The U.S. Cybersecurity and Infrastructure Security Agency issued Binding Operational Directive 26-02, requiring federal civilian agencies to strengthen lifecycle management of edge network devices and replace unsupported hardware within 12–18 months. The move follows mounting evidence that state-sponsored actors target unpatched, end-of-support appliances, elevating risks at the perimeter. Agencies should inventory, segment, and accelerate refresh plans for all edge gear to meet the mandate.
Source: Security Affairs
DNife router toolkit secretly hijacks traffic and delivers malware since 2019
Cisco Talos researchers detailed “DKnife,” a Linux-based toolkit used in long-running cyber-espionage operations to spy on and manipulate traffic traversing routers and other edge devices. The framework can inspect and alter data-in-transit and then push malware onto downstream PCs and mobile devices, underscoring how compromised infrastructure can become a stealthy staging point inside networks. Defenders should scrutinize router integrity, enforce least privilege on management interfaces, and monitor for anomalous egress patterns.
Source: Security Affairs
Germany warns of Signal-based phishing targeting high-profile figures
Germany’s BfV and BSI issued a joint alert about a likely state-sponsored campaign using Signal messages to phish politicians, military personnel, and journalists. Abusing a trusted, encrypted messenger helps bypass email gateways and social engineering defenses. Organizations should verify sender identities out-of-band, limit contact-channel sprawl, and educate VIPs on messaging-app phishing tactics.
Source: TheHackerNews
“Fake PDF” lure mounts virtual drives to silently install AsyncRAT
Researchers tracked a complex phishing operation that swaps traditional attachments for decentralized “fake PDFs” that actually download and mount virtual disk images, installing AsyncRAT with minimal user friction. The technique evades many attachment filters and capitalizes on default OS behaviors. Security teams should block disk-image execution from untrusted sources, harden file associations, and expand detection to catch virtual-drive mounting from browsers.
Source: CyberNews
GSA’s quiet move adds CMMC-like requirements for federal contractors
A newly revealed policy shift by the U.S. General Services Administration introduces CMMC-style cybersecurity obligations, reshaping compliance for federal contractors handling controlled unclassified information. The change signals tighter procurement-driven security standards and raises the bar for documenting controls and assurance. Contractors should assess gaps now to align with anticipated audit and attestation expectations.
Source: Forbes Security
AI agents’ social network “Moltbook” exposed real people’s data
Security researchers found that Moltbook, a platform built for AI agents to interact, leaked data belonging to actual humans, highlighting emergent privacy risks in agent ecosystems. The incident underscores how experimental AI infrastructures can inadvertently blend synthetic and real identities, complicating consent and data governance. Organizations exploring agent frameworks should subject them to the same threat modeling and privacy reviews as production apps.
Source: Wired
OpenClaw partners with VirusTotal to scan marketplace “skills” for threats
OpenClaw (formerly Moltbot/Clawdbot) will have all skills uploaded to its ClawHub marketplace scanned using VirusTotal’s threat intelligence and Code Insight. The integration aims to reduce malicious or unsafe agent capabilities entering the ecosystem and provides developers and operators with an added layer of supply chain defense. It’s a timely step as agent platforms grow and attackers probe new vectors.
Source: TheHackerNews
You May Also Be Interested In...
Italian university La Sapienza still offline after cyberattack
Firefox to add an AI “kill switch” for privacy-conscious users
Study: More hacking groups operate from China than any other country