Qualys researchers disclosed nine vulnerabilities in the Linux kernel’s AppArmor module that allow unprivileged users to bypass security policies, escalate to root, and weaken container isolation. The bugs have existed since 2017, putting many Linux distributions and containerized workloads at risk. Admins should track vendor advisories, prioritize kernel updates, and review LSM and container hardening to detect and mitigate potential exploitation.
Source: Security Affairs
Google rushes emergency Chrome fix for two actively exploited zero‑days
Google shipped an urgent Chrome update after confirming attackers are exploiting two zero-day vulnerabilities in the wild. Organizations should expedite updates across desktop and mobile fleets and enforce relaunch to apply patches, given Chrome’s ubiquity and attackers’ fast weaponization cycles.
Source: Forbes
SEO poisoning drives fake VPN downloads; Microsoft flags Storm‑2561 credential theft
Microsoft warns that threat actor Storm-2561 is hijacking search results to push bogus VPN installers that steal credentials. The campaign uses SEO poisoning to lure users to convincing download pages, highlighting the need to verify software sources and enforce application allowlisting and web filtering.
Source: CyberNews
AI‑assisted phishing abuses browser permissions to harvest photos, audio, location
Cyble reports a widespread campaign hosted on edgeone.app that tricks users into granting camera, microphone, and contacts access under “verification” pretexts, then exfiltrates multimedia and device telemetry via the Telegram Bot API. Indicators suggest generative AI helped build the kit, and stolen data could fuel deepfakes, account recovery fraud, and extortion. Limit hardware permissions, monitor browser-origin traffic to api.telegram.org, and train users to treat permission prompts as high risk.
Source: Cyble
TLS certificates head toward much shorter lifespans—are ops ready?
Industry momentum, spurred by moves from Google and Apple, is driving TLS certificate validity down sharply, with CA/Browser Forum timelines moving from one year to 200 days and eventually 100. Many enterprises lack the automation to rotate certs reliably at this cadence, risking outages and compliance gaps. Now is the time to inventory certificates, adopt ACME-based automation, and implement continuous expiry monitoring.
Source: Help Net Security
Telus outsourcer breach may have spilled a petabyte to ShinyHunters
Canadian services provider Telus Digital confirmed a cyberattack amid claims by ShinyHunters that up to a petabyte of data was stolen. While the scope remains under investigation, the potential scale underscores third‑party risk, the need for rapid credential rotation, and aggressive log review and containment across connected environments.
Source: The Register
Hack attempt hits Poland’s nuclear research center; possible Iran link or false flag
Polish authorities disclosed an intrusion attempt against the National Centre for Nuclear Research, with preliminary indicators pointing to Iran—while cautioning it could be a false flag. The incident highlights the persistent targeting of critical infrastructure and the importance of strong OT/IT segmentation, rigorous monitoring, and geo‑politically informed threat hunting.
Source: SecurityWeek
You May Also Be Interested In...
45,000 malicious IPs taken down, 94 suspects arrested in INTERPOL’s Synergia IIIAndroid 17 to block non‑accessibility apps from Accessibility API under Advanced Protection
VulHunt: Open‑source framework for detecting vulnerabilities in binaries and firmware