Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Apple has issued fresh warnings to users in 110 countries who may be targeted by mercenary spyware, part of an ongoing effort since 2021 that has now reached over 150 countries. The company describes these as some of the most advanced digital threats, typically aimed at high-profile individuals such as journalists, activists, politicians, and diplomats.
A new White House memorandum signed by President Donald Trump directs the National Coordination Center (NCC) to establish a program within 60 days that authorizes vetted U.S. private sector companies to conduct offensive cyber operations against foreign Transnational Criminal Organizations (TCOs). The program permits two types of operations: cyber surveillance (unauthorized access to sensitive data) and cyber effects (disruption, denial, degradation, or destruction of information systems, networks, or infrastructure).
Kaspersky researchers detail a major evolution of the CoolClient backdoor used by the HoneyMyte APT group, which now includes a signed kernel-mode driver that acts as a rootkit. The driver hides malicious processes, files, and registry entries and communicates with the user-mode backdoor through IOCTL requests.
A former data analyst contractor for Brightly Software was sentenced to two years in prison for stealing company data and attempting to extort $2.5 million from his employer. The case highlights the significant risk posed by insider threats, especially from contractors with privileged access.
The China-linked threat actor Jewelbug, assessed to be a hackers-for-hire group, is conducting simultaneous cyber espionage against governments and militaries in the Middle East, Southeast Asia, and South Asia, while also running a for-profit cryptocurrency fraud operation targeting Chinese-speaking users. Broadcom’s Symantec and Carbon Black Threat Hunter Team found that both missions are administered from a single control panel called XG-Web, a browser-centric remote-access and information-stealing framework that converts a victim’s browser into a remote-control channel and expands into the host and internal network.
Apple has begun sending new threat notifications to users whose iPhones may be targeted by mercenary spyware, often used by state-sponsored actors. The alerts are designed to inform individuals at high risk, such as journalists or activists, about potential compromise.