Cyber News 06NOV2025
General
- Actively exploited WordPress email plugin 'Post SMTP', can be used to read WordPress password-reset emails, enabling account takeover.
- Google's Threat Intelligence Group (GTIG) on attacker use of AI tools. Yes - people have tried things, no - the examples don't work, yes - existing tools detect them with no problem.
- Sticking with Google - their acquisition of Wiz looks a step closer to finally closing, after gaining DoJ approval.
- [EU] 18 arrested in old (2016-2021) 'low and slow' €300m credit-card fraud operation
- https://www.eurojust.europa.eu/news/eurojust-coordinates-major-operation-against-eur-300-million-global-credit-card-fraud-18
- https://www.bleepingcomputer.com/news/security/europol-credit-card-fraud-rings-stole-eur-300-million-from-43-million-cardholders/
- https://therecord.media/europe-police-bust-global-fraud-ring-payment-firms
- [UK] Cost of a breach - M&S profits down 99% (£291.1m -> £3.4m) in the first half-year, even after a £100m insurance payout
Geo-Politics
- [CN] Heavy sentences for chinese nationals involved in scam Myanmar compounds.
According to Xinhua, the Bai family and its associates built 41 industrial parks where they “engaged in telecommunications and online fraud, operating casinos, intentional homicide, intentional injury, kidnapping, extortion, organizing and forcing prostitution, and organizing illegal border crossings.” They defrauded people of more than 29 billion yuan (more than $4 billion), the court alleged, and their operations resulted in the deaths of at least six Chinese citizens.
- [US] Impact of Government Shutdown - US Army lists food banks in Germany, that could help support the staff at their bases.
Privacy
- [US] DHS proposes massive increase in biometric collection powers
AI
- Anthropic propose the next evolution beyond direct Model Context Protocol (MCP) execution. Essentially, turning the MCP calls and data flow into an external program. This has performance, accuracy and security benefits.
To add some numbers - GitHub MCP definition at launch took +50k tokens of context - most self-hosted models max out at 128k of context. Anthropic, Google and X all charge more for context over either 128k or 200k. - Amazon and Perplexity clash over shopping agents
- (Bloomberg) https://archive.li/nGmOJ
- AI everywhere...now entering the dating-apps space
- (NY Times) https://archive.li/Y0JuN
- Speaking of space - how about putting your AI chips in orbit? Better access to solar power, but the radiation might hurt.
- Cassie Kozyrkov breaks down the "AI Therapist" arguments, for and against.