Dutch intelligence agencies warned that Russian state-backed actors are running a global social engineering campaign to seize Signal and WhatsApp accounts used by diplomats, military personnel, government officials, and journalists. Rather than exploiting app flaws, attackers trick victims into revealing verification codes and PINs—often via fake “support” chats—then take over accounts. Officials urge enabling registration locks, treating any unsolicited code request as hostile, and reviewing backup/linked device settings.
Source: Help Net Security
‘InstallFix’ surge: Fake Claude Code install pages spread infostealers via paid search
Attackers are cloning Anthropic’s Claude Code installation pages on lookalike domains and paying to rank them in search results, then swapping legitimate commands for malware that steals credentials and browser sessions. Researchers note the campaign’s evolution from earlier ClickFix techniques, with delivery targeting both Windows and macOS. Security teams should block newly registered lookalike domains, monitor for suspicious Terminal/PowerShell paste activity, and validate install guides only from official vendor domains.
Source: Help Net Security
CISA adds SolarWinds, Ivanti, Workspace One flaws to KEV; exploitation confirmed
The U.S. CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog, including an SSRF bug in Workspace One UEM (CVE-2021-22054), alongside issues in SolarWinds and Ivanti. Federal agencies must remediate by set deadlines; enterprises should treat these as active priorities for patching, access restriction, and compensating controls. Inventory exposed instances, review logs for suspicious requests, and validate upstream integrations that could amplify SSRF impact.
Source: The Hacker News
Threat actors mass-scan Salesforce Experience Cloud for guest access misconfigurations
Salesforce warns adversaries are using a modified AuraInspector tool to find overly permissive Experience Cloud guest configurations, enabling access to sensitive records. The activity underscores the risk of “secure-by-default” assumptions in SaaS: review guest user sharing rules, tighten object/field-level permissions, and enable IP restrictions and auditing on public sites.
Source: The Hacker News
New White House cyber strategy vows to “impose costs” while easing regulatory friction
The administration’s national cyber strategy pledges more offensive operations against criminal networks and hostile governments while streamlining overlapping cyber regulations. The framework emphasizes coordinated action across government, industry, and allies—signaling more joint takedowns and pressure campaigns paired with incentives for critical infrastructure resilience.
Source: The Record
AirSnitch Wi‑Fi attack enables full MitM by abusing cross‑layer identity desynchronization
New research details “AirSnitch,” which exploits Layer 1/2 Wi‑Fi design behaviors and identity desynchronization across SSIDs to pull off bidirectional machine‑in‑the‑middle attacks—even across separate SSIDs or segments on the same AP. The technique threatens home and enterprise networks alike; defenders should enforce client isolation where possible, segment guest/IoT traffic, and validate end‑to‑end TLS with certificate pinning for sensitive apps.
Source: Schneier on Security
Global crackdown disrupts ‘Tycoon 2FA’ phishing-as-a-service that targeted 500k+ orgs
A joint effort led by Microsoft, Europol, and partners disrupted infrastructure behind the Tycoon 2FA PhaaS platform, which blasted tens of millions of phishing emails monthly and enabled MFA bypass at scale. While a notable win, copycat kits and residual infrastructure persist—organizations should rotate exposed credentials, enforce phishing‑resistant MFA, and monitor for lookalike lures.
Source: Security Affairs
You May Also Be Interested In...
OpenAI to acquire AI security platform Promptfoo
Cloudflare patches request smuggling flaws in Pingora OSS deployments
Critical NGINX UI vulnerability could expose server backups and keys