Cyber News 20OCT2025
General
- The alliance that never was (LockBit, DragonForce, Qilin)
- Using (Zendesk) ticket-creation emails for spamming and email-bombing
- Watch out macOS users….Google ads for fake Homebrew, LogMeIn sites push infostealers
- Rust isn't a silver bullet - Windows Kernel Vuln (<sarcasm>surprise - it's in the graphics-handling pathway!</sarcasm>) doesn't lead to Code Exec, but still leads to DoS.
- Why hack, when you can just ask the user to run it? Hackers Exploit TikTok Videos to Deliver Self-Compiling PowerShell Malware
- Finding malware traces in backups - Rubrik scanning finds CN-linked Brickstorm malware
- [AU] Dodo's email system breached, 1600 accounts accessed. Motivation unclear.
- [DE] Volkswagen the 'next' auto-maker to be hit by ransomware? (Listed by 8base - Volkswagen Group - in OCT2024, Qilin - Volkswagen Group France - in OCT2025). This might be some confused initial reporting.
- [EU] Europol dismantles SIM box operation renting numbers for cybercrime. Looks professional, but they still do it bigger in the US.
- [FR] Did France arrest the leader of ShinyHunters?
- [NKO] Latest on North Korea’s fake job interview malware - same technique, new code
Retro Corner
- Cisco Desk, IP, and Video Phones Vulnerable to Remote DoS and XSS Attacks
- Bringing ConnectWise security into the 21st century
- Macro-laden Word docs are still a thing? Weaponized Office Documents Enable APT28 to Deliver BeardShell and Covenant
- Phishing leads to tech-support scam
- Using an installer package for malware distribution - Exploiting Windows MSIX Packages for Persistent and Covert Malware Distribution
- Remote Admin Tool, with unprotected remote includes. Clearly it's been pentested....
Getting Techy
- Reversing Kindle Web DRM, so that you can backup the books you own
- Using EDR-whitelisted executables to drop files in EDR's own folders
Geo-Politics
- [AU] Planning for 6G - secure sovereign networks
- [AU] Nex Cyber Affairs Ambassador, 20yr ASD veteran
- [CN/EU] China / Europe chip battles heat up, over NL's Nexperia (ex. NXP) move
- [CN/US] China claims US was in its (time server) network
Privacy
- [NL] Experian fined €2.7m for GDPR violations
- [US] Pushing back against (TX) age-verification laws
- [US] Pushing back against social-media surveillance - EFF and labour unions sue US administration (Dep. State and Homeland Security)
AI
- MIT "State of AI in Business 2025"