Attackers are actively exploiting a critical unauthenticated remote code execution flaw in F5’s BIG-IP Access Policy Manager, prompting CISA to add CVE-2025-53521 to its Known Exploited Vulnerabilities catalog. Organizations should prioritize patching per F5’s updated advisory and hunt for post-exploitation activity on exposed APM appliances.
Source: Help Net Security
Citrix NetScaler CVE-2026-3055 (CVSS 9.3) draws active reconnaissance for data-leakage bug
Researchers report active scanning for a newly disclosed memory overread in Citrix NetScaler ADC and Gateway (CVE-2026-3055) caused by insufficient input validation. While the flaw facilitates information leakage rather than direct code execution, exposed gateways are being probed at scale—admins should apply vendor fixes and monitor for anomalous requests and spikes in error responses.
Source: The Hacker News
TA446 wields leaked “DarkSword” iOS exploit kit in targeted spear-phishing
Proofpoint observed Russia-linked TA446 (aka Callisto) running a focused email campaign that uses the recently leaked DarkSword exploit kit to target iOS devices. The activity highlights growing mobile exploitation via social engineering; enterprises should harden mobile fleets, enforce rapid iOS patching, and train users to treat unsolicited links as hostile.
Source: The Hacker News
Apple pushes lock screen alerts urging updates amid active web-based iOS/iPadOS exploits
Apple is issuing on-device lock screen warnings to users running outdated iOS and iPadOS versions, citing active web-based attacks. The company urges immediate updates, reinforcing that delaying patches substantially increases exposure on mobile endpoints frequently targeted via malicious links and drive‑by exploits.
Source: Security Affairs
ShinyHunters claim breach of the European Commission; alleged mail server data posted
The ShinyHunters group added the European Commission to its leak site, alleging theft of internal communications and mail server content. Officials are investigating the claims; if confirmed, the incident could carry significant diplomatic and regulatory ramifications across the EU’s institutions and vendors.
Source: Security Affairs
Cloudflare-themed “ClickFix” lure drops Infiniti Stealer on Macs
A new macOS campaign impersonates Cloudflare challenges to socially engineer users into running a Bash script that loads a Nuitka-built Python component and delivers the Infiniti info‑stealer. The multilayer chain underscores that macOS users remain high‑value targets; tighten browser download controls, block unknown scripts, and expand EDR visibility on Macs.
Source: SecurityWeek
TeamPCP supply-chain campaign shifts from intrusion to monetization, no new compromises in 48 hours
SANS ISC reports an operational tempo change in the TeamPCP campaign as actors move into monetization, with no new compromises observed over the past two days. Earlier phases included the Telnyx PyPI compromise and ties to a Vect ransomware partnership—teams should review dependencies and lockdown CI/CD trust boundaries.
Source: SANS ISC
You May Also Be Interested In...
RSAC 2026: More auto-updating supply-chain attacks on the way
BSides SF: SaaS and cloud assets vulnerable to identity-based ransomware
Iran-linked group claims hack of FBI Director’s personal email