Security Affairs newsletter Round 544 by Pierluigi Paganini – INTERNATIONAL EDITION


Security Affairs newsletter Round 544 by Pierluigi Paganini – INTERNATIONAL EDITION

Pierluigi Paganini
October 05, 2025

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

GreyNoise detects 500% surge in scans targeting Palo Alto Networks portals
U.S. CISA adds Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities catalog
ShinyHunters Launches Data Leak Site: Trinity of Chaos Announces New Ransomware Victims
ProSpy, ToSpy malware pose as Signal and ToTok to steal data in UAE
Google warns of Cl0p extortion campaign against Oracle E-Business users
CERT-UA warns UAC-0245 targets Ukraine with CABINETRAT backdoor
Allianz Life data breach impacted 1.5 Million people
Cybercrime group claims to have breached Red Hat ‘s private GitHub repositories
China-linked APT Phantom Taurus uses Net-Star malware in espionage campaigns against key sectors
OpenSSL patches 3 vulnerabilities, urging immediate updates
Apple urges users to update iPhone and Mac to patch font bug
WestJet confirms cyberattack exposed IDs, passports in June incident
Broadcom patches VMware Zero-Day actively exploited by UNC5174
UK convicts Chinese national in £5.5B crypto fraud, marks world’s largest Bitcoin seizure
U.S. CISA adds Adminer, Cisco IOS, Fortra GoAnywhere MFT, Libraesva ESG, and Sudo flaws to its Known Exploited Vulnerabilities catalog
Asahi halts ordering, shipping, and customer service after cyberattack
Scattered Spider, ShinyHunters Restructure – New Attacks Underway 
UK grants £1.5B loan to Jaguar Land Rover after cyberattack
Harrods alerts customers to new data breach linked to third-party provider
Akira Ransomware bypasses MFA on SonicWall VPNs
Despite Russian influence, Moldova votes Pro-EU, highlighting future election risks
Dutch teens arrested for spying on behalf of pro-Russian hackers
Cyberattack on Co-op leaves shelves empty, data stolen, and $275M in lost revenue

International Press – Newsletter

Cybercrime

Smash and Grab: Aggressive Akira Campaign Targets SonicWall VPNs, Deploys Ransomware in an Hour or Less

Woman convicted following world’s largest crypto seizure 

The Kids Aren’t Alright

Trinity of Chaos: The LAPSUS$, ShinyHunters, and Scattered Spider Alliance Embarks on Global Cybercrime Spree  

‘You’ll never need to work again’: Criminals offer reporter money to hack BBC  

Red Hat confirms security incident after hackers claim GitHub breach 

Researchers Say They Flagged Cyber Flaws at Jaguar Ahead of Crippling Breach  

Oracle Apps Exploited by Hackers in New Extortion Campaign 

Silent Smishing : The Hidden Abuse of Cellular Router APIs  

Malware

First Malicious MCP in the Wild: The Postmark Backdoor That’s Stealing Your Emails  

Klopatra: exposing a new Android banking trojan operation with roots in Turkey  

Check Your Socks – A Deep Dive into soopsocks PyPI Package  

New spyware campaigns target privacy-conscious Android users in the UAE  

Rhadamanthys 0.9.x – walk through the updates

Hacking

AppSuite, OneStart & ManualFinder: The Nexus of Deception 

Apple fixes critical font processing bug. Update now! 

Why hackers are targeting the world’s shipping  

HackerOne Report Finds 210% Spike in AI Vulnerability Reports Amid Rise of AI Autonomy  

Palo Alto Scanning Surges ~500% in 48 Hours, Marking 90-Day High  

WireTap: Breaking Server SGX via DRAM Bus Interposition

Battering RAM Low-Cost Interposer Attacks on Confidential Computing

OneLogin, Many Secrets: Clutch Uncovers Critical API Vulnerability Exposing Client Credentials        

Intelligence and Information Warfare

Two Dutch teens arrested in rare Russian espionage case  

Pro-EU party in Moldova set to win vote mired in claims of Russian interference 

You name it, VMware elevates it (CVE-2025-41244)  

Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite

SVG Phishing hits Ukraine with Amatera Stealer, PureMiner

CABINETRAT backdoor used by UAC-0245 for targeted cyberattacks against SOU (CERT-UA#17479)  

Cavalry Werewolf raids Russia’s public sector with trusted relationship attacks

Confucius Espionage: From Stealer to Backdoor  

Cybersecurity

Harrods warns customers their data may have been stolen in IT breach  

Government backs Jaguar Land Rover with £1.5 billion loan guarantee  

WestJet confirms recent breach exposed customers’ passports

AI Agents Are Eroding the Foundations of Cybersecurity    

Feds cut funding to program that shared cyber threat info with local governments  

California enacts AI safety law targeting tech giants  

Package Maintainers Call for Improvements to GitHub’s New npm Security Plan 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews



The Roku Sports interface now shows content you can watch on YouTube TV. The new feature, which is rolling out to all Roku devices in the U.S. starting today, will make it easier for fans to find games from YouTube TV, including all the NFL games that come with NFL Sunday Ticket.

Adding YouTube TV pushes Roku’s Sports section pretty far. The section already includes a bunch of other partners like DAZN Live Sports, FOX One, Frndly TV, Spectrum TV, and Xfinity Stream. The whole point is to give sports fans a central hub to find their favorite games, highlights, and scores from all the top leagues.

According to Joe Franzetta, Roku Media’s Head of Sports, the company’s main goal is to make “game time effortless for our users. Partnering with YouTube TV is a major step in delivering a comprehensive fan-centered experience that simplifies sports discovery and puts live action front and center for millions of fans.”

Roku also reported that YouTube TV will be available in other content discovery areas on the platform in the future. This means you’ll be able to find YouTube TV content in other sections that Rokue has, so you don’t miss out on anything important.

YouTube TV is a great app when it comes to live TV, but since the service added the NFL Sunday Ticket, it’s become a massive player in sports broadcasting. It’s also got some pretty sweet features for sports fans, like multiview, which lets you watch up to four games at once. It also has the ability to catch up on key plays, so you don’t have to worry if you’re running a little late. This integration will let YouTube TV subscribers make the most of their subscription by making it easy to find and jump into games.

You can still go straight to the YouTube TV app and look for your sports content there, since nothing will be changing on the app itself. The difference is that now you don’t need to look through the app to find its content, which makes it easier to find what you want since Roku’s sports interface saves a lot of time. I use it during the Super Bowl and on many Sundays. This is easier than trying to keep up with which company owns the right to broadcast the game I want to see.

Roku does offer a lot of content for free, but this does not mean the content shown on YouTube TV will be free. While you only need a Roku TV to get to the sports section, you still need a subscription to watch the content from YouTube TV. You also need the NFL Sunday Ticket for the NFL games included in the pass. It is just like the content shown by other broadcasters that is displayed in the Roku Sports section. So you’ll still need to pay the $85 month-to-month price, unless you took advantage of a promotion.

Source: Roku



Source link