CAPI Backdoor targets Russia’s auto and e-commerce sectors
The CAPI Backdoor malware targets Russia’s automobile and e-commerce sectors through phishing emails containing a malicious LNK file that installs a .NET backdoor.
Daily curated cyber threat intelligence for security professionals.
Sourcesecurityaffairs.com
Curated
The CAPI Backdoor malware targets Russia’s automobile and e-commerce sectors through phishing emails containing a malicious LNK file that installs a .NET backdoor.
Sourcewww.malwarebytes.com
Curated
Chinese gangs have made over $1 billion through scam texts targeting Americans, primarily through toll payment and refund scams. These scams are orchestrated using SIM farms and money mules to steal credit card information and launder money via digital wallets and gift cards.
Sourcewww.404media.co
Curated
A hacking group has doxed thousands of U.S. government officials, including NSA employees, by using stolen Salesforce customer data. The group has compiled personal data on officials from various agencies, such as the Defense Intelligence Agency, Federal Trade Commission, and Centers for Disease Control and Prevention.
Sourcewww.cyber.gc.ca
Curated
The Canadian Centre for Cyber Security issued Ubuntu security advisory AV25-681 on October 20, 2025 to address vulnerabilities in the Linux kernel affecting several Ubuntu products.
Sourcewww.cyber.gc.ca
Curated
The Canadian Centre for Cyber Security issued Microsoft Edge security advisory AV25-683 on October 20, 2025, urging users to update Microsoft Edge Stable Channel versions prior to 141.0.3537.85.
Sourcewww.cyber.gc.ca
Curated
Red Hat published security advisories (AV25-684) addressing vulnerabilities in multiple products, including the Linux kernel, between October 13 and 19, 2025.
Sourcewww.cyber.gc.ca
Curated
Sourceproton.me
Curated
A major AWS outage on October 20, 2025, disrupted numerous services, highlighting the internet’s reliance on a few corporations. This centralization creates vulnerabilities, including single points of failure, data concentration, and economic leverage for Big Tech. To mitigate these risks, individuals and businesses should consider independent cloud storage, offline backups, and multi-region deployments.
Sourcewww.govinfosecurity.com
Curated
The UK Ministry of Defense is investigating a data breach by the Russian-speaking ransomware group Lynx, which allegedly stole 4TB of data from the Dodd Group, a contractor providing services to British military bases. The breach exposed sensitive information, including contractor and Ministry of Defense personnel details. The UK government is reviewing legislation to ban ransom payments by critical infrastructure organizations.
Published
Windows 10 refugees flock to Linux in what devs call their “biggest launch ever” www.neowin.net/news/wind…
Windows 10 died a few days ago, leaving users with three options: stick with the OS, upgrade to Windows 11, or switch to an entirely different platform like macOS or GNU/Linux. But months before Microsoft dropped support for the OS, Linux-focused companies were already campaigning to poach Microsoft customers and convert them into Linux users.
The Document Foundation, the folks behind LibreOffice, started its push as far back as June this year, criticizing Microsoft’s decision to end support, which would render millions of perfectly functional PCs obsolete, and presented Linux as a cost-effective and secure alternative. We have also seen initiatives like The “End of 10” Campaign by KDE, making the case for Linux and providing guides and info on how to switch.
Of all the projects trying to poach Windows users, Zorin Group might be the most aggressive, launching its biggest OS upgrade, Zorin OS 18, on the very day Windows 10 died.
Published
Extortion and ransomware drive over half of cyberattacks blogs.microsoft.com/on-the-is…
In 80% of the cyber incidents Microsoft’s security teams investigated last year, attackers sought to steal data—a trend driven more by financial gain than intelligence gathering. According to the latest Microsoft Digital Defense Report, written with our Chief Information Security Officer Igor Tsyganskiy, over half of cyberattacks with known motives were driven by extortion or ransomware. That’s at least 52% of incidents fueled by financial gain, while attacks focused solely on espionage made up just 4%. Nation-state threats remain a serious and persistent threat, but most of the immediate attacks organizations face today come from opportunistic criminals looking to make a profit.
Published
Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide thehackernews.com/2025/10/e…
Europol on Friday announced the disruption of a sophisticated cybercrime-as-a-service (CaaS) platform that operated a SIM farm and enabled its customers to carry out a broad spectrum of crimes ranging from phishing to investment fraud.
The coordinated law enforcement effort, dubbed Operation SIMCARTEL, saw 26 searches carried out, resulting in the arrest of seven suspects and the seizure of 1,200 SIM box devices, which contained 40,000 active SIM cards. Five of those detained are Latvian nationals.
In addition, five servers were dismantled and two websites gogetsms[.]com and apisim[.]com) advertising the service was taken over on October 10, 2025, to display a seizure banner. Separately, four luxury vehicles were confiscated, and €431,000 ($502,000) in suspects' bank accounts and €266,000 ($310,000) in their cryptocurrency accounts were frozen.
The countries that participated in the operation comprised authorities from Austria, Estonia, Finland, and Latvia, in collaboration with Europol and Eurojust.
Published
American Airlines subsidiary Envoy confirms Oracle data theft attack www.bleepingcomputer.com/news/secu…
Envoy Air, a regional airline carrier owned by American Airlines, confirms that data was compromised from its Oracle E-Business Suite application after the Clop extortion gang listed American Airlines on its data leak site.
“We are aware of the incident involving Envoy’s Oracle E-Business Suite application,” Envoy Air told BleepingComputer.
“Upon learning of the matter, we immediately began an investigation and law enforcement was contacted. We have conducted a thorough review of the data at issue and have confirmed no sensitive or customer data was affected. A limited amount of business information and commercial contact details may have been compromised.”
Published
Google ads for fake Homebrew, LogMeIn sites push infostealers www.bleepingcomputer.com/news/secu…
A new malicious campaign is targeting macOS developers with fake Homebrew, LogMeIn, and TradingView platforms that deliver infostealing malware like AMOS (Atomic macOS Stealer) and Odyssey.
The campaign employs “ClickFix” techniques where targets are tricked into executing commands in Terminal, infecting themselves with malware.
Homebrew is a popular open-source package management system that makes it easier to install software on macOS and Linux. Threat actors have used in the past the platform’s name to distribute AMOS in malvertising campaigns.
LogMeIn is a remote access service, and TradingView is a financial charting and market analysis platform, both widely used by Apple users.
Sourcesecurityaffairs.com
Curated
Winos 4.0 hackers, also known as ValleyRAT, have expanded their attacks from China and Taiwan to Japan and Malaysia. The attackers used phishing emails with PDFs disguised as Finance Ministry documents to deliver the HoldingHands RAT malware. The campaign involved a multi-stage process, including anti-VM checks, privilege escalation, and the use of the Windows Task Scheduler to evade detection.
Sourcewww.bloomberg.com
Curated
State-backed hackers from China are blamed for a breach at F5 Inc., a major US-based cybersecurity provider. The hackers gained long-term access to F5’s networks, stealing source code and information about vulnerabilities in F5’s BIG-IP suite of application services. The breach has prompted warnings from US and UK authorities, urging organizations to update their F5 technology to prevent potential exploitation.
Sourcewww.reuters.com
Curated
Envoy Air, American Airlines’ largest regional carrier, confirmed a hack linked to a campaign targeting Oracle E-Business Suite applications. The company stated that no sensitive customer data was compromised, but a limited amount of business information may have been affected.
Sourcemashable.com
Curated
A notorious hacker group, the Com, leaked personal information of hundreds of FBI, ICE, and DOJ officials. The leaked data, shared on private Telegram channels, includes email addresses, names, phone numbers, and residential addresses. The group, linked to other hacking collectives, has been responsible for several high-profile data breaches.
Sourcewww.govinfosecurity.com
Curated
Nation-state hackers, linked to China, exploited stolen source code from F5, compromising federal networks. The breach, exacerbated by a government shutdown, poses an “imminent risk” due to the sheer volume of devices requiring patching. F5 has released software updates and is advising customers to install them immediately.
Sourcewww.govinfosecurity.com
Curated
A cross-border phishing campaign is spreading remote access trojans across Asia, targeting Chinese-speakers in multiple countries with malware like HoldingHands Trojan and Winos 4.0. Researchers have linked these attacks to a single threat actor using phishing emails and Tencent Cloud storage to deceive users.
Sourcewww.govinfosecurity.com
Curated
Hackers stole personal information from 17.6 million individuals from peer-to-peer lending marketplace Prosper. The breach exposed names, dates of birth, contact information, Social Security numbers, and credit details. Prosper is investigating the breach and implementing additional security measures.
Sourcewww.govinfosecurity.com
Curated
The Scattered Lapsus$ Hunters are a group of Western teenagers who employ a mix of social engineering and technical tactics to target major businesses, often leveraging the madman theory to extract concessions from victims. The group’s activities have evolved from initial noise and theatrics into a coordinated cybercrime ecosystem, blurring the lines between social-engineering gangs and mature intrusion operations.
Published
Orion by Kagi pairs Safari-class performance with verifiable zero telemetry, native tracker blocking, and full Chrome/Firefox extension support—funded by users, not ads. My review covers the benefits, limitations, and who should switch. If you want speed, battery life, and control on macOS/iOS, start here.
Sourceblogs.microsoft.com
Curated
Microsoft’s 2025 Digital Defense Report reveals that 80% of investigated cyber incidents involved data theft, with over half driven by financial motives such as extortion or ransomware, while only 4% focused on espionage. The report highlights the growing accessibility of cybercrime tools, AI-powered attacks, and the surge in identity-based breaches—97% of which stem from password attacks. Critical infrastructure sectors remain prime targets due to their limited defences, while nation-state actors, particularly from China, Russia, Iran, and North Korea, continue expanding operations for espionage and financial gain. Microsoft stresses that cybersecurity must now be treated as a strategic, shared responsibility across governments and industries, requiring AI-enabled defences, collaboration, and widespread adoption of phishing-resistant multifactor authentication.
Sourceblogs.microsoft.com
Curated
Microsoft’s 2025 Digital Defense Report reveals that 80% of investigated cyber incidents involved data theft, with over half driven by financial motives such as extortion or ransomware, while only 4% focused on espionage. The report highlights the growing accessibility of cybercrime tools, AI-powered attacks, and the surge in identity-based breaches—97% of which stem from password attacks. Critical infrastructure sectors remain prime targets due to their limited defences, while nation-state actors, particularly from China, Russia, Iran, and North Korea, continue expanding operations for espionage and financial gain. Microsoft stresses that cybersecurity must now be treated as a strategic, shared responsibility across governments and industries, requiring AI-enabled defences, collaboration, and widespread adoption of phishing-resistant multifactor authentication.