Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Woman convicted following world’s largest crypto seizure
‘You’ll never need to work again’: Criminals offer reporter money to hack BBC
Red Hat confirms security incident after hackers claim GitHub breach
Researchers Say They Flagged Cyber Flaws at Jaguar Ahead of Crippling Breach
Oracle Apps Exploited by Hackers in New Extortion Campaign
Silent Smishing : The Hidden Abuse of Cellular Router APIs
Malware
First Malicious MCP in the Wild: The Postmark Backdoor That’s Stealing Your Emails
Klopatra: exposing a new Android banking trojan operation with roots in Turkey
Check Your Socks – A Deep Dive into soopsocks PyPI Package
New spyware campaigns target privacy-conscious Android users in the UAE
Rhadamanthys 0.9.x – walk through the updates
Hacking
AppSuite, OneStart & ManualFinder: The Nexus of Deception
Apple fixes critical font processing bug. Update now!
Why hackers are targeting the world’s shipping
HackerOne Report Finds 210% Spike in AI Vulnerability Reports Amid Rise of AI Autonomy
Palo Alto Scanning Surges ~500% in 48 Hours, Marking 90-Day High
WireTap: Breaking Server SGX via DRAM Bus Interposition
Battering RAM Low-Cost Interposer Attacks on Confidential Computing
OneLogin, Many Secrets: Clutch Uncovers Critical API Vulnerability Exposing Client Credentials
Intelligence and Information Warfare
Two Dutch teens arrested in rare Russian espionage case
Pro-EU party in Moldova set to win vote mired in claims of Russian interference
You name it, VMware elevates it (CVE-2025-41244)
Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite
SVG Phishing hits Ukraine with Amatera Stealer, PureMiner
CABINETRAT backdoor used by UAC-0245 for targeted cyberattacks against SOU (CERT-UA#17479)
Cavalry Werewolf raids Russia’s public sector with trusted relationship attacks
Confucius Espionage: From Stealer to Backdoor
Cybersecurity
Harrods warns customers their data may have been stolen in IT breach
Government backs Jaguar Land Rover with £1.5 billion loan guarantee
WestJet confirms recent breach exposed customers’ passports
AI Agents Are Eroding the Foundations of Cybersecurity
Feds cut funding to program that shared cyber threat info with local governments
California enacts AI safety law targeting tech giants
Package Maintainers Call for Improvements to GitHub’s New npm Security Plan
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)