Apple released iOS/iPadOS 26.4.2 and 18.7.8 to fix a Notification Services logging flaw that retained notifications marked for deletion, enabling forensic recovery of message previews from secure messengers like Signal. The incident underscores the risks of notification previews and device logging: update immediately, and consider disabling sensitive content in lock-screen notifications for high‑risk users.
Source: Help Net Security
CISA: US federal agency breached via Cisco device vuln; “FIRESTARTER” backdoor persisted for months
CISA disclosed that hackers exploited a Cisco device vulnerability at a US department and deployed “FIRESTARTER” to regain access as recently as March without re-exploitation. In parallel, Cisco Talos warned of UAT-4356 actively targeting Firepower FXOS via n‑days (CVE-2025-20333, CVE-2025-20362), reinforcing urgency to patch, audit for persistence on edge gear, and restrict management interfaces.
Source: The Record (Recorded Future News)
Bitwarden CLI npm package compromised in supply-chain attack; rotate secrets and verify artifacts
Security researchers report the @bitwarden/cli 2026.4.0 npm release was tainted with malicious code (bw1.js) in a wider Checkmarx-linked campaign that targeted developer distribution paths. Teams should identify systems that installed the affected version, rotate any credentials/tokens ever handled by the CLI, verify package integrity (lockfiles, checksums, signed releases), and pin trusted versions.
Source: SecurityWeek
New China-aligned APT “GopherWhisper” hides C2 in Slack, Discord, Outlook drafts
ESET uncovered GopherWhisper, a China-nexus group targeting Mongolian government entities with a Go-heavy toolset and injectors/loaders that blend communications into everyday collaboration platforms and file-sharing services. The campaign highlights a growing trend of abuse of sanctioned enterprise apps to mask C2; defenders should inventory sanctioned tenants/workspaces, enforce egress rules, and monitor atypical API and webhook activity.
Source: ESET Research
Surveillance vendors abused telco signaling to secretly track phone locations worldwide
Researchers mapped real attack traffic showing commercial surveillance firms exploiting long-known telecom signaling weaknesses to pose as legitimate carriers and pinpoint targets’ locations. The findings renew pressure on operators to harden SS7/Diameter/GTP-C with strict filtering, anomaly detection, and interconnect governance—and remind enterprises that device location can be exposed even without app-level compromises.
Source: CyberScoop
Microsoft Teams lures + malicious Edge extension: UNC6692’s “SNOW” ecosystem lives off trusted cloud
Google’s Threat Intelligence Group detailed UNC6692 using IT helpdesk impersonation on Teams to push AutoHotkey payloads that install a Chromium extension (SNOWBELT), then pivot with Python tunneling (SNOWGLAZE) and a local HTTP backdoor (SNOWBASIN). The operation leverages Amazon S3/CloudFront and Heroku for C2, evading reputation controls—watch for headless Edge processes, unusual scheduled tasks, unsanctioned extensions, and egress to suspicious S3 buckets/WebSockets.
Source: Google Threat Intelligence
NCSC and partners warn: China-linked actors building covert botnets from hijacked consumer devices
A multi-nation advisory describes widespread use of compromised routers, cameras, DVRs, and NAS as proxy networks to hide state-linked intrusions. Guidance urges organizations to baseline and map edge traffic (especially VPN/remote access), enforce dynamic threat feed filtering, patch/replace EoL gear, and lock down remote management to reduce attacker cover and lateral movement paths.
Source: NCSC (UK)
You May Also Be Interested In... - PhantomRPC: A new privilege escalation technique in Windows RPC (Kaspersky) - AI can autonomously hack cloud systems with minimal oversight: Unit 42 PoC (SecurityWeek) - LMDeploy flaw exploited within 13 hours of disclosure (The Hacker News)