In other news: Zombie map attack, T-Mobile cuts cord to stop hackers, GitHub denies AI-caused bug

SecurityWeek weekly newspaper overview of cybersecurity news offers a brief overview of important developments that may not receive full stand-alone coverage but remain relevant to the broader threat landscape.

This curated summary highlights key vulnerability disclosure stories, emerging attack methods, policy updates, industry reports, and other notable events to help readers stay fully informed of the evolving cybersecurity landscape.

Here are this week’s highlights:

CISA warns of actively exploited Ray vulnerability

CISA authorized all federal civilian agencies to prioritize fixing a serious code injection vulnerability (CVE-2025-62593) in Ray-Project Ray. The downside was added to the catalog of known exploited vulnerabilities after threats were observed actively abusing it in the wild. BitSight saw that the vulnerability was being exploited by RondoDoxa Mirai-inspired botnet using a staggering 174 different exploits to compromise vulnerable endpoints.

Advertising. Scroll to continue reading.

GitHub says the vulnerability discovered by an autonomous Wiz agent was not introduced by AI

An autonomous AI tool successfully developed by Wiz identified and exploited a critical GitHub Actions workflow vulnerability in a public Snowflake repository, gaining unauthorized access to the company’s internal Jira tickets. Although it was initially reported as a bug introduced by GitHub Copilot, GitHub clarified about Security Week that the vulnerable code fragment was entirely human-made.

Threema DDoS attack

Encrypted messaging provider Threema recently suffered significant service outages following a series of complex, lengthy DDoS attacks aimed at its infrastructure and colocation partner. To stabilize operations, the company quickly implemented specialized upstream traffic filtering to block malicious requests before they could reach and overload its servers.

Evooo1Bot Linux botnet

FortiGuard Labs tracks Evooo1Bota highly modular Linux botnet that targets Internet-connected devices by exploiting over a dozen known CVEs. Going beyond standard DDoS capabilities, this Mirai variant is equipped with an SSH brute-forcer, a credential sniffer, and a SOCKS5 relay module designed to turn infected hosts into permanent proxy nodes for attackers.

T-Mobile physically cut the router cable to stop Chinese hackers

To stop an active network infiltration by the Chinese state-sponsored hacking group Salt Typhoon in 2024, T-Mobile’s cybersecurity team physically cut (Bloomberg paid report) Compromised network cable on scissor router in Bellevue data center. T-Mobile was the target of an extensive spying campaign that affected several other major US carriers.

TeamPCP claims massive data theft from Alation

Data catalog provider Alation confirmed an unauthorized intrusion into its internal network following a recent cyber attack. Hacker group TeamPCP has publicly took responsibility of the breach, claiming they successfully dumped 73 gigabytes of sensitive data from the enterprise software company.

Data breach at Japan’s Sakura Internet affects over 1 million customer records

Japanese hosting provider Sakura Internet found it hard data breach in its sales management system, potentially compromising contract and membership information for up to 1.36 million users. The mass exposure was identified while security teams were investigating an entirely separate malware infection that affected a small subset of the company’s leased server accounts.

Medusa ransomware targeting GoAnywhere and BeyondTrust vulnerabilities

A joint consultation from CISA, the FBI and HHS warn that Medusa ransomware affiliates are rapidly exploiting newly discovered vulnerabilities in Fortra GoAnywhere and BeyondTrust to compromise critical infrastructure. The updated warning highlights the group’s evolving evasion toolkit, which now includes using Minidump to steal credentials and dynamic Interactsh URLs to verify successful network exploitation. The announcement said that over 500 critical infrastructure organizations have been affected so far.

Zombie card attack

Academic researchers have demonstrated a new Zombie map an attack that bypasses cryptographic checks to make contactless payments using physically expired Visa credit cards. By using a smartphone relay setting to change the expiration date fed to the POS terminal, attackers can exploit the communication gap between local hardware and the issuing bank. The attack doesn’t seem to work against Mastercard, American Express and Discover cards, and it doesn’t work against all banks. Visa did not respond to SecurityWeek’s request for comment.

A Canadian security firm provides the highest level of NIST certification for a post-quantum hardware module

Crypto4A became the first company worldwide to achieve FIPS 140-3 Level 3 validation for an HSM supporting all NIST-approved post-quantum cryptographic algorithms. The newly certified QASM module provides a tamper-proof foundation for protecting sensitive cryptographic keys from the future threat of advanced quantum computing attacks.

Connected: Other news: Rapid7 layoffs, Boeing 737 hack, refrigeration vulnerabilities

Connected: In other news: AI Slop Limits Apple Rewards, North Carolina Port Attacks, Wall Street Hackers

Leave a Reply

Your email address will not be published. Required fields are marked *