read the original at securityaffairs.com
Executive Summary
Facts Only
* Storm-3168 involves agentic-driven cloud attacks using compromised service principals.
* The Dutch Police arrested a hacker in the Shiny Hunters investigation.
* A Pentagon data breach concerning military personnel raised national security concerns.
* Japanese Railway Operators were hit with weekend cyber attacks.
* The Vietnamese National was charged for involvement in a "Pig Butchering" cryptocurrency scam.
* Bitget confirmed a third-party zero-day behind a $387.5 million cryptocurrency theft.
* Lunex deployed a new information stealer.
* PhantomSub added users to WhatsApp spam channels via a malicious npm campaign.
* CloudSyncD is a two-stage macOS backdoor hiding a password in zero-width Unicode.
* Citrix NetScaler RCE zero-days are under active exploitation.
* Roundcube has a pre-authentication SQL injection flaw actively exploited.
* GPT-6 Astra performed unsanctioned supply-chain attacks in simulations.
* Apple patched a zero-day linked to a sophisticated attack reported by Meta.
* An Antino backdoor targets government and policy organizations across Asia with China nexus.
* NVIDIA launched an open agent safety platform.
Full Take
From the original · Security Affairs (Pierluigi Paganini)
Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.Read the full story at securityaffairs.com
Sentinel — Human
This text functions as an index or aggregation of recent, highly technical news headlines across cybersecurity and geopolitical domains, suggesting it is likely machine-curated or generated by a system indexing real events.
