Google has pushed an emergency Chrome security update amid reports that attackers are actively exploiting two zero-day vulnerabilities. Enterprises should expedite browser updates and ensure users restart Chrome to apply the fixes, reducing exposure to active exploitation. Admins should also review enterprise policies to enforce automatic updates.
Source: Forbes Security
Critical flaw puts 875 million Android phones at risk of a 60‑second device compromise
A newly reported Android vulnerability could let attackers bypass protections and access locked devices in under a minute, potentially affecting roughly one in four Android phones. Until vendor patches are available and applied, users should minimize opportunities for physical access and keep device security updates current.
Source: Forbes Security
Critical HPE AOS‑CX bug allows remote, unauthenticated admin password resets
A critical vulnerability in HPE’s AOS‑CX networking platform can be exploited remotely—without authentication—to bypass existing controls and reset administrator passwords. Organizations should urgently apply vendor fixes or mitigations and restrict management plane exposure to trusted networks only.
Source: SecurityWeek
GlassWorm escalates: 72 Open VSX extensions abused to target developers
Researchers uncovered a new GlassWorm supply‑chain wave abusing the Open VSX registry, where 72 extensions leverage extensionPack and extensionDependencies to spread malicious loaders transitively. The technique turns seemingly benign extensions into Trojan horses, increasing the risk of developer environment compromise and downstream code tampering.
Source: TheHackerNews
Storm‑2561 uses SEO‑poisoned spoofed VPN sites to steal corporate credentials
Microsoft analysts tracked a credential‑theft campaign where Storm‑2561 seeded search results with fake Ivanti, Cisco, and Fortinet VPN downloads. The look‑alike sites deliver trojanized clients that harvest enterprise logins, underscoring the need to download software only from official vendor domains, verify signatures, and enforce phishing‑resistant MFA.
Source: Security Affairs
Global crackdown: INTERPOL dismantles 45,000 malicious IPs/servers, 94 arrests
Operation Synergia III, spanning 72 countries, took down 45,000 IP addresses and servers tied to phishing, malware, and ransomware operations, leading to 94 arrests and more than 100 ongoing investigations. The action disrupts major criminal infrastructure and highlights the value of cross‑border intelligence sharing.
Source: Security Affairs
ShinyHunters claims 1 petabyte data theft from Telus Digital
The ShinyHunters group says it exfiltrated up to 1 PB of data from Telus Digital, including support recordings, source code, and employee records. While the scope is still being evaluated, the alleged cache could fuel targeted scams and intellectual property exposure; customers and staff should watch for credential reuse and spear‑phishing.
Source: HackRead
You May Also Be Interested In...
Loblaw Data Breach Impacts Customer Information
OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration
New Federal Strategies, Rising Risk From Iran Top Cyber Themes