Attackers are actively exploiting a critical unauthenticated file upload vulnerability (CVSS 9.8) in the Breeze Cache WordPress plugin, enabling arbitrary file placement on servers. Wordfence has observed over 170 attack attempts, putting more than 400,000 sites at risk. Site owners should update immediately, audit webroots for unexpected files, and restrict write permissions where possible.
Source: Security Affairs
U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to Known Exploited Vulnerabilities list
CISA expanded its KEV catalog with vulnerabilities impacting SimpleHelp, Samsung, and D-Link products, signaling confirmed in-the-wild exploitation. Inclusion in KEV elevates patching urgency for U.S. federal agencies and should prompt rapid remediation by enterprises using the affected devices and software. Prioritize vendor updates and apply compensating controls if patches are unavailable.
Source: Security Affairs
China-linked APT ‘GopherWhisper’ abuses legitimate services in government attacks
Researchers detail a campaign by GopherWhisper that leverages multiple Go-based backdoors with custom loaders and injectors, blending into normal traffic by riding trusted services. Targeting government entities, the group’s tradecraft complicates detection and response, underscoring the need for deeper egress monitoring and behavior-based analytics.
Source: SecurityWeek
Crime crew impersonates help desks on Microsoft Teams, drops custom ‘Snow’ malware
A previously unknown threat group is using Teams chat invitations and help desk impersonation to socially engineer victims and deliver custom data-stealing malware dubbed Snow. According to Google’s Threat Intelligence Group, this combination of trusted-channel abuse and bespoke tooling raises the stakes for organizations that allow external Teams communications.
Source: The Register
Researchers uncover pre-Stuxnet ‘fast16’ malware designed to sabotage engineering software
SentinelOne identified “fast16,” a Lua-based sabotage framework dating back to 2005 that targeted high-precision engineering calculation software—years before Stuxnet. The findings highlight long-standing interest in manipulating industrial processes by corrupting engineering workflows, reinforcing the importance of securing OT-adjacent engineering workstations and software supply chains.
Source: TheHackerNews
Discord sleuths reportedly gained unauthorized access to Anthropic’s ‘Mythos’
Investigators on Discord allegedly “guessed” their way into Anthropic’s Mythos, raising fresh concerns about access controls and security gating for AI systems. The incident underscores the need for stronger auth, rate-limiting, and monitoring around sensitive AI models and developer portals as adversarial interest grows.
Source: Wired
Fake CAPTCHA scam turns clicks into costly international SMS (Click2SMS fraud)
Infoblox researchers warn of a large-scale Click2SMS scheme that uses fake CAPTCHA pages and back-button hijacking to trick users into sending premium international texts. The campaign monetizes simple user interactions, demonstrating how low-friction lures can quickly rack up charges and evade basic web filtering.
Source: HackRead
You May Also Be Interested In...
Google Changes Gmail—New Gemini Attack Warning
Head of UK data watchdog voluntarily steps aside amid HR probe