⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10035 | Deserialization Flaw in Fortra GoAnywhere MFT License Servlet Enables RCE CVE-2025-10035 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in the License Servlet of Fortra GoAnywhere Managed File Transfer (MFT). It is triggered when the servlet processes a license response carrying a validly forged signature, causing it to deserialize an arbitrary attacker-controlled object; the CVSS vector indicates the attack is network-based and requires no privileges or user interaction. Successful exploitation can lead to command injection (CWE-77), effectively giving an attacker command execution on the MFT server and access to the files and credentials that flow through it. Any organization running GoAnywhere MFT, which is commonly deployed as a central file-transfer hub, is affected, although specific affected/fixed version ranges are not provided in the available data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2025-09-29 with known ransomware use, Microsoft attributes attacks to the Storm-1175 ransomware affiliate (Medusa, now reportedly replaced by StormEncryptor), and EPSS assigns a 99.8% probability of exploitation within 30 days. Do: Apply mitigations or patches per Fortra's vendor instructions immediately, as this is a KEV entry carrying BOD 22-01 requirements for federal agencies (patch or discontinue use if mitigations are unavailable). Because a ransomware affiliate (Storm-1175, using Medusa/StormEncryptor) is actively exploiting it, hunt for compromise: review License Servlet traffic and logs for forged license responses, check for unexpected processes or new accounts, and look for signs of lateral movement. Until patched, restrict or remove internet exposure of GoAnywhere MFT admin and license interfaces. | 9.8 | 100% | KEV ransomware |
| moderatelow thousands of internet-exposed GoAnywhere MFT instances (estimate) | |
| CVE-2025-11371 | Unauthenticated Local File Inclusion in Gladinet CentreStack and Triofox Gladinet CentreStack and Triofox, in their default installation and configuration, contain an unauthenticated local file inclusion flaw (CWE-552) that allows unintended disclosure of system files to remote attackers. The flaw requires no privileges or user interaction (CVSS 3.1: AV:N/PR:N/UI:N, 7.5 High), so any internet-facing deployment is directly reachable over the network. An attacker gains access to system files that should not be externally readable, and related reporting indicates active attacks have chained the flaw — including with Gladinet's hardcoded keys — toward unauthorized access, code execution, and deployment of remote access tools. All versions prior to and including 16.7.10368.56560 of both products are affected. Exploitation has been observed in the wild: the vulnerability was added to CISA's KEV on 2025-11-04 and carries a 92.1% EPSS probability of exploitation within 30 days. Do: Upgrade CentreStack and Triofox to a release newer than 16.7.10368.56560, and apply vendor mitigations per CISA BOD 22-01 requirements (federal agencies must mitigate or discontinue use of affected versions). Until patched, restrict internet exposure of the service and review logs for suspicious unauthenticated requests, unexpected file reads, new accounts, or signs of follow-on compromise such as remote-access tool installation. The Huntress write-up referenced in this record provides exploitation context for detection guidance; no exploit code is required to confirm patch status. | 7.5 | 92% | KEV PoC |
| moderate≈ thousands (10^3–10^4) of internet-facing CentreStack/Triofox server deployments; exact counts unknown | |
| CVE-2025-11462 | Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated privileges. Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated privileges. Insufficient validation checks on the log destination directory during log rotation could allow a non-administrator user to create a symlink from a client log file to a privileged location. On log rotation, this could lead to code execution with root privileges if the user made crafted API calls which injected arbitrary code into the log file. We recommend users upgrade to AWS VPN Client for macOS 5.2.1 or the latest version. NVD description · AI analysis pending | 9.3 | <1% | — | — | ||
| CVE-2025-27237 | In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification a In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL. NVD description · AI analysis pending | 7.3 | <1% | — | — | ||
| CVE-2025-36604 | Unauthenticated OS Command Injection in Dell Unity 5.5 and Prior Dell Unity versions 5.5 and prior contain an OS command injection flaw (CWE-78) in which special elements passed to an operating system command are not properly neutralized by the Unity operating environment. An unauthenticated, remote attacker can trigger the flaw by sending crafted input containing shell metacharacters, causing arbitrary commands to execute on the affected system. Successful exploitation gives the attacker command execution with high impact to confidentiality, integrity, and availability, reflected in the critical 9.8 CVSS score. Any organization running a Dell Unity array on version 5.5 or earlier is affected, with practical risk concentrated on arrays whose management interfaces are reachable from untrusted networks. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 63.9% EPSS score (99th percentile) signals a high predicted likelihood of exploitation within 30 days. Do: Upgrade affected Unity systems to the fixed release identified in Dell's security advisory for CVE-2025-36604. Until patched, restrict network access to Unity management services to trusted management networks and eliminate any direct internet exposure of the array. Inventory your environment for Unity arrays running version 5.5 or earlier and prioritize internet-facing systems given the high EPSS score. | 9.8 | 64% |
| large≈10,000–100,000 deployed Unity arrays (version 5.5 and prior spans essentially the entire installed base of this midrange storage line) | ||
| CVE-2025-37728 | Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access. NVD description · AI analysis pending | 5.4 | <1% | — | — | ||
| CVE-2025-42701 | A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary fil A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (LTV) sensors. There is no indication of exploitation of these issues in the wild. Our threat hunting and intelligence team are actively monitoring for exploitation and we maintain visibility into any such attempts. The Falcon sensor for Mac, the Falcon sensor for Linux and the Falcon sensor for Legacy Systems are not impacted by this. CrowdStrike was made aware of this issue through our HackerOne bug bounty program. It was discovered by Cong Cheng and responsibly disclosed. NVD description · AI analysis pending | 5.6 | <1% | — | — | ||
| CVE-2025-42706 | A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (LTV) sensors. There is no indication of exploitation of these issues in the wild. Our threat hunting and intelligence teams are actively monitoring for exploitation and we maintain visibility into any such attempts. The Falcon sensor for Mac, the Falcon sensor for Linux and the Falcon sensor for Legacy Systems are not impacted by this. CrowdStrike was made aware of this issue through our HackerOne bug bounty program. It was discovered by Cong Cheng and responsibly disclosed. NVD description · AI analysis pending | 6.5 | <1% | — | — | ||
| CVE-2025-49844 | Use-After-Free (RediShell) RCE in Redis Lua Scripting CVE-2025-49844, dubbed "RediShell," is a use-after-free (CWE-416) in Redis's embedded Lua scripting engine that per vendor and press coverage has existed for roughly 13 years in all Redis versions with Lua scripting enabled. An authenticated user triggers it by submitting a specially crafted Lua script (via EVAL/EVALSHA) that manipulates the garbage collector and causes a use-after-free condition. Successful exploitation can lead to remote code execution in the context of the redis-server process; the CVSS 3.1 score of 9.9 (critical) reflects network reachability, low required privileges, and changed scope. Redis versions up to and including 8.2.1 are affected, with 8.2.2 containing the fix, and the CPE data also lists the Valkey fork as affected. No confirmed in-the-wild exploitation is reported (not in CISA KEV), but a public proof-of-concept exists and EPSS assigns an 82.3% probability of exploitation within 30 days (100th percentile). Do: Upgrade redis-server to version 8.2.2 or later; for Valkey, apply the vendor's corresponding Lua fix when available. If patching is not immediately possible, restrict the EVAL and EVALSHA commands using Redis ACLs so users cannot execute Lua scripts, and verify that any internet-exposed instances require authentication. Review logs for unexpected or anomalous EVAL/EVALSHA usage from authenticated clients. | 9.9 | 82% | PoC |
| large≈60,000+ internet-exposed Redis servers; total Redis/Valkey deployments including private and cloud-hosted instances are likely in the millions | |
| CVE-2025-53967 | Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl command. The vulnerable endpoint fails to properly sanitize user-supplied input, enabling the attacker to inject malicious commands that are executed with the privileges of the MCP process. Exploitation requires network access to the MCP interface. NVD description · AI analysis pending | 8.0 | 6% | — | — | ||
| CVE-2025-56383 | Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users. NVD description · AI analysis pending | 8.4 | <1% | — | — | ||
| CVE-2025-5947 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the service_finder_switch_back() function. This makes it possible for unauthenticated attackers to login as any user including admins. NVD description · AI analysis pending | 9.8 | 4% |
| — | ||
| CVE-2025-59489 | Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended lo Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications. NVD description · AI analysis pending | 7.4 | <1% | PoC |
| — | |
| CVE-2025-61882 | Unauthenticated Takeover of Oracle E-Business Suite Concurrent Processing CVE-2025-61882 is a critical (CVSS 9.8) authentication flaw (CWE-287) in the BI Publisher Integration component of the Oracle Concurrent Processing product within Oracle E-Business Suite. An unauthenticated attacker with network access over HTTP can exploit it remotely with no credentials and no user interaction, achieving a takeover of Oracle Concurrent Processing with high confidentiality, integrity, and availability impact. Any organization running Oracle E-Business Suite 12.2.3 through 12.2.14 is affected, especially instances reachable from the internet. The flaw is being actively exploited in the wild: the Cl0p data-theft group has used it to breach dozens of organizations (including Harvard University, with 1.3 TB of data leaked), CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06 with known ransomware use, and EPSS puts its 30-day exploitation probability at 99.7%. Do: Apply Oracle's released patch or mitigations for CVE-2025-61882 to affected E-Business Suite 12.2.3-12.2.14 deployments as instructed by the vendor; per CISA KEV requirements, federal agencies must follow BOD 22-01 guidance or discontinue use if mitigations are unavailable. Until patched, limit internet exposure of EBS and its BI Publisher/Concurrent Processing HTTP endpoints, and review web and application logs for unauthenticated access and signs of Cl0p-style data theft or follow-on ransomware. | 9.8 | 100% | KEV ransomware |
| largetens of thousands of EBS environments worldwide across an estimated ~5,000+ customer organizations (est.) | |
| CVE-2025-61884 | Unauthenticated SSRF in Oracle E-Business Suite Configurator Oracle Configurator, a component of Oracle E-Business Suite, is affected by a server-side request forgery (SSRF) flaw in its Runtime UI component (CVE-2025-61884). The flaw is easily exploitable: an unauthenticated attacker with network access over HTTP can trigger the server to make attacker-controlled requests, compromising Oracle Configurator and gaining unauthorized access to critical data or complete access to all data accessible to Oracle Configurator. The CVSS 3.1 score is 7.5 (high) with confidentiality-only impact, meaning the flaw primarily exposes sensitive data rather than altering or destroying it. All supported Oracle E-Business Suite 12.2.x releases from 12.2.3 through 12.2.14 are affected, and Oracle has issued an emergency security update in response. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-20 with known ransomware use, and EPSS assigns a 97.8% probability of exploitation in the next 30 days (100th percentile). Do: Apply the fixes from Oracle's emergency security update for CVE-2025-61884 across all E-Business Suite 12.2.3-12.2.14 environments, prioritizing internet-exposed instances; U.S. federal agencies must remediate per BOD 22-01 or follow applicable cloud-service guidance by the KEV due date. Until patched, restrict untrusted network access to the Configurator Runtime UI (HTTP) and monitor EBS logs and outbound server-side requests for signs of exploitation. Given the confirmed ransomware association, hunt for follow-on activity such as unusual data access or lateral movement originating from EBS servers. | 7.5 | 96% | KEV ransomware PoC |
| largetens of thousands of enterprise deployments overall; several thousand Oracle E-Business Suite instances exposed to the internet |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | breachforums.hn | S. Federal Bureau of Investigation (FBI) seized a website ("breachforums[.]hn") that was being used by Scattered LAPSUS$ Hunters to ext |
Full article3,001 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 13, 2025Cybersecurity / Hacking News
Every week, the cyber world reminds us that silence doesn’t mean safety. Attacks often begin quietly — one unpatched flaw, one overlooked credential, one backup left unencrypted. By the time alarms sound, the damage is done.
This week’s edition looks at how attackers are changing the game — linking different flaws, working together across borders, and even turning trusted tools into weapons. From major software bugs to AI abuse and new phishing tricks, each story shows how fast the threat landscape is shifting and why security needs to move just as quickly.
⚡ Threat of the Week
Dozens of Orgs Impacted by Exploitation of Oracle EBS Flaw — Dozens of organizations may have been impacted following the zero-day exploitation of a security flaw in Oracle's E-Business Suite (EBS) software since August 9, 2025, according to Google Threat Intelligence Group (GTIG) and Mandiant. The activity, which bears some hallmarks associated with the Cl0p ransomware crew, is assessed to have fashioned together multiple distinct vulnerabilities, including a zero-day flaw tracked as CVE-2025-61882 (CVSS score: 9.8), to breach target networks and exfiltrate sensitive data. The attack chains have been found to trigger two different payload chains, dropping malware families like GOLDVEIN.JAVA, SAGEGIFT, SAGELEAF, and SAGEWAVE. Oracle has also released updates to EBS to address another vulnerability in the same product (CVE-2025-61884) that could lead to unauthorized access to sensitive data. The company did not mention if it was being exploited in the wild.
🔔 Top News
- Storm-1175 Linked to Exploitation of GoAnywhere MFT Flaw — A cybercriminal group Microsoft tracks as Storm-1175 exploited a maximum-severity vulnerability in GoAnywhere MFT (CVE-2025-10035) to initiate multi-stage attacks, including Medusa ransomware. Storm-1175's attacks are opportunistic, and have affected organizations in the transportation, education, retail, insurance, and manufacturing sectors. The activity blends legitimate tools with stealthy techniques to stay under the radar and monetize access through extortion and data theft, using the access to install remote monitoring tools such as SimpleHelp and MeshAgent, drop web shells, and move laterally across networks using built-in Windows utilities. Fortra has since disclosed that it began its investigation on September 11 following a "potential vulnerability" reported by a customer, uncovering "potentially suspicious activity" related to the flaw.
- OpenAI Disrupted Three Clusters from China, North Korea, and Russia — OpenAI said it disrupted three activity clusters for misusing its ChatGPT artificial intelligence (AI) tool to facilitate malware development. This includes a Russian‑language threat actor, who is said to have used the chatbot to help develop and refine a remote access trojan (RAT), a credential stealer with an aim to evade detection. The second cluster of activity originated from North Korea, which used ChatGPT for malware and command-and-control (C2) development, focusing on developing macOS Finder extensions, configuring Windows Server VPNs, or converting Chrome extensions to their Safari equivalents. The third set of banned accounts shared overlaps with a cluster tracked as UNK_DropPitch (aka UTA0388), a Chinese hacking group which employed the AI chatbot to generate content for phishing campaigns in English, Chinese, and Japanese; assist with tooling to accelerate routine tasks such as remote execution and traffic protection using HTTPS; and search for information related to installing open-source tools like nuclei and fscan.
- Over 175 npm Packages Used for Phishing Campaign — In an unusual twist, threat actors have been observed to push throwaway npm packages that, once installed, are designed to create and publish an npm package of its own with the pattern "redirect-xxxxxx" or "mad-xxxxxx," which, in turn, auto-redirects victims to credential-harvesting sites when opened from crafted HTML business documents. "Unlike the more familiar tactic of simply uploading malicious packages to compromise developers during package installation, this campaign takes a different path," Snyk said. "Instead of infecting users via npm install, the attackers leverage the browser delivery path through UNPKG, turning legitimate open source hosting infrastructure into a phishing mechanism." It's believed that the HTML files generated through the npm packages are distributed to victims, who are then redirected to the credential phishing sites when they attempt to open them. In the packages analyzed by Snyk, the pages masquerade as Cloudflare security checks before leading victims to an attacker-controlled URL fetched from a remote GitHub-hosted file.
- LockBit, Qilin, and DragonForce Join Forces — Three of the most notorious ransomware-as-a-service operations, LockBit, Qilin, and DragonForce, have formed a criminal cartel aimed at coordinating attacks and sharing resources. The partnership was announced early last month, shortly following the emergence of LockBit 5.0. "Create equal competition conditions, no conflicts and no public insults," DragonForce wrote in a post on a dark web forum. "This way, we can all increase our income and dictate market conditions. Call it whatever you like – coalition, cartel, etc. The main thing is to stay in touch, be friendly to each other, and be strong allies, not enemies." The teaming up of the three groups comes amid mounting pressure from law enforcement disruptions, prompting them to attack sectors previously considered off-limits, such as nuclear power plants, thermal power plants, and hydroelectric power plants. It also follows a similar consolidation pattern among primarily English-speaking cybercrime collectives like Scattered Spider, ShinyHunters, and LAPSUS$, which began collaborating under the name Scattered LAPSUS$ Hunters. That said, the cartelization of ransomware also comes at a time of record fragmentation in the broader ecosystem, with the number of active data leak sites reaching an all-time high of 81 in the third quarter of 2025.
- China-Nexus Hackers Weaponize Open-Source Nezha Tool in Attacks — Threat actors with suspected ties to China have turned a legitimate open-source monitoring tool called Nezha into an attack weapon, using it to deliver a known malware called Gh0st RAT to targets. The campaign is said to have likely compromised more than 100 victim machines since August 2025, with a majority of the infections reported in Taiwan, Japan, South Korea, and Hong Kong. The activity is yet another indication of how threat actors continue to twist legitimate tools for malicious purposes and blend in with normal network traffic. In one instance observed by Huntress, the attackers targeted an exposed phpMyAdmin panel to deploy a web shell by means of a log poisoning attack. The access obtained through the web shell was then used to drop Nezha and ultimately drop Gh0st RAT, but not before laying the necessary groundwork to avoid detection.
️🔥 Trending CVEs
Hackers move fast. They often exploit new vulnerabilities within hours, turning a single missed patch into a major breach. One unpatched CVE can be all it takes for a full compromise. Below are this week’s most critical vulnerabilities gaining attention across the industry. Review them, prioritize your fixes, and close the gap before attackers take advantage.
This week’s list includes — CVE-2025-61884 (Oracle E-Business Suite), CVE-2025-11371 (Gladinet CentreStack and TrioFox), CVE-2025-5947 (Service Finder theme), CVE-2025-53967 (Framelink Figma MCP server), CVE-2025-49844 (Redis), CVE-2025-27237 (Zabbix Agent), CVE-2025-59489 (Unity for Android and Windows), CVE-2025-36604 (Dell UnityVSA), CVE-2025-37728 (Elastic Kibana Connector), CVE-2025-56383 (Notepad++), CVE-2025-11462 (AWS Client VPN for macOS), CVE-2025-42701, CVE-2025-42706 (CrowdStrike Falcon), CVE-2025-11001, CVE-2025-11002 (7-Zip), CVE-2025-59978 (Juniper Networks Junos Space), CVE-2025-11188, CVE-2025-11189, CVE-2025-11190 (SynchroWeb Kiwire Captive Portal), CVE-2025-3600 (Progress Telerik UI for ASP.NET AJAX), a cross-site scripting (XSS) vulnerability in REDCap, and unpatched security vulnerabilities in Ivanti Endpoint Manager (from ZDI-25-935 through ZDI-25-947).
📰 Around the Cyber World
- TwoNet Targets Forescout Honeypot — An ICS/OT honeypot run by Forescout, designed to mimic a water treatment facility, was targeted last month by a Russia-linked group named TwoNet. The financially motivated hacktivist group subsequently attempted to deface the associated human machine interface (HMI), disrupt processes, and manipulate other ICS. Forescout's honeypots also saw attack attempts that have been linked to Russia and Iran. TwoNet first emerged in January, primarily focused on DDoS attacks using the MegaMedusa Machine malware, per Intel471. Through an affiliated group, CyberTroops, TwoNet announced it was ceasing operations on September 30, 2025. "This underscores the ephemeral nature of the ecosystem where channels and groups are short-lived, while operators typically persist by rebranding, shifting alliances, joining other groups, learning new techniques, or targeting other organizations," Forescout said. "Groups moving from DDoS/defacement to OT/ICS often misread targets, trip over honeypots, or overclaim. That doesn’t make them harmless; it shows where they are headed."
- Sophos Probes WhatsApp Worm's Links to Coyote — A recently disclosed campaign dubbed Water Saci involved the threat actors using self-propagating malware dubbed SORVEPOTEL that spreads via the popular messaging app WhatsApp. Sophos said it's investigating to determine if the activity could be related to prior reported campaigns that distributed a banking trojan named Coyote targeting users in Brazil, and if the malware used in the attacks, Maverick, is an evolution of Coyote. The WhatsApp messages contain a zipped LNK file that, when launched, initiates a series of malicious PowerShell commands to drop next-stage PowerShell, which then attempts to modify local security controls. In some cases, Sophos said it observed an additional payload, the legitimate Selenium browser automation tool, that enabled control of running browser sessions on the infected host. It's suspected that Selenium is delivered alongside Maverick via the same command-and-control (C2) infrastructure.
- North Korean IT Workers Seek Jobs in New Sectors — The infamous North Korean IT workers are now seeking remote jobs in the industrial design and architecture fields, according to security company KELA. "Their involvement could pose risks related to espionage, sanctions evasion, safety concerns, and access to sensitive infrastructure designs," it said, describing the threat as a "a highly organized, state-backed network that extends far beyond IT roles." One of IT workers, Hailong Jin, has been identified as connected to the development of a malicious game called DeTankZone, while also sharing ties with another IT worker named Lian Hung, who has claimed to be a mobile app developer in Tanzania. It's believed that Hailong Jin and Lian Hung may be the same person, the Chollima Group said, adding Bells Inter Trading Limited is a North Korean run front company employing IT Workers in Tanzania. The company, for its part, has been linked to several VPN apps published on both Apple and Google's iOS and Android app stores. "Rather than viewing them as a monolithic entity, North Korean IT Workers are more akin to individual entrepreneurs operating under the blessing of a higher-status boss," the Chollima Group noted. "As an IT Worker gains more status and respect, they are able to climb the organization's ranks and eventually become bosses themselves. From there they may form their own front companies and gain the status necessary to take on more malicious activity (if they so choose). We believe Lian Hung and Hailong Jin, both appearing to be in their 30s-40s, may be operating as middle managers or hold higher statuses in this structure, which may explain their titles of choice being 'Project Manager.'"
- FBI Seizes Site Used by Salesforce Extortionists — The U.S. Federal Bureau of Investigation (FBI) seized a website ("breachforums[.]hn") that was being used by Scattered LAPSUS$ Hunters to extort Salesforce and its customers. The action marks another chapter in the ongoing cat-and-mouse game to dismantle the persistent data leak site. That said, the dark web version of the leak site is still up and running. "BreachForums was seized by the FBI and international partners today. All our domains were taken from us by the U.S. Government. The era of forums is over," the Scattered Lapsus$ Hunters group said in a PGP-encrypted statement on Telegram. While the groups initially claimed they were shutting down their operations, the website resurfaced merely a few days later, transitioning from a hacking forum to a dedicated extortion site. The group also admitted that the BreachForums servers and backups were destroyed, and that database archives and escrow data from as far back as 2023 were compromised. Scattered LAPSUS$ Hunters (aka the Trinity of Chaos) is a newly formed alliance comprising Scattered Spider (aka Muddled Libra), LAPSUS$, and ShinyHunters (aka Bling Libra). In recent weeks, the threat actors breached Salesloft's systems and used the access to obtain customers' Salesforce data. Last month, Salesloft revealed that the data breach linked to its Drift application started with the compromise of its GitHub account. BreachForums has a long and turbulent history, punctuated by numerous takedowns and resurrections since its original administrator was arrested in March 2023.
- NSO Group Acquired by U.S. Investment Group — Israeli spyware maker NSO Group has disclosed that a U.S. investment group has acquired the controversial company. A company's spokesperson told TechCrunch that "an American investment group has invested tens of millions of dollars in the company and has acquired controlling ownership.”
- Apple Revises its Bug Bounty Program — Apple announced significant updates to its bug bounty program, with the company now offering up to $2 million for exploit chains that can achieve similar goals as sophisticated mercenary spyware attacks. It's also rewarding one-click WebKit sandbox escapes with up to $300,000, and up to $1 million for wireless proximity exploits over any radio, broad unauthorized iCloud access, and WebKit exploit chains leading to unsigned arbitrary code execution. "Since we launched the public Apple Security Bounty program in 2020, we're proud to have awarded over $35 million to more than 800 security researchers, with multiple individual reports earning $500,000 rewards," the company said. The new payouts will go into effect in November 2025.
- Spanish Guardia Civil Disrupts GXC Team — Spanish authorities dismantled the GXC Team and arrested its alleged mastermind, a 25-year-old Brazilian national who went online as GoogleXcoder. According to Group-IB, GXC Team operated a crime-as-a-service (CaaS) platform offering AI-powered phishing kits, Android malware, and voice scam tools via Telegram and a Russian-speaking hacker forum to cybercriminals targeting banks, transportation, and e-commerce, in Spain, Slovakia, the UK, US, and Brazil."To avoid capture, the suspect adopted a 'digital nomad' lifestyle, frequently relocating between Spanish provinces and using stolen identities to secure housing, phone lines, and payment cards," Group-IB said.
- Inside Russian Market — Rapid7 said Russian Market has evolved its operations over time, pivoting from selling RDP access to stolen credit card data and, more recently, infostealer logs. "Stolen credentials originate from organizations worldwide, with 26% originating in the US and 23% in Argentina," the company said. "Most sellers have adopted a multi-stealer approach over the years, leveraging various malware variants in their operations, with Lumma emerging as a widely used tool. The most common types of infostealers being used by sellers in Russian Market over the years have been Raccoon, Vidar, Lumma, RedLine, and Stealc, with Rhadamanthys and Acreed gaining popularity in the first half of 2025." The findings came as Red Canary revealed that Atomic, Poseidon, and Odyssey have emerged as the three prominent stealer families targeting Apple macOS systems, while also sharing many tactical similarities. Odyssey Stealer is a successor to Poseidon that was first detected in March 2025.
- Austria Says Microsoft Violated E.U. Laws — Austria's privacy regulator found that Microsoft violated E.U. law by illegally tracking students through Microsoft 365 Education using tracking cookies without their consent. The decision was reached following noyb's complaint in 2024. The Austrian Data Protection Authority (DSB) has ordered the deletion of the relevant personal data. "The decision by the Austrian DPA really highlights the lack of transparency with Microsoft 365 Education," noyb said. "It is almost impossible for schools to inform students, parents and teachers about what is happening with their data."
- AI Models Can Acquire Backdoors from About 250 Malicious Documents — A new academic study from Anthropic, the U.K. AISI's Safeguards team, and The Alan Turing Institute has found that it takes approximately 250 malicious documents to establish a simple "backdoor" in large language models. The research challenges the idea that attackers need to control or poison a large portion of the training data in order to influence an LLM's output. "Poisoning attacks require a near-constant number of documents regardless of model and training data size," it said. "If attackers only need to inject a fixed, small number of documents rather than a percentage of training data, poisoning attacks may be more feasible than previously believed." A 2024 study by researchers at Carnegie Mellon University, ETH Zürich, Meta, and Google DeepMind showed that attackers controlling 0.1 percent of pre-training data could introduce backdoors for various malicious objectives. "Our results suggest that injecting backdoors through data poisoning may be easier for large models than previously believed as the number of poisons required does not scale up with model size," the researchers said, "highlighting the need for more research on defences to mitigate this risk in future models." The disclosure coincided with OpenAI's stating that its GPT-5 model exhibits lower levels of political bias than any previous models.
🎥 Cybersecurity Webinars
- Drowning in Vulnerability Alerts? Here’s How to Finally Regain Control - Most security teams face the same problem — too many vulnerabilities and not enough time. Dynamic Attack Surface Reduction (DASR) helps fix this by finding and closing risks automatically, before attackers can use them. Instead of chasing endless alerts, teams can focus on what really matters: keeping systems safe and running smoothly. It’s a smarter, faster way to stay one step ahead.
- How Leading Teams Are Using AI to Simplify Compliance and Reduce Risk - AI is changing how organizations handle Governance, Risk, and Compliance (GRC). It can make compliance faster and smarter—but it also brings new risks and rules to follow. This session will show you how to use AI safely and effectively, with real examples, lessons from early adopters, and practical tips to prepare your team for the future of compliance.
- From Firefighting to Secure-by-Design: A Practical Playbook - AI is changing fast, but security can’t lag behind. The smartest teams now treat security controls as launchpads, not roadblocks — enabling AI agents to move quickly and safely. By shifting from reactive firefighting to a secure-by-design mindset, organizations gain both speed and confidence. With the right framework, you can control AI risks while accelerating innovation instead of slowing it down.
🔧 Cybersecurity Tools
- P0LR Espresso - A new open-source tool from Permiso that helps security teams quickly analyze multi-cloud logs during live response. It normalizes data from platforms like AWS, Azure, and GCP to deliver clear timelines, behavioral insights, and IOC analysis—making it easier to spot compromised identities and understand what really happened.
- Ouroboros - A new open-source decompiler built in Rust that uses symbolic execution to recover high-level code structure from compiled binaries. Unlike traditional decompilers that rely on static assignment models, Ouroboros tracks constraints and data flow to understand how registers and memory change during execution. This approach helps it reconstruct logical code patterns such as loops, conditions, and control flow regions, making it a practical tool for reverse engineering, program analysis, and security research.
Disclaimer: These tools are for educational and research use only. They haven’t been fully security-tested and could pose risks if used incorrectly. Review the code before trying them, test only in safe environments, and follow all ethical, legal, and organizational rules.
🔒 Tip of the Week
Don’t Leave Your Backups Unlocked — Backups are your safety net — but if they’re not encrypted, they can become your biggest risk. Anyone who gets access to an unencrypted backup can read everything inside: passwords, emails, financial data, customer info — all of it.
The Simple Fix: Always encrypt your backups before saving or sending them anywhere (USB, cloud, or server). Encryption locks your data so only you can open it.
🔐 Easy, Trusted Open-Source Tools:
- Restic: Fast, simple, and encrypts everything automatically. Works with many cloud services.
- BorgBackup: Compresses, deduplicates, and encrypts your backups — perfect for long-term storage.
- Duplicity: Uses GPG encryption and supports encrypted backups to local or remote storage.
- rclone: Syncs files securely to cloud storage with built-in encryption options.
Pro Tip: Test your backup regularly — make sure you can decrypt and restore it. A locked or broken backup is as bad as no backup at all.
Conclusion
The week’s stories show both sides of cybersecurity — the creativity of attackers and the resilience of defenders. Our strength lies in awareness, collaboration, and action. Let’s use every lesson learned to make next week’s news a little less alarming.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/10/weekly-recap-whatsapp-worm-critical.html