Researchers disclosed a critical remote code execution vulnerability in protobuf.js, a popular JavaScript implementation of Google’s Protocol Buffers, with proof-of-concept exploit code now publicly available. The library’s ubiquity across Node.js and browser-based applications raises supply-chain risk concerns, making rapid updates and dependency audits urgent for development teams.
Source: Bleeping Computer
Attackers hide malware in “invisible” QEMU VMs to evade detection
Sophos warns of rising abuse of QEMU, with adversaries running malware inside stealthy virtual machines to bypass endpoint controls and leave minimal forensic traces. The technique enables quiet data theft and ransomware deployment while complicating incident response, pushing defenders to monitor for unusual virtualization artifacts and off-host activity.
Source: Security Affairs
Nexcorium Mirai variant hijacks TBK DVRs and EOL TP-Link routers for DDoS firepower
Fortinet researchers report a Mirai offshoot dubbed “Nexcorium” exploiting vulnerabilities in TBK DVRs and outdated TP-Link routers to conscript devices into DDoS botnets. The campaign underscores how unpatched and end-of-life IoT gear remains low-hanging fruit for threat actors and a persistent risk to upstream networks.
Source: Security Affairs
Old but gold: 5-year-old ShowDoc bug (patched in 2020) exploited for full server takeovers
Threat actors are actively abusing a long-patched ShowDoc vulnerability (CVE-2025-0520) to drop web shells, achieve remote code execution, and seize servers worldwide. The wave of compromises highlights lingering exposure from legacy internet-facing tools and the need to verify patching, remove abandoned instances, and hunt for web shell indicators.
Source: HackRead
Operation PowerOFF: 75,000 users of DDoS-for-hire services unmasked; arrests and domain seizures follow
In a Europol-led crackdown, authorities identified and warned 75,000 consumers of DDoS-for-hire platforms, made four arrests, and seized 53 domains. The action signals mounting legal pressure on both operators and customers, raising the stakes for organizations tempted to outsource cyberattacks.
Source: HackRead
White House to meet Anthropic CEO as anxiety over “Mythos” model’s capabilities grows
The Biden administration plans talks with Anthropic amid concerns and policy questions surrounding the company’s new “Mythos” AI model. As officials weigh potential government use during an ongoing rift with the vendor, the meeting spotlights governance, security safeguards, and downstream risk from increasingly powerful AI systems.
Source: Politico Cyber
Report: EU age-verification app can be hacked in two minutes
Security researchers say the EU’s new age-verification app can be compromised in roughly two minutes, raising questions about the integrity of digital identity checks. The findings amplify calls for stronger security-by-design standards in government-backed identity and verification tools.
Source: Wired
You May Also Be Interested In...
Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks — SecurityWeek
Microsoft Teams right-click paste broken by Edge update bug — Bleeping Computer
$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims — TheHackerNews