Week in Review: Supply Chain Attacks, APT Campaigns, and Critical Patches Dominate Cybersecurity Landscape

A roundup of the week's top cybersecurity news includes supply chain attacks on Google Android and DAEMON Tools, active exploitation of critical flaws in PAN-OS and Apache HTTP/2, and emerging threats from AI agent blind spots and IoT botnets.

The Latest

Breaking News and Alerts

DigiCert Breach: Stolen EV Code Signing Certificates Linked to Zhong Stealer Malware

The attacker exploited a malfunctioning endpoint sensor to maintain undetected access for ten days, stealing certificates used to sign Zhong Stealer malware.

Spotlight

Cybersecurity Profiles and Stories

FBI and Dubai Police Dismantle Global Crypto Fraud Ring, Seizing $701 Million

The international operation involved 276 arrests and the shutdown of nine scam centers, with human trafficking victims forced to run pig butchering schemes targeting Americans.

AI Driven Zero Day Discovery Now Automates Attacks at Machine Speed

Attackers now use AI models to discover and exploit zero day vulnerabilities in minutes, with documented campaigns like GAMECHANGE showing LLMs orchestrating espionage in real time.

MOVEit Automation Patches Critical Backend Flaws Allowing Full Server Takeover

Two critical MOVEit Automation vulnerabilities discovered by Airbus SecLab researchers allow unauthenticated attackers to bypass authentication and escalate privileges to full administrative control.

Rogue DHCP Server Attack Can Fully Compromise FreeBSD Systems

The flaw allows attackers on the same local network to inject commands into the dhclient configuration file through unescaped double quotes in BOOTP responses.

Features

Research and Thought Leadership