Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.
International Press – Newsletter
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation
FBI Probes Service Selling 153M+ Drivers Licenses
The Town 2025 ticketing data sold as a Ticketmaster breach
Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Malware
Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts
Gryxa: The AI-Built Toolkit That Watches How You Remove It
ValleyRAT masquerading as adware
13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds
Mini Shai-Hulud’s Latest Wave: 280 New Places It Hunts for Your Secrets
Hacking
Eclypsium flags 1,051 CVEs in infrastructure advisories
Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP
Kaspersky zero-day exploit HardBreacher
PrettyPrague: GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability
Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack
Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
When Sorting Leads To Confusion
Intelligence and Information Warfare
Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist
Fire Ant Evolves: From Hypervisors to Trusted Infrastructure
Insights into Suspected DPRK Workers: Red Flags to Look Out For
Leaked Russian Cyber-Operations Training Materials
Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline
Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia
How the Russians Got Inside My Phone
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Cybersecurity
Judge says Pentagon’s measures against Anthropic were ‘illegal and baseless’
How AI could make it harder for governments to use hacking tools
Own a gun? Go to church? Do yoga? AI can find out in seconds
Path to Astra: critical capabilities and frontier safeguards
PostGREShell: The database powering much of the internet had an open door for 12 years
Fighting AI with AI: The US’s New Cyber Rules of Engagement
ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)