
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.
International Press – Newsletter
McDonald’s employee data listed for sale in wider Entra campaign
$7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret
Live Stripe keys for 659 merchants, published for free
Clop Returns with Custom Implant in Mass-Extortion Campaign
Justice Department Secures $400M Settlement with TikTok and ByteDance to Resolve Children’s Privacy Litigation
Malware
Akira Hits Safe Mode: Ransomware Rebooting Around EDR
Hunting MacSync Stealer infrastructure through behavioral pivots
Manic: Blend between Banking Malware & Spyware
The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile
The invisible passenger in your car
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Hacking
Large-scale DDoS attacks disrupted Threema secure messaging service
Actively exploited vulnerability in Zimbra Collaboration Suite
AI-assisted tool helped secure satellite communication system after 2022 Russian hacking
Expired credit cards revived by researchers to make unauthorized payments
CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks
Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories
Intelligence and Information Warfare
Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia
Defending Against an Active Threat to Siemens S7 Series PLCs
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
SilkParasite: Tracking a China-Nexus APT Across Central Asia
Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network
Cybersecurity
France probes unprecedented cyberattack after tax data of 678,000 users stolen
Person Hides Prompt Injection in Legal Filing Telling AI to Side With Them
SafePal Unauthorized Access To A Subset Of Customer Order Information
This ‘adversarial’ pattern can prevent surveillance cameras from detecting you
France’s cybersecurity problem demands strong political will
The Powerful Chinese AI Model Experts Warned About—and Waited for—Is Here
OpenAI president says companies should do 10 things ASAP to defend against AI cyber threats
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)



