A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Seeking Victim Information in Steam Malware Investigation
Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat
INTERPOL report warns of increasingly sophisticated global financial fraud threat
He Built the Definitive Epstein Database—and It Consumed His Life
Malware
New Payload ransomware – malware analysis
AI Coding Tools Under Fire: Mapping the Malvertising Campaigns Targeting the Vibe Coding Ecosystem
RondoDox Botnet: From Zero to 174 Exploited Vulnerabilities
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
Hacking
ChatGPT as a Covert C2 Channel
CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root
Evil evolution: ClickFix and macOS infostealers
ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push
CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root
Attackers Wielding DarkSword Threaten iOS Users
Large-Scale Magento Defacement Campaign Impacts Global Brands and Government Domains
Magento PolyShell: unrestricted file upload in Magento and Adobe Commerce
Intelligence and Information Warfare
Cyberattack against former BND vice president
Spies and subsidies: China joins Brazil’s $20bn delivery app war
DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear
Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia
Russia Turns Vienna Into West’s Biggest Spy Hub – Tracking NATO Communications
Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency
FBI seizes pro-Iranian hacking group’s websites after destructive Stryker hack
Cybersecurity
Android 17 Blocks Non-Accessibility Apps from Accessibility API to Prevent Malware Abuse
Stryker attack wiped tens of thousands of devices, no malware needed
Email blunder exposes $90bn Russian oil smuggling ring
Robotic Surgery Giant Intuitive Discloses Cyberattack
Health plan information for over 2.6 million stolen from third-party admin Navia
Update iOS to protect your iPhone from web attacks
Meta on trial over child safety: can it really protect its next generation of users?
Jaguar Land Rover’s cyber bailout sets worrying precedent, watchdog warns
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)


