Google pushed an urgent Chrome update to fix two zero-day vulnerabilities already exploited in the wild. Security teams should expedite updates across Windows, macOS, and Linux fleets to limit exposure and verify browsers are on the latest Stable channel release.
Source: SCMagazine
“CrackArmor” flaws in Linux AppArmor could lead to root and weakened container isolation
Nine AppArmor vulnerabilities described as “confused deputy” issues allow low-privilege users to coerce trusted programs (e.g., Sudo, Postfix) into dangerous actions, potentially escalating to root. The bugs, present since 2017, could impact millions of Linux systems and degrade container isolation; administrators should track distro kernel advisories and apply patches promptly.
Source: SCMagazine
GlassWorm supply-chain campaign expands via malicious IDE extensions and hijacked repos
The GlassWorm operation has intensified, using dozens of malicious Open VSX extensions and compromising 150+ GitHub repositories to seed developer environments with malware. The campaign underscores mounting risks in the developer toolchain—teams should rotate tokens, audit recent commits and dependencies, and validate extensions and SDKs before use.
Source: SCMagazine
Microsoft warns: SEO-poisoned fake VPN downloads stealing enterprise credentials
Threat actor Storm-2561 is manipulating search results to funnel users to spoofed enterprise VPN sites, delivering trojans and harvesting logins. Organizations should restrict software downloads to official vendor channels, verify code signatures, and monitor for VPN login anomalies and new device enrollments.
Source: SecurityWeek
Meta to drop end-to-end encryption for Instagram DMs in May
Instagram will discontinue optional end-to-end encrypted messaging after May 8, citing low usage and advising privacy-minded users to move to WhatsApp where E2EE is default. The reversal reduces secure chat options on the platform and will notify affected users with migration guidance.
Source: Help Net Security
Teams-based IT impersonation scams push Quick Assist for hands-on compromise
Rapid7 is tracking a surge of phishing on Microsoft Teams where attackers pose as “IT Support” and convince users to launch Quick Assist, granting remote control for malware deployment and data theft. Recommended mitigations include limiting external Teams chats to allowlisted domains, enabling spoof protections, disabling Quick Assist where unneeded, and enforcing out-of-band verification for remote help.
Source: Rapid7
Hidden instructions in README files can make AI coding agents leak data
Researchers showed that semantic injection embedded in project READMEs can trigger AI agents to exfiltrate local files or run unsafe actions during setup. Development teams using agents should treat docs as untrusted input, sandbox agent file/network access, and require human approval for sensitive operations.
Source: Help Net Security
You May Also Be Interested In...
45,000 malicious IP addresses taken down, 94 suspects arrested (INTERPOL)
Hackers tried to breach Poland’s nuclear research centre
CISA flags actively exploited Wing FTP vulnerability leaking server paths