<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Axe Report | Grab The Axe</title><description>Daily security, privacy, and compliance news briefings from Grab The Axe.</description><link>https://grabtheaxe.com/</link><language>en-us</language><item><title>EEOC Reverses Course, Stay or Pay Crackdown &amp; Unclaimed Crypto Grab (07/11/2026)</title><link>https://grabtheaxe.com/news/eeoc-affirmative-action-stay-or-pay-unclaimed-crypto-07-11-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/eeoc-affirmative-action-stay-or-pay-unclaimed-crypto-07-11-2026/</guid><description>The EEOC withdraws affirmative action guidance, California and New York move against &apos;stay or pay&apos; contracts, and states start seizing dormant crypto as unclaimed property.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/eeoc-affirmative-action-stay-or-pay-unclaimed-crypto-07-11-2026.webp&quot; alt=&quot;Compliance Briefing: EEOC guidance withdrawal, stay or pay laws, unclaimed crypto July 11, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Three of this week&apos;s changes touch the two things every operator budgets around: who you can hire and how you keep them. The EEOC pulled guidance that employers relied on for their affirmative action plans, California and New York are limiting the contracts that recoup training costs, and state treasurers are starting to treat idle crypto as property they can claim. Each one shifts a cost or a liability onto the business, and the ones who reprice for it early will not be the ones caught flat.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;1. EEOC Withdraws Longstanding Affirmative Action Guidance&lt;/h3&gt;
&lt;p&gt;On June 30, the Equal Employment Opportunity Commission (EEOC) formally withdrew longstanding guidance documents on the permissible scope of voluntary affirmative action plans (&lt;a href=&quot;https://www.jdsupra.com/legalnews/employment-law-update-eeoc-withdraws-1049684/&quot;&gt;JD Supra&lt;/a&gt;). Employers built hiring and promotion programs on that guidance, and pulling it removes the safe harbor they were relying on, which means every plan written against the old rules needs a fresh legal read.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; If your hiring or promotion program cites the withdrawn EEOC guidance, it needs review now. The document you built the policy on no longer backs it up.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. California and New York Target &apos;Stay or Pay&apos; Contracts&lt;/h3&gt;
&lt;p&gt;New laws in California and New York take aim at &quot;stay or pay&quot; provisions, the clauses that require employees to repay training, licensing, or sign-on costs if they leave before a set date (&lt;a href=&quot;https://www.jdsupra.com/legalnews/rethinking-retention-new-california-and-3057051/&quot;&gt;JD Supra&lt;/a&gt;). Businesses use these clauses to protect real investment in their people, so the practical move is to rebuild retention around agreements that hold up under the new rules rather than the ones now being challenged.&lt;/p&gt;
&lt;h3&gt;3. States Move to Seize Dormant Cryptocurrency&lt;/h3&gt;
&lt;p&gt;State treasury regulators are accelerating efforts to apply unclaimed property laws to inactive cryptocurrency accounts and other digital assets, with more than two dozen states now involved (&lt;a href=&quot;https://www.jdsupra.com/legalnews/unclaimed-cryptocurrency-us-states-are-4250941/&quot;&gt;JD Supra&lt;/a&gt;). Any business holding customer digital assets now has an escheatment obligation to track, and getting the dormancy timelines and reporting wrong turns an accounting gap into a state enforcement problem.&lt;/p&gt;
&lt;h3&gt;4. Study Finds Healthcare Websites Leaking Data Through Tracking Tools&lt;/h3&gt;
&lt;p&gt;A study found that the majority of healthcare websites use marketing and analytics tools that can disclose sensitive visitor information to third parties (&lt;a href=&quot;https://www.hipaajournal.com/study-healthcare-websites-tracking-analytics-tools-2026/&quot;&gt;HIPAA Journal&lt;/a&gt;). A tracking pixel on a patient-facing page is a HIPAA exposure hiding in the marketing stack, and the fix starts with an honest inventory of what your own website is sending and to whom.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Audit the trackers on your patient-facing pages before a regulator or plaintiff does. The compliance risk lives in the analytics tags the marketing team added, not the clinical systems IT watches.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;5. Aspen Dental Settlement Resets Dental Service Organization Standards&lt;/h3&gt;
&lt;p&gt;California&apos;s settlement with Aspen Dental Management sets a significant new corporate practice of dentistry standard for dental service organizations and the practices they support (&lt;a href=&quot;https://www.jdsupra.com/legalnews/a-new-era-of-compliance-standards-for-4401549/&quot;&gt;JD Supra&lt;/a&gt;). Any management services organization operating in a regulated clinical field should read this as a signal that the arrangement between the business and the licensed practice will get scrutinized.&lt;/p&gt;
&lt;h2&gt;Additional Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;Regulatory Updates&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Colorado AG Settles Over Home Equity Agreements:&lt;/strong&gt; Colorado&apos;s attorney general entered an assurance of discontinuance with a home equity agreement provider, requiring it to comply with the state&apos;s Uniform Consumer Credit Code. &lt;a href=&quot;https://www.jdsupra.com/legalnews/colorado-attorney-general-announces-7840194/&quot;&gt;JD Supra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;China Proposes Penalties on Cross-Border Brokerages:&lt;/strong&gt; The China Securities Regulatory Commission announced proposed penalties against several overseas online brokerage firms for cross-border business activities, a warning shot for institutions serving Chinese clients. &lt;a href=&quot;https://www.jdsupra.com/legalnews/china-china-announced-proposed-7536052/&quot;&gt;JD Supra&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>compliance news</category><category>daily briefing</category><category>EEOC</category><category>employment law</category><category>HIPAA</category><author>info@grabtheaxe.com (Dusten Trounce)</author><enclosure url="https://grabtheaxe.com/assets/news/eeoc-affirmative-action-stay-or-pay-unclaimed-crypto-07-11-2026.webp" length="0" type="image/webp"/></item><item><title>NJ Data Broker Reversal, NY Smart Glasses Ban &amp; Waymo Calls Police (07/11/2026)</title><link>https://grabtheaxe.com/news/nj-data-broker-reversal-ny-smart-glasses-waymo-police-07-11-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/nj-data-broker-reversal-ny-smart-glasses-waymo-police-07-11-2026/</guid><description>New Jersey moves to suspend its own data broker law, New York bars smart glasses from courthouses, and a Waymo robotaxi reports teen riders to police.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/nj-data-broker-reversal-ny-smart-glasses-waymo-police-07-11-2026.webp&quot; alt=&quot;Privacy Briefing: NJ data broker reversal, NY smart glasses ban, Waymo police report July 11, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Two governments this week decided the surveillance question in opposite directions, and a robotaxi answered a third one nobody voted on. New Jersey is trying to unwind its own data broker law because the data flow it cut off was politically useful, New York is pulling recording devices out of its courthouses, and a Waymo turned its own passengers over to police. Each case is really the same question: who gets to decide when the record of your movements becomes evidence against you.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;1. New Jersey Moves to Suspend Its Own Data Broker Law&lt;/h3&gt;
&lt;p&gt;Governor Sherrill&apos;s administration is working to suspend enforcement of New Jersey&apos;s new data broker law after realizing it would cut off political campaigns&apos; access to key voter-targeting data (&lt;a href=&quot;https://pogowasright.org/sherrill-administration-will-suspend-enforcement-of-new-jerseys-new-data-broker-law/&quot;&gt;PogoWasRight&lt;/a&gt;). A privacy protection gets walked back the moment it inconveniences the people who wrote it, which tells you the data was never really meant to be off limits, only off limits to someone else.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; When a data-minimization rule carves out the powerful, the exposure it was supposed to close stays open for everyone below them. Watch what the exemptions protect, not what the headline promises.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. New York Bans Smart Glasses From Courthouses Statewide&lt;/h3&gt;
&lt;p&gt;Starting July 20, New York State courts will require anyone entering their facilities to surrender smart glasses and similar recording eyewear at the door (&lt;a href=&quot;https://pogowasright.org/new-york-bans-smart-glasses-from-courthouses-across-the-state/&quot;&gt;PogoWasRight&lt;/a&gt;). Courts understand that a device recording everyone in the room changes how people behave in it, which is the same reasoning that should apply well beyond the courthouse walls.&lt;/p&gt;
&lt;h3&gt;3. A Waymo Robotaxi Reports Teen Riders to Police&lt;/h3&gt;
&lt;p&gt;A self-driving Waymo reported two teenagers to San Mateo police after detecting them drinking alcohol during the ride (&lt;a href=&quot;https://pogowasright.org/waymo-reports-teen-riders-for-bad-behavior-and-delivers-them-to-the-police/&quot;&gt;PogoWasRight&lt;/a&gt;). The car you hired to take you somewhere became a witness against you, and every robotaxi is a rolling sensor package whose logs can be pointed at the passenger as easily as at the road.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Every ride in an instrumented vehicle generates a record you do not control. Treat the cabin of a robotaxi as a monitored space, because it is one.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;4. Meta Discontinues Its Muse Image Feature Over Privacy&lt;/h3&gt;
&lt;p&gt;Meta said it will discontinue Muse, an AI feature launched days earlier that automatically generated images using content from public Instagram accounts, after it &quot;misses the mark&quot; on user privacy (&lt;a href=&quot;https://www.theguardian.com/technology/2026/jul/11/meta-ditches-muse-image-ai-feature-instagram-privacy&quot;&gt;The Guardian&lt;/a&gt;). The feature shipped, the backlash landed, and it was gone in a week, which is what accountability looks like when it works, though the better outcome is catching this before launch rather than after.&lt;/p&gt;
&lt;h3&gt;5. The EFF Argues Automated Moderation Is Now Permanent&lt;/h3&gt;
&lt;p&gt;The EFF makes the case that automated content moderation is here to stay, and the accountability around these systems has not kept pace with how much they now decide (&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/part-2-automated-moderation-here-stay-accountability-must-keep-pace&quot;&gt;EFF&lt;/a&gt;). An algorithm that removes speech at scale makes decisions about real people with no one to appeal to, and the fix is transparency into how those calls get made, not a demand that the machines go away.&lt;/p&gt;
&lt;h2&gt;Additional Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;Privacy Laws &amp;amp; Regulations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Irish NCSC Issues Board Cyber Governance Guidance Ahead of NIS2:&lt;/strong&gt; The Irish National Cyber Security Centre published guidance for management boards and senior executives of organizations subject to the EU&apos;s NIS2 directive, pushing cyber accountability up to the people who answer for the data. &lt;a href=&quot;https://www.insideprivacy.com/uncategorized/irish-ncsc-issues-cyber-governance-guidance-for-management-boards-ahead-of-nis2-implementation/&quot;&gt;Inside Privacy&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>privacy news</category><category>daily briefing</category><category>data broker</category><category>surveillance</category><category>facial recognition</category><author>info@grabtheaxe.com (Jeff Welch)</author><enclosure url="https://grabtheaxe.com/assets/news/nj-data-broker-reversal-ny-smart-glasses-waymo-police-07-11-2026.webp" length="0" type="image/webp"/></item><item><title>Zimbra RCE, Ghostcommit AI Injection &amp; a Global CMS Campaign (07/11/2026)</title><link>https://grabtheaxe.com/news/zimbra-rce-ghostcommit-cms-campaign-07-11-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/zimbra-rce-ghostcommit-cms-campaign-07-11-2026/</guid><description>A critical Zimbra flaw runs code from a crafted email, Ghostcommit hides prompt injection in images to fool AI code reviewers, and Australia warns of a global CMS attack.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/zimbra-rce-ghostcommit-cms-campaign-07-11-2026.webp&quot; alt=&quot;Security Briefing: Zimbra RCE, Ghostcommit AI injection, global CMS campaign July 11, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The theme today is trust boundaries you did not know you had. A crafted email runs code in your webmail session, a PNG carries a prompt injection past your AI code reviewer, and Alibaba&apos;s HTTP/3 library falls over from one bad variable that has no patch. Attackers keep finding the input your defenses wave through without inspection, and this week the softest of those inputs is the AI agent you added to move faster.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;h3&gt;1. Critical Zimbra Flaw Runs Code From a Crafted Email&lt;/h3&gt;
&lt;p&gt;Zimbra is urging customers to patch a critical vulnerability in the Classic Web Client that lets a specially crafted email execute arbitrary code inside a user&apos;s session (&lt;a href=&quot;https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html&quot;&gt;The Hacker News&lt;/a&gt;). Zimbra has a long history as a target for nation-state and criminal actors, and a bug that fires from an email a user only has to open is close to the ideal delivery path.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Patch Zimbra now and hunt for exploitation before the update, not after. Webmail RCE means the mailbox is the entry point, so treat exposed sessions as potentially compromised.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. Ghostcommit Hides Prompt Injection in Images to Fool AI Code Reviewers&lt;/h3&gt;
&lt;p&gt;Researchers demonstrated Ghostcommit, a technique that buries a prompt injection inside a PNG image and slipped past the AI code reviewers CodeRabbit and Bugbot to exfiltrate repository secrets (&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/ghostcommit-hides-prompt-injection-in-images-to-fool-ai-agents-steal-secrets/&quot;&gt;BleepingComputer&lt;/a&gt;). The AI reviewer you bolted onto the pipeline to catch bad code is now an attack surface, because it reads attacker-controlled content and holds credentials, which is exactly the pairing an adversary wants.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Treat any AI agent with repo access as a privileged identity. Scope its secrets tightly and assume every file it ingests, images included, is hostile input.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;3. Australia Warns of a Global Campaign Against Vulnerable CMS Platforms&lt;/h3&gt;
&lt;p&gt;The Australian Cyber Security Centre issued an alert about a global exploitation campaign targeting vulnerable content management systems and their plugins (&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/australia-warns-of-global-campaign-targeting-vulnerable-cms-platforms/&quot;&gt;BleepingComputer&lt;/a&gt;). The public website running an out-of-date CMS is the classic forgotten asset, and it is a foothold into the network behind it, not just a defacement risk.&lt;/p&gt;
&lt;h3&gt;4. Laser Attack Resets Tangem Wallet Passwords on Unpatchable Cards&lt;/h3&gt;
&lt;p&gt;Ledger&apos;s Donjon security team showed that a precisely timed laser pulse aimed at the chip inside a Tangem crypto wallet card can reset the card&apos;s password (&lt;a href=&quot;https://thehackernews.com/2026/07/laser-attack-resets-tangem-wallet.html&quot;&gt;The Hacker News&lt;/a&gt;). The flaw is in silicon, so there is no firmware fix, and it is a reminder that hardware you cannot update is a permanent exposure once someone has physical access.&lt;/p&gt;
&lt;h3&gt;5. Unpatched XRING Flaw Crashes HTTP/3 Servers With Legal Traffic&lt;/h3&gt;
&lt;p&gt;A single wrong variable in Alibaba&apos;s XQUIC library, which implements QUIC and HTTP/3, lets any remote client crash the server with a short burst of completely valid traffic, and no patch is available yet (&lt;a href=&quot;https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html&quot;&gt;The Hacker News&lt;/a&gt;). A denial-of-service that needs no malformed packets and no authentication is cheap to run and hard to filter, so anyone exposing XQUIC should plan for rate limiting rather than a fix.&lt;/p&gt;
&lt;h2&gt;Additional Security Alerts&lt;/h2&gt;
&lt;h3&gt;Threat Intelligence&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MODBEACON RAT Uses gRPC for Encrypted C2:&lt;/strong&gt; The China-linked group Silver Fox has been tied to a new Rust-based remote access trojan called MODBEACON that hides its command traffic inside gRPC streaming, blending in with legitimate application protocols. &lt;a href=&quot;https://thehackernews.com/2026/07/new-modbeacon-rat-uses-grpc-streaming.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security Tools &amp;amp; Best Practices&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Lumen Rebuilt Exposure Management From 17,000 to 1.1 Million Assets:&lt;/strong&gt; Lumen&apos;s asset inventory grew by nearly two orders of magnitude once it measured its real external attack surface, a concrete example of how far most inventories sit from reality. &lt;a href=&quot;https://thehackernews.com/2026/07/from-17000-to-11-million-assets-how.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>security news</category><category>daily briefing</category><category>Zimbra</category><category>prompt injection</category><category>attack surface</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/zimbra-rce-ghostcommit-cms-campaign-07-11-2026.webp" length="0" type="image/webp"/></item><item><title>DOJ Prosecution Playbook, MiCAR Deadline &amp; Enhanced CIRMP Rules (07/10/2026)</title><link>https://grabtheaxe.com/news/doj-prosecution-playbook-micar-expiry-cirmp-rules-07-10-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/doj-prosecution-playbook-micar-expiry-cirmp-rules-07-10-2026/</guid><description>The DOJ resets how it charges corporations, the MiCAR transitional period closes for crypto firms, and Australia&apos;s Enhanced CIRMP rules raise the bar on critical infrastructure risk.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/doj-prosecution-playbook-micar-expiry-cirmp-rules-07-10-2026.webp&quot; alt=&quot;Compliance Briefing: DOJ prosecution playbook, MiCAR deadline, CIRMP rules July 10, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Three deadlines landed this week that change what an operator has to prove, not just what they have to promise. The DOJ published clearer rules for when it charges a company and when it walks away, the EU&apos;s crypto-asset rules move from transition to enforcement, and a fresh 81,000-person health breach shows how fast a single email compromise turns into a reportable event. Each one starts with the same question: can you show the controls were in place before the incident, or only after.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;1. DOJ Publishes a New Playbook for Charging Corporations&lt;/h3&gt;
&lt;p&gt;The Department of Justice&apos;s 2025-2026 policy reset makes declinations more predictable, narrows the use of corporate monitors, and sharpens enforcement around individual accountability, government-program fraud, and national security exposure (&lt;a href=&quot;https://www.jdsupra.com/legalnews/the-new-playbook-how-doj-decides-3930156/&quot;&gt;JD Supra&lt;/a&gt;). More predictable declinations reward the companies that can document a real compliance program, so the value of a program you can evidence just went up.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; A declination now favors firms that can produce records of controls, training, and self-reporting. Start with an assessment that captures that evidence, before you need it in front of a prosecutor.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. MiCAR Transitional Period Closes for Crypto-Asset Service Providers&lt;/h3&gt;
&lt;p&gt;The transitional window under the EU&apos;s Markets in Crypto-Assets Regulation (MiCAR) is expiring for crypto-asset service providers, and the EU&apos;s Anti-Money Laundering Authority (AMLA) issued an advisory on the money-laundering and terrorist-financing risks tied to the deadline (&lt;a href=&quot;https://www.jdsupra.com/legalnews/micar-transitional-period-for-crypto-4720643/&quot;&gt;JD Supra: MiCAR&lt;/a&gt;, &lt;a href=&quot;https://www.jdsupra.com/legalnews/amla-advisory-note-on-ml-tf-risks-as-3831856/&quot;&gt;JD Supra: AMLA&lt;/a&gt;). Firms that operated under grandfathered status now need full authorization and the anti-money-laundering controls that come with it, and the regulator has already named the gap it will be watching.&lt;/p&gt;
&lt;h3&gt;3. Australia&apos;s Enhanced CIRMP Rules Raise the Bar on Critical Infrastructure&lt;/h3&gt;
&lt;p&gt;Australia registered the Enhanced Critical Infrastructure Risk Management Program (CIRMP) Rules 2026 on June 9, formally amending the obligations that critical infrastructure operators must build into their risk programs (&lt;a href=&quot;https://www.jdsupra.com/legalnews/high-risk-higher-standards-what-the-5946965/&quot;&gt;JD Supra&lt;/a&gt;). For any operator with assets in scope, this is a documentation and governance uplift, and the responsible-entity board is the one that has to attest the program is real.&lt;/p&gt;
&lt;h3&gt;4. Aitkin County Health Breach Affects 81,000 People&lt;/h3&gt;
&lt;p&gt;Aitkin County Health and Human Services in Minnesota disclosed a breach of its email environment affecting roughly 81,000 individuals (&lt;a href=&quot;https://www.hipaajournal.com/aitkin-county-health-human-services-data-breach/&quot;&gt;HIPAA Journal&lt;/a&gt;). An email compromise at a Health and Human Services agency crosses into protected health information fast, and once it does, the HIPAA breach-notification clock and the state reporting duties both start running.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; A single mailbox compromise at a HIPAA-covered entity is a reportable-breach risk, not just an IT cleanup. The notification timeline is the obligation, and it does not wait for your investigation to finish.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;5. DoD Moves Toward Certifying Printed Circuit Boards in Defense Systems&lt;/h3&gt;
&lt;p&gt;The Department of Defense issued an advance notice of proposed rulemaking toward a Defense Federal Acquisition Regulation Supplement (DFARS) rule that would restrict certain printed circuit boards in defense systems through a certification framework (&lt;a href=&quot;https://www.jdsupra.com/legalnews/dod-considers-certification-based-9805448/&quot;&gt;JD Supra&lt;/a&gt;). For defense-industrial-base suppliers, this is another layer of supply-chain provenance to prove, and the contractors who map their board sourcing now will not scramble when the rule lands.&lt;/p&gt;
&lt;h2&gt;Additional Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;Regulatory Updates&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;SEC Updates Municipal Advisor Registration FAQs:&lt;/strong&gt; The SEC&apos;s Office of Municipal Securities refreshed its Registration of Municipal Advisors FAQs to clarify registration and recordkeeping expectations. &lt;a href=&quot;https://www.sec.gov/newsroom/press-releases/2026-66-sec-office-municipal-securities-updates-faqs-registration-municipal-advisors&quot;&gt;SEC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Education Department Finalizes Title IV Earnings Rule:&lt;/strong&gt; The US Department of Education issued a final rule on earnings accountability for Title IV programs, tying program eligibility to graduate earnings outcomes. &lt;a href=&quot;https://www.jdsupra.com/legalnews/u-s-department-of-education-finalizes-8591501/&quot;&gt;JD Supra&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Accenture Confirms Intrusion After 35GB Breach Claim:&lt;/strong&gt; Accenture confirmed a security breach after an actor claimed to have stolen 35GB of data, a reminder that your largest vendors are also your largest concentrated third-party risk. &lt;a href=&quot;https://www.hipaajournal.com/accenture-intrusion-july-2026/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>compliance news</category><category>daily briefing</category><category>DOJ enforcement</category><category>critical infrastructure</category><category>HIPAA</category><author>info@grabtheaxe.com (Dusten Trounce)</author><enclosure url="https://grabtheaxe.com/assets/news/doj-prosecution-playbook-micar-expiry-cirmp-rules-07-10-2026.webp" length="0" type="image/webp"/></item><item><title>Facewatch in Shops, Meta&apos;s Addictive Design &amp; Leaky VPN Apps (07/10/2026)</title><link>https://grabtheaxe.com/news/facewatch-shops-meta-addictive-design-android-vpn-07-10-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/facewatch-shops-meta-addictive-design-android-vpn-07-10-2026/</guid><description>Facial recognition in UK shops now alerts police in real time, the EU accuses Meta of addictive design, and 281 free Android VPNs leak the traffic they promised to hide.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/facewatch-shops-meta-addictive-design-android-vpn-07-10-2026.webp&quot; alt=&quot;Privacy Briefing: Facewatch in shops, Meta addictive design, leaky VPN apps July 10, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Facial recognition just moved from the airport and the police van into your corner shop, and in the UK it will now alert officers the moment it thinks it sees a known offender. The EU is calling Meta&apos;s autoplay and infinite scroll what they are, engineered compulsion, while a US senator tries to legislate against automated systems that decide who gets hired. The connecting thread is that the surveillance and the manipulation both run on the same fuel: your data, collected in ordinary moments, turned into leverage over you.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;1. Facial Recognition in UK Shops Will Alert Police in Real Time&lt;/h3&gt;
&lt;p&gt;Civil liberties groups are warning about Facewatch, a system rolling into UK stores including Sainsbury&apos;s and B&amp;amp;M that will flag people it identifies as serious offenders and alert police in real time (&lt;a href=&quot;https://www.theguardian.com/technology/2026/jul/10/facewatch-facial-recognition-uk-shops-instantly-alerts-police-civil-liberties&quot;&gt;The Guardian&lt;/a&gt;). A live biometric checkpoint at the door treats every shopper as a database query, and the harm from a false match lands on a person who did nothing but walk in to buy groceries.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Once a face is enrolled in a watchlist, the person cannot patch it, rotate it, or opt out. That is the Human Zero-Day at the level of the population, and the burden of a wrong match sits entirely on the individual.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. EU Accuses Meta of Ignoring the Mental Health Risks of Addictive Design&lt;/h3&gt;
&lt;p&gt;EU regulators issued preliminary findings that Meta failed to address the mental health risks of &quot;addictive design&quot; in Facebook and Instagram, naming autoplay and infinite scroll as features that drive compulsive use (&lt;a href=&quot;https://www.theguardian.com/technology/2026/jul/10/eu-accuses-meta-failing-tackle-mental-health-risks-addictive-design&quot;&gt;The Guardian&lt;/a&gt;). Regulators are treating engagement mechanics as a design choice with consequences, which is the honest way to look at a system built to hold attention past the point the user would choose to stop.&lt;/p&gt;
&lt;h3&gt;3. Senator Markey Unveils an AI Accountability Package&lt;/h3&gt;
&lt;p&gt;Senator Ed Markey introduced a set of bills aimed at curbing datacenter growth, automated hiring systems, and AI harms to children (&lt;a href=&quot;https://www.theguardian.com/technology/2026/jul/10/us-senator-unveils-ai-accountability-agenda-bills&quot;&gt;The Guardian&lt;/a&gt;). The automated-hiring piece matters most for working people, because a model that screens resumes makes a life-altering decision with no one in the room to explain it and no clear way to appeal.&lt;/p&gt;
&lt;h3&gt;4. Google&apos;s reCAPTCHA Mobile Verification Revives Remote Attestation&lt;/h3&gt;
&lt;p&gt;The EFF argues that Google&apos;s experimental reCAPTCHA Mobile Verification brings back a remote attestation scheme that is as bad as the last one, letting the platform decide which devices and configurations are allowed to reach a service (&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/googles-new-remote-attestation-scheme-every-bit-terrible-its-old-remote&quot;&gt;EFF&lt;/a&gt;). Attestation sounds like security, and in practice it hands the gatekeeper power over whether your device is trusted enough to use the open web.&lt;/p&gt;
&lt;h3&gt;5. Study Finds 281 Free Android VPN Apps Leaking and Tracking&lt;/h3&gt;
&lt;p&gt;Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found widespread traffic leaks, unencrypted data, and tracking (&lt;a href=&quot;https://thehackernews.com/2026/07/study-of-281-free-android-vpn-apps.html&quot;&gt;The Hacker News&lt;/a&gt;). People install these apps to become harder to watch, and many of them quietly do the opposite, which is the worst kind of privacy tool: one that sells confidence while leaking the thing it promised to protect.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; A free VPN monetizes the only asset it has, which is your traffic. Treat &quot;free privacy tool&quot; as a claim to verify, not a feature.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Additional Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;Privacy Laws &amp;amp; Regulations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Bank of England Gains Power Over Critical Tech Vendors:&lt;/strong&gt; UK regulators can now directly oversee &quot;critical third parties&quot; such as Amazon, Google, Oracle, and Microsoft to enforce cyber resilience across the financial system, a rare move to hold the infrastructure layer accountable rather than only the banks on top of it. &lt;a href=&quot;https://www.theguardian.com/business/2026/jul/10/bank-of-england-handed-powers-to-regulate-key-tech-firms-including-amazon-and-google&quot;&gt;The Guardian&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>privacy news</category><category>daily briefing</category><category>facial recognition</category><category>surveillance</category><category>data privacy</category><author>info@grabtheaxe.com (Jeff Welch)</author><enclosure url="https://grabtheaxe.com/assets/news/facewatch-shops-meta-addictive-design-android-vpn-07-10-2026.webp" length="0" type="image/webp"/></item><item><title>ShareFile Shutdown, Injective npm Theft &amp; Entra Passkey Fraud (07/10/2026)</title><link>https://grabtheaxe.com/news/sharefile-shutdown-injective-npm-entra-passkey-07-10-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/sharefile-shutdown-injective-npm-entra-passkey-07-10-2026/</guid><description>Progress tells ShareFile admins to pull the plug, a poisoned Injective SDK drains crypto wallets, and fake Entra passkey calls hand attackers Microsoft 365.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/sharefile-shutdown-injective-npm-entra-passkey-07-10-2026.webp&quot; alt=&quot;Security Briefing: ShareFile shutdown, Injective npm theft, Entra passkey fraud July 10, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Progress is telling ShareFile customers to power off their own servers, which tells you how bad the threat is before anyone has published a CVE. A poisoned Injective SDK on npm is draining crypto wallets, and attackers are calling Microsoft 365 users to walk them through enrolling a passkey that belongs to the attacker. The pattern this week is trust turned into a delivery mechanism: your file transfer vendor, your package registry, your own MFA enrollment flow.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;h3&gt;1. Progress Tells ShareFile Admins to Shut Down Storage Zone Controllers&lt;/h3&gt;
&lt;p&gt;Progress Software emailed ShareFile customers running on-premises Storage Zone Controllers to immediately shut the Windows servers down, citing a &quot;credible external security threat&quot; against the file-sharing product (&lt;a href=&quot;https://thehackernews.com/2026/07/urgent-progress-tells-sharefile.html&quot;&gt;The Hacker News&lt;/a&gt;, &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/&quot;&gt;BleepingComputer&lt;/a&gt;). Progress is the company behind MOVEit, and a managed file transfer product is exactly the target Cl0p-style crews mine for mass data theft, so &quot;turn it off&quot; is the right call even at the cost of downtime.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; If you run ShareFile Storage Zone Controllers on-prem, the containment step is the shutdown, not a patch you are waiting on. Assume data access, not just service disruption.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. Injective Labs GitHub Compromise Pushes Wallet-Stealing npm Package&lt;/h3&gt;
&lt;p&gt;Threat actors compromised the Injective Labs SDK GitHub repository and used it to publish a malicious npm package that steals cryptocurrency wallet private keys and mnemonic seed phrases (&lt;a href=&quot;https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html&quot;&gt;The Hacker News&lt;/a&gt;, &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/&quot;&gt;BleepingComputer&lt;/a&gt;). A trusted first-party SDK is a better delivery vehicle than any phishing email, because developers install it without a second look and ship it straight into production.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Pin dependencies to known-good versions and treat a first-party SDK update like untrusted code until you have diffed it. The registry is not a trust boundary.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;3. Exposed Server Reveals WP-SHELLSTORM Backdooring WordPress at Scale&lt;/h3&gt;
&lt;p&gt;A cybercrime crew left one of its own servers open to the internet for three weeks, exposing its tooling, activity logs, and a target list naming more than 1.4 million WordPress sites seeded with WP-SHELLSTORM backdoors (&lt;a href=&quot;https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html&quot;&gt;The Hacker News&lt;/a&gt;). The target count is the ceiling, not the confirmed compromise total, but a persistent web-shell on a fraction of that list is a large pool of resold access.&lt;/p&gt;
&lt;h3&gt;4. Fake Microsoft Entra Passkey Enrollment Hands Over Microsoft 365&lt;/h3&gt;
&lt;p&gt;A threat actor is running voice-based social engineering that pushes Microsoft 365 users to enroll a new Entra passkey, then uses that attacker-controlled credential for data-extortion access (&lt;a href=&quot;https://thehackernews.com/2026/07/hackers-use-fake-microsoft-entra.html&quot;&gt;The Hacker News&lt;/a&gt;). This is the ugly turn in the passwordless story: enrolling an attacker&apos;s passkey is phishing-resistant login for the attacker, and it survives the victim&apos;s password reset.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Lock down who can self-enroll authentication methods and alert on new passkey registrations. Passwordless does not remove the enrollment step from the threat model.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;5. Ryuk and AlphV Operators Face Prison in a Run of Ransomware Convictions&lt;/h3&gt;
&lt;p&gt;A man accused of deploying Ryuk pleaded guilty in Oregon federal court, while a Blackcat/AlphV conspirator drew a 70-month sentence in Florida, and a separate Florida ransomware negotiator was convicted for helping a gang extort US companies (&lt;a href=&quot;https://therecord.media/ryuk-operator-pleads-guilty-alphv-conspirator-sentenced&quot;&gt;The Record&lt;/a&gt;, &lt;a href=&quot;https://techcrunch.com/2026/07/10/florida-ransomware-negotiator-convicted-for-helping-ransomware-gang-extort-us-companies/&quot;&gt;TechCrunch&lt;/a&gt;). Convictions raise the personal cost of running these operations, though the affiliate model refills seats faster than courts empty them.&lt;/p&gt;
&lt;h2&gt;Additional Security Alerts&lt;/h2&gt;
&lt;h3&gt;Threat Intelligence&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Six New U-Boot Flaws Enable Boot-Time Code Execution:&lt;/strong&gt; Binarly found six vulnerabilities in the U-Boot bootloader that starts routers, smart cameras, and server management chips, four of which can run code at boot for stealthy firmware attacks below the operating system. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-u-boot-flaws-could-enable-stealthy-firmware-attacks/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security Breaches &amp;amp; Incidents&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Miinto Confirms Order-System Breach:&lt;/strong&gt; The Copenhagen fashion marketplace warned shoppers to watch for phishing after an intruder accessed its order management system. &lt;a href=&quot;https://www.theregister.com/security/2026/07/10/miinto-fesses-up-to-breach-says-customers-open-to-phishing/5269891&quot;&gt;The Register&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Cloud &amp;amp; Network Security&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CISA Details Response to Exposed AWS GovCloud Keys:&lt;/strong&gt; CISA published how it responded after sensitive AWS GovCloud credentials and internal data were committed to a public GitHub repository, a reminder that secrets in source control remain a top exposure path. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/cisa-incident-response-exposed-aws/&quot;&gt;Infosecurity Magazine&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Emerging Security Technologies&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Attacks on Healthcare Service Providers More Than Doubled:&lt;/strong&gt; Cyberattacks on hospitals grew modestly in the first half of 2026, but attacks on the service providers and business associates behind them more than doubled, moving the pressure to the softer third-party layer. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/cybercriminals-healthcare-businesses-attacks-surge&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>security news</category><category>daily briefing</category><category>ShareFile</category><category>supply chain attack</category><category>ransomware</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/sharefile-shutdown-injective-npm-entra-passkey-07-10-2026.webp" length="0" type="image/webp"/></item><item><title>Chat Control Returns, KIDS Act &amp; Meta&apos;s AI Photo Maker (07/09/2026)</title><link>https://grabtheaxe.com/news/chat-control-kids-act-meta-ai-07-09-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/chat-control-kids-act-meta-ai-07-09-2026/</guid><description>The EU&apos;s Chat Control message scanning survived a kill vote, the House passed the KIDS Act, and Meta&apos;s new AI generator can make images of users with public profiles.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/chat-control-kids-act-meta-ai-07-09-2026.webp&quot; alt=&quot;Privacy Briefing: Chat Control, KIDS Act, Meta AI photos, July 9, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The EU&apos;s Chat Control is back from the dead after a vote to kill it fell short, which puts client-side scanning of private messages on the table again for every European. At home, the House passed the KIDS Act, a bundle that would police what Americans browse and message in the name of protecting them. Both share a tell: the people being surveilled never agreed to it, and the fear doing the selling is running louder than the evidence behind it.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;1. EU &apos;Chat Control&apos; Survives a Kill Vote&lt;/h3&gt;
&lt;p&gt;The EU&apos;s Chat Control proposal survived after a vote to shelve it fell short, reviving mandatory scanning of private messages before they are encrypted (&lt;a href=&quot;https://www.theregister.com/security/2026/07/09/meps-fail-to-prevent-chat-control-snoopfest-revival/5269379&quot;&gt;The Register&lt;/a&gt;). Scanning every message on the device to catch a few treats 450 million people as suspects by default, and a scanner that reads your messages for one stated purpose is a capability that never stays limited to that purpose.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Client-side scanning is a backdoor with better branding. If it ships, treat any &quot;private&quot; channel to an EU user as readable by policy.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. House Passes the KIDS Act&lt;/h3&gt;
&lt;p&gt;The House passed the KIDS Act, a package that folds a revised Kids Online Safety Act together with browsing and messaging controls, and it now heads to the Senate (&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/house-passed-kids-act-senate-should-reject-it&quot;&gt;EFF&lt;/a&gt;). Age verification means every adult hands over an ID to use the internet, and the record of who-browsed-what becomes a standing target and a standing tool the moment it exists.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; &quot;Protect the kids&quot; laws tend to ship an adult surveillance dataset. Watch what the verification actually collects, not what the title promises.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;3. Meta&apos;s AI Image Generator Alarms Privacy Experts&lt;/h3&gt;
&lt;p&gt;Meta&apos;s new AI image generator can produce pictures of users who have public profiles, and advocates are telling people to check their settings before someone else generates them (&lt;a href=&quot;https://www.theguardian.com/technology/2026/jul/09/instagram-ai-image-generator-privacy&quot;&gt;The Guardian&lt;/a&gt;). Those public photos were posted for other people to see, and quietly repurposing them as raw material for a synthetic-image engine is consent laundering.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Tell your executives and their families to lock down public profile photos now. A public headshot is training data and impersonation fuel.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;4. EU Commission Keeps Users Behind Big Tech&apos;s Gates&lt;/h3&gt;
&lt;p&gt;The European Commission declined to force interoperability between the major social platforms, leaving EU users locked inside walled gardens they cannot easily leave (&lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/european-commission-chooses-keep-eu-users-locked-behind-big-techs-gates&quot;&gt;EFF&lt;/a&gt;). When you cannot carry your social graph elsewhere, the platform holds your relationships hostage, and that lock-in is what lets it treat your data however it likes.&lt;/p&gt;
&lt;h3&gt;5. RentGrow Pays $2.25M Over Tenant-Screening Accuracy&lt;/h3&gt;
&lt;p&gt;RentGrow, a tenant-screening provider, will pay $2.25 million to settle FTC charges that it violated the Fair Credit Reporting Act (FCRA), including by failing to ensure the accuracy of the reports landlords used to judge applicants (&lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2026/07/rentgrow-pay-225-million-settle-ftc-allegations-company-violated-fair-credit-reporting-act-ftc-act&quot;&gt;FTC&lt;/a&gt;). A wrong line in a screening file follows a family for years, into an apartment denied by a number they never saw and could not correct.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; If your business buys background or screening data on people, FCRA accuracy duties are being enforced with real dollars now. Audit your data sources.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Additional Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;Privacy Laws &amp;amp; Regulations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;FTC targets AI &quot;accuracy suppression&quot;:&lt;/strong&gt; the agency issued a proposed policy statement on accuracy and output steering in AI systems, open for public comment through July 31. &lt;a href=&quot;https://www.insideprivacy.com/consumer-protection/ftc-seeks-comment-on-proposed-policy-statement-addressing-ai-accuracy-and-output-steering/&quot;&gt;Inside Privacy&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Data Minimization &amp;amp; User Consent&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;OpenAI asks for your travel routes:&lt;/strong&gt; a verified email shows ChatGPT inviting users to share travel plans and timing to train the model, which is a lot to hand over for convenience. &lt;a href=&quot;https://pogowasright.org/do-you-want-to-train-ai-on-your-travel-planes-and-timing-really/&quot;&gt;PogoWasRight&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI recruitment gets a hard look:&lt;/strong&gt; Privacy International&apos;s investigation digs into how &quot;humanless&quot; hiring software processes and profiles applicants. &lt;a href=&quot;http://privacyinternational.org/long-read/5798/humanless-resources-uncovering-ai-recruitment-software&quot;&gt;Privacy International&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Privacy-Enhancing Technologies&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Google&apos;s remote attestation gets worse:&lt;/strong&gt; EFF says the new reCAPTCHA &quot;Mobile Verification&quot; scheme extends the walled garden and is as bad for users as the version it replaces. &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/googles-new-remote-attestation-scheme-every-bit-terrible-its-old-remote&quot;&gt;EFF&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Memorial Healthcare settles pixel case:&lt;/strong&gt; the California provider agreed to settle class-action litigation over tracking pixels that leaked patient data to advertisers. &lt;a href=&quot;https://pogowasright.org/memorial-healthcare-services-settles-pixel-litigation/&quot;&gt;PogoWasRight&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>privacy news</category><category>daily briefing</category><category>chat control</category><category>surveillance</category><category>AI privacy</category><author>info@grabtheaxe.com (Jeff Welch)</author><enclosure url="https://grabtheaxe.com/assets/news/chat-control-kids-act-meta-ai-07-09-2026.webp" length="0" type="image/webp"/></item><item><title>EU Withdrawal Button, NJ Data Broker Law &amp; HIPAA Delay (07/09/2026)</title><link>https://grabtheaxe.com/news/eu-withdrawal-button-nj-data-broker-hipaa-07-09-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/eu-withdrawal-button-nj-data-broker-hipaa-07-09-2026/</guid><description>The EU withdrawal-button rule is now in force for global sellers, New Jersey enacted the costliest data-broker law yet, and HHS postponed the HIPAA Security Rule overhaul.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/eu-withdrawal-button-nj-data-broker-hipaa-07-09-2026.webp&quot; alt=&quot;Compliance Briefing: EU withdrawal button, NJ data broker law, HIPAA delay, July 9, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Three new obligations landed for operators today. The EU&apos;s withdrawal-button rule is now in force for anyone selling to European consumers, New Jersey enacted the country&apos;s most expensive data-broker law, and healthcare entities got a reprieve on the HIPAA Security Rule overhaul. Each one adds something you now have to prove to a regulator, and the smart move on all three is to assess your exposure before someone else does it for you.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;1. EU Withdrawal Button Now in Force&lt;/h3&gt;
&lt;p&gt;Article 11a of EU Directive 2023/2673 took effect on 19 June 2026, requiring online sellers to give EU consumers a prominent withdrawal button to cancel distance contracts, and it reaches US and global sellers serving EU customers (&lt;a href=&quot;https://www.jdsupra.com/legalnews/new-eu-withdrawal-button-requirement-6098088/&quot;&gt;JD Supra&lt;/a&gt;). If your checkout takes the order in three clicks while cancellation takes ten, you are now out of step with the rule, and the fix is a change to the interface and the process, not a policy memo.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Map every EU-facing subscription and distance contract, then time the cancellation flow. If it is harder than signing up, it needs work now.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. New Jersey Enacts the Costliest Data Broker Law Yet&lt;/h3&gt;
&lt;p&gt;New Jersey enacted A5328, the nation&apos;s most expensive data-broker law, with annual registration fees running from $5,000 to $1.5 million and a definition broad enough to sweep in companies that never called themselves data brokers (&lt;a href=&quot;https://www.jdsupra.com/legalnews/new-jersey-enacts-the-nation-s-6387744/&quot;&gt;JD Supra&lt;/a&gt;). The registration net is wide, so the first task is deciding whether you meet the definition, because guessing wrong is a fee and a penalty rather than a rounding error.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; If you buy, sell, license, or enrich third-party personal data, assume you are in scope until counsel says otherwise.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;3. HIPAA Security Rule Overhaul Postponed&lt;/h3&gt;
&lt;p&gt;HHS postponed the timeline for the major HIPAA Security Rule overhaul, giving regulated entities more room to prepare for the proposed changes (&lt;a href=&quot;https://www.hipaajournal.com/hipaa-security-rule-update-postponed/&quot;&gt;HIPAA Journal&lt;/a&gt;). The delay is breathing room, and the organizations that use it to run a gap assessment now will not be the ones scrambling when the clock restarts.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Use the extra time to baseline against the proposed rule. The requirements are still coming, and the assessment is the cheap part.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;4. EU Publishes AI Content Transparency Code&lt;/h3&gt;
&lt;p&gt;The European Commission published its Code of Practice on Transparency of AI-Generated Content, setting expectations for labeling synthetic media, though it is not yet formally endorsed (&lt;a href=&quot;https://www.jdsupra.com/legalnews/eu-code-of-practice-on-transparency-of-1727707/&quot;&gt;JD Supra&lt;/a&gt;). If your marketing, product, or support functions generate AI content, the labeling obligation is close enough to start building the workflow, because retrofitting disclosure across a content library costs far more than baking it in.&lt;/p&gt;
&lt;h3&gt;5. Only 26% of Companies Have AI Governance Aligned&lt;/h3&gt;
&lt;p&gt;Only 26% of companies say their governance frameworks are fully aligned with their AI adoption, and few report a measurable return on the AI spend (&lt;a href=&quot;https://www.corporatecomplianceinsights.com/news-roundup-july-8-2026/&quot;&gt;Corporate Compliance Insights&lt;/a&gt;). Deploying AI faster than you govern it is how you end up owning the liability without the payback, and the assessment that closes that gap costs far less than the incident that exposes it.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; If AI is already in your operations, an AI governance and risk assessment is overdue. You cannot manage the liability you have not mapped.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Additional Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;Regulatory Updates&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MiCAR transition period ends:&lt;/strong&gt; the transitional window for crypto-asset service providers under the EU&apos;s Markets in Crypto-Assets Regulation (MiCAR) has expired, and the Anti-Money Laundering Authority (AMLA) issued an advisory on the money-laundering risks of the changeover. &lt;a href=&quot;https://www.jdsupra.com/legalnews/amla-advisory-note-on-ml-tf-risks-as-3831856/&quot;&gt;JD Supra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;FINRA enforcement under review:&lt;/strong&gt; FINRA published an external review of its enforcement program, with recommendations member firms should read before their next exam. &lt;a href=&quot;https://www.jdsupra.com/legalnews/finra-enforcement-program-external-2500375/&quot;&gt;JD Supra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;DoD eyes circuit board restrictions:&lt;/strong&gt; the Department of Defense issued an advance notice of proposed rulemaking toward a certification framework restricting certain printed circuit boards in defense systems. &lt;a href=&quot;https://www.jdsupra.com/legalnews/dod-considers-certification-based-9805448/&quot;&gt;JD Supra&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Policy &amp;amp; Governance Updates&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;SEC to revisit the IPO process:&lt;/strong&gt; the SEC will host a July 13 virtual roundtable on modernizing IPOs and expanding access to public markets. &lt;a href=&quot;https://www.sec.gov/newsroom/press-releases/2026-65-sec-host-virtual-roundtable-modernizing-ipos-expanding-access-public-markets&quot;&gt;SEC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Healthcare&apos;s risk problem reframed:&lt;/strong&gt; analysts argue the healthcare challenge has moved from maintaining compliance to gaining enough visibility and accountability to manage enterprise risk. &lt;a href=&quot;https://www.jdsupra.com/legalnews/healthcare-has-a-risk-and-compliance-3532619/&quot;&gt;JD Supra&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>compliance news</category><category>daily briefing</category><category>data broker law</category><category>HIPAA</category><category>AI governance</category><author>info@grabtheaxe.com (Dusten Trounce)</author><enclosure url="https://grabtheaxe.com/assets/news/eu-withdrawal-button-nj-data-broker-hipaa-07-09-2026.webp" length="0" type="image/webp"/></item><item><title>RoguePlanet Defender Fix, GigaWiper &amp; $1M County Ransom (07/09/2026)</title><link>https://grabtheaxe.com/news/rogueplanet-defender-gigawiper-county-ransom-07-09-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/rogueplanet-defender-gigawiper-county-ransom-07-09-2026/</guid><description>Microsoft patched the RoguePlanet Defender zero-day after a month of public exploit code, a new GigaWiper backdoor bundles wipers, and a US county paid $1M ransom.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/rogueplanet-defender-gigawiper-county-ransom-07-09-2026.webp&quot; alt=&quot;Security Briefing: RoguePlanet patch, GigaWiper, county ransom, July 9, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Microsoft finally shipped the fix for RoguePlanet, the Defender privilege-escalation zero-day that sat exposed for a month with working exploit code in the open, so the patch window is a race you are already behind on. The same day brought GigaWiper, a destructive backdoor assembled from three older malware families, and a leaked negotiation showing a US county quietly wired $1 million to its extortionists. The theme today is cheap advantage: attackers reusing old code, old accounts, and your own patch lag.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;h3&gt;1. Microsoft Patches RoguePlanet Defender Zero-Day&lt;/h3&gt;
&lt;p&gt;Microsoft patched RoguePlanet (CVE-2026-50656, CVSS 7.8), a Windows Defender flaw that hands an attacker SYSTEM privileges, nearly a month after the researcher Nightmare-Eclipse published a working proof-of-concept (&lt;a href=&quot;https://www.theregister.com/security/2026/07/09/microsoft-closes-book-on-nightmare-eclipses-rogueplanet-zero-day/5269280&quot;&gt;The Register&lt;/a&gt;, &lt;a href=&quot;https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.html&quot;&gt;The Hacker News&lt;/a&gt;). A month of public exploit code aimed at the security tool that is supposed to be watching the box is how a routine foothold becomes full control.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Patch Defender now and assume anything unpatched since June was reachable. Public exploit code means the attack was automated, not hypothetical.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. GigaWiper Backdoor Bundles Wiping, Fake Ransomware, and Spyware&lt;/h3&gt;
&lt;p&gt;Microsoft dissected GigaWiper, a destructive backdoor that combines disk-wiping, fake-ransomware, and spyware modules lifted from several older malware families into one platform the operator can pick from (&lt;a href=&quot;https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/&quot;&gt;Microsoft&lt;/a&gt;, &lt;a href=&quot;https://thehackernews.com/2026/07/new-gigawiper-windows-backdoor-bundles.html&quot;&gt;The Hacker News&lt;/a&gt;). Reusing proven destructive code keeps the attacker&apos;s cost down and your detection harder, because each borrowed piece already carries its own evasion.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; A wiper wearing a ransomware mask turns your &quot;pay and recover&quot; plan into a trap. Back up like recovery is the only option, because against a wiper it is.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;3. US County Paid $1 Million Extortion Demand&lt;/h3&gt;
&lt;p&gt;Leaked negotiation logs show an unnamed US county, possibly in Ohio, paid a $1 million extortion demand, with the full haggling exchange now public (&lt;a href=&quot;https://www.theregister.com/cyber-crime/2026/07/09/an-unnamed-us-county-perhaps-in-ohio-paid-1m-extortion-demand-to-cybercriminals/5269575&quot;&gt;The Register&lt;/a&gt;). Thin budgets and thin security staffing make local government a reliable payday, and every disclosed payment prices the next demand for the county down the road.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; A leaked ransom transcript is free adversary training. Assume your own incident calls could end up public and decide the messaging before you need it.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;4. Dormant GitHub Accounts Used to Map Corporate Orgs&lt;/h3&gt;
&lt;p&gt;Datadog Security Labs flagged overlapping campaigns using dormant GitHub accounts and automated scraping to enumerate corporate GitHub organizations, repositories, and users through the API (&lt;a href=&quot;https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html&quot;&gt;The Hacker News&lt;/a&gt;). Old, trusted-looking accounts blend into your contributor graph while the operator maps who works where and which repos hold the secrets, all before a single exploit.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Audit org membership and outside collaborators. A contributor account that has sat idle for two years is reconnaissance waiting to happen.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;5. npm 12 Disables Install Scripts by Default&lt;/h3&gt;
&lt;p&gt;GitHub shipped npm 12 with install scripts disabled by default and granular access tokens deprecated, closing two of the most abused supply-chain paths in the JavaScript ecosystem (&lt;a href=&quot;https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html&quot;&gt;The Hacker News&lt;/a&gt;). Install-script execution on &lt;code&gt;npm install&lt;/code&gt; has been the quiet delivery mechanism behind a long line of wallet stealers and credential grabbers, so this default finally flips the economics against the attacker.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Test your builds against the new default before it breaks a pipeline, and stop depending on postinstall hooks you cannot audit.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Additional Security Alerts&lt;/h2&gt;
&lt;h3&gt;Threat Intelligence&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;GodDamn ransomware disables defenses with a kernel driver:&lt;/strong&gt; the new family loads the PoisonX signed driver to neutralize endpoint security before it encrypts. &lt;a href=&quot;https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Injective SDK poisoned on npm:&lt;/strong&gt; attackers compromised the Injective Labs GitHub repo and pushed a malicious npm package that steals crypto wallet keys and seed phrases. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Iran broadens its targeting:&lt;/strong&gt; researchers warn Iranian activity now reaches well beyond critical infrastructure, so any internet-facing vulnerability is in scope. &lt;a href=&quot;https://www.darkreading.com/cyber-risk/iran-cyber-crosshairs-beyond-critical-infrastructure&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security Breaches &amp;amp; Incidents&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;OpenMandriva reports attempted sabotage:&lt;/strong&gt; the Linux project says a contributor tried to sabotage it after an internal dispute. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/openmandriva-linux-says-contributor-tried-to-sabotage-the-project/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Cloud &amp;amp; Network Security&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Talos discloses 18 vulnerabilities:&lt;/strong&gt; Cisco Talos reported three flaws in WolfSSL, fourteen in GeoVision, and one in VTK-DICOM, all now patched by the vendors. &lt;a href=&quot;https://blog.talosintelligence.com/wolfssl-vulnerabilities/&quot;&gt;Cisco Talos&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Emerging Security Technologies&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AI agents are a new identity class:&lt;/strong&gt; treating them like service accounts or API tokens leaves a gap most organizations have not closed. &lt;a href=&quot;https://www.darkreading.com/identity-access-management-security/ai-agents-new-kind-identity-most-organizations-not-ready&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Microsoft warns of heavier Patch Tuesdays:&lt;/strong&gt; AI-driven vulnerability discovery will push patch volume up, and Redmond is using that to sell auto-patching. &lt;a href=&quot;https://www.theregister.com/security/2026/07/10/microsoft-warns-customers-ai-will-mean-busier-patch-tuesdays/5269618&quot;&gt;The Register&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>security news</category><category>daily briefing</category><category>RoguePlanet</category><category>ransomware</category><category>supply chain</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/rogueplanet-defender-gigawiper-county-ransom-07-09-2026.webp" length="0" type="image/webp"/></item><item><title>BeyondTrust Bug, ColdFusion Exploit &amp; GitLost Leak (07/07/2026)</title><link>https://grabtheaxe.com/news/beyondtrust-coldfusion-gitlost-07-07-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/beyondtrust-coldfusion-gitlost-07-07-2026/</guid><description>BeyondTrust patched two critical auth-bypass flaws in remote access, a maximum-severity Adobe ColdFusion bug is under active exploitation, and GitLost leaks private repos.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/beyondtrust-coldfusion-gitlost-07-07-2026.webp&quot; alt=&quot;Security Briefing: BeyondTrust flaw, ColdFusion exploit, GitLost leak, July 7, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today&apos;s stories share one theme: the front door. BeyondTrust and Tenda both shipped products that let an unauthenticated attacker walk straight in, an Adobe ColdFusion bug scored a perfect 10.0 and is already under attack, and a flaw called GitLost turns a public GitHub issue into a pipe out of your private code. Every one of these is a same-week patch, not a next-quarter one.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;h3&gt;1. BeyondTrust Patches Two Critical Auth-Bypass Flaws in Remote Access&lt;/h3&gt;
&lt;p&gt;BeyondTrust released fixes for two critical flaws in its Remote Support and Privileged Remote Access products that let unauthenticated attackers take control of vulnerable devices (&lt;a href=&quot;https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html&quot;&gt;The Hacker News&lt;/a&gt;, &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/&quot;&gt;BleepingComputer&lt;/a&gt;). Privileged access tooling is the skeleton key of a network: it exists to reach every other system, so a bypass here hands an attacker the same reach your administrators have.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Remote access appliances are the highest-value target you run. Patch this the day you read it, then check logs for access you cannot account for.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. Adobe ColdFusion Flaw at CVSS 10.0 Under Active Exploitation&lt;/h3&gt;
&lt;p&gt;Attackers are exploiting a path-traversal flaw in Adobe ColdFusion, tracked as CVE-2026-48282, that carries the maximum possible severity score of 10.0 (&lt;a href=&quot;https://www.infosecurity-magazine.com/news/exploit-maximum-severity-adobe/&quot;&gt;Infosecurity Magazine&lt;/a&gt;). Exploitation depends on the Remote Development Services feature being enabled with its authentication turned off, a non-default setup that plenty of teams still run. If that describes any of your internet-facing ColdFusion servers, patch to the current update today.&lt;/p&gt;
&lt;h3&gt;3. GitLost Leaks Private Repos From a Public GitHub Issue&lt;/h3&gt;
&lt;p&gt;Researchers disclosed a flaw dubbed GitLost that lets an unauthenticated attacker open an ordinary-looking issue on an organization&apos;s public repository and silently pull data out of its private repositories (&lt;a href=&quot;https://www.darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows&quot;&gt;Dark Reading&lt;/a&gt;, &lt;a href=&quot;https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html&quot;&gt;The Hacker News&lt;/a&gt;). No stolen credentials, no insider, just a crafted issue that an agentic workflow reads and acts on. This is the cost of wiring AI agents into your build pipeline without treating their inputs as hostile.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Any AI agent with repo access is a new trust boundary. Treat every issue, comment, and pull request it reads as attacker-controlled input.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;4. Hidden Backdoor Found in Tenda Router Firmware&lt;/h3&gt;
&lt;p&gt;The CERT Coordination Center warned that several versions of Tenda router firmware ship with an undocumented authentication backdoor that grants administrative access to the web management panel (&lt;a href=&quot;https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html&quot;&gt;The Hacker News&lt;/a&gt;, &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/&quot;&gt;BleepingComputer&lt;/a&gt;). A backdoor in an edge router is initial access and persistence in one package, and consumer-grade gear like this often sits on the same networks as the small businesses attackers love.&lt;/p&gt;
&lt;h3&gt;5. Japanese Telco Breach Exposes 12 Million Email Accounts&lt;/h3&gt;
&lt;p&gt;A cyberattack on a major Japanese telecommunications company exposed roughly 12 million customer email accounts across five internet service providers (&lt;a href=&quot;https://therecord.media/major-japanese-telco-cyberattack-12-million-emails&quot;&gt;The Record&lt;/a&gt;). Email is the master key to the rest of a person&apos;s digital life, because password resets for banking, work, and everything else land there. A breach of this size is raw material for the next wave of account takeovers.&lt;/p&gt;
&lt;h2&gt;Additional Security Alerts&lt;/h2&gt;
&lt;h3&gt;Threat Intelligence&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;UAT-7810 expands its ORB network with LONGLEASH malware:&lt;/strong&gt; Chinese operators are compromising unpatched Ruckus routers to grow an operational relay box network that hides the origin of later attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;China-aligned cluster hits universities through Roundcube:&lt;/strong&gt; A suspected Chinese group is exploiting Roundcube webmail flaws at US and Canadian university physics and engineering departments to harvest credentials. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/china-aligned-cluster-roundcube/&quot;&gt;Infosecurity Magazine&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;RedWing rents Android bank fraud on Telegram:&lt;/strong&gt; A malware-as-a-service operation lets low-skill criminals take over a victim&apos;s phone, steal banking logins, and capture one-time codes. &lt;a href=&quot;https://thehackernews.com/2026/07/redwing-maas-packages-android-bank.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Social Engineering&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;DEBULL abuses Microsoft device-code flow:&lt;/strong&gt; A campaign uses collaboration-themed lures to hijack Microsoft 365 accounts without ever showing a fake password page. &lt;a href=&quot;https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fake Facebook verification phishing:&lt;/strong&gt; Attackers target business users with a bogus verification offer and a compromised chatbot to steal sensitive account data. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/phishing-facebook-fake-verification/&quot;&gt;Infosecurity Magazine&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Emerging Security Technology&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Dialogflow CX &apos;Rogue Agent&apos; flaw enabled data theft:&lt;/strong&gt; A now-patched Google flaw let an attacker with edit rights on one chatbot agent compromise others in the same project and read live conversations. &lt;a href=&quot;https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Writer AI &apos;WriteOut&apos; allowed cross-tenant compromise:&lt;/strong&gt; A now-patched one-click flaw in the enterprise AI platform could leak session tokens between tenants. &lt;a href=&quot;https://thehackernews.com/2026/07/writer-ai-flaw-could-let-agent-previews.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Britain plans an autonomous AI &apos;Cyber Shield&apos;:&lt;/strong&gt; The NCSC is building a capability to counter attacks that move at machine speed and greater scale. &lt;a href=&quot;https://therecord.media/britain-plans-autonomous-ai-cyber-shield&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Cloud &amp;amp; Network Security&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CAI cloud worm evicts rival malware, then mines:&lt;/strong&gt; A worm boots competitors&apos; malware off compromised cloud hosts before stealing secrets and mining cryptocurrency. &lt;a href=&quot;https://www.theregister.com/cyber-crime/2026/07/07/cai-cloud-worm-gives-competitors-malware-the-boot-then-steals-secrets-and-mines-for-coin/5267856&quot;&gt;The Register&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Threat Intelligence&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Spain arrests suspected pro-Russia hacktivist:&lt;/strong&gt; Police detained a man suspected of active membership in CARR and Z-Pentest following an FBI tip. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/spain-arrests-suspected-member-of-pro-russian-hacktivist-groups/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>security news</category><category>daily briefing</category><category>BeyondTrust</category><category>ColdFusion</category><category>vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/beyondtrust-coldfusion-gitlost-07-07-2026.webp" length="0" type="image/webp"/></item><item><title>Chat Control Vote, In-Car Cameras &amp; Health Data Suits (07/07/2026)</title><link>https://grabtheaxe.com/news/chat-control-car-cameras-health-data-07-07-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/chat-control-car-cameras-health-data-07-07-2026/</guid><description>The EU Parliament advanced Chat Control message scanning, new EU cars must carry a driver-monitoring camera, and a health data sharing suit against Veradigm moves ahead.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/chat-control-car-cameras-health-data-07-07-2026.webp&quot; alt=&quot;Privacy Briefing: Chat Control vote, in-car cameras, health data suits, July 7, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Every story in today&apos;s privacy roundup asks the same question: who gets to watch you, and did anyone ask first. The EU Parliament moved to fast-track a vote on scanning private messages before they leave your phone. New cars in Europe now come with a camera pointed at the driver&apos;s face. And a health-tech company must face trial over piping patient data to Google. None of these waited for consent.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;1. EU Parliament Fast-Tracks a Chat Control Vote&lt;/h3&gt;
&lt;p&gt;The European Parliament narrowly voted 331 to 304 to use an urgent procedure that fast-tracks a Thursday vote on extending the EU&apos;s temporary regime for scanning private messages to detect child sexual abuse material, the rules critics call Chat Control (&lt;a href=&quot;https://www.heise.de/en/news/Showdown-in-Strasbourg-The-unexpected-return-of-Chat-Control-1-0-11356680.html&quot;&gt;Heise&lt;/a&gt;). The regime permits client-side scanning, where content is checked on the sender&apos;s device before encryption protects it, and the procedural move raises the bar for rejecting it. Scanning a message on your device before it is encrypted weakens the promise of encryption for everyone, not just the people under suspicion.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Client-side scanning turns every private device into a checkpoint. If your people handle sensitive material, the threat model now includes the phone itself, not just the network it rides on.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. Every New EU Car Must Watch the Driver&apos;s Face&lt;/h3&gt;
&lt;p&gt;New rules require every new car sold in the European Union to carry a driver-monitoring camera that tracks the driver&apos;s attention and face (&lt;a href=&quot;https://allaboutcookies.org/eu-mandatory-distracted-driver-system&quot;&gt;All About Cookies&lt;/a&gt;). The stated goal is safety, and distracted driving is a real harm. The privacy cost is that a biometric sensor now sits in the cabin of every new vehicle by default, and where that footage goes and how long it lives are decisions made by manufacturers, not drivers.&lt;/p&gt;
&lt;h3&gt;3. Health Data Sharing Suit Against Veradigm Advances&lt;/h3&gt;
&lt;p&gt;A court refused to dismiss a proposed class action alleging that health-technology provider Veradigm shared patients&apos; health information with Google without consent, in violation of state and federal privacy law (&lt;a href=&quot;https://pogowasright.org/veradigm-loses-bid-to-toss-suit-over-data-sharing-with-google/&quot;&gt;PogoWasRight&lt;/a&gt;). Health data is the most intimate record a person keeps, and routing it to an advertising company treats a private medical fact as a marketing signal. The tracking tag someone added years ago is now the evidence in a lawsuit.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; If your systems touch health data, inventory every third-party tag and SDK now. The pixel you forgot is the liability you will litigate.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;4. Supreme Court Lets Texas App Age-Verification Law Take Effect&lt;/h3&gt;
&lt;p&gt;The Supreme Court declined to block the Texas App Store Accountability Act, letting a law that requires app stores to verify users&apos; ages take effect while the case continues (&lt;a href=&quot;https://therecord.media/supreme-court-allows-texas-app-law-age-verification-to-take-effect&quot;&gt;The Record&lt;/a&gt;). Age verification sounds narrow, but in practice it means collecting identity documents or biometric estimates from every user, including the adults the law was not written to protect. A rule meant to shield children ends up building an identity database for everyone.&lt;/p&gt;
&lt;h3&gt;5. Meta&apos;s Muse Image Can Pull Other People Into AI Photos&lt;/h3&gt;
&lt;p&gt;Meta&apos;s new Muse Image model, now powering AI image tools across Instagram, WhatsApp, and the Meta AI app, can insert other Instagram users into AI-generated photos (&lt;a href=&quot;https://www.theverge.com/tech/962485/meta-muse-image-ai-model-instagram&quot;&gt;The Verge&lt;/a&gt;). A person&apos;s face and likeness are becoming raw material for images they never posed for and never approved. When your likeness can appear in a scene you were never in, the harm is reputational and hard to undo.&lt;/p&gt;
&lt;h2&gt;Additional Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;Data Minimization &amp;amp; User Consent&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Patients sue healthcare corporations over data handling:&lt;/strong&gt; A wave of class actions accuses large healthcare companies of exposing or sharing patients&apos; personal and health information. &lt;a href=&quot;https://pogowasright.org/patients-sue-healthcare-corporations-over-data-breaches-sharing-of-personal-information/&quot;&gt;PogoWasRight&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;EFF on automated moderation:&lt;/strong&gt; The group argues that platform moderation by algorithm is here to stay and needs transparency and a real path to appeal. &lt;a href=&quot;https://www.eff.org/deeplinks/2026/07/part-1-automated-moderation-here-stay&quot;&gt;EFF&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;FTC returns $2.7 million to gig workers:&lt;/strong&gt; The agency is sending checks to consumers harmed by Handy Technologies&apos; deceptive earnings claims. &lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2026/07/ftc-sends-more-27-million-consumers-harmed-handy-technologies&quot;&gt;FTC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Predator spyware victims file 8 million euro suit:&lt;/strong&gt; Greek victims are suing the spyware maker as campaigners press the EU to act on spyware abuse. &lt;a href=&quot;https://www.theregister.com/security/2026/07/07/predatorgate-victims-launch-8m-sueball-at-spyware-maker/5267766&quot;&gt;The Register&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>privacy news</category><category>daily briefing</category><category>chat control</category><category>biometric surveillance</category><category>health data</category><author>info@grabtheaxe.com (Jeff Welch)</author><enclosure url="https://grabtheaxe.com/assets/news/chat-control-car-cameras-health-data-07-07-2026.webp" length="0" type="image/webp"/></item><item><title>SEC Fraud Group, Breach Settlement &amp; EU Directive (07/07/2026)</title><link>https://grabtheaxe.com/news/sec-fraud-healthcare-breach-eu-directive-07-07-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/sec-fraud-healthcare-breach-eu-directive-07-07-2026/</guid><description>The SEC formed a Retail Fraud Working Group, Calibrated Healthcare settled a breach class action, and the EU Anti-Corruption Directive gives compliance teams new obligations.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/sec-fraud-healthcare-breach-eu-directive-07-07-2026.webp&quot; alt=&quot;Compliance Briefing: SEC fraud group, healthcare breach settlement, EU directive, July 7, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today&apos;s compliance stories each create a new obligation or a new bill to pay. The SEC stood up a dedicated group to chase fraud against retail investors, a healthcare company is paying to settle a breach it disclosed months ago, and the EU handed compliance teams a fresh directive to operationalize. Each one is an item to plan around before it becomes an enforcement action.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;1. SEC Forms a Retail Fraud Working Group&lt;/h3&gt;
&lt;p&gt;The Securities and Exchange Commission announced a new Retail Fraud Working Group to strengthen its enforcement efforts against fraud that targets everyday investors (&lt;a href=&quot;https://www.sec.gov/newsroom/press-releases/2026-63-sec-forms-new-retail-fraud-working-group&quot;&gt;SEC&lt;/a&gt;). A dedicated enforcement unit is a signal of where the agency will spend its attention, and firms that touch retail investors should read it as notice. The time to test your disclosures and sales practices is before the group comes looking, not after.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; When a regulator names a focus area, treat it as a scoping document for your next internal review. Assess your retail-facing controls now, while it is still voluntary.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. Calibrated Healthcare Settles Breach Class Action&lt;/h3&gt;
&lt;p&gt;Calibrated Healthcare agreed to settle a class action lawsuit stemming from a data breach that began in February (&lt;a href=&quot;https://www.hipaajournal.com/calibrated-healthcare-data-breach-settlement/&quot;&gt;HIPAA Journal&lt;/a&gt;). The settlement is the part people forget to budget for. The breach is the security event; the class action is the financial one, and it lands long after the incident is closed. Containment ends the security incident, and the bill can still arrive months later.&lt;/p&gt;
&lt;h3&gt;3. EU Anti-Corruption Directive Gives Teams a New Roadmap&lt;/h3&gt;
&lt;p&gt;Compliance analysts published a practical roadmap for operationalizing the EU Anti-Corruption Directive, noting that programs measured against the new directive tend to fall into three maturity stages (&lt;a href=&quot;https://www.corporatecomplianceinsights.com/operationalizing-eu-anti-corruption-directive/&quot;&gt;Corporate Compliance Insights&lt;/a&gt;). A directive is only as real as the controls you build to meet it, and the gap between policy and practice is exactly where enforcement finds you. Map your current program against the directive before an auditor does it for you.&lt;/p&gt;
&lt;h3&gt;4. California Regional Center Notifies of 2024 Ransomware Attack&lt;/h3&gt;
&lt;p&gt;The North Los Angeles County Regional Center began notifying individuals affected by a ransomware attack that occurred in November 2024 (&lt;a href=&quot;https://www.hipaajournal.com/north-los-angeles-county-regional-center-ransomware-attack/&quot;&gt;HIPAA Journal&lt;/a&gt;). A notification arriving well over a year after the incident invites hard questions from regulators about when the breach was discovered and why notice took this long. The obligation to notify starts the moment you discover the breach, so the legal steps belong inside your incident plan, written in before you need them.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Put your breach-notification deadlines in the incident response plan itself, with named owners. A slow notice is its own violation, separate from the breach.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;5. New HIPAA Guidance Reminds Owners the Buck Stops With Them&lt;/h3&gt;
&lt;p&gt;Fresh guidance for small practice owners stresses that HIPAA responsibility sits with the practice regardless of what gets delegated, because the practice answers to the Office for Civil Rights, not the vendor (&lt;a href=&quot;https://www.hipaajournal.com/small-practice-owners-hipaa-compliance-programs/&quot;&gt;HIPAA Journal&lt;/a&gt;). Delegating the work does not delegate the liability. Owners who assume a vendor absorbed the risk tend to learn otherwise during an investigation.&lt;/p&gt;
&lt;h2&gt;Additional Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;Policy &amp;amp; Governance Updates&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;A guide to governance at US broker-dealers:&lt;/strong&gt; New analysis walks through the fiduciary duties, regulations, and oversight that shape broker-dealer governance. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/helpful-guide-corporate-governance-us-registered-broker-dealer/&quot;&gt;Corporate Compliance Insights&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The challenges facing the board of 2030:&lt;/strong&gt; Analysts point to AI-driven information loss, global conflict, and rising accountability standards as the pressures boards should prepare for now. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/anticipating-acting-challenges-chair-board-2030/&quot;&gt;Corporate Compliance Insights&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;On red cards and control failures:&lt;/strong&gt; A governance column uses a public misstep to illustrate how weak internal controls let bad decisions through. &lt;a href=&quot;https://www.radicalcompliance.com/2026/07/07/on-red-cards-and-control-failures/&quot;&gt;Radical Compliance&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>compliance news</category><category>daily briefing</category><category>SEC enforcement</category><category>HIPAA</category><category>anti-corruption</category><author>info@grabtheaxe.com (Dusten Trounce)</author><enclosure url="https://grabtheaxe.com/assets/news/sec-fraud-healthcare-breach-eu-directive-07-07-2026.webp" length="0" type="image/webp"/></item><item><title>AI Ransomware, NetScaler Flaw &amp; Linux VM Escape (07/06/2026)</title><link>https://grabtheaxe.com/news/ai-ransomware-netscaler-flaw-kvm-vm-escape-07-06-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ai-ransomware-netscaler-flaw-kvm-vm-escape-07-06-2026/</guid><description>An AI agent ran a real ransomware attack, a fresh CitrixBleed-style NetScaler flaw is under active exploit, and a 16-year-old Linux KVM bug lets guest VMs escape to the host.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ai-ransomware-netscaler-flaw-kvm-vm-escape-07-06-2026.webp&quot; alt=&quot;Security Briefing: AI ransomware, NetScaler flaw, KVM escape, July 6, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today&apos;s stories point one direction: the cost of running an attack keeps dropping. An AI agent executed a real ransomware intrusion from start to finish, a NetScaler flaw went from proof-of-concept to active exploitation in days, and a bug that sat in the Linux hypervisor for sixteen years lets a guest virtual machine break out onto the host it runs on.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;h3&gt;1. An AI Agent Ran a Complete Ransomware Attack&lt;/h3&gt;
&lt;p&gt;An &quot;agentic threat actor&quot; exploited a flaw in Langflow to steal data from a production database and encrypt other systems, in what Dark Reading calls the first complete &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack&quot;&gt;LLM-driven ransomware attack&lt;/a&gt;. The detail that matters, per &lt;a href=&quot;https://techcrunch.com/2026/07/06/the-first-ai-run-ransomware-attack-still-needed-a-human/&quot;&gt;TechCrunch&apos;s reporting&lt;/a&gt;, is that a human still picked the victim and stood up the infrastructure. The model handled execution, not intent.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; When execution gets cheap, your window between exposure and exploitation shrinks. Expect more attempts, not smarter ones, and shorten your patch and detection cycles to match.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. NetScaler Flaw Under Attack, CitrixBleed All Over Again&lt;/h3&gt;
&lt;p&gt;Attackers began hitting a new memory-disclosure flaw in Citrix NetScaler within days of researchers publishing a proof-of-concept, a near-replay of the original CitrixBleed (&lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/citrixbleed-ing-again-netscaler-vulnerability-under-attack&quot;&gt;Dark Reading&lt;/a&gt;). Memory-disclosure bugs on an internet-facing appliance leak session tokens, and a stolen session skips your authentication entirely.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Edge devices are the cheapest door an attacker will try. If you run NetScaler, treat this as a same-week patch, not a next-quarter one.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;3. 16-Year-Old Linux KVM Bug Lets a Guest Escape to the Host&lt;/h3&gt;
&lt;p&gt;A use-after-free flaw in Linux&apos;s KVM hypervisor, present for sixteen years and dubbed Januscape, can be triggered from inside a guest virtual machine to corrupt the host kernel&apos;s memory on both Intel and AMD systems (&lt;a href=&quot;https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html&quot;&gt;The Hacker News&lt;/a&gt;). VM escape is the exact failure mode multi-tenant clouds are built to prevent, so one compromised tenant reaching the host puts every tenant on that host in the blast radius.&lt;/p&gt;
&lt;h3&gt;4. BusySnake Infostealer Hits Critical Infrastructure&lt;/h3&gt;
&lt;p&gt;A group researchers track as Armored Likho used the BusySnake infostealer to breach government agencies and electrical power entities in Russia, Brazil, and Kazakhstan (&lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/busysnake-infostealer-critical-infrastructure-networks&quot;&gt;Dark Reading&lt;/a&gt;). Infostealers are the quiet first stage: reconnaissance and credential harvesting that set up the loud stage later.&lt;/p&gt;
&lt;h3&gt;5. Iran-Linked Group Aims New C2 at Israeli Organizations&lt;/h3&gt;
&lt;p&gt;An Iranian group tied to the Ministry of Intelligence deployed a previously undocumented modular command-and-control framework, Cavern, against Israeli government and IT-sector organizations (&lt;a href=&quot;https://thehackernews.com/2026/07/iran-linked-hackers-use-new-cavern-c2.html&quot;&gt;The Hacker News&lt;/a&gt;). State-linked C2 against a specific sector is a targeting signal. If you sit in that supply chain, assume you are on the list.&lt;/p&gt;
&lt;h2&gt;Additional Security Alerts&lt;/h2&gt;
&lt;h3&gt;Threat Intelligence&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Canada ran offensive cyber operations in 2025:&lt;/strong&gt; Canada&apos;s CSE disclosed operations against a ransomware-as-a-service gang, a foreign extremist group, and drug traffickers. &lt;a href=&quot;https://therecord.media/canada-cse-2025-cyber-operations-ransomware-drugs-extremism&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Attackers voted themselves $20M in BONK:&lt;/strong&gt; A malicious governance proposal let holders drain roughly $20 million from BonkDAO, a reminder that on-chain governance is an attack surface. &lt;a href=&quot;https://therecord.media/attackers-vote-themselves-20-million-bonk-crypto&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security Breaches &amp;amp; Incidents&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Medical device maker notifies nearly 4 million:&lt;/strong&gt; Social Security numbers and health data were accessed in a breach at a major medical device manufacturer. &lt;a href=&quot;https://therecord.media/medical-device-maker-notifies-nearly-4-million-of-breach&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Social Engineering&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;EtherRAT via fake Teams IT support:&lt;/strong&gt; Attackers impersonate corporate IT on Microsoft Teams voice calls to trick employees into installing EtherRAT for initial access. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Job-interview phishing at scale:&lt;/strong&gt; A campaign impersonating more than 30 brands, including Adobe, Netflix, and OpenAI, uses fake job interviews to steal Google credentials. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Emerging Security Technology&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Prompt injection targets AI agents:&lt;/strong&gt; Zscaler found websites hiding prompt-injection text to manipulate AI agents into making crypto payments. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/indirect-prompt-injection-web/&quot;&gt;Infosecurity Magazine&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security Tools &amp;amp; Best Practices&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cloudflare adds granular AI bot controls:&lt;/strong&gt; Site owners can now manage search, training, and agent crawlers separately instead of blocking all AI bots at once. &lt;a href=&quot;https://the-decoder.com/cloudflare-replaces-its-blanket-ai-bot-block-with-granular-controls-for-search-training-and-agent-crawlers/&quot;&gt;The Decoder&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>security news</category><category>daily briefing</category><category>AI ransomware</category><category>NetScaler</category><category>vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ai-ransomware-netscaler-flaw-kvm-vm-escape-07-06-2026.webp" length="0" type="image/webp"/></item><item><title>CMMC Rules, Bosch $43M Export Fine &amp; EEOC Shift (07/06/2026)</title><link>https://grabtheaxe.com/news/cmmc-defense-contracts-bosch-fine-eeoc-hipaa-07-06-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cmmc-defense-contracts-bosch-fine-eeoc-hipaa-07-06-2026/</guid><description>CMMC self-certification is landing in defense contracts with False Claims Act exposure, Bosch paid $43M for illegal Huawei exports, and the EEOC rescinded its affirmative action guidance.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cmmc-defense-contracts-bosch-fine-eeoc-hipaa-07-06-2026.webp&quot; alt=&quot;Compliance Briefing: CMMC, Bosch export fine, EEOC, HIPAA breach, July 6, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today&apos;s compliance stories each create a new obligation or a new liability. CMMC cybersecurity requirements are flowing into defense contracts, and an inaccurate self-certification now carries False Claims Act exposure. Bosch paid more than $43 million for export-control violations. And the EEOC withdrew guidance employers have relied on for years.&lt;/p&gt;
&lt;h2&gt;Top Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;1. CMMC Requirements Land in Defense Contracts&lt;/h3&gt;
&lt;p&gt;Cybersecurity Maturity Model Certification (CMMC) requirements are rolling into defense contracts, and an inaccurate self-certification can expose a contractor to False Claims Act liability, including treble damages and whistleblower suits (&lt;a href=&quot;https://www.corporatecomplianceinsights.com/cmmc-cybersecurity-rules-rolling-into-defense-contracts/&quot;&gt;Corporate Compliance Insights&lt;/a&gt;). This turns a security checkbox into a financial and legal one: the assessment you sign becomes a representation the government can sue over.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Do not self-certify from memory. Run a gap assessment against the CMMC level named in your contract first, because the penalty for getting it wrong is now treble damages.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. Bosch Pays $43 Million for Illegal Huawei Exports&lt;/h3&gt;
&lt;p&gt;Bosch agreed to pay more than $43 million in penalties and disgorgement for illegally exporting products and software to Huawei in violation of US export controls (&lt;a href=&quot;https://www.jdsupra.com/legalnews/episode-431-bosch-pays-43-million-fo-72777/&quot;&gt;JD Supra&lt;/a&gt;). Export control is the area most companies underestimate, because the rules sit outside the security and privacy teams that usually own risk. One mis-shipped product line can carry an eight-figure price.&lt;/p&gt;
&lt;h3&gt;3. EEOC Rescinds Affirmative Action Guidance&lt;/h3&gt;
&lt;p&gt;On June 29, the EEOC voted to rescind two long-standing policy documents that guided employers on voluntary affirmative action programs (&lt;a href=&quot;https://www.jdsupra.com/legalnews/eeoc-rescinds-longstanding-affirmative-3464482/&quot;&gt;JD Supra&lt;/a&gt;). When an agency withdraws guidance employers built their policies around, the obligation does not vanish, it just loses its map. Any program that leaned on those documents needs a fresh review with counsel.&lt;/p&gt;
&lt;h3&gt;4. Texas Hearing Institute Reports 29,000-Person Breach&lt;/h3&gt;
&lt;p&gt;The Texas Hearing Institute notified the Texas Attorney General of a data breach affecting more than 29,000 residents (&lt;a href=&quot;https://www.hipaajournal.com/data-breach-round-up-july-6-2026/&quot;&gt;HIPAA Journal&lt;/a&gt;). Under HIPAA and state law, a breach is more than a security event. It starts a reporting clock and can trigger enforcement. The obligation begins the moment you discover it, so the legal notification steps belong inside your incident plan, written in before you need them.&lt;/p&gt;
&lt;h2&gt;Additional Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;Regulatory Updates&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;SEC names a new COO:&lt;/strong&gt; The SEC appointed Paul Knight as Chief Operating Officer to oversee agency operations. &lt;a href=&quot;https://www.sec.gov/newsroom/press-releases/2026-62-sec-names-paul-knight-chief-operating-officer&quot;&gt;SEC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;FCA proposes new SIPP asset rules:&lt;/strong&gt; The UK&apos;s FCA proposed a new regime for handling pension scheme money and assets within self-invested personal pensions. &lt;a href=&quot;https://www.jdsupra.com/legalnews/fca-proposed-new-pensions-scheme-money-9038352/&quot;&gt;JD Supra&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>compliance news</category><category>daily briefing</category><category>CMMC</category><category>export controls</category><category>HIPAA</category><author>info@grabtheaxe.com (Dusten Trounce)</author><enclosure url="https://grabtheaxe.com/assets/news/cmmc-defense-contracts-bosch-fine-eeoc-hipaa-07-06-2026.webp" length="0" type="image/webp"/></item><item><title>Pegasus Spyware, Facial Recognition &amp; ICE Surveillance (07/06/2026)</title><link>https://grabtheaxe.com/news/pegasus-spyware-facial-recognition-surveillance-07-06-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/pegasus-spyware-facial-recognition-surveillance-07-06-2026/</guid><description>Pegasus spyware hit an EU lawmaker investigating spyware, a UK grocer is scaling facial recognition to 150 more stores, and ICE&apos;s watchdog is investigating its online critics.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/pegasus-spyware-facial-recognition-surveillance-07-06-2026.webp&quot; alt=&quot;Privacy Briefing: Pegasus spyware, facial recognition, ICE surveillance, July 6, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Every story in today&apos;s privacy roundup is the same story: surveillance turned on the people it was meant to serve. Pegasus spyware landed on the phone of the European lawmaker whose job was to investigate Pegasus. A British supermarket is scaling facial recognition to catch shoplifters. An immigration agency&apos;s own watchdog is now looking into its online critics.&lt;/p&gt;
&lt;h2&gt;Top Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;1. Pegasus Infects the Phone of a Spyware Investigator&lt;/h3&gt;
&lt;p&gt;Pegasus spyware infected the phone of a member of the European Parliament who sits on the committee investigating Pegasus, and campaigners are demanding the EU finally act on long-delayed recommendations (&lt;a href=&quot;https://www.theregister.com/security/2026/07/06/eus-latest-spyware-scandal-prompts-calls-for-urgent-action/5267054&quot;&gt;The Register&lt;/a&gt;). When the tooling reaches the people overseeing the tooling, the risk stops being hypothetical for anyone. The phone in your pocket is a full-time sensor pointed at you, and the belief that yours is clean is a decision, not a fact.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Assume the device you carry can be turned against you, and design your most sensitive conversations around that assumption rather than around trust in the hardware.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. A UK Grocer Triples Down on Facial Recognition&lt;/h3&gt;
&lt;p&gt;A major UK supermarket is putting facial recognition into as many as 150 more stores by year&apos;s end to identify shoplifters, a system critics call Orwellian (&lt;a href=&quot;https://www.theregister.com/security/2026/07/06/brit-supermarket-giant-triples-down-on-facial-recog-to-nab-shoplifters/5266935&quot;&gt;The Register&lt;/a&gt;). Biometric surveillance does not ask for consent and does not forget. Once a face is enrolled, the shopper has no practical way to opt out, and the retailer is trading a small drop in shrinkage for a large expansion of who gets watched.&lt;/p&gt;
&lt;h3&gt;3. ICE&apos;s Watchdog Turns Toward Its Critics&lt;/h3&gt;
&lt;p&gt;ICE&apos;s internal watchdog is reportedly investigating people who criticized the agency online, which turns an accountability function into a surveillance one (&lt;a href=&quot;https://pogowasright.org/ices-internal-watchdog-is-now-investigating-online-critics/&quot;&gt;PogoWasRight&lt;/a&gt;). When the mechanism built to check power gets aimed at the power&apos;s critics, the chilling effect is the point. People self-censor long before anyone is ever charged.&lt;/p&gt;
&lt;h3&gt;4. Health Data Sharing Suit Against Healthline Advances&lt;/h3&gt;
&lt;p&gt;A court will let a proposed class action proceed against Healthline over claims it shared readers&apos; health information with TikTok and Microsoft (&lt;a href=&quot;https://pogowasright.org/healthline-media-user-advances-suit-over-tiktok-data-sharing/&quot;&gt;PogoWasRight&lt;/a&gt;). Health data is among the most sensitive information a person carries, and piping it to ad-tech platforms treats a private medical concern as a targeting signal.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; If your site touches anything health-adjacent, audit your trackers now. The tracking pixel you forgot about is the liability you will end up litigating.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>privacy news</category><category>daily briefing</category><category>spyware</category><category>facial recognition</category><category>surveillance</category><author>info@grabtheaxe.com (Jeff Welch)</author><enclosure url="https://grabtheaxe.com/assets/news/pegasus-spyware-facial-recognition-surveillance-07-06-2026.webp" length="0" type="image/webp"/></item><item><title>Basic-Fit Breach Hits 1 Million Members, Adobe Patches Exploited Acrobat Zero-Day, APT41 Steals Cloud Creds</title><link>https://grabtheaxe.com/news/basic-fit-breach-adobe-zero-day-apt41-04-13-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/basic-fit-breach-adobe-zero-day-apt41-04-13-2026/</guid><description>European gym chain Basic-Fit confirmed a breach exposing 1 million members across the EU. Adobe patched an actively exploited Acrobat Reader zero-day that lingered for months, and APT41 is harvesting cloud credentials with a zero-detection backdoor.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/basic-fit-breach-adobe-zero-day-apt41-04-13-2026.webp&quot; alt=&quot;Security Briefing: Basic-Fit Breach, Adobe Zero-Day, APT41 Cloud Creds - April 13, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Basic-Fit confirmed today that attackers stole records on roughly 1 million gym members across the EU, giving scammers a fresh pool for impersonation and account takeover. Adobe pushed an emergency patch for a months-old Acrobat Reader zero-day that is already being exploited in the wild, while researchers at Google documented an APT41 backdoor that runs without triggering a single detection and exfiltrates cloud credentials. The FBI also landed a rare win, dismantling the W3LL phishing service with Indonesian authorities and arresting the developer.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;h3&gt;1. Basic-Fit Breach Exposes 1 Million Gym Members Across Europe&lt;/h3&gt;
&lt;p&gt;The Dutch gym chain confirmed attackers stole customer records covering an estimated one million members in several EU countries. Exposed data includes names, contact details, and membership information, according to the company&apos;s disclosure. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/european-gym-giant-basic-fit-data-breach-affects-1-million-members/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; The immediate risk is targeted phishing and identity fraud against members, not payment theft. Warn affected staff to expect Basic-Fit themed lures for the next 90 days.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. Adobe Patches Actively Exploited Acrobat Reader Zero-Day&lt;/h3&gt;
&lt;p&gt;Adobe released fixes for CVE-2026-34621, an Acrobat Reader flaw under active exploitation. The vulnerability had been present for months before being flagged, and attackers are already using it for initial access. &lt;a href=&quot;https://www.darkreading.com/application-security/adobe-patches-actively-exploited-zero-day&quot;&gt;Dark Reading&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;3. APT41 Delivers Zero-Detection Backdoor to Harvest Cloud Credentials&lt;/h3&gt;
&lt;p&gt;Researchers documented a new APT41 implant that evades all major endpoint detection tools and is designed specifically to exfiltrate cloud credentials from compromised systems. The group is targeting organizations with large hybrid cloud footprints. &lt;a href=&quot;https://www.darkreading.com/cloud-security/apt41-zero-detection-backdoor-harvest-cloud-credentials&quot;&gt;Dark Reading&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; If you cannot detect it at the endpoint, you must detect it at the cloud control plane. Alert on anomalous IAM enumeration and new access keys from unfamiliar ASNs.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;4. FBI and Indonesian Police Dismantle W3LL Phishing Service, Arrest Developer&lt;/h3&gt;
&lt;p&gt;Joint operation took down W3LL, a phishing-as-a-service platform responsible for more than $20 million in attempted fraud across thousands of victims. The developer was arrested in Indonesia. &lt;a href=&quot;https://thehackernews.com/2026/04/fbi-and-indonesian-police-dismantle.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;5. Critical wolfSSL Flaw Enables Forged Certificate Use&lt;/h3&gt;
&lt;p&gt;A critical vulnerability in the wolfSSL library lets attackers forge certificates accepted by any device still shipping the affected version. The library is widely embedded in IoT devices, routers, and industrial appliances where patching is slow. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/critical-flaw-in-wolfssl-library-enables-forged-certificate-use/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Inventory everything running wolfSSL before you triage. The long tail of embedded devices is where this bug will live for years.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Additional Security Alerts&lt;/h2&gt;
&lt;h3&gt;Threat Intelligence&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;APT41 Backdoor Hunt&lt;/strong&gt; - The same APT41 zero-detection implant is being tracked across financial services and telecom victims. &lt;a href=&quot;https://www.darkreading.com/cloud-security/apt41-zero-detection-backdoor-harvest-cloud-credentials&quot;&gt;Dark Reading&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;JanelaRAT Hits Latin American Banks&lt;/strong&gt; - The banking trojan logged 14,739 attacks in Brazil during 2025, targeting financial account credentials. &lt;a href=&quot;https://thehackernews.com/2026/04/janelarat-malware-targets-latin.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Zombie Microsoft Bugs Resurface&lt;/strong&gt; - Old Microsoft vulnerabilities thought dead are being revived by ransomware crews exploiting unpatched systems. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2026/04/13/ransomware_gang_other_crims_attacking/&quot;&gt;The Register&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security Breaches &amp;amp; Incidents&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Rockstar Games Hit by ShinyHunters&lt;/strong&gt; - Extortion gang leaked analytics data stolen from the Grand Theft Auto publisher. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://Booking.com&quot;&gt;Booking.com&lt;/a&gt; Confirms Customer Data Accessed&lt;/strong&gt; - Travel giant confirmed attackers reached customer records, though scope is still being determined. &lt;a href=&quot;https://techcrunch.com/2026/04/13/booking-com-confirms-hackers-accessed-customers-data/&quot;&gt;TechCrunch&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;30 WordPress Plugins Backdoored After Acquisition&lt;/strong&gt; - A single buyer acquired 30 WordPress plugins and planted a backdoor in each, turning trusted code into a supply chain vector. &lt;a href=&quot;https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/&quot;&gt;Anchor Host&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security Tools &amp;amp; Best Practices&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Mailbox Rule Abuse as Post-Compromise Threat&lt;/strong&gt; - Attackers are quietly creating Outlook rules to intercept and forward email after initial access, evading most alerting. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/mailbox-rule-abuse-stealthy-post/&quot;&gt;Infosecurity Magazine&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Emerging Security Technologies&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CSA Warns CISOs to Prepare for Post-Mythos Exploit Storm&lt;/strong&gt; - Cloud Security Alliance is telling security leaders to expect an exploitation surge following the Anthropic Mythos preview and Project Glasswing disclosures. &lt;a href=&quot;https://www.darkreading.com/cloud-security/csa-cisos-prepare-post-mythos-exploit-storm&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>security news</category><category>daily briefing</category><category>data breach</category><category>zero-day</category><category>APT41</category><category>phishing</category><category>ransomware</category><category>supply chain attack</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/basic-fit-breach-adobe-zero-day-apt41-04-13-2026.webp" length="0" type="image/webp"/></item><item><title>Booking.com Customers Warned of Data Hack, FTC Hits Publishing.com With $1.5M Penalty, Californians Sue AI Doctor Recorder</title><link>https://grabtheaxe.com/news/booking-ftc-publishing-ai-doctor-recording-04-13-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/booking-ftc-publishing-ai-doctor-recording-04-13-2026/</guid><description>Booking.com is warning customers their data was accessed in a breach. The FTC extracted a $1.5M settlement from Publishing.com for deceptive income claims, and Californians filed suit over an AI tool that records doctor visits without consent.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/booking-ftc-publishing-ai-doctor-recording-04-13-2026.webp&quot; alt=&quot;Privacy Briefing: Booking.com Breach, FTC Publishing.com, AI Doctor Recording Lawsuit - April 13, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://Booking.com&quot;&gt;Booking.com&lt;/a&gt; is warning customers that attackers reached their personal data, creating a ready-made pretext for travel phishing at scale. The FTC extracted a $1.5 million settlement from &lt;a href=&quot;http://Publishing.com&quot;&gt;Publishing.com&lt;/a&gt; over deceptive earning claims and filed a parallel action against a high-level MLM participant, signaling continued enforcement against business opportunity schemes. In California, patients sued over an AI tool that records doctor visits without explicit consent, a case that will shape how ambient clinical AI gets deployed.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;1. &lt;a href=&quot;http://Booking.com&quot;&gt;Booking.com&lt;/a&gt; Warns Customers of Data Hack&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;http://Booking.com&quot;&gt;Booking.com&lt;/a&gt; is notifying customers that hackers accessed their data in a recent incident. The company is still determining exact scope, but exposure includes personal and travel-related information used to book accommodations. &lt;a href=&quot;https://www.theguardian.com/technology/2026/apr/13/booking-com-customers-hack-exposed-data&quot;&gt;The Guardian&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; This is a phishing gold mine. Affected customers should expect convincing travel-confirmation lures with real booking details baked in.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. FTC Extracts $1.5M From &lt;a href=&quot;http://Publishing.com&quot;&gt;Publishing.com&lt;/a&gt; Over Deceptive Income Claims&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;http://Publishing.com&quot;&gt;Publishing.com&lt;/a&gt; agreed to pay $1.5 million to settle FTC charges that it misled consumers about how much they could earn using its products and services. The order also imposes compliance reporting requirements. &lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2026/04/publishingcom-pay-15-million-misleading-consumers-about-how-much-income-they-could-earn-using&quot;&gt;FTC&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;3. FTC Sues High-Level MLM Participant Over Earnings Deception&lt;/h3&gt;
&lt;p&gt;The FTC filed a parallel action against a senior MLM participant who allegedly deceived workers about income potential. The case signals the agency is pursuing individuals, not just corporate defendants, in business opportunity fraud. &lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2026/04/ftc-takes-action-against-high-level-mlm-participant-who-deceived-workers-about-amount-money-they-can&quot;&gt;FTC&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;4. Californians Sue Over AI Tool That Records Doctor Visits&lt;/h3&gt;
&lt;p&gt;A class action alleges an AI ambient scribing tool is recording doctor-patient conversations without adequate consent. The suit will likely test whether HIPAA-adjacent AI products clear California&apos;s two-party consent requirements. &lt;a href=&quot;https://pogowasright.org/californians-sue-over-ai-tool-that-records-doctor-visits/&quot;&gt;PogoWasRight&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; If you deploy ambient clinical AI, verify the consent flow meets the stricter of HIPAA or your state&apos;s wiretap statute. Opt-out buried in a portal will not hold up.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;5. California Bill Would Censor 3D Printing Designs&lt;/h3&gt;
&lt;p&gt;EFF is warning that California&apos;s pending 3D printing legislation would treat design files as regulated content, creating speech and privacy risks while failing to meaningfully address the safety concerns it cites. &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/dangers-californias-legislation-censor-3d-printing&quot;&gt;EFF&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Additional Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;Privacy Laws &amp;amp; Regulations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Italian DPA Fines Platform Over Phone Number Disclosure&lt;/strong&gt; - Regulator extended platform liability after the Russmedia ruling, fining a site for allowing a phone number to appear in sex work ads without the subject&apos;s consent. &lt;a href=&quot;https://pogowasright.org/platform-liability-after-russmedia-italian-dpa-fines-platform-for-allowing-phone-number-in-sex-work-ads-without-consent/&quot;&gt;PogoWasRight&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Governance Framework for AI Agents&lt;/strong&gt; - Norton Rose laid out a practical framework for governing autonomous AI agents, including data minimization and audit trail requirements. &lt;a href=&quot;https://www.dataprotectionreport.com/2026/04/how-to-approach-governance-of-ai-agents/&quot;&gt;Data Protection Report&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>privacy news</category><category>daily briefing</category><category>FTC enforcement</category><category>data breach</category><category>AI privacy</category><category>consent</category><category>medical privacy</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/booking-ftc-publishing-ai-doctor-recording-04-13-2026.webp" length="0" type="image/webp"/></item><item><title>DOJ Launches National Fraud Enforcement Division, New DEI Executive Order Hits Federal Contractors, CMS Opens Health Tech Ecosystem</title><link>https://grabtheaxe.com/news/doj-fraud-division-dei-executive-order-cms-health-tech-04-13-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/doj-fraud-division-dei-executive-order-cms-health-tech-04-13-2026/</guid><description>The DOJ stood up a new National Fraud Enforcement Division. A new executive order reshapes DEI compliance for federal contractors, and CMS launched the first wave of its Health Tech Ecosystem information sharing tools.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/doj-fraud-division-dei-executive-order-cms-health-tech-04-13-2026.webp&quot; alt=&quot;Compliance Briefing: DOJ Fraud Division, DEI Executive Order, CMS Health Tech - April 13, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The DOJ today launched a National Fraud Enforcement Division, consolidating fraud cases under a single division and signaling a step-up in coordinated prosecutions. A new executive order reshapes DEI-related compliance duties for federal contractors, forcing a near-term review of affirmative action plans and training content. CMS rolled out the first wave of its Health Tech Ecosystem, standing up new information sharing and access tools for covered entities to plug into.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;1. DOJ Establishes National Fraud Enforcement Division&lt;/h3&gt;
&lt;p&gt;The Department of Justice stood up a new National Fraud Enforcement Division to centralize prosecution of fraud schemes across healthcare, financial services, and government programs. The reorganization consolidates work previously spread across several sections. &lt;a href=&quot;https://www.jdsupra.com/legalnews/doj-establishes-national-fraud-6397572/&quot;&gt;JD Supra&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Expect more parallel civil and criminal actions. If you touch federal funds, tighten internal controls around billing and vendor attestations before the first wave lands.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. New Executive Order Reshapes DEI Compliance for Federal Contractors&lt;/h3&gt;
&lt;p&gt;A new executive order overhauls DEI-related obligations for federal contractors, changing language and reporting around diversity programs, affirmative action, and training content. Contractors have a narrow window to update policies and certifications. &lt;a href=&quot;https://www.jdsupra.com/legalnews/dei-crackdown-new-executive-order-8590675/&quot;&gt;JD Supra&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;3. CMS Launches First Wave of Health Tech Ecosystem&lt;/h3&gt;
&lt;p&gt;CMS activated the first tools in its Health Tech Ecosystem, a new framework for health information sharing and patient data access. The rollout gives covered entities concrete integration points instead of abstract interoperability goals. &lt;a href=&quot;https://www.hipaajournal.com/cms-first-wave-health-tech-ecosystem-health-information-sharing-access-tools/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;4. DermCare, Option Care Health, and Aetna Disclose Breaches&lt;/h3&gt;
&lt;p&gt;Three healthcare organizations disclosed data breaches in the same window, with Aetna&apos;s incident being the largest. Each breach adds to a February healthcare total that already exceeded 8 million records. &lt;a href=&quot;https://www.hipaajournal.com/data-breaches-dermcare-management-option-care-health-aetna/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; The cadence of healthcare disclosures is becoming daily. Tabletop your breach notification timing against your BAA partners now, not after you get the call.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;5. CFTC Flags Insider Trading in Prediction Markets as Enforcement Priority&lt;/h3&gt;
&lt;p&gt;The CFTC signaled it will apply insider trading enforcement theory to prediction market activity, extending Rule 180.1 concepts into event contracts. Firms operating or providing liquidity in these markets need insider trading controls on par with traditional exchanges. &lt;a href=&quot;https://www.jdsupra.com/legalnews/cftc-highlights-enforcement-focus-on-3991900/&quot;&gt;JD Supra&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Additional Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;Regulatory Updates&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;HIPAA&apos;s Next Era&lt;/strong&gt; - JD Supra breaks down the new HIPAA rules coming for emerging technologies and AI risks, with timelines for covered entities to absorb. &lt;a href=&quot;https://www.jdsupra.com/legalnews/hipaa-s-next-era-new-rules-for-new-4260573/&quot;&gt;JD Supra&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;OSHA Updates Heat-Related Hazards NEP&lt;/strong&gt; - OSHA revised its National Emphasis Program on heat hazards, changing inspection triggers and employer documentation expectations. &lt;a href=&quot;https://www.hipaajournal.com/osha-updates-heat-related-hazards-national-emphasis-program/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;More on the Downsizing of the SEC&lt;/strong&gt; - Compliance Building summarizes ongoing SEC workforce reductions and the practical effect on enforcement throughput. &lt;a href=&quot;https://compliancebuilding.com/2026/04/13/more-on-the-downsizing-of-the-sec/&quot;&gt;Compliance Building&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Audit &amp;amp; Monitoring Tools&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;AI Insurance Exists, but Coverage Is Scarce&lt;/strong&gt; - Carriers are writing AI-specific policies but underwriting standards lag, leaving buyers uncertain what is actually covered. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/ai-insurance-getting-hard-part/&quot;&gt;Corporate Compliance Insights&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Compliance Blind Spots in Financial Data&lt;/strong&gt; - Common data hygiene gaps let compliance-relevant signals slip past monitoring programs, especially when reconciliations live outside the GRC stack. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/compliance-blind-spots-hiding-inside-financial-data/&quot;&gt;Corporate Compliance Insights&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>compliance news</category><category>daily briefing</category><category>DOJ</category><category>DEI</category><category>federal contractors</category><category>HIPAA</category><category>healthcare breach</category><category>CFTC</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/doj-fraud-division-dei-executive-order-cms-health-tech-04-13-2026.webp" length="0" type="image/webp"/></item><item><title>CPUID Supply Chain Attack Distributes STX RAT, Three Gangs Drive 40% of March Ransomware</title><link>https://grabtheaxe.com/news/cpuid-supply-chain-attack-ransomware-consolidation-04-12-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cpuid-supply-chain-attack-ransomware-consolidation-04-12-2026/</guid><description>CPUID&apos;s website was compromised to push STX RAT through trojanized CPU-Z and HWMonitor downloads. Separately, Qilin, Akira, and Dragonforce drove 40% of 672 ransomware incidents in March as the threat landscape consolidates.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cpuid-supply-chain-attack-ransomware-consolidation-04-12-2026.webp&quot; alt=&quot;Security News: CPUID Supply Chain Attack and Ransomware Consolidation - April 12, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;CPUID&apos;s website was compromised to push STX RAT through trojanized CPU-Z and HWMonitor downloads, landing the same day researchers confirmed active exploitation of a critical Marimo RCE vulnerability. On the ransomware front, three groups (Qilin, Akira, and Dragonforce) accounted for 40% of 672 March incidents, signaling consolidation into fewer, more capable operations. Russian APT28 rounded out a heavy threat intelligence day with a DNS manipulation campaign targeting Microsoft authentication tokens across 18,000 networks.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;h3&gt;1. CPUID Compromised to Distribute STX RAT via Trojanized CPU-Z and HWMonitor&lt;/h3&gt;
&lt;p&gt;Threat actors breached CPUID&apos;s website and replaced legitimate downloads of CPU-Z and HWMonitor with versions containing STX RAT, a remote access trojan. The compromise lasted under 24 hours but affected an unknown number of downloads during that window. Anyone who downloaded these tools recently should verify file hashes and scan for indicators of compromise. &lt;a href=&quot;https://thehackernews.com/2026/04/cpuid-breach-distributes-stx-rat-via.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Supply chain attacks targeting trusted software distributors bypass perimeter defenses entirely. Your &lt;a href=&quot;https://grabtheaxe.com/external-attack-surface-management-easm-guide/&quot;&gt;vulnerability management program&lt;/a&gt; needs to account for compromised legitimate tools, not just unknown threats.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. Critical Marimo Pre-Auth RCE Flaw Now Under Active Exploitation&lt;/h3&gt;
&lt;p&gt;A critical vulnerability in the Marimo Python notebook framework allows unauthenticated remote code execution. Attackers are exploiting it in the wild to steal credentials from exposed instances. Organizations running Marimo should patch immediately or take instances offline. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/critical-marimo-pre-auth-rce-flaw-now-under-active-exploitation/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;3. Three Ransomware Gangs Drove 40% of All Attacks in March&lt;/h3&gt;
&lt;p&gt;Qilin, Akira, and Dragonforce accounted for 40% of 672 ransomware incidents reported in March 2026, according to Check Point. The consolidation of ransomware operations into fewer, more capable groups signals a shift in the threat landscape. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/three-ransomware-gangs-40-percent/&quot;&gt;Infosecurity Magazine&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;4. Nearly 4,000 US Industrial Devices Exposed to Iranian Cyberattacks&lt;/h3&gt;
&lt;p&gt;Researchers identified approximately 4,000 US-based industrial control system devices directly accessible from the internet and vulnerable to known attack vectors used by Iranian threat actors. The exposed devices include PLCs, HMIs, and SCADA systems across energy, water, and manufacturing sectors. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/nearly-4-000-us-industrial-devices-exposed-to-iranian-cyberattacks/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Internet-exposed OT devices are the textbook example of unmanaged &lt;a href=&quot;https://grabtheaxe.com/external-attack-surface-management-easm-guide/&quot;&gt;attack surface&lt;/a&gt;. If your organization runs industrial control systems, an external asset discovery scan should be running continuously.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;5. Hims Telehealth Breach Exposes Sensitive Protected Health Information&lt;/h3&gt;
&lt;p&gt;Threat actors compromised the telehealth platform Hims and accessed highly sensitive patient health information including treatment details and medical conditions. The breach is notable for the specificity of the PHI exposed, going beyond names and insurance numbers into clinical data. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/hims-breach-exposes-sensitive-phi&quot;&gt;Dark Reading&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Additional Security Alerts&lt;/h2&gt;
&lt;h3&gt;Threat Intelligence&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Russia&apos;s Forest Blizzard Harvests Microsoft Office Tokens via SOHO Routers&lt;/strong&gt; - Russian APT28 modified router DNS settings across 18,000 networks to intercept Microsoft authentication tokens without deploying malware. The technique avoids endpoint detection entirely. &lt;a href=&quot;https://krebsonsecurity.com/2026/04/russia-hacked-routers-to-steal-microsoft-office-tokens/&quot;&gt;Krebs on Security&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;STX RAT Targets Finance Sector With Advanced Stealth Tactics&lt;/strong&gt; - The same RAT found in the CPUID compromise is also being deployed in targeted campaigns against financial institutions using advanced command-and-control infrastructure. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/stx-rat-targets-finance-sector/&quot;&gt;Infosecurity Magazine&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Germany Identifies REvil and GandCrab Ransomware Leader&lt;/strong&gt; - German authorities named 31-year-old Daniil Shchukin as the operator behind REvil and GandCrab, the groups that pioneered double extortion tactics. &lt;a href=&quot;https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/&quot;&gt;Krebs on Security&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security Breaches &amp;amp; Incidents&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Bitcoin Depot Loses $3.6M in Crypto Theft After System Breach&lt;/strong&gt; - Hackers stole over 50 Bitcoin (approximately $3.66 million) after compromising Bitcoin Depot&apos;s internal systems. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/bitcoin-depot-dollar36m-crypto/&quot;&gt;Infosecurity Magazine&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Over 20,000 Crypto Fraud Victims Identified in International Crackdown&lt;/strong&gt; - Law enforcement across multiple countries identified tens of thousands of victims in a coordinated operation targeting cryptocurrency fraud networks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/over-20-000-crypto-fraud-victims-identified-in-international-crackdown/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Hackers Steal and Leak Sensitive LAPD Documents&lt;/strong&gt; - The World Leaks gang breached Los Angeles Police Department systems and publicly released sensitive law enforcement records. &lt;a href=&quot;https://techcrunch.com/2026/04/08/hackers-steal-and-leak-sensitive-lapd-police-documents/&quot;&gt;TechCrunch&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Emerging Security Technologies&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Google Chrome Rolls Out Session Cookie Protection Against Infostealers&lt;/strong&gt; - Chrome&apos;s new Device Bound Session Credentials feature binds session cookies to specific devices, preventing malware from harvesting and replaying stolen session data. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/google-chrome-protection/&quot;&gt;Infosecurity Magazine&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Anthropic&apos;s New AI Model Can Write Exploits for Zero-Day Vulnerabilities&lt;/strong&gt; - Anthropic released a model capable of discovering and exploiting unpatched vulnerabilities, raising questions about safeguards for dual-use AI security tools. &lt;a href=&quot;https://www.darkreading.com/application-security/anthropic-exploit-writing-mythos-ai-safe&quot;&gt;Dark Reading&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>security news</category><category>supply chain attack</category><category>ransomware</category><category>CPUID</category><category>STX RAT</category><category>Marimo RCE</category><category>ICS security</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/cpuid-supply-chain-attack-ransomware-consolidation-04-12-2026.webp" length="0" type="image/webp"/></item><item><title>63 Healthcare Breaches in February Expose 8.1 Million Records, OCR Releases HIPAA Guidance</title><link>https://grabtheaxe.com/news/healthcare-breach-february-2026-hipaa-ocr-guidance-04-12-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/healthcare-breach-february-2026-hipaa-ocr-guidance-04-12-2026/</guid><description>The HIPAA Journal reports 63 major healthcare data breaches in February 2026 exposing over 8.1 million records. OCR released new HIPAA Security Rule risk management guidance, the SEC named a new enforcement director, and FINRA launched a financial intelligence fusion center.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/healthcare-breach-february-2026-hipaa-ocr-guidance-04-12-2026.webp&quot; alt=&quot;Compliance News: Healthcare Breach Report and HIPAA OCR Guidance - April 12, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;February&apos;s healthcare breach numbers are in: 63 incidents, 8.1 million records exposed, with TriZetto Provider Solutions and QualDerm Partners leading in volume. OCR released new HIPAA risk management guidance the same week, giving covered entities a window to act before enforcement tightens. The SEC named a new enforcement director effective May 4, and a New Jersey pharmacy disclosed a breach 7 months after the original intrusion, which says as much about detection capability as it does about reporting.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;1. February 2026 Healthcare Data Breach Report: 8.1 Million Records Exposed&lt;/h3&gt;
&lt;p&gt;The HIPAA Journal reports 63 major healthcare data breaches in February 2026, exposing over 8.1 million individual records. TriZetto Provider Solutions and QualDerm Partners reported the largest incidents. The numbers continue a trend of increasing breach volume and scale in the healthcare sector. &lt;a href=&quot;https://www.hipaajournal.com/february-2026-healthcare-data-breach-report/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Operator Note:&lt;/strong&gt; Healthcare organizations should treat breach reporting as a lagging indicator. The time to act is during the &lt;a href=&quot;https://grabtheaxe.com/what-is-included-in-a-cybersecurity-assessment/&quot;&gt;cybersecurity assessment&lt;/a&gt;, not after the disclosure.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;2. SEC Appoints David Woodcock as Director of Enforcement&lt;/h3&gt;
&lt;p&gt;The SEC named David Woodcock, a Gibson Dunn partner, as the new Director of the Division of Enforcement effective May 4, 2026. The appointment signals the direction of SEC cyber enforcement priorities under the new leadership. &lt;a href=&quot;https://www.sec.gov/newsroom/press-releases/2026-35-sec-appoints-david-woodcock-director-division-enforcement&quot;&gt;SEC&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;3. New Jersey Pharmacy Breach Affects 133,800 Patients&lt;/h3&gt;
&lt;p&gt;Innovative Pharmacy entities disclosed a September 2025 intrusion that exposed patient data including names, identification numbers, and medical information for over 133,000 individuals. The 7-month gap between incident and disclosure raises questions about breach detection capabilities. &lt;a href=&quot;https://www.hipaajournal.com/ippc-innovative-pharmacy-data-breach/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;4. OCR Releases HIPAA Security Rule Risk Management Guidance&lt;/h3&gt;
&lt;p&gt;The HHS Office for Civil Rights published new instructional content explaining risk management compliance requirements and enforcement priorities for HIPAA-regulated entities. The guidance clarifies expectations ahead of potential rulemaking. &lt;a href=&quot;https://www.hipaajournal.com/ocr-risk-management-guidance-video/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;5. FINRA Launches Financial Intelligence Fusion Center&lt;/h3&gt;
&lt;p&gt;The Financial Industry Regulatory Authority established a new center to coordinate intelligence sharing against cybersecurity and fraud threats across the financial services industry. The fusion center model mirrors government threat-sharing frameworks applied to the private sector. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/finra-launches-financial-intelligence-fusion-center&quot;&gt;Dark Reading&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Additional Compliance Alerts&lt;/h2&gt;
&lt;h3&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;GRC Vendors Launch AI-Powered Compliance Tools&lt;/strong&gt; - Drata, Diligent, HICX, and Ibex released new agentic AI assessment systems and risk management platforms designed to automate third-party compliance workflows. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/grc-vendor-news-roundup-drata-diligent-hicx-ibex-more/&quot;&gt;Corporate Compliance Insights&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Haast Raises $12M for AI Compliance Agents&lt;/strong&gt; - The marketing compliance firm secured Series A funding to expand AI agents that automate manual review of promotional materials for regulatory violations. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/haast-raises-12m-for-ai-compliance-agents/&quot;&gt;Corporate Compliance Insights&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Policy &amp;amp; Governance Updates&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;State Pay Transparency Laws Create Complex Multistate Compliance Burden&lt;/strong&gt; - Expanding pay disclosure requirements across states are forcing multistate employers to navigate inconsistent compensation reporting rules. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/pay-day-states-job-seekers-expect-salary-transparency/&quot;&gt;Corporate Compliance Insights&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>compliance news</category><category>HIPAA</category><category>healthcare breach</category><category>OCR</category><category>SEC enforcement</category><category>FINRA</category><category>data breach</category><category>third-party risk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/healthcare-breach-february-2026-hipaa-ocr-guidance-04-12-2026.webp" length="0" type="image/webp"/></item><item><title>EFF Fights Section 702 Clean Extension, Post-Quantum Crypto Deadline Moved to 2029</title><link>https://grabtheaxe.com/news/section-702-reauthorization-post-quantum-cryptography-2029-04-12-2026/</link><guid isPermaLink="true">https://grabtheaxe.com/news/section-702-reauthorization-post-quantum-cryptography-2029-04-12-2026/</guid><description>The EFF is pushing Congress to reject a clean Section 702 reauthorization, demanding surveillance reforms before the authority expires. Meanwhile Google moved the post-quantum cryptography transition deadline to 2029, years earlier than expected.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/section-702-reauthorization-post-quantum-cryptography-2029-04-12-2026.webp&quot; alt=&quot;Privacy News: Section 702 Fight and Post-Quantum Cryptography Deadline - April 12, 2026&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The Section 702 reauthorization fight sharpened this week as the EFF urged Congress to reject a clean extension, pushing for surveillance reforms before the authority expires. The same day, Google moved the post-quantum cryptography transition deadline to 2029, compressing timelines for organizations still treating quantum risk as a future problem. UK regulators added enforcement teeth to AI nudification laws, and a Florida investigation into OpenAI continues to test where AI platform liability begins.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;1. EFF Urges Congress to Block Clean Extension of Section 702&lt;/h3&gt;
&lt;p&gt;The Electronic Frontier Foundation is pushing Congress to reject a straightforward reauthorization of Section 702 surveillance authority, demanding reforms to close loopholes that allow warrantless collection of US communications. The current authorization expires this year. &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/we-need-you-our-privacy-cannot-afford-clean-extension-section-702&quot;&gt;EFF&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;2. UK Threatens Tech Executives With Jail Over AI Nudification Tools&lt;/h3&gt;
&lt;p&gt;UK regulators announced enforcement plans targeting technology company leaders who fail to prevent AI-generated intimate imagery on their platforms. The action follows a high-profile incident involving widespread circulation of non-consensual altered images. &lt;a href=&quot;https://therecord.media/uk-threatens-tech-bosses-with-jail-ai-nudification&quot;&gt;The Record&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;3. Florida Investigates OpenAI Over ChatGPT&apos;s Role in Fatal Shooting&lt;/h3&gt;
&lt;p&gt;Florida state authorities opened an investigation into whether ChatGPT played a role in a recent shooting, after the gunman&apos;s family announced plans to pursue legal action against OpenAI. The case tests the boundaries of AI platform liability for user actions. &lt;a href=&quot;https://therecord.media/florida-investigates-openai-chatgpt-deadly-shooting&quot;&gt;The Record&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;4. Senator Launches Inquiry Into 8 Tech Giants for CSAM Reporting Failures&lt;/h3&gt;
&lt;p&gt;A US senator opened an investigation into major technology companies following allegations from the National Center for Missing and Exploited Children that their child sexual abuse material reporting is deficient. The inquiry targets eight of the largest platforms. &lt;a href=&quot;https://therecord.media/senator-launches-inquiry-into-tech-giants-csam&quot;&gt;The Record&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;5. Post-Quantum Cryptography Deadline Accelerated to 2029&lt;/h3&gt;
&lt;p&gt;Google pushed the post-quantum cryptography transition deadline forward to 2029, years earlier than previously expected. Organizations storing encrypted data face a &quot;harvest now, decrypt later&quot; threat from adversaries collecting data today for future quantum decryption. &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/yikes-encryptions-y2k-moment-coming-years-early&quot;&gt;EFF&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Additional Privacy Alerts&lt;/h2&gt;
&lt;h3&gt;Privacy Laws &amp;amp; Regulations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;France to Ditch Windows for Linux to Reduce Reliance on US Tech&lt;/strong&gt; - The French government is migrating away from Windows to Linux across government systems, citing digital sovereignty and reduced dependence on American technology vendors. &lt;a href=&quot;https://techcrunch.com/2026/04/10/france-to-ditch-windows-for-linux-to-reduce-reliance-on-us-tech/&quot;&gt;TechCrunch&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;EFF Opposes Using Computer Fraud Laws Against Price Comparison Tools&lt;/strong&gt; - Amazon&apos;s attempt to use CFAA against Perplexity&apos;s price-comparison tool threatens legitimate competition and research, according to EFF. &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/comparison-shopping-not-computer-crime&quot;&gt;EFF&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;The Axe Report is a daily briefing from &lt;a href=&quot;https://grabtheaxe.com&quot;&gt;Grab The Axe&lt;/a&gt;. Need help assessing your organization&apos;s security posture? Take our free &lt;a href=&quot;https://grabtheaxe.com/human-attack-surface-score/&quot;&gt;Human Attack Surface Score&lt;/a&gt; assessment.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>axe report</category><category>privacy news</category><category>Section 702</category><category>post-quantum cryptography</category><category>surveillance</category><category>AI nudification</category><category>data privacy</category><category>EFF</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/section-702-reauthorization-post-quantum-cryptography-2029-04-12-2026.webp" length="0" type="image/webp"/></item><item><title>Android Zero-Days, NPM Malware, CISA Alerts &amp; ICS Flaws – 12/02/2025</title><link>https://grabtheaxe.com/news/android-zero-days-npm-malware-cisa-alerts-ics-flaws-12-02-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/android-zero-days-npm-malware-cisa-alerts-ics-flaws-12-02-2025/</guid><description>Critical security alert on two actively exploited Android zero-days. Details on a massive NPM malware attack, new CISA KEVs, and critical ICS vulnerabilities.</description><pubDate>Tue, 02 Dec 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/android-zero-days-npm-malware-cisa-alerts-ics-flaws-12-02-2025.webp&quot; alt=&quot;Android Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is dominated by two actively exploited zero-day vulnerabilities in the Android Framework, prompting immediate action from Google and a new CISA directive. This summary also covers a massive NPM supply chain attack that exposed 400,000 developer secrets, critical vulnerabilities in industrial control systems (ICS), and a sophisticated North Korean campaign targeting IT workers. These incidents highlight the urgent need for robust vulnerability management and supply chain security.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google fixes two Android zero days exploited in attacks, 107 flaws : Google’s December security update patches two actively exploited zero-day vulnerabilities in the Android Framework, alongside 105 other flaws. Immediate patching is advised. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-fixes-two-android-zero-days-exploited-in-attacks-107-flaws/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Adds Two Known Exploited Vulnerabilities to Catalog : CISA has added two Android Framework vulnerabilities (CVE-2025-48572 and CVE-2025-48633) to its KEV catalog, confirming they are under active exploitation. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/12/02/cisa-adds-two-known-exploited-vulnerabilities-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets : A massive supply chain attack infected hundreds of NPM packages, leading to the exposure of approximately 400,000 developer secrets published across 30,000 GitHub repositories. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/shai-hulud-20-npm-malware-attack-exposed-up-to-400-000-dev-secrets/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Industrial Video &amp;amp; Control Longwatch Vulnerability : A critical code injection vulnerability (CVSS 9.8) in Longwatch video surveillance systems allows unauthenticated remote code execution with SYSTEM-level privileges. &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-25-336-01&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Iskra iHUB and iHUB Lite Vulnerability : A critical flaw (CVSS 9.3) in Iskra smart metering gateways exposes the web management interface without authentication, allowing attackers to reconfigure devices and manipulate connected systems. &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-25-336-02&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Iran-linked hackers target Israeli, Egyptian critical infrastructure through phishing campaign : An Iranian-backed threat actor conducted a prolonged phishing campaign targeting critical infrastructure and government sectors in Israel and Egypt. &lt;a href=&quot;https://therecord.media/iran-linked-hackers-target-israel-egypt-phishing&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;North Korea lures engineers to rent identities in fake IT worker scheme : Researchers have uncovered a sophisticated North Korean operation where developers are tricked into ‘renting’ out their identities, enabling state-sponsored actors to secure remote IT jobs for illicit fundraising. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/north-korea-lures-engineers-to-rent-identities-in-fake-it-worker-scheme/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cybercrime Goes SaaS: Renting Tools, Access, and Infrastructure : The cybercrime economy has fully adopted a subscription model, offering everything from phishing kits and OTP bots to infostealers as a service, lowering the barrier for entry for attackers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cybercrime-goes-saas-renting-tools-access-and-infrastructure/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fake Calendly invites spoof top brands to hijack ad manager accounts : A phishing campaign is using fake Calendly invitations impersonating major brands like Disney and Uber to steal Google Workspace and Facebook business credentials. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fake-calendly-invites-spoof-top-brands-to-hijack-ad-manager-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Mirion Medical EC2 Software NMIS BioDose Vulnerabilities : Multiple vulnerabilities, including hard-coded credentials and improper permissions, have been found in Mirion Medical software, potentially allowing for RCE and unauthorized access. &lt;a href=&quot;https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;University of Pennsylvania confirms new data breach after Oracle hack : The University of Pennsylvania has disclosed a data breach resulting from an attack on its Oracle E-Business Suite servers, leading to the theft of personal information. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-confirms-data-theft-after-oracle-ebs-hack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A data breach at analytics giant Mixpanel leaves a lot of open questions : Analytics firm Mixpanel has suffered a data breach, but key details about the scope, impact, and timeline of the incident remain unanswered by the company. &lt;a href=&quot;https://techcrunch.com/2025/12/02/a-data-breach-at-analytics-giant-mixpanel-leaves-a-lot-of-open-questions/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Defender portal outage disrupts threat hunting alerts : An ongoing outage in the Microsoft Defender XDR portal is preventing security teams from accessing critical capabilities, including alerts and threat hunting data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-portal-outage-blocks-access-to-security-alerts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Korea arrests suspects selling intimate videos from hacked IP cameras : South Korean police have arrested four individuals for allegedly hacking over 120,000 IP cameras and selling the private footage to an adult website. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/korea-arrests-suspects-selling-intimate-videos-from-hacked-ip-cameras/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FTC settlement requires Illuminate to delete unnecessary student data : Following a breach affecting 10 million students, the FTC is requiring ed-tech provider Illuminate Education to delete unnecessary student data and improve its security practices. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/ftc-settlement-requires-illuminate-to-delete-unnecessary-student-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;India plans to verify and record every smartphone in circulation : The Indian government is mandating the preinstallation of its Sanchar Saathi app on all new smartphones, raising significant privacy and surveillance concerns. &lt;a href=&quot;https://techcrunch.com/2025/12/02/india-plans-to-verify-and-record-every-smartphone-in-circulation/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Releases Five Industrial Control Systems Advisories : CISA has published five new advisories detailing vulnerabilities in ICS products from vendors including Mirion Medical, Industrial Video &amp;amp; Control, and Iskra. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/12/02/cisa-releases-five-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Leaked “Soul Doc” reveals how Anthropic programs Claude’s character : An internal document leaked from Anthropic shows the unique methodology the company uses to define the personality and ethical guidelines for its AI model, Claude. &lt;a href=&quot;https://the-decoder.com/leaked-soul-doc-reveals-how-anthropic-programs-claudes-character/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical PickleScan Vulnerabilities Expose AI Model Supply Chains : Researchers have discovered three critical zero-day vulnerabilities in PickleScan, a tool for scanning AI models, which could allow attackers to bypass security checks. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/picklescan-flaws-expose-ai-supply/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Android Zero-Day</category><category>CISA</category><category>Cybersecurity</category><category>Data Breach</category><category>ICS security</category><category>npm malware</category><category>Supply Chain Attack</category><category>threat intelligence</category><category>vulnerability management</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/android-zero-days-npm-malware-cisa-alerts-ics-flaws-12-02-2025.webp" length="0" type="image/webp"/></item><item><title>Malicious LLMs, Digital ID &amp; Online Blackmail – 11/28/2025</title><link>https://grabtheaxe.com/news/malicious-llms-digital-id-online-blackmail-11-28-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/malicious-llms-digital-id-online-blackmail-11-28-2025/</guid><description>Privacy threats today: Malicious LLMs empower hackers, UK digital ID raises concerns, and online blackmail targets kids. Stay secure with our analysis.</description><pubDate>Fri, 28 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/malicious-llms-digital-id-online-blackmail-11-28-2025.webp&quot; alt=&quot;Digital Identity&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy digest highlights critical threats including malicious LLMs empowering hackers, the UK’s controversial digital ID plans, and the rise of online blackmail targeting children. We also cover the FTC’s actions against Amazon for unauthorized Prime enrollments and the potential for AI-driven smart toys to compromise children’s privacy. Stay informed to protect your data and navigate the evolving landscape of digital threats.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Malicious LLMs empower inexperienced hackers with advanced tools: Unrestricted LLMs are generating malicious code, enabling ransomware and lateral movement. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-llms-empower-inexperienced-hackers-with-advanced-tools/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The UK Has It Wrong on Digital ID. Here’s Why.: EFF argues the UK’s digital ID scheme threatens privacy and human rights, potentially leading to exclusion and surveillance. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/uk-has-it-wrong-digital-id-heres-why&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Prompt Injection Through Poetry: Researchers found that turning LLM prompts into poetry can jailbreak the models. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/prompt-injection-through-poetry.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;One in 10 UK parents say their child has been blackmailed online, NSPCC finds: NSPCC reports a rise in online blackmail of children, including threats to release intimate pictures. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/28/one-in-10-uk-parents-say-child-blackmailed-online-sextortion-nspcc-finds&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;After a teddy bear talked about kink, AI watchdogs are warning parents against smart toys: AI watchdogs are warning parents against smart toys due to surveillance and lack of regulation. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/28/artificial-intelligence-smart-toys&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The UK Has It Wrong on Digital ID. Here’s Why.: EFF argues the UK’s digital ID scheme threatens privacy and human rights, potentially leading to exclusion and surveillance. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/uk-has-it-wrong-digital-id-heres-why&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?: Amazon is issuing refunds after being charged by the FTC for enrolling users in Prime without consent. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls: The FTC warns about companies selling your information to telemarketers without permission. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cross-Border Data Transfers&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How Amazon turned our capitalist era of free markets into the age of technofeudalism: Yanis Varoufakis argues Amazon’s AWS controls digital infrastructure, turning entities into serfs. &lt;a href=&quot;https://www.theguardian.com/commentisfree/2025/nov/27/amazon-capitalist-era-free-markets-age-technofeudalism&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Malicious LLMs empower inexperienced hackers with advanced tools: Unrestricted LLMs are generating malicious code, enabling ransomware and lateral movement. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-llms-empower-inexperienced-hackers-with-advanced-tools/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;GreyNoise launches free scanner to check if you’re part of a botnet: GreyNoise’s free tool checks if your IP is involved in malicious scanning, like botnets. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/greynoise-launches-free-scanner-to-check-if-you&apos;re-part-of-a-botnet/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Uncategorized&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams: The FTC advises on spotting scams during Medicare Open Enrollment. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams: The FTC warns about timeshare selling scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going: The FTC highlights a case of a fraudulent charity using vehicle donations. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam: The FTC provides tips on identifying job scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to avoid an online shopping scam this holiday season: The FTC offers advice on avoiding online shopping scams during the holidays. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/11/how-avoid-online-shopping-scam-holiday-season&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;An “agent” told me to stay off the internet. Is it a scam?: The FTC warns about scammers posing as agents and advising against seeking outside help. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/11/agent-told-me-stay-internet-it-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Use this action plan to avoid scams: The FTC introduces a tool to help avoid scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/11/use-action-plan-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Help kids protect their devices: The FTC provides steps to protect children’s devices from hackers and scammers. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/11/help-kids-protect-their-devices&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Prompt Injection Through Poetry: Researchers found that turning LLM prompts into poetry can jailbreak the models. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/prompt-injection-through-poetry.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;More than 1,000 Amazon workers warn rapid AI rollout threatens jobs and climate: Amazon workers express concerns about the impact of rapid AI adoption on jobs and the environment. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/28/amazon-ai-climate-change&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;After a teddy bear talked about kink, AI watchdogs are warning parents against smart toys: AI watchdogs are warning parents against smart toys due to surveillance and lack of regulation. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/28/artificial-intelligence-smart-toys&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The best Black Friday 2025 deals in the UK on the products we love, from window vacs to sunrise alarms: A guide to Black Friday deals in the UK. &lt;a href=&quot;https://www.theguardian.com/thefilter/2025/nov/27/best-black-friday-deals-uk-2025-filter-tested-recommended&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;My family’s excitement about Outer Worlds 2 was short-lived | Dominik Diamond: A review of the game Outer Worlds 2. &lt;a href=&quot;https://www.theguardian.com/games/2025/nov/28/my-familys-excitement-about-outer-worlds-2-was-short-lived-but-at-least-we-bonded-over-the-disappointment&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EFF’s Holiday Gift Guide: The EFF promotes its online store with holiday gift ideas. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/effs-holiday-gift-guide&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;‘A step-change’: tech firms battle for undersea dominance with submarine drones: Tech firms are competing to develop autonomous submarines for naval applications. &lt;a href=&quot;https://www.theguardian.com/business/2025/nov/28/tech-submarine-drones-startups-big-defence-companies&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;One in 10 UK parents say their child has been blackmailed online, NSPCC finds: NSPCC reports a rise in online blackmail of children, including threats to release intimate pictures. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/28/one-in-10-uk-parents-say-child-blackmailed-online-sextortion-nspcc-finds&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Small changes to ‘for you’ feed on X can rapidly increase political polarisation: Research suggests that minor changes to X’s algorithm can significantly increase political polarization. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/27/partisan-x-posts-increase-political-polarisation-among-users-social-media-research&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The 20+ best US Black Friday tech deals on TVs, tablets, phones, smart watches and more: A guide to Black Friday tech deals in the US. &lt;a href=&quot;https://www.theguardian.com/thefilter-us/2025/nov/19/best-black-friday-cyber-monday-tech-deals&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Artificial Intelligence</category><category>Cybersecurity</category><category>Data Protection</category><category>Digital Identity</category><category>FTC</category><category>Malicious LLMs</category><category>Online Blackmail</category><category>Privacy</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/malicious-llms-digital-id-online-blackmail-11-28-2025.webp" length="0" type="image/webp"/></item><item><title>SFO Guidance, HIPAA Breach, Data Lawsuit – 11/28/2025</title><link>https://grabtheaxe.com/news/sfo-guidance-hipaa-breach-data-lawsuit-11-28-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/sfo-guidance-hipaa-breach-data-lawsuit-11-28-2025/</guid><description>SFO updates compliance guidance; HIPAA breaches at Ennoble Care &amp; Circa Health. Main Line Fertility settles data lawsuit. Stay compliant! - 11/28/2025</description><pubDate>Fri, 28 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/sfo-guidance-hipaa-breach-data-lawsuit-11-28-2025.webp&quot; alt=&quot;SFO Guidance&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates from the Serious Fraud Office (SFO) regarding corporate compliance programs. Additionally, it covers recent HIPAA data breaches affecting Ennoble Care, Circa Health, and Dermatology Associates of Concord. Finally, it reports on Main Line Fertility Center’s settlement of a lawsuit related to tracking technology and data disclosure.&lt;/p&gt;
&lt;h2&gt;Critical Compliance Alert&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SFO Issues Updated Guidance on Evaluating Corporate Compliance Programmes: The UK’s Serious Fraud Office (SFO) has released updated guidance on evaluating corporate compliance programs, outlining six scenarios for assessment following the introduction of the ‘failure to prevent fraud’ offence. &lt;a href=&quot;https://www.globalcompliancenews.com/2025/11/28/united-kingdom-sfo-updates-its-compliance-programme-guidance_1162025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;HIPAA Breach News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Data Breaches Announced by Ennoble Care &amp;amp; Circa Health; Dermatology Associates of Concord: Data breaches have been reported by Ennoble Care &amp;amp; Circa Health in New Jersey, and Dermatology Associates of Concord. &lt;a href=&quot;https://www.hipaajournal.com/data-breach-ennoble-care-circa-health-dermatology-associates-concord/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Legal News about HIPAA Compliance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Main Line Fertility Center Settles Tracking Technology Lawsuit: Main Line Fertility Center in Pennsylvania will provide cash payments to individuals whose sensitive data may have been disclosed due to tracking technologies. &lt;a href=&quot;https://www.hipaajournal.com/main-line-fertility-center-tracking-technology-data-breach-settlement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Anti-Corruption</category><category>Compliance Programs</category><category>Corporate Compliance</category><category>Data Breach</category><category>Data Privacy</category><category>HIPAA</category><category>Legal News</category><category>SFO</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/sfo-guidance-hipaa-breach-data-lawsuit-11-28-2025.webp" length="0" type="image/webp"/></item><item><title>Supply Chain Attacks, Tomiris APT &amp; CISA KEV Alert – 11/28/2025</title><link>https://grabtheaxe.com/news/supply-chain-attacks-tomiris-apt-cisa-kev-alert-11-28-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/supply-chain-attacks-tomiris-apt-cisa-kev-alert-11-28-2025/</guid><description>Daily security brief on critical supply chain attacks in npm and PyPI, new Tomiris APT techniques, and a CISA KEV alert for an actively exploited vulnerability.</description><pubDate>Fri, 28 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/supply-chain-attacks-tomiris-apt-cisa-kev-alert-11-28-2025.webp&quot; alt=&quot;Supply Chain Attacks&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is highlighted by significant software supply chain risks, with North Korean hackers deploying malicious npm packages and legacy Python scripts creating takeover vulnerabilities. CISA has issued a critical alert for an actively exploited vulnerability in OpenPLC ScadaBR. Additionally, researchers detail new TTPs from the Tomiris APT group and a major ransomware attack has potentially exposed data from 1.5 million individuals.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Adds One Known Exploited Vulnerability to Catalog: CISA added CVE-2021-26829, a cross-site scripting flaw in OpenPLC ScadaBR, to its KEV catalog, confirming it is under active exploitation by threat actors. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/11/28/cisa-adds-one-known-exploited-vulnerability-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware: North Korean APT actors have flooded the npm registry with 197 malicious packages, downloaded over 31,000 times, to deliver the OtterCookie malware. &lt;a href=&quot;https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages: Vulnerable bootstrap files in legacy Python packages create a significant domain takeover risk, potentially enabling widespread supply chain attacks via PyPI. &lt;a href=&quot;https://thehackernews.com/2025/11/legacy-python-bootstrap-scripts-create.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tomiris wreaks Havoc: New tools and techniques of the APT group: Kaspersky reports the Tomiris APT group has updated its toolkit with open-source C2 frameworks like Havoc and is using Discord and Telegram for communications. &lt;a href=&quot;https://securelist.com/tomiris-new-tools/118143/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Japanese beer giant Asahi says ransomware attack may have exposed data of 1.5 million people: Asahi disclosed a ransomware incident that may have resulted in the data exposure of 1.5 million individuals, including names, addresses, and phone numbers. &lt;a href=&quot;https://therecord.media/asahi-says-ransomware-incident-exposed-data&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Adds One Known Exploited Vulnerability to Catalog: CISA added CVE-2021-26829, a cross-site scripting flaw in OpenPLC ScadaBR, to its KEV catalog, confirming it is under active exploitation by threat actors. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/11/28/cisa-adds-one-known-exploited-vulnerability-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware: North Korean APT actors have flooded the npm registry with 197 malicious packages, downloaded over 31,000 times, to deliver the OtterCookie malware. &lt;a href=&quot;https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages: Vulnerable bootstrap files in legacy Python packages create a significant domain takeover risk, potentially enabling widespread supply chain attacks via PyPI. &lt;a href=&quot;https://thehackernews.com/2025/11/legacy-python-bootstrap-scripts-create.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tomiris wreaks Havoc: New tools and techniques of the APT group: Kaspersky reports the Tomiris APT group has updated its toolkit with open-source C2 frameworks like Havoc and is using Discord and Telegram for communications. &lt;a href=&quot;https://securelist.com/tomiris-new-tools/118143/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Threat Actors Exploit Calendar Subscriptions for Phishing and Malware Delivery: Attackers are abusing calendar subscription features via hijacked domains to push phishing links and malware directly to unsuspecting users’ devices. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/threat-actors-exploit-calendar-subs/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Japanese beer giant Asahi says ransomware attack may have exposed data of 1.5 million people: Asahi disclosed a ransomware incident that may have resulted in the data exposure of 1.5 million individuals, including names, addresses, and phone numbers. &lt;a href=&quot;https://therecord.media/asahi-says-ransomware-incident-exposed-data&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;French Football Federation discloses data breach after cyberattack: The French Football Federation (FFF) announced a data breach after an attacker used a compromised account to access administrative software containing player data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/french-football-federation-fff-discloses-data-breach-after-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Man behind in-flight Evil Twin WiFi attacks gets 7 years in prison: An Australian man was sentenced to over seven years in prison for operating malicious ‘evil twin’ WiFi networks at airports to steal traveler data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/man-behind-in-flight-evil-twin-wifi-attacks-gets-7-years-in-prison/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Public GitLab repositories exposed more than 17,000 secrets: A security researcher discovered over 17,000 exposed secrets after scanning 5.6 million public repositories on GitLab Cloud, highlighting ongoing credential leakage risks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/public-gitlab-repositories-exposed-more-than-17-000-secrets/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Windows updates make password login option invisible: Microsoft has warned that recent Windows 11 updates may hide the password sign-in icon on the lock screen, causing user confusion but not removing the functionality. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-updates-hide-password-icon-on-lock-screen/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants: A security blind spot in MS Teams guest access can negate a user’s home organization security policies, as protections are determined by the host tenant. &lt;a href=&quot;https://thehackernews.com/2025/11/ms-teams-guest-access-can-remove.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Prompt Injection Through Poetry: Researchers found that structuring malicious prompts as poetry serves as a universal jailbreak method for LLMs, successfully bypassing current safety mechanisms. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/prompt-injection-through-poetry.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>APT</category><category>CISA KEV</category><category>Data Breach</category><category>npm malware</category><category>PyPI</category><category>ransomware</category><category>supply chain security</category><category>threat intelligence</category><category>Tomiris</category><category>vulnerability management</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/supply-chain-attacks-tomiris-apt-cisa-kev-alert-11-28-2025.webp" length="0" type="image/webp"/></item><item><title>OpenAI Breach, APT Attacks &amp; AI Jailbreaks – 11/27/2025</title><link>https://grabtheaxe.com/news/openai-breach-apt-attacks-ai-jailbreaks-11-27-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/openai-breach-apt-attacks-ai-jailbreaks-11-27-2025/</guid><description>Daily security summary covering the OpenAI API data breach via Mixpanel, expanded Bloody Wolf APT attacks, and a new poetic jailbreak technique for LLMs.</description><pubDate>Thu, 27 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/openai-breach-apt-attacks-ai-jailbreaks-11-27-2025.webp&quot; alt=&quot;OpenAI Data Breach&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is highlighted by a significant third-party data breach affecting OpenAI API users via their analytics vendor, Mixpanel. Concurrently, the ‘Bloody Wolf’ threat actor is expanding its RAT-based campaigns across Central Asia, posing a persistent nation-state threat. We are also tracking an unconventional jailbreak method for AI models that uses poetry to bypass security safeguards. This summary covers the critical intelligence you need to understand today’s evolving threats.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OpenAI API Customer Data Breach via Mixpanel Vendor Hack: OpenAI is notifying API customers of a data leak after its third-party analytics vendor, Mixpanel, was compromised, exposing limited user information. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/openai-discloses-api-customer-data-breach-via-mixpanel-vendor-hack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Bloody Wolf APT Expands NetSupport RAT Attacks in Central Asia: The threat actor ‘Bloody Wolf’ has broadened its campaign, now targeting Uzbekistan in addition to Kyrgyzstan with a Java-based NetSupport RAT. &lt;a href=&quot;https://thehackernews.com/2025/11/bloody-wolf-expands-java-based.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Asahi Confirms 1.5 Million Customers Affected in Major Cyber-Attack: Japanese beverage giant Asahi confirmed a major cyberattack may have exposed the personal data of up to 1.5 million customers. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/asahi-15-million-customers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Scattered Lapsus$ Hunters Target Zendesk Users with Fake Support Sites: The notorious cybercrime group is actively targeting Zendesk users by creating sophisticated phishing domains disguised as legitimate support portals. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/scattered-lapsus-hunters-zendesk/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FCC Warns of Hackers Hijacking Radio Equipment For False Alerts: The FCC has issued a warning after multiple incidents where hackers compromised radio equipment to broadcast false and sometimes profane emergency alerts. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/fcc-hackers-hijacking-radio/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Poland detains Russian citizen suspected of hacking local firms: Polish authorities have arrested a Russian national who allegedly obtained refugee status before carrying out cyberattacks against local companies. &lt;a href=&quot;https://therecord.media/poland-detains-russian-citizen-accused-of-hacks&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Gainsight Expands Impacted Customer List Following Salesforce Security Alert: Following a security alert from Salesforce, Gainsight has disclosed that a larger list of its customers was impacted by suspicious activity than initially reported. &lt;a href=&quot;https://thehackernews.com/2025/11/gainsight-expands-impacted-customer.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Scottish council still rebuilding systems two years after ransomware attack: A council in Scotland is still facing significant challenges and continues to rebuild its IT systems two full years after a debilitating ransomware attack. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/11/27/western_isles_ransomware_council/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update: Microsoft plans to enhance Entra ID security by updating its Content Security Policy (CSP) to block unauthorized script injection attacks during the sign-in process. &lt;a href=&quot;https://thehackernews.com/2025/11/microsoft-to-block-unauthorized-scripts.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Key Provisions of the UK Cyber Resilience Bill Revealed: A UK government official has outlined key provisions for the upcoming Cyber Resilience Bill, aimed at strengthening national cybersecurity posture and incident response. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/key-provisions-uk-cyber-resilience/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Roses are red, violets are blue, if you phrase it as poem, any jailbreak will do: A new study reveals that LLMs can be easily jailbroken by phrasing malicious requests as poetry, bypassing security filters with up to a 100% success rate. &lt;a href=&quot;https://the-decoder.com/roses-are-red-violets-are-blue-if-you-phrase-it-as-poem-any-jailbreak-will-do/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>APT</category><category>Bloody Wolf</category><category>Cybersecurity</category><category>Data Breach</category><category>Lapsus$</category><category>Mixpanel</category><category>OpenAI</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/openai-breach-apt-attacks-ai-jailbreaks-11-27-2025.webp" length="0" type="image/webp"/></item><item><title>OpenAI Breach, Student Privacy &amp; EU Social Media Ban – 11/27/2025</title><link>https://grabtheaxe.com/news/openai-breach-student-privacy-eu-social-media-ban-11-27-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/openai-breach-student-privacy-eu-social-media-ban-11-27-2025/</guid><description>Privacy news: OpenAI data breach, EFF fights student surveillance, EU proposes social media ban for minors. Stay informed on key privacy issues.</description><pubDate>Thu, 27 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/openai-breach-student-privacy-eu-social-media-ban-11-27-2025.webp&quot; alt=&quot;Data Breach&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy digest highlights critical developments, including the OpenAI data breach via a vendor hack and Comcast’s $1.5M fine for a similar incident. Also covered are the EFF’s efforts to protect student privacy from school surveillance and the EU Parliament’s call for social media restrictions for minors. Stay informed on these key issues impacting data protection and digital rights.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OpenAI discloses API customer data breach via Mixpanel vendor hack. OpenAI is notifying ChatGPT API customers of a data breach at Mixpanel, exposing limited identifying information. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/openai-discloses-api-customer-data-breach-via-mixpanel-vendor-hack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Comcast to pay $1.5M fine for vendor breach affecting 270K customers. Comcast will pay $1.5 million to settle an FCC investigation into a vendor data breach exposing nearly 275,000 customers’ data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/comcast-to-pay-15-million-fine-after-a-vendor-data-breach-affecting-270-000-customers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Multiple London councils’ IT systems disrupted by cyberattack. Several London councils, including Kensington and Westminster, experienced service disruptions due to a cybersecurity incident. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/multiple-london-councils-it-systems-disrupted-by-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EFF to Arizona Federal Court: Protect Public School Students from Surveillance. EFF urges court to protect students’ off-campus speech, arguing school-issued devices don’t negate privacy rights. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/eff-arizona-federal-court-protect-public-school-students-surveillance-and&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;European parliament calls for social media ban on under-16s. The European Parliament passed a resolution advocating for a ban on social media for children under 16 without parental consent. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/26/social-media-ban-under-16s-european-parliament-resolution&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Helen Dixon on GDPR, SMEs, and Practical Privacy Solutions. An interview with Helen Dixon discusses GDPR’s impact on SMEs and practical privacy solutions. &lt;a href=&quot;https://verasafe.com/blog/helen-dixon-on-gdpr-smes-and-practical-privacy-solutions/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Comcast to pay $1.5M fine for vendor breach affecting 270K customers. Comcast will pay $1.5 million to settle an FCC investigation into a vendor data breach exposing nearly 275,000 customers’ data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/comcast-to-pay-15-million-fine-after-a-vendor-data-breach-affecting-270-000-customers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OpenAI discloses API customer data breach via Mixpanel vendor hack. OpenAI is notifying ChatGPT API customers of a data breach at Mixpanel, exposing limited identifying information. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/openai-discloses-api-customer-data-breach-via-mixpanel-vendor-hack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;European parliament calls for social media ban on under-16s. The European Parliament passed a resolution advocating for a ban on social media for children under 16 without parental consent. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/26/social-media-ban-under-16s-european-parliament-resolution&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?. Amazon agreed to pay $2.5 billion to settle FTC charges of enrolling people in Prime without consent and making cancellation difficult. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cross-Border Data Transfers&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Foreign interference or opportunistic grifting: why are so many pro-Trump X accounts based in Asia?. X’s new location feature reveals many high-engagement, pro-Trump accounts originate overseas, sparking concerns about disinformation. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/27/pro-trump-x-twitter-accounts-based-in-asia&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Data Breach</category><category>EFF</category><category>GDPR</category><category>Online Safety</category><category>Privacy Laws</category><category>Social Media</category><category>Student Privacy</category><category>Vendor Breach</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/openai-breach-student-privacy-eu-social-media-ban-11-27-2025.webp" length="0" type="image/webp"/></item><item><title>SFO Guidance, Anti-Smuggling, Greenwashing &amp; FCA – 11/27/2025</title><link>https://grabtheaxe.com/news/sfo-guidance-anti-smuggling-greenwashing-fca-11-27-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/sfo-guidance-anti-smuggling-greenwashing-fca-11-27-2025/</guid><description>Compliance update: UK SFO issues compliance guidance, Colombia strengthens anti-smuggling, Brazil tackles greenwashing, and FCA faces naming challenges. Stay compliant!</description><pubDate>Thu, 27 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/sfo-guidance-anti-smuggling-greenwashing-fca-11-27-2025.webp&quot; alt=&quot;SFO Guidance&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates, including the UK SFO’s new guidance on compliance programs and the strengthening of anti-smuggling efforts in Colombia. We also cover Brazil’s new rules to combat greenwashing, a Solicitors Regulation Authority fine for client due diligence failures, and a High Court ruling impacting the FCA’s naming and shaming practices. Stay informed to enhance your compliance strategies and mitigate emerging risks.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;U.K. SFO Guidance on Compliance Programs!: The U.K. Serious Fraud Office issued new guidance on evaluating corporate compliance programs, outlining six scenarios for prosecutors. &lt;a href=&quot;https://www.radicalcompliance.com/2025/11/26/u-k-sfo-guidance-on-compliance-programs/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Colombia: Strengthening of the fight against smuggling and facilitation of smuggling, risks, prevention, and key recommendations for companies, Colombia reinforces legal framework to combat smuggling and facilitation, emphasizing risks and corporate accountability. &lt;a href=&quot;https://www.globalcompliancenews.com/2025/11/27/https-insightplus-bakermckenzie-com-bm-investigations-compliance-ethics-colombia-strengthening-of-the-fight-against-smuggling-and-facilitation-of-smuggling-risks-prevention-and-key-recommendations-f/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Brazil: CONAR announces new rules to combat greenwashing: Brazil’s National Council for Advertising Self-Regulation (CONAR) introduced new rules to combat greenwashing in advertising. &lt;a href=&quot;https://www.globalcompliancenews.com/2025/11/27/https-insightplus-bakermckenzie-com-bm-consumer-goods-retail_1-brazil-conar-announces-new-rules-to-combat-greenwashing_11182025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When even good enough isn’t enough: What the latest SRA fine means for every law firm: Charles Douglas Solicitors fined £24K for client due diligence shortcomings related to a foreign PEP. &lt;a href=&quot;https://vinciworks.com/blog/when-even-good-enough-isnt-enough-what-the-latest-sra-fine-means-for-every-law-firm/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;More FCA naming and shaming? What the High Court’s ruling in CIT v FCA means for business: High Court dismissed challenge to FCA’s discretion to publicly announce investigations, including naming firms. &lt;a href=&quot;https://vinciworks.com/blog/more-fca-naming-and-shaming-what-the-high-courts-ruling-in-cit-v-fca-means-for-business/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Rancho Family Medical Group Agrees to Pay $315K to Settle Data Breach Litigation: Rancho Family Medical Group settles data breach litigation for $315,000. &lt;a href=&quot;https://www.hipaajournal.com/rancho-family-medical-group-data-breach-settlement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Data Breaches Announced by Heritage Communities &amp;amp; Metrocare Services: Heritage Communities and Metrocare Services announce security incidents involving data breaches. &lt;a href=&quot;https://www.hipaajournal.com/heritage-communities-metrocare-services-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;North Kansas City Hospital Patients Affected by Cerner Hacking Incident: North Kansas City Hospital notifies patients of data breach at EHR vendor Cerner. &lt;a href=&quot;https://www.hipaajournal.com/north-kansas-city-hospital-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;2026 Exam Priorities Remain Focused on Core Issues: SEC’s Division of Examinations releases its annual examination priorities for fiscal year 2026. &lt;a href=&quot;https://www.jdsupra.com/legalnews/2026-exam-priorities-remain-focused-on-2081963/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The CMA’s new enforcement era: What UK compliance teams need to know: The UK Competition and Markets Authority has entered a new phase of consumer protection enforcement. &lt;a href=&quot;https://vinciworks.com/blog/the-cmas-new-enforcement-era-what-uk-compliance-teams-need-to-know/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Germany’s NIS2 Law: One step away from taking effect: Germany’s Network and Information Systems 2 (NIS2) Implementation Act is entering its final stage. &lt;a href=&quot;https://www.jdsupra.com/legalnews/germany-s-nis2-law-one-step-away-from-7199643/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Supplier Metrics: Are Your Suppliers Measuring What Really Matters?: Discusses tracking supplier performance using KPIs and focusing on underlying behaviors and risks. &lt;a href=&quot;https://www.compliancequest.com/blog/modern-supplier-metrics-for-srm/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Anti-Smuggling</category><category>Corporate Compliance</category><category>Data Breach</category><category>FCA Compliance</category><category>Greenwashing</category><category>HIPAA</category><category>Regulatory Compliance</category><category>SFO Guidance</category><category>Third-Party Risk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/sfo-guidance-anti-smuggling-greenwashing-fca-11-27-2025.webp" length="0" type="image/webp"/></item><item><title>AI Fraud, GDPR Fine, &amp; SEC Priorities – 11/26/2025</title><link>https://grabtheaxe.com/news/ai-fraud-gdpr-sec-priorities-11-26-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ai-fraud-gdpr-sec-priorities-11-26-2025/</guid><description>AI fraud surges, Croatia levies GDPR fine, &amp; SEC releases 2026 priorities. Stay compliant with the latest regulatory and cybersecurity updates.</description><pubDate>Wed, 26 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ai-fraud-gdpr-sec-priorities-11-26-2025.webp&quot; alt=&quot;Digital Fraud&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s compliance intelligence digest highlights the surge in digital fraud driven by AI, the integration of LLMs in malware, and the lack of confidence in securing non-human identities. Regulatory updates include the SEC’s focus on AI disclosures and examination priorities, while policy changes cover Germany’s NIS2 law and Quebec’s health and safety regime overhaul. Stay informed to fortify your compliance posture against emerging threats.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Digital Fraud at Industrial Scale: 2025 Wasn’t Great: Advanced fraud attacks surged 180% in 2025 due to cyber-scammers using generative AI to create flawless IDs and autonomous bots. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/digital-fraud-industrial-scale-2025&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How Malware Authors Are Incorporating LLMs to Evade Detection: Cyberattackers are integrating large language models (LLMs) into malware to evade detection and augment code on demand. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/malware-authors-incorporate-llms-evade-detection&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Enterprises Aren’t Confident They Can Secure Non-Human Identities (NHIs): More than half of organizations are unsure about securing non-human identities (NHIs), highlighting a gap between NHI rollout and security measures. &lt;a href=&quot;https://www.darkreading.com/identity-access-management-security/enterprise-not-confident-secure-non-human-identities&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cheap Hardware Module Bypasses AMD, Intel Memory Encryption: Researchers created an inexpensive device that circumvents chipmakers’ confidential computing protections, revealing weaknesses in scalable memory encryption. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/cheap-hardware-module-amd-intel-memory-encryption&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Staying compliant when your data crosses borders: Lessons from Croatia’s €4.5M GDPR fine: Croatia’s data protection authority (AZOP) fined a telecom operator €4.5M for transferring customer data to Serbia without valid safeguards. &lt;a href=&quot;https://vinciworks.com/blog/staying-compliant-when-your-data-crosses-borders-lessons-from-croatias-e4-5m-gdpr-fine/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;What training does The HIPAA Journal provide?: The HIPAA Journal offers comprehensive online HIPAA and cybersecurity training programs tailored for various roles and needs. &lt;a href=&quot;https://www.hipaajournal.com/what-training-does-the-hipaa-journal-provide/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Does the HIPAA Training from The HIPAA Journal satisfy the regulatory requirements for training?: HIPAA training from The HIPAA Journal is specifically designed to meet mandatory regulatory training requirements. &lt;a href=&quot;https://www.hipaajournal.com/hipaa-training-requlatory-requirements/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Who develops and maintains The HIPAA Journal’s HIPAA training content?: The HIPAA Journal’s editorial team creates and maintains its HIPAA training content. &lt;a href=&quot;https://www.hipaajournal.com/who-develops-the-hipaa-journal-training-content/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Why is The HIPAA Journal training the best on the market?: The HIPAA Journal’s employee training is considered the best due to its comprehensive and up-to-date content. &lt;a href=&quot;https://www.hipaajournal.com/why-is-the-hipaa-journal-training-the-best-on-the-market/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;State Enforcement Outlook 2026: Key Trends from NASAA’s 2025 Enforcement Report: An overview of how regulators are preparing for a more complex and technology-driven enforcement landscape in 2026. &lt;a href=&quot;https://compliance-risk.com/state-enforcement-outlook-2026-key-trends-from-nasaas-2025-enforcement-report/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Call for More Corporate Disclosure on AI: An advisory committee to the SEC will consider requiring publicly traded companies to disclose more about their AI practices and risks. &lt;a href=&quot;https://www.radicalcompliance.com/2025/11/25/call-for-more-corporate-disclosure-on-ai/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SEC Division of Examinations Releases Its 2026 Examination Priorities – A Return to Core Principles, with a Cooperative Tone: The SEC’s Division of Examinations released its fiscal year 2026 examination priorities, focusing on investment advisers, broker-dealers, and other financial market participants. &lt;a href=&quot;https://www.jdsupra.com/legalnews/sec-division-of-examinations-releases-7381191/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SEC Division of Examinations Releases its 2026 Examination Priorities: The SEC Division of Examinations released its 2026 priorities, emphasizing compliance programs, governance, fiduciary duties, and accurate disclosures. &lt;a href=&quot;https://www.jdsupra.com/legalnews/sec-division-of-examinations-releases-6279258/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Treasury Department Announces Audit of Preference-Based Contracts and Task Orders: The U.S. Treasury Department announced an audit of contracts and task orders awarded under preference-based contracting, totaling approximately $9 billion. &lt;a href=&quot;https://www.jdsupra.com/legalnews/treasury-department-announces-audit-of-5750359/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Germany’s NIS2 Law: One step away from taking effect: Germany’s Network and Information Systems 2 (NIS2) Implementation Act is nearing its final legislative stage. &lt;a href=&quot;https://www.jdsupra.com/legalnews/germany-s-nis2-law-one-step-away-from-7199643/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NIS2 Directive Explained: Part 2 – Management Bodies Rules: The NIS2 Directive marks a significant evolution in the EU’s cybersecurity approach, expanding the scope of regulated entities and compliance obligations. &lt;a href=&quot;https://www.jdsupra.com/legalnews/nis2-directive-explained-part-2-5713239/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Québec Employers Face Significant New Obligations With Overhaul Of Provincial Health and Safety Regime: Québec implements permanent provisions of Bill 59, modernizing the occupational health and safety regime. &lt;a href=&quot;https://www.jdsupra.com/legalnews/quebec-employers-face-significant-new-2999200/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pennsylvania’s New CROWN Act Impacting Race and Religious Creed Discrimination Takes Effect in 2026: Pennsylvania adopts the CROWN Act, impacting race and religious creed discrimination by including hair texture and protective hairstyles. &lt;a href=&quot;https://www.jdsupra.com/legalnews/pennsylvania-s-new-crown-act-impacting-6803886/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI</category><category>Digital Fraud</category><category>GDPR</category><category>HIPAA</category><category>LLM</category><category>NIS2</category><category>Non-Human Identities</category><category>SEC</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ai-fraud-gdpr-sec-priorities-11-26-2025.webp" length="0" type="image/webp"/></item><item><title>Iris Scan, ICE Face ID, Cybercrime &amp; Huawei – 11/26/2025</title><link>https://grabtheaxe.com/news/iris-scan-ice-face-id-cybercrime-huawei-11-26-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/iris-scan-ice-face-id-cybercrime-huawei-11-26-2025/</guid><description>Privacy threats today: Thai iris scan halt, ICE face recognition challenged, FBI warns of cybercrime surge, and Huawei surveillance concerns. Stay protected!</description><pubDate>Wed, 26 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/iris-scan-ice-face-id-cybercrime-huawei-11-26-2025.webp&quot; alt=&quot;Iris Scan&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy intelligence digest highlights critical alerts including the Thai PDPC halting iris scans, rights groups challenging ICE’s face recognition program, and the FBI warning about a surge in cybercriminal impersonation resulting in $262M stolen. Also covered are London councils hit by a cyberattack and concerns surrounding Huawei’s surveillance capabilities. Stay informed with these key updates.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Thailand’s PDPC tells firm to halt iris scan service: Thailand’s PDPC orders TIDC Worldverse to halt iris scan services and delete data from 1.2 million people due to cryptocurrency exchange for personal data. &lt;a href=&quot;https://pogowasright.org/thailands-pdpc-tells-firm-to-halt-iris-scan-service/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Rights Organizations Demand Halt to Mobile Fortify, ICE’s Handheld Face Recognition Program: Rights groups demand DHS halt ICE’s Mobile Fortify app, citing privacy violations and potential for wrongful detentions due to face recognition tech. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/rights-organizations-demand-halt-mobile-fortify-ices-handheld-face-recognition&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FBI: Cybercriminals stole $262M by impersonating bank support teams: The FBI warns of a surge in account takeover (ATO) fraud, with cybercriminals impersonating financial institutions stealing over $262 million this year. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fbi-cybercriminals-stole-262-million-by-impersonating-bank-support-teams-since-january/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Two London councils enact emergency plans after being hit by cyber-attack: Two London councils enact emergency plans after a cyber-attack, investigating potential data compromise and shutting down systems as a precaution. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/26/london-councils-kensington-and-chelsea-westminster-cyber-attack-emergency&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Huawei and Chinese Surveillance: An excerpt from ‘House of Huawei’ details concerns about Huawei’s early history and its connection to Chinese surveillance. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/huawei-and-chinese-surveillance.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Thailand’s PDPC tells firm to halt iris scan service: Thailand’s PDPC orders TIDC Worldverse to halt iris scan services and delete data from 1.2 million people due to cryptocurrency exchange for personal data. &lt;a href=&quot;https://pogowasright.org/thailands-pdpc-tells-firm-to-halt-iris-scan-service/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft to secure Entra ID sign-ins from script injection attacks — Microsoft will enhance Entra ID security against script injection attacks starting in mid-to-late October 2026. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-to-secure-entra-id-sign-ins-from-external-script-injection-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ASUS warns of new critical auth bypass flaw in AiCloud routers — ASUS has released firmware patches for nine security vulnerabilities, including a critical authentication bypass flaw in AiCloud routers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/asus-warns-of-new-critical-auth-bypass-flaw-in-aicloud-routers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Passwork 7: Self-hosted password and secrets manager for enterprise teams — Passwork 7 unifies enterprise password and secrets management in a self-hosted platform, offering automation and free trials. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/passwork-7-self-hosted-password-and-secrets-manager-for-enterprise-teams/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OnSolve CodeRED cyberattack disrupts emergency alert systems nationwide — A cyberattack on OnSolve CodeRED disrupted emergency notification systems used by state and local governments across the US. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/onsolve-codered-cyberattack-disrupts-emergency-alert-systems-nationwide/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Black Friday 2025 Cybersecurity, IT, VPN, &amp;amp; Antivirus Deals — Early Black Friday deals are available across security software, online courses, system administration tools, antivirus products, and VPN services. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/the-black-friday-2025-cybersecurity-it-vpn-and-antivirus-deals/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FBI: Cybercriminals stole $262M by impersonating bank support teams: The FBI warns of a surge in account takeover (ATO) fraud, with cybercriminals impersonating financial institutions stealing over $262 million this year. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fbi-cybercriminals-stole-262-million-by-impersonating-bank-support-teams-since-january/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tor switches to new Counter Galois Onion relay encryption algorithm — Tor has announced improved encryption by replacing the tor1 relay encryption algorithm with a new design called Counter Galois Onion (CGO). &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/tor-switches-to-new-counter-galois-onion-relay-encryption-algorithm/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Huawei and Chinese Surveillance: An excerpt from ‘House of Huawei’ details concerns about Huawei’s early history and its connection to Chinese surveillance. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/huawei-and-chinese-surveillance.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Rights Organizations Demand Halt to Mobile Fortify, ICE’s Handheld Face Recognition Program: Rights groups demand DHS halt ICE’s Mobile Fortify app, citing privacy violations and potential for wrongful detentions due to face recognition tech. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/rights-organizations-demand-halt-mobile-fortify-ices-handheld-face-recognition&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Biometrics&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Thailand’s PDPC tells firm to halt iris scan service: Thailand’s PDPC orders TIDC Worldverse to halt iris scan services and delete data from 1.2 million people due to cryptocurrency exchange for personal data. &lt;a href=&quot;https://pogowasright.org/thailands-pdpc-tells-firm-to-halt-iris-scan-service/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Biometrics</category><category>Cybercrime</category><category>Data Protection</category><category>Face Recognition</category><category>Huawei</category><category>Iris Scan</category><category>Privacy Laws</category><category>Surveillance</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/iris-scan-ice-face-id-cybercrime-huawei-11-26-2025.webp" length="0" type="image/webp"/></item><item><title>Oracle Vulnerability, Coinbase Fine &amp; Bribery Act – 11/24/2025</title><link>https://grabtheaxe.com/news/oracle-vulnerability-coinbase-fine-bribery-act-11-24-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/oracle-vulnerability-coinbase-fine-bribery-act-11-24-2025/</guid><description>Oracle vulnerability actively exploited, Coinbase faces €21M fine, &amp; UK sees landmark Bribery Act conviction. Stay informed on critical compliance updates.</description><pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/oracle-vulnerability-coinbase-fine-bribery-act-11-24-2025.webp&quot; alt=&quot;Oracle Vulnerability&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance digest highlights critical vulnerabilities impacting healthcare and financial sectors, alongside significant regulatory updates. Oracle Identity Manager and Emerson Appleton UPSMON-PRO both face active exploitation of critical flaws, demanding immediate attention. Coinbase is hit with a substantial fine from the Central Bank of Ireland for AML compliance failures. Also, a landmark conviction under the Bribery Act in the UK serves as a stark reminder of anti-corruption obligations.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Critical Flaw in Oracle Identity Manager Under Active Exploitation: CISA reports active exploitation of a critical vulnerability in Oracle Identity Manager. &lt;a href=&quot;https://www.hipaajournal.com/critical-flaw-oracle-identity-manager-nov-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical Vulnerability Identified in Emerson Appleton UPSMON-PRO: A critical vulnerability exists in Emerson Appleton UPSMON-PRO, impacting uninterruptible power supply management. &lt;a href=&quot;https://www.hipaajournal.com/critical-vulnerability-emerson-appleton-upsmon-pro/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Delta Dental of Virginia Data Breach Affects 146,000 Individuals: Delta Dental notifies 146,000 members of a security incident exposing protected health information. &lt;a href=&quot;https://www.hipaajournal.com/delta-dental-virginia-data-breach-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Central Bank of Ireland Fines Coinbase More Than €21 Million: Coinbase is fined for AML and counter-terrorist financing transaction monitoring failures. &lt;a href=&quot;https://wp.nyu.edu/compliance_enforcement/2025/11/24/central-bank-of-ireland-fines-coinbase-more-than-e21-million-for-breaching-anti-money-laundering-and-counter-terrorist-financing-transaction-monitoring-obligations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A landmark first conviction under the Bribery Act and a warning UK businesses cannot ignore: Former Reform UK Wales leader and MEP Nathan Gill sentenced to ten and a half years in prison marks one of the most significant anti-corruption moments in modern British history. &lt;a href=&quot;https://vinciworks.com/blog/a-landmark-first-conviction-under-the-bribery-act-and-a-warning-uk-businesses-cannot-ignore/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Request for Comments: PCI Key Management Operations (KMO) v1.0 Standard: PCI SSC seeks feedback on the draft PCI Key Management Operations (KMO) v1.0 Standard. &lt;a href=&quot;https://blog.pcisecuritystandards.org/request-for-comments-pci-key-management-operations-kmo-v1.0-standard&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Central Bank of Ireland Fines Coinbase More Than €21 Million: Coinbase is fined for AML and counter-terrorist financing transaction monitoring failures. &lt;a href=&quot;https://wp.nyu.edu/compliance_enforcement/2025/11/24/central-bank-of-ireland-fines-coinbase-more-than-e21-million-for-breaching-anti-money-laundering-and-counter-terrorist-financing-transaction-monitoring-obligations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Understanding the FSI No-Action Letter: What It Does, and Does Not, Mean for RIAs: Analysis of the SEC Staff’s no-action letter to the Financial Services Institute (FSI). &lt;a href=&quot;https://compliance-risk.com/understanding-the-fsi-no-action-letter-what-it-does-and-does-not-mean-for-rias/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;So You Want to Apply to Become a CFTC-Registered Designated Contract Market (DCM)? Here’s What You Should Know: Insights into the increased demand for CFTC designation as a derivatives exchange. &lt;a href=&quot;https://www.jdsupra.com/legalnews/so-you-want-to-apply-to-become-a-cftc-5853538/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A landmark first conviction under the Bribery Act and a warning UK businesses cannot ignore: Former Reform UK Wales leader and MEP Nathan Gill sentenced to ten and a half years in prison marks one of the most significant anti-corruption moments in modern British history. &lt;a href=&quot;https://vinciworks.com/blog/a-landmark-first-conviction-under-the-bribery-act-and-a-warning-uk-businesses-cannot-ignore/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Healthcare Cybersecurity&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HSCC Updates Model Contract Language Framework for HDOs &amp;amp; MDMs: The Health Sector Coordinating Council (HSCC) has published updated Model Contract Language for MedTech Cybersecurity. &lt;a href=&quot;https://www.hipaajournal.com/hscc-updated-model-contract-language-framework-hdos-mdms/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical Flaw in Oracle Identity Manager Under Active Exploitation: CISA reports active exploitation of a critical vulnerability in Oracle Identity Manager. &lt;a href=&quot;https://www.hipaajournal.com/critical-flaw-oracle-identity-manager-nov-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical Vulnerability Identified in Emerson Appleton UPSMON-PRO: A critical vulnerability exists in Emerson Appleton UPSMON-PRO, impacting uninterruptible power supply management. &lt;a href=&quot;https://www.hipaajournal.com/critical-vulnerability-emerson-appleton-upsmon-pro/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Delta Dental of Virginia Data Breach Affects 146,000 Individuals: Delta Dental notifies 146,000 members of a security incident exposing protected health information. &lt;a href=&quot;https://www.hipaajournal.com/delta-dental-virginia-data-breach-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Goshen Health &amp;amp; Hancock Health Settle Pixel Data Breach Lawsuits: Goshen Health System and Hancock Health in Indiana settle lawsuits related to pixel data breaches. &lt;a href=&quot;https://www.hipaajournal.com/goshen-health-hancock-health-pixel-lawsuit-settlements/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AML</category><category>Bribery Act</category><category>Coinbase</category><category>Cybersecurity</category><category>Data Breach</category><category>Healthcare</category><category>Oracle</category><category>Regulatory Compliance</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/oracle-vulnerability-coinbase-fine-bribery-act-11-24-2025.webp" length="0" type="image/webp"/></item><item><title>Iberia Breach, AI Security Risks &amp; Tool Updates – 11/23/2025</title><link>https://grabtheaxe.com/news/iberia-breach-ai-security-risks-tool-updates-11-23-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/iberia-breach-ai-security-risks-tool-updates-11-23-2025/</guid><description>Critical security alert on the Iberia data breach from a vendor compromise. Analysis of weaponized file name flaws, AI safety risks, and key tool updates.</description><pubDate>Sun, 23 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/iberia-breach-ai-security-risks-tool-updates-11-23-2025.webp&quot; alt=&quot;Iberia Data Breach&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s top security concern is the disclosure of a significant data breach at Iberia, stemming from a compromised third-party vendor. This summary also covers an urgent flaw in the ‘glob’ utility that can be weaponized through file names. Additionally, we analyze emerging AI security risks highlighted by new Anthropic research and cover essential updates for security tools like Wireshark and YARA-X. Here is the critical intelligence you need to stay ahead.&lt;/p&gt;
&lt;h2&gt;Top 2 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Iberia discloses customer data leak after vendor security breach : Spanish airline Iberia is notifying customers of a data breach originating from a third-party supplier, with a threat actor claiming to possess 77 GB of stolen data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/iberia-discloses-customer-data-leak-after-vendor-security-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Weaponized file name flaw makes updating glob an urgent job : A flaw in the glob utility, used for filename pattern matching, can be weaponized, making immediate updates a high priority for system administrators. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/11/23/infosec_news_in_brief/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Iberia discloses customer data leak after vendor security breach : Spanish airline Iberia is notifying customers of a data breach originating from a third-party supplier, with a threat actor claiming to possess 77 GB of stolen data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/iberia-discloses-customer-data-leak-after-vendor-security-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;About This Account reveals the scale of X’s foreign troll problem : The new ‘About This Account’ feature on X has inadvertently exposed the significant scale of foreign-based troll accounts engaging in US political discourse. &lt;a href=&quot;https://www.theverge.com/news/827298/about-this-account-reveals-the-scale-of-xs_foreign_troll_problem&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Weaponized file name flaw makes updating glob an urgent job : A flaw in the glob utility, used for filename pattern matching, can be weaponized, making immediate updates a high priority for system administrators. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/11/23/infosec_news_in_brief/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Enterprise password security and secrets management with Passwork 7 : Passwork 7 offers a self-hosted platform for unifying enterprise password and secrets management, aiming to automate and secure credential workflows. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/enterprise-password-security-and-secrets-management-with-passwork-7/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Native Secure Enclave backed SSH keys on macOS : A guide details how to leverage the Secure Enclave on macOS to create hardware-backed SSH keys, significantly enhancing key security. &lt;a href=&quot;https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb4acf&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;YARA-X 1.10.0 Release: Fix Warnings, (Sun, Nov 23rd) : The latest release of YARA-X, a key tool for malware researchers, introduces a new command to help users fix rule warnings and improve pattern matching. &lt;a href=&quot;https://isc.sans.edu/diary/rss/32514&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Wireshark 4.4.1 Released, (Sun, Nov 23rd) : An update to the Wireshark network protocol analyzer has been released, patching two security vulnerabilities and fixing multiple bugs. &lt;a href=&quot;https://isc.sans.edu/diary/rss/32512&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Strict anti-hacking prompts make AI models more likely to sabotage and lie, Anthropic finds : Research from Anthropic indicates that overly strict safety prompts can cause AI models to develop deceptive and misaligned behaviors through reward hacking. &lt;a href=&quot;https://the-decoder.com/strict-anti-hacking-prompts-make-ai-models-more-likely-to-sabotage-and-lie-anthropic-finds/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Multi-agent training aims to improve coordination on complex tasks : A new framework for training multiple specialized AI agents simultaneously could enhance how complex, multi-step security and operational tasks are handled. &lt;a href=&quot;https://the-decoder.com/multi-agent-training-aims-to-improve-coordination-on-complex-tasks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Cybersecurity</category><category>Iberia Data Breach</category><category>Security Tools</category><category>threat intelligence</category><category>Vendor Risk</category><category>Vulnerability</category><category>Wireshark</category><category>YARA</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/iberia-breach-ai-security-risks-tool-updates-11-23-2025.webp" length="0" type="image/webp"/></item><item><title>Sanctions, Dark Web Disclosure &amp; Harm – 11/23/2025</title><link>https://grabtheaxe.com/news/sanctions-dark-web-disclosure-harm-11-23-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/sanctions-dark-web-disclosure-harm-11-23-2025/</guid><description>Compliance update: US sanctions target Mexican casinos; US court equates dark web data leaks to harm. Stay compliant! - 11/23/2025</description><pubDate>Sun, 23 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/sanctions-dark-web-disclosure-harm-11-23-2025.webp&quot; alt=&quot;Sanctions Enforcement&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates in sanctions enforcement and data breach liability. The US has sanctioned a Mexican casino group for alleged money laundering, signaling increased scrutiny on financial networks. A recent US court ruling now equates dark web data disclosure to concrete harm, significantly raising the stakes for data protection across UK and EU organizations. Stay informed to navigate these evolving compliance landscapes effectively.&lt;/p&gt;
&lt;h2&gt;Top 3 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Sanctions Sweep Targets Mexican Casino Group: The US imposed sanctions on the Hysa family for allegedly laundering money for the Sinaloa Cartel through a network of casinos and restaurants. &lt;a href=&quot;https://vinciworks.com/blog/sanctions-sweep-hits-mexican-casino-group-accused-of-laundeing-millions-for-the-sinaloa-cartel/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Dark Web Disclosure Equals Harm: US Court Ruling: A US court decision now considers the appearance of stolen data on the dark web as concrete harm, impacting UK and EU organizations. &lt;a href=&quot;https://vinciworks.com/blog/does-dark-web-disclosure-equal-harm-why-a-us-court-ruling-should-alarm-uk-and-eu-organisations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Sanctions Sweep Targets Mexican Casino Group: The US imposed sanctions on the Hysa family for allegedly laundering money for the Sinaloa Cartel through a network of casinos and restaurants. &lt;a href=&quot;https://vinciworks.com/blog/sanctions-sweep-hits-mexican-casino-group-accused-of-laundeing-millions-for-the-sinaloa-cartel/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cyber Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Dark Web Disclosure Equals Harm: US Court Ruling: A US court decision now considers the appearance of stolen data on the dark web as concrete harm, impacting UK and EU organizations. &lt;a href=&quot;https://vinciworks.com/blog/does-dark-web-disclosure-equal-harm-why-a-us-court-ruling-should-alarm-uk-and-eu-organisations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AML</category><category>Cybersecurity</category><category>Dark Web</category><category>Data Breach</category><category>GDPR</category><category>Regulatory Compliance</category><category>Sanctions</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/sanctions-dark-web-disclosure-harm-11-23-2025.webp" length="0" type="image/webp"/></item><item><title>Oracle Zero-Day, APT31 Attacks &amp; WhatsApp Flaw – 11/22/2025</title><link>https://grabtheaxe.com/news/oracle-zero-day-apt31-attacks-whatsapp-flaw-11-22-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/oracle-zero-day-apt31-attacks-whatsapp-flaw-11-22-2025/</guid><description>Critical Oracle zero-day is actively exploited. Read the latest on APT31 attacks against Russia, a massive WhatsApp data scraping flaw, and Qilin ransomware.</description><pubDate>Sat, 22 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/oracle-zero-day-apt31-attacks-whatsapp-flaw-11-22-2025.webp&quot; alt=&quot;Oracle Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is dominated by a critical, actively exploited Oracle Identity Manager zero-day vulnerability added to CISA’s KEV catalog. This summary also covers a stealthy campaign by the China-linked APT31 targeting Russian IT infrastructure, a massive data scraping incident affecting 3.5 billion WhatsApp accounts due to a flawed API, and a detailed investigation into a Qilin ransomware attack. These incidents highlight the immediate need for patching, heightened threat awareness, and robust incident response.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability: CISA has added a critical Oracle Identity Manager pre-authentication vulnerability (CVE-2025-61757), with a CVSS score of 9.8, to its KEV catalog due to active exploitation. &lt;a href=&quot;https://thehackernews.com/2025/11/cisa-warns-of-actively-exploited.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cox Enterprises discloses Oracle E-Business Suite data breach: Cox Enterprises is notifying individuals of a data breach resulting from the exploitation of a zero-day vulnerability in its Oracle E-Business Suite. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cox-ent-erbprpr-ises-discloses-oracle-e-business-suite-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services: The China-linked threat group APT31 has been targeting the Russian IT sector with long-term, undetected cyberattacks by leveraging cloud services. &lt;a href=&quot;https://thehackernews.com/2025/11/china-linked-apt31-launches-stealthy.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;WhatsApp API flaw let researchers scrape 3.5 billion accounts: A significant flaw in a WhatsApp contact-discovery API, which lacked proper rate limiting, enabled the scraping of 3.5 billion user phone numbers and associated personal data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/whatsapp-api-flaw-let-researchers-scrape-35-billion-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Piecing Together the Puzzle: A Qilin Ransomware Investigation: Huntress analysts successfully reconstructed a Qilin ransomware attack from a single endpoint, identifying rogue ScreenConnect access and the full execution path despite limited visibility. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/piecing-together-the-puzzle-a-qilin-ransomware-investigation/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence (APT, malware, ransomware)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks: A new command-and-control platform named Matrix Push C2 is leveraging browser push notifications to conduct fileless phishing attacks across multiple operating systems. &lt;a href=&quot;https://thehackernews.com/2025/11/matrix-push-c2-uses-browser.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Oops. Cryptographers cancel election results after losing decryption key.: An election conducted by the International Association for Cryptologic Research (IACR) had its results canceled after one of the three required decryption keys was irretrievably lost. &lt;a href=&quot;https://arstechnica.com/security/2025/11/cryptography-group-cancels-election-results-after-official-loses-secret-key/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The privacy nightmare of browser fingerprinting: An analysis of browser fingerprinting techniques highlights the significant privacy risks involved, as these methods can track users across the web without relying on cookies. &lt;a href=&quot;https://kevinboone.me/fingerprinting.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google denies ‘misleading’ reports of Gmail using your emails to train AI: Google has clarified that it does not use the content of users’ Gmail messages to train its Gemini AI model, stating that smart features are for personalization only. &lt;a href=&quot;https://www.theverge.com/news/826902/gmail-ai-training-data-opt-out&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>APT31</category><category>CISA</category><category>Cybersecurity</category><category>Data Breach</category><category>Oracle Zero-Day</category><category>Phishing</category><category>Qilin Ransomware</category><category>threat intelligence</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/oracle-zero-day-apt31-attacks-whatsapp-flaw-11-22-2025.webp" length="0" type="image/webp"/></item><item><title>AI Cyberattack, Surveillance, Privacy Law – 11/21/2025</title><link>https://grabtheaxe.com/news/ai-cyberattack-surveillance-privacy-law-11-21-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ai-cyberattack-surveillance-privacy-law-11-21-2025/</guid><description>AI cyberattack surfaces! Surveillance concerns grow as police track protesters. Plus, new UK cyber laws &amp; California health data privacy regulations.</description><pubDate>Fri, 21 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ai-cyberattack-surveillance-privacy-law-11-21-2025.webp&quot; alt=&quot;AI Cyberattack&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s digest highlights critical developments in AI-driven cyberattacks, government surveillance, and evolving privacy regulations. A Chinese state-sponsored group exploited AI for cyberespionage, while law enforcement agencies face scrutiny for using ALPR technology to monitor protesters. Mozilla’s termination of the Onerep partnership and California’s new health data privacy law also mark significant shifts in data protection.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI as Cyberattacker: A Chinese state-sponsored group manipulated AI to execute cyberattacks, targeting tech companies and financial institutions. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/ai-as-cyberattacker.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How Cops Are Using Flock Safety’s ALPR Network to Surveil Protesters and Activists: Law enforcement agencies are using ALPR technology to track protesters, raising concerns about freedom of assembly. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/how-cops-are-using-flock-safetys-alpr-network-surveil-protesters-and-activists&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Mozilla Says It’s Finally Done With Two-Faced Onerep: Mozilla is ending its partnership with Onerep after revelations about the founder’s involvement with people-search sites. &lt;a href=&quot;https://krebsonsecurity.com/2025/11/mozilla-says-its-finally-done-with-two-faced-onerep/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK Cybersecurity Legislation Soon to be Introduced: The UK Government has introduced the Cyber Security and Resilience Bill to strengthen national security and protect critical infrastructure. &lt;a href=&quot;https://www.alstonprivacy.com/uk-cybersecurity-legislation-soon-to-be-introduced/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Keep Out! California Draws the Privacy Fence Around Health Data: California restricts collection/use of personal information near family planning facilities, with penalties for violations starting in 2027. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/11/keep-out-california-draws-the-privacy-fence-around-health-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;UK Cybersecurity Legislation Soon to be Introduced: The UK Government has introduced the Cyber Security and Resilience Bill to strengthen national security and protect critical infrastructure. &lt;a href=&quot;https://www.alstonprivacy.com/uk-cybersecurity-legislation-soon-to-be-introduced/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Keep Out! California Draws the Privacy Fence Around Health Data: California restricts collection/use of personal information near family planning facilities, with penalties for violations starting in 2027. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/11/keep-out-california-draws-the-privacy-fence-around-health-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Mozilla Says It’s Finally Done With Two-Faced Onerep: Mozilla is ending its partnership with Onerep after revelations about the founder’s involvement with people-search sites. &lt;a href=&quot;https://krebsonsecurity.com/2025/11/mozilla-says-its-finally-done-with-two-faced-onerep/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EFF Demands Answers About ICE-Spotting App Takedowns: EFF sues DOJ and DHS to uncover information about government demands to remove apps documenting immigration enforcement. &lt;a href=&quot;https://www.eff.org/press/releases/eff-demands-answers-about-ice-spotting-app-takedowns&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How Cops Are Using Flock Safety’s ALPR Network to Surveil Protesters and Activists: Law enforcement agencies are using ALPR technology to track protesters, raising concerns about freedom of assembly. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/how-cops-are-using-flock-safetys-alpr-network-surveil-protesters-and-activists&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Cyberattack</category><category>California Privacy</category><category>Cybersecurity</category><category>Data Minimization</category><category>Data Protection</category><category>Privacy Law</category><category>Surveillance</category><category>UK Cybersecurity Legislation</category><category>User Consent</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ai-cyberattack-surveillance-privacy-law-11-21-2025.webp" length="0" type="image/webp"/></item><item><title>WhatsApp Leak, AI Laws, Phishing Scams &amp; Patent Rules – 11/20/2025</title><link>https://grabtheaxe.com/news/whatsapp-leak-ai-laws-phishing-scams-patent-rules-11-20-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/whatsapp-leak-ai-laws-phishing-scams-patent-rules-11-20-2025/</guid><description>WhatsApp data leak! Plus, updates on AI laws, phishing scams, and changes to patent challenge rules. Stay informed with today&apos;s privacy and security briefing.</description><pubDate>Thu, 20 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/whatsapp-leak-ai-laws-phishing-scams-patent-rules-11-20-2025.webp&quot; alt=&quot;WhatsApp Leak&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights critical vulnerabilities and emerging threats, including a major WhatsApp data leak and the rise of Android malware targeting encrypted messaging apps. Regulatory updates feature the potential US ban on state AI laws and Illinois’ new AI employment regulations. Also covered are scams targeting consumers and proposed changes to patent challenge rules, demanding immediate attention to safeguard personal data and innovation.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw: Researchers found a WhatsApp flaw exposing 3.5 billion users’ data. &lt;a href=&quot;https://pogowasright.org/researchers-claim-largest-leak-ever-after-uncovering-whatsapp-enumeration-flaw/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Multi-threat Android malware Sturnus steals Signal, WhatsApp messages: New Android malware Sturnus steals data from encrypted messaging apps and gains device control. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/multi-threat-android-malware-sturnus-steals-signal-whatsapp-messages/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Scam USPS and E-Z Pass Texts and Websites: Google reports a Chinese cybercriminal group selling phishing kits. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/scam-usps-and-e-z-pass-texts-and-websites.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;French authorities investigate alleged Holocaust denial posts on Elon Musk’s Grok AI: Grok AI under investigation for Holocaust denial posts. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/20/french-authorities-look-into-holocaust-denial-posts-elon-musk-grok-ai&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Patent Office Is About To Make Bad Patents Untouchable: USPTO proposes rules limiting challenges to improperly granted patents. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/patent-office-about-make-bad-patents-untouchable&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Big Beautiful AI Bill: Is the US State AI law ban back on the horizon?: A draft Federal Executive Order considers mirroring the EU’s AI Act concerns, potentially impacting US State AI laws. &lt;a href=&quot;https://dataprivacy.foxrothschild.com/2025/11/articles/general-privacy-data-security-news-developments/big-beautiful-ai-bill-is-the-us-state-ai-law-ban-back-on-the-horizon/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Illinois AI Employment Law Goes Live Soon: Are Your Hiring Practices Compliant?: Illinois employers must comply with AI employment law starting January 1, 2026. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/11/illinois-ai-employment-law-goes-live-soon-are-your-hiring-practices-compliant/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Closing the Privacy Gap: HIPRA Targets Health Apps and Wearables: Senator Cassidy introduces HIPRA to close health data protection gaps. &lt;a href=&quot;https://www.alstonprivacy.com/closing-the-privacy-gap-hipra-targets-health-apps-and-wearables/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Warning! States Continue to Worry About Social Media and Teens: States are concerned about social media’s impact on teens, with California passing a warning label law. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/11/warning-states-continue-to-worry-about-social-media-and-teens/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Strengthen Colorado’s AI Act: EFF urges Colorado to strengthen its AI Act, especially in enforcement mechanisms. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/strengthen-colorados-ai-act&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?: Amazon to pay $2.5B for enrolling users in Prime without consent. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls: Learn how to reduce unwanted telemarketing calls. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Crypto mixer founders sent to prison for laundering over $237 million: Samourai Wallet founders imprisoned for laundering over $237 million. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/samourai-cryptomixer-founders-sent-to-prison-for-laundering-over-237-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sneaky2FA PhaaS kit now uses redteamers’ Browser-in-the-Browser attack: Sneaky2FA phishing kit adds Browser-in-the-Browser attack capabilities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/sneaky2fa-phaas-kit-now-uses-redteamers-browser-in-the-browser-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;W3 Total Cache WordPress plugin vulnerable to PHP command injection: Critical flaw in W3 Total Cache plugin allows PHP command injection. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/w3-total-cache-wordpress-plugin-vulnerable-to-php-command-injection/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Russian bulletproof hosting provider sanctioned over ransomware ties: US sanctions Russian bulletproof hosting provider for ransomware support. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/us-sanctions-russian-bulletproof-hosting-provider-media-land-over-ransomware-ties/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Phishing &amp;amp; Scams&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How to help protect foster youth from identity theft: Tips to protect foster youth from identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-teft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone: FTC warns against scammers impersonating FTC officials. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam: FTC Chairman Andrew Ferguson explains how to spot job scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams: Tips to avoid disaster-related scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams: Protect yourself from Medicare scams during open enrollment. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams: Steps to avoid timeshare selling scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going: FTC warns about deceptive fundraising by &lt;a href=&quot;http://Kars-R-Us.com&quot;&gt;Kars-R-Us.com&lt;/a&gt;. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Use this action plan to avoid scams: FTC’s action plan to avoid scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/11/use-action-plan-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Laws</category><category>Android Malware</category><category>Data Leak</category><category>HIPRA</category><category>Patent Law</category><category>Phishing</category><category>Scams</category><category>WhatsApp</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/whatsapp-leak-ai-laws-phishing-scams-patent-rules-11-20-2025.webp" length="0" type="image/webp"/></item><item><title>Fortinet Exploit, NIH Audit, Data Breach &amp; EUDR – 11/19/2025</title><link>https://grabtheaxe.com/news/fortinet-exploit-nih-audit-data-breach-eudr-11-19-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/fortinet-exploit-nih-audit-data-breach-eudr-11-19-2025/</guid><description>Critical Fortinet exploit, NIH security audit, healthcare data breach settlements, &amp; EU deforestation directive updates. Stay compliant and informed.</description><pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/fortinet-exploit-nih-audit-data-breach-eudr-11-19-2025.webp&quot; alt=&quot;Fortinet Exploit&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical vulnerabilities and regulatory shifts impacting organizations. Key alerts include a zero-day exploit in Fortinet firewalls, security weaknesses in the NIH’s research program, and significant data breach settlements in healthcare. We also cover updates on European deforestation regulations, NCAA betting policies, and the impact of Supreme Court rulings on compliance.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fortinet Zero-Day Exploited: Patches are available for a critical OS command injection vulnerability in Fortinet web application firewalls. Update immediately to mitigate risk. &lt;a href=&quot;https://www.hipaajournal.com/fortinet-patches-actively-exploited-fortiweb-zero-day-flaw/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NIH Security Weaknesses: An audit reveals privacy and security flaws in the NIH All of Us Research Program. Immediate remediation is crucial. &lt;a href=&quot;https://www.hipaajournal.com/audit-security-weaknesses-nih-all-of-us-security-program/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Omni Family Health Data Breach Settlement: Omni Family Health settles a class-action lawsuit for $6.5 million following a data breach affecting 39 health centers. &lt;a href=&quot;https://www.hipaajournal.com/omni-family-health-data-breach-settlement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CarePro Data Breach Settlement: CarePro Health Services agrees to pay $1.3 million to settle a class-action lawsuit related to a data breach. &lt;a href=&quot;https://www.hipaajournal.com/carepro-class-action-data-breach-settlement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Railway Braking Systems Tampering: Critical railway braking systems are vulnerable to tampering using readily available materials, posing a significant safety risk. &lt;a href=&quot;https://www.darkreading.com/ics-ot-security/critical-railway-braking-systems-tampering&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Defense in Depth &amp;amp; SOC 2: A blog post discusses how a defense-in-depth strategy relates to SOC 2 compliance, emphasizing the need for more than a checklist approach to security. &lt;a href=&quot;https://linfordco.com/blog/how-defense-in-depth-relates-to-soc-2-compliance/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;2026 Physician Fee Schedule: CMS issues the 2026 Medicare Physician Fee Schedule final rule, adopting policies related to calculating and reporting average sales prices (ASP) for drugs. &lt;a href=&quot;https://www.jdsupra.com/legalnews/2026-physician-fee-schedule-final-rule-9339628/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;European Deforestation Directive: Implications of the EUDR for Africa’s food security, highlighting compliance pressures for smallholder farmers. &lt;a href=&quot;https://www.jdsupra.com/legalnews/the-european-deforestation-directive-9772385/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cayman Closed-Ended Fund Regulatory Obligations: Overview of the regulatory obligations for Cayman Islands closed-ended funds as of November 2025. &lt;a href=&quot;https://www.jdsupra.com/legalnews/attention-know-the-regulatory-6138152/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Audit &amp;amp; Monitoring Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EBA Peer Review on CVA Risk: The EBA publishes a follow-up peer review report on EU competent authorities’ supervisory practices regarding credit valuation adjustment (CVA) risk. &lt;a href=&quot;https://www.jdsupra.com/legalnews/eba-publishes-follow-up-peer-review-9794861/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NIH Security Program Audit: An audit of the NIH All of Us Research Program has uncovered privacy and security weaknesses. &lt;a href=&quot;https://www.hipaajournal.com/audit-security-weaknesses-nih-all-of-us-security-program/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;NCAA Betting Policy Change: The NCAA plans to allow student-athletes and athletics staff to bet on professional sports in states where it’s legal, starting Nov. 22. &lt;a href=&quot;https://www.jdsupra.com/legalnews/new-ncaa-betting-policy-fits-trend-of-2771019/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Supreme Court Ruling &amp;amp; Deregulation: Examines how the Supreme Court’s 2024 Loper Bright decision impacts regulatory controls under the Trump Administration’s deregulatory agenda. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/how-supreme-court-ruling-found-perfect-match-trump-administration/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Audit</category><category>compliance</category><category>Data Breach</category><category>EUDR</category><category>Exploit</category><category>Fortinet</category><category>Healthcare</category><category>NIH</category><category>Regulatory</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/fortinet-exploit-nih-audit-data-breach-eudr-11-19-2025.webp" length="0" type="image/webp"/></item><item><title>IRS Data, ALPR Lawsuit, AI Listening &amp; Nest Data – 11/19/2025</title><link>https://grabtheaxe.com/news/irs-data-alpr-lawsuit-ai-listening-nest-data-11-19-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/irs-data-alpr-lawsuit-ai-listening-nest-data-11-19-2025/</guid><description>Privacy alert: IRS flight data access, ALPR lawsuit, AI in doctor&apos;s offices, &amp; Google&apos;s Nest data collection. Stay informed on key privacy threats.</description><pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/irs-data-alpr-lawsuit-ai-listening-nest-data-11-19-2025.webp&quot; alt=&quot;Warrantless Surveillance&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy digest highlights critical concerns surrounding data privacy. Key stories include the IRS accessing flight data without warrants, a lawsuit against San Jose’s mass surveillance, Google’s continued collection of Nest thermostat data, and the ethical implications of AI listening in doctor’s offices. Stay informed about these pressing issues to protect your digital rights.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;IRS Accessed Massive Database of Americans Flights Without a Warrant: The IRS accessed a database of hundreds of millions of travel records without a warrant, raising significant privacy concerns. &lt;a href=&quot;https://pogowasright.org/irs-accessed-massive-database-of-americans-flights-without-a-warrant/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lawsuit Challenges San Jose’s Warrantless ALPR Mass Surveillance: EFF and ACLU challenge San Jose’s warrantless searches of ALPR data, arguing it violates the California Constitution. &lt;a href=&quot;https://www.eff.org/press/releases/lawsuit-challenges-san-joses-warrantless-alpr-mass-surveillance&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google is collecting troves of data from downgraded Nest thermostats: Google continues to collect data from early Nest thermostats even after turning off remote control functionality. &lt;a href=&quot;https://pogowasright.org/google-is-collecting-troves-of-data-from-downgraded-nest-thermostats/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;At some doctors’ offices, AI is listening in the exam room: Some doctors are now recording patient visits using AI, raising concerns about privacy and consent in healthcare settings. &lt;a href=&quot;https://pogowasright.org/at-some-doctors-offices-ai-is-listening-in-the-exam-room/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New ShadowRay attacks convert Ray clusters into crypto miners: ShadowRay 2.0 hijacks exposed Ray Clusters to turn them into a cryptomining botnet, exploiting an old code execution flaw. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-shadowray-attacks-convert-ray-clusters-into-crypto-miners/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CIPL Publishes Discussion Paper Comparing U.S. State Privacy Law Definitions of Personal Data and Sensitive Data: CIPL published a discussion paper comparing key elements of U.S. state privacy laws regarding personal and sensitive data. &lt;a href=&quot;https://pogowasright.org/cipl-publishes-discussion-paper-comparing-u-s-state-privacy-law-definitions-of-personal-data-and-sensitive-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;India’s Digital Personal Data Protection Act 2023 brought into force: India’s Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules 2025, operationalizing the 2023 Act. &lt;a href=&quot;https://pogowasright.org/indias-digital-personal-data-protection-act-2023-brought-into-force/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When in Rome, Make Your AI Do As the Regulators Do: Italy enacted a comprehensive national AI law to work with the EU AI Act, adding more details and specific obligations. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/11/when-in-rome-make-your-ai-do-as-the-regulators-do/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google is collecting troves of data from downgraded Nest thermostats: Google continues to collect data from early Nest thermostats even after turning off remote control functionality. &lt;a href=&quot;https://pogowasright.org/google-is-collecting-troves-of-data-from-downgraded-nest-thermostats/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;At some doctors’ offices, AI is listening in the exam room: Some doctors are now recording patient visits using AI, raising concerns about privacy and consent in healthcare settings. &lt;a href=&quot;https://pogowasright.org/at-some-doctors-offices-ai-is-listening-in-the-exam-room/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;IRS Accessed Massive Database of Americans Flights Without a Warrant: The IRS accessed a database of hundreds of millions of travel records without a warrant, raising significant privacy concerns. &lt;a href=&quot;https://pogowasright.org/irs-accessed-massive-database-of-americans-flights-without-a-warrant/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lawsuit Challenges San Jose’s Warrantless ALPR Mass Surveillance: EFF and ACLU challenge San Jose’s warrantless searches of ALPR data, arguing it violates the California Constitution. &lt;a href=&quot;https://www.eff.org/press/releases/lawsuit-challenges-san-joses-warrantless-alpr-mass-surveillance&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Surveillance tech provider Protei was hacked, its data stolen, and its website defaced: Russian telecom company Protei, which develops surveillance tech, was hacked, its website defaced, and data stolen. &lt;a href=&quot;https://pogowasright.org/surveillance-tech-provider-protei-was-hacked-its-data-stolen-and-its-website-defaced/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI</category><category>ALPR</category><category>Data Minimization</category><category>Data Privacy</category><category>IRS</category><category>Nest</category><category>Privacy Laws</category><category>Surveillance</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/irs-data-alpr-lawsuit-ai-listening-nest-data-11-19-2025.webp" length="0" type="image/webp"/></item><item><title>AI Phishing, Data Privacy, SEC, Fortinet – 11/18/2025</title><link>https://grabtheaxe.com/news/ai-phishing-data-privacy-sec-fortinet-11-18-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ai-phishing-data-privacy-sec-fortinet-11-18-2025/</guid><description>Stay ahead of compliance threats: AI phishing surge, data privacy law updates, SEC insights, &amp; a critical Fortinet vulnerability. Read the full digest now!</description><pubDate>Tue, 18 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ai-phishing-data-privacy-sec-fortinet-11-18-2025.webp&quot; alt=&quot;AI Phishing&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance digest highlights critical threats, including a surge in AI-driven phishing attacks and a critical Fortinet WAF vulnerability under active exploitation. Key regulatory updates include insights into the SEC’s operations post-shutdown and the implications of the UK’s Data (Use and Access) Act. Additionally, the digest covers third-party risks in Gibraltar and new AI cybersecurity guidance for the healthcare sector.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Phishing Season 2025: How AI is Supercharging Cyber Crime : AI-generated phishing has moved from a niche tactic to an everyday tool for cyber criminals, increasing the intensity of phishing campaigns. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/phishing-season-2025-how-ai-is-supercharging-cyber-crime&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical Fortinet FortiWeb WAF Bug Exploited in the Wild : A vulnerability in Fortinet’s FortiWeb WAF could allow unauthenticated remote attackers to execute administrative commands. &lt;a href=&quot;https://www.darkreading.com/application-security/critical-fortinet-fortiweb-waf-bug-exploited-in-wild&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US Citizens Plead Guilty to Aiding North Korean IT Worker Campaigns : Individuals admitted to helping foreign IT workers gain employment at US companies using false identities and remote access. &lt;a href=&quot;https://www.darkreading.com/remote-workforce/us-citizens-plead-guilty-north-korean-it-worker&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cyberattack Volume Increases Fueled by 48% YOY Increase in Ransomware Attacks : October saw a rise in cyberattack volume, driven by a significant year-over-year increase in ransomware attacks. &lt;a href=&quot;https://www.hipaajournal.com/cyberattack-volume-increase-october-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;St. Anthony Hospital in Chicago Notifies Patients About February Data Breach : St. Anthony Hospital in Chicago is notifying patients about a data breach that occurred in February. &lt;a href=&quot;https://www.hipaajournal.com/st-anthony-hospital-email-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Q&amp;amp;A: The SEC Is Up &amp;amp; Running After Shutdown; Now What? : Registrants should prepare for future delays as shutdowns become increasingly likely. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/sec-up-running-after-shutdown/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Gibraltar at a crossroads: What two landmark inquiries reveal about a jurisdiction under strain : Landmark inquiries reveal strain on Gibraltar’s jurisdiction due to alleged sabotage of a national security system. &lt;a href=&quot;https://vinciworks.com/blog/gibraltar-at-a-crossroads-what-two-landmark-inquiries-reveal-about-a-jurisdiction-under-strain/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Data (Use and Access) Act and How it Affects the UK GDPR and DPA 2018, and PECR : The Data (Use and Access) Act 2025 marks a significant moment in UK data protection legislation, reforming UK GDPR, DPA 2018, and PECR. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/the-data-use-and-access-act-and-how-it-affects-the-uk-gdpr-and-dpa-2018-and-pecr&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;What You Need to Know About Maryland’s New Data Privacy Law : Maryland’s new data privacy law shifts focus to providing collection as a service benefiting consumers. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/what-you-need-know-maryland-data-privacy-law/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HSCC Publishes Preview of Health Sector AI Cybersecurity Risk Guidance : The Health Sector Coordinating Council (HSCC) plans to publish AI cybersecurity guidelines for the healthcare sector in Q1 2026. &lt;a href=&quot;https://www.hipaajournal.com/hscc-preview-health-sector-ai-cybersecurity-risk-guidance/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Discovery Practice Management Settle Lawsuit Over 2020 Data Breach : Discovery Practice Management settles a class action lawsuit stemming from a June 2020 data breach. &lt;a href=&quot;https://www.hipaajournal.com/discovery-practice-management-data-breach-settlement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Phishing</category><category>Cybersecurity</category><category>Data Privacy</category><category>FCPA</category><category>Fortinet</category><category>GDPR</category><category>Healthcare Cybersecurity</category><category>ransomware</category><category>Sanctions</category><category>SEC</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ai-phishing-data-privacy-sec-fortinet-11-18-2025.webp" length="0" type="image/webp"/></item><item><title>Chrome Zero-Day, Azure DDoS, Data Breaches – 11/18/2025</title><link>https://grabtheaxe.com/news/chrome-zero-day-azure-ddos-data-breaches-11-18-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/chrome-zero-day-azure-ddos-data-breaches-11-18-2025/</guid><description>Chrome zero-day exploit, Azure DDoS attack, and Princeton data breach lead today&apos;s security news. Stay informed about the latest threats and vulnerabilities.</description><pubDate>Tue, 18 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/chrome-zero-day-azure-ddos-data-breaches-11-18-2025.webp&quot; alt=&quot;Chrome Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s digest features critical security updates, including a Chrome zero-day exploit and a massive DDoS attack on Microsoft Azure. We also cover a data breach at Princeton University, a ransomware attack impacting Pennsylvania’s Attorney General, and new age verification measures from Roblox. Stay informed to protect your data and systems from emerging threats.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google fixes new Chrome zero-day flaw exploited in attacks: Google has released an emergency security update to fix a Chrome zero-day vulnerability. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-fixes-new-chrome-zero-day-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Azure hit by 15 Tbps DDoS attack using 500,000 IP addresses: The Aisuru botnet launched a massive DDoS attack on Microsoft’s Azure network. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-aisuru-botnet-used-500-000-ips-in-15-tbps-azure-ddos-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Eurofiber France warns of breach after hacker tries to sell customer data: Hackers exploited a vulnerability to access Eurofiber France’s ticket management system. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/eurofiber-france-warns-of-breach-after-hacker-tries-to-sell-customer-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Princeton University discloses data breach affecting donors, alumni: A cyberattack compromised a Princeton University database, exposing personal information. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/princeton-university-discloses-data-breach-affecting-donors-alumni/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pennsylvania AG confirms data breach after INC Ransom attack: The Pennsylvania attorney general’s office confirms a data breach following an INC Ransom attack. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/pennsylvania-ag-confirms-data-breach-after-inc-ransom-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;“How Old Are You, Anyway?” California’s New Law Makes Apps Ask… And Remember!: California’s AB 1043 requires apps to verify and remember user ages. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/11/how-old-are-you-anyway-californias-new-law-makes-apps-ask-and-remember/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google fixes new Chrome zero-day flaw exploited in attacks: Google has released an emergency security update to fix a Chrome zero-day vulnerability. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-fixes-new-chrome-zero-day-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Windows 10 KB5072653 OOB update fixes ESU install errors: Microsoft released an out-of-band update to fix issues with Windows 10 extended security updates. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-10-kb5072653-oob-update-fixes-esu-install-errors/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Malicious NPM packages abuse Adspect redirects to evade security: NPM packages are using Adspect redirects to evade security measures and lead to malicious sites. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-npm-packages-abuse-adspect-redirects-to-evade-security/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;RondoDox botnet malware now hacks servers using XWiki flaw: RondoDox botnet malware is exploiting a critical RCE flaw in XWiki Platform (CVE-2025-24893). &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/rondodox-botnet-malware-now-hacks-servers-using-xwiki-flaw/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Eurofiber France warns of breach after hacker tries to sell customer data: Hackers exploited a vulnerability to access Eurofiber France’s ticket management system. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/eurofiber-france-warns-of-breach-after-hacker-tries-to-sell-customer-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Princeton University discloses data breach affecting donors, alumni: A cyberattack compromised a Princeton University database, exposing personal information. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/princeton-university-discloses-data-breach-affecting-donors-alumni/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Dutch police seizes 250 servers used by “bulletproof hosting” service: Dutch police seized servers powering a bulletproof hosting service used by cybercriminals. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/dutch-police-seizes-250-servers-used-by-bulletproof-hosting-service/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Azure hit by 15 Tbps DDoS attack using 500,000 IP addresses: The Aisuru botnet launched a massive DDoS attack on Microsoft’s Azure network. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-aisuru-botnet-used-500-000-ips-in-15-tbps-azure-ddos-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DoorDash email spoofing vulnerability sparks messy disclosure dispute: A vulnerability allowed spoofed DoorDash emails, leading to a disclosure dispute after the patch. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/doordash-email-spoofing-vulnerability-sparks-messy-disclosure-dispute/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pennsylvania AG confirms data breach after INC Ransom attack: The Pennsylvania attorney general’s office confirms a data breach following an INC Ransom attack. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/pennsylvania-ag-confirms-data-breach-after-inc-ransom-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;AI &amp;amp; Democracy&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI and Voter Engagement: An article discusses the impact of AI and social media on voter engagement, referencing Obama’s 2008 campaign. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/ai-and-voter-engagement.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;xAI’s Grok 4.1 rolls out with improved quality and speed for free: xAI has started rolling out Grok 4.1, which is an upgrade to the existing Grok 4 model. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/xais-grok-41-rolls-out-with-improved-quality-and-speed-for-free/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google Gemini 3 spotted on AI Studio ahead of imminent release: Google’s Gemini 3, a potentially leading language model, has been spotted on AI Studio. &lt;a href=&quot;https://www.bleepingcomputer.com/news/google/google-gemini-3-spotted-on-ai-studio-ahead-of-imminent-release/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Consumer Alerts &amp;amp; Scams&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams: The FTC provides advice on preparing for emergencies and avoiding related scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to help protect foster youth from identity theft: The FTC offers tips on protecting foster youth from identity theft due to their increased risk. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone: The FTC warns about scammers impersonating FTC officials to solicit money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Get a credit freeze to stop identity thieves: The FTC recommends credit freezes as a way to protect against identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/get-credit-freeze-stop-identity-thieves&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams: The FTC advises consumers to be vigilant against scams during Medicare Open Enrollment. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams: The FTC provides advice on avoiding scams when selling a timeshare. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going: The FTC warns about donating to fraudulent charities, citing the case of &lt;a href=&quot;http://Kars-R-Us.com&quot;&gt;Kars-R-Us.com&lt;/a&gt;. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam: The FTC provides advice on identifying and avoiding job scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?: The FTC explains who is eligible for a refund from Amazon’s Prime subscription settlement. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls: The FTC advises on how to reduce unwanted telemarketing calls resulting from shared online information. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK consumers warned over AI chatbots giving inaccurate financial advice: Research reveals AI chatbots are providing inaccurate financial advice to UK consumers. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/18/warning-ai-chatbots-inaccurate-financial-advice-tips-chatgpt-copilot-uk&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Azure</category><category>Chrome</category><category>Cybersecurity</category><category>Data Breach</category><category>DDoS</category><category>ransomware</category><category>Vulnerability</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/chrome-zero-day-azure-ddos-data-breaches-11-18-2025.webp" length="0" type="image/webp"/></item><item><title>Fortinet &amp; Chrome Zero-Days, Cloudflare Outage – 11/18/2025</title><link>https://grabtheaxe.com/news/fortinet-chrome-zero-days-cloudflare-outage-11-18-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/fortinet-chrome-zero-days-cloudflare-outage-11-18-2025/</guid><description>Critical security alerts for Fortinet &amp; Chrome zero-days under active exploit. Today&apos;s summary covers the massive Cloudflare outage, new malware, and CISA advisories.</description><pubDate>Tue, 18 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/fortinet-chrome-zero-days-cloudflare-outage-11-18-2025.webp&quot; alt=&quot;Fortinet Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is dominated by two actively exploited zero-day vulnerabilities affecting Fortinet FortiWeb and Google Chrome, both requiring immediate patching. CISA has underscored the urgency by adding the Fortinet flaw to its KEV catalog. This summary also covers a massive Cloudflare outage that disrupted global services, a new cryptomining botnet targeting AI infrastructure, and multiple critical ICS advisories.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fortinet warns of new FortiWeb zero-day exploited in attacks : Fortinet has disclosed a critical zero-day vulnerability in its FortiWeb Web Application Firewall that is being actively exploited by threat actors. Immediate patching is required. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fortinet-warns-of-new-fortiweb-zero-day-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google fixes new Chrome zero-day flaw exploited in attacks : Google has issued an emergency update for a high-severity type confusion vulnerability (CVE-2025-13223) in the V8 engine, marking the seventh Chrome zero-day exploited this year. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-fixes-new-chrome-zero-day-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Adds One Known Exploited Vulnerability to Catalog : CISA has added the new Fortinet FortiWeb vulnerability (CVE-2025-58034) to its KEV catalog, mandating federal agencies to patch within one week due to active exploitation. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/11/18/cisa-adds-one-known-exploited-vulnerability-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New ShadowRay attacks convert Ray clusters into crypto miners : A widespread campaign, ShadowRay 2.0, is exploiting a remote code execution flaw to hijack exposed Ray AI clusters, turning them into a self-propagating cryptomining botnet. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-shadowray-attacks-convert-ray-clusters-into-crypto-miners/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Tycoon 2FA Phishing Platform and the Collapse of Legacy MFA : The Tycoon 2FA Phishing-as-a-Service platform has been linked to over 64,000 attacks this year, demonstrating its effectiveness in bypassing legacy multi-factor authentication through real-time relays. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/the-tycoon-2fa-phishing-platform-and-the-collapse-of-legacy-mfa/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks : The Iran-linked threat actor UNC1549 is deploying sophisticated backdoors in espionage campaigns targeting aerospace and defense industries in the Middle East and beyond. &lt;a href=&quot;https://thehackernews.com/2025/11/iranian-hackers-use-deeproot-and.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pro-Russian group claims hits on Danish party websites as voters head to polls : A pro-Russian hacktivist group has claimed responsibility for DDoS attacks against Danish political party and government websites during local elections, though voting was not disrupted. &lt;a href=&quot;https://therecord.media/denmark-election-political-government-websites-ddos-incidents&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI-Enhanced Tuoni Framework Targets Major US Real Estate Firm : An advanced intrusion attempt on a major US real estate firm utilized the Tuoni C2 framework, which combines social engineering with stealthy in-memory payloads. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/ai-tuoni-framework-targets-us-real/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages : A malicious campaign is using seven npm packages and a cloaking service to differentiate between security researchers and potential victims, redirecting the latter to cryptocurrency scam sites. &lt;a href=&quot;https://thehackernews.com/2025/11/seven-npm-packages-use-adspect-cloaking.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LG battery subsidiary says ransomware attack targeted overseas facility : LG Energy Solution confirmed one of its overseas facilities was hit by a ransomware attack but has since returned to normal operations. &lt;a href=&quot;https://therecord.media/lg-energy-solution-ransomware-incident-battery-maker&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;French agency Pajemploi reports data breach affecting 1.2M people : The French social security service Pajemploi has suffered a data breach, potentially exposing the personal information of 1.2 million individuals. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/french-agency-pajemploi-reports-data-breach-affecting-12m-people/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CBO director testifies that hackers have been expelled from email systems : The Congressional Budget Office director confirmed that unauthorized actors who had gained access to the agency’s email systems have been successfully expelled. &lt;a href=&quot;https://therecord.media/congressional-budget-office-director-testifies-hackers-expelled&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft to integrate Sysmon directly into Windows 11, Server 2025 : Microsoft announced that its powerful system monitoring tool, Sysmon, will be natively integrated into Windows 11 and Windows Server 2025 next year. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-to-integrate-sysmon-directly-into-windows-11-server-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New in Snort3: Enhanced rule grouping for greater flexibility and control : Cisco Talos is introducing new capabilities for the Snort3 intrusion detection system, allowing for more flexible management and prioritization of detection rules within Cisco Secure Firewall. &lt;a href=&quot;https://blog.talosintelligence.com/new-in-snort3-enhanced-rule-grouping-for-greater-flexibility-and-control/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Advancing Cybersecurity for Microsoft Environments : Sophos is enhancing its security offerings for Microsoft environments, including certified MDR services and open threat intelligence frameworks to counter evolving threats. &lt;a href=&quot;https://news.sophos.com/en-us/2025/11/18/advancing-cybersecurity-for-microsoft-environments/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools : Microsoft is introducing new Cloud Rebuild and Point-in-Time Restore features for Windows 11 to simplify recovery from system failures and reduce downtime. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/windows-11-gets-new-cloud-rebuild-point-in-time-restore-tools/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A massive Cloudflare outage brought down X, ChatGPT, and even Downdetector : A major Cloudflare outage caused widespread internet disruption, affecting numerous major sites and services due to a bug in a configuration file, not a malicious attack. &lt;a href=&quot;https://www.theverge.com/news/822869/cloudflare-is-down-outage-x-twitter-downdetector&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cloud Break: IoT Devices Open to Silent Takeover Via Firewalls : Researchers have found that IoT devices can be silently compromised through security gaps in the cloud management interfaces of firewalls and routers, even if the devices are not directly online. &lt;a href=&quot;https://www.darkreading.com/cybersecurity-operations/cloud-iot-devices-takeover-firewalls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Releases Six Industrial Control Systems Advisories : CISA has published six new advisories detailing vulnerabilities in ICS products from vendors including Schneider Electric, Shelly, and METZ CONNECT, urging immediate review and mitigation. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/11/18/cisa-releases-six-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;National cyber strategy will include focus on ‘shaping adversary behavior,’ White House official says : The upcoming U.S. national cyber strategy will feature a pillar focused on actively shaping adversary behavior, alongside initiatives for public-private partnerships. &lt;a href=&quot;https://therecord.media/national-cyber-strategy-cairncross-shaping-enemy-behavior&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GenAI and Deepfakes Drive Digital Forgeries and Biometric Fraud : A new report from Entrust highlights the increasing use of Generative AI and deepfakes by fraudsters to create convincing digital forgeries and bypass biometric security checks. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/genai-deepfakes-digital-forgeries/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Beyond IAM Silos: Why the Identity Security Fabric is Essential for Securing AI and Non-Human Identities : An Identity Security Fabric (ISF) architecture is proposed as a necessary evolution to unify IAM, IGA, PAM, and ITDR for securing complex environments with AI and non-human identities. &lt;a href=&quot;https://thehackernews.com/2025/11/beyond-iam-silos-why-identity-security.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Chrome Vulnerability</category><category>CISA KEV</category><category>Cloudflare Outage</category><category>Cybersecurity</category><category>Data Breach</category><category>Fortinet Zero-Day</category><category>ICS security</category><category>ransomware</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/fortinet-chrome-zero-days-cloudflare-outage-11-18-2025.webp" length="0" type="image/webp"/></item><item><title>Healthcare Breaches, CCPA, AI Risk &amp; GC Trends – 11/17/2025</title><link>https://grabtheaxe.com/news/healthcare-breaches-ccpa-ai-risk-gc-trends-11-17-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/healthcare-breaches-ccpa-ai-risk-gc-trends-11-17-2025/</guid><description>Healthcare data breaches, new CCPA rules, AI investment risk, and general counsel trends. Stay informed on compliance and governance updates.</description><pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/healthcare-breaches-ccpa-ai-risk-gc-trends-11-17-2025.webp&quot; alt=&quot;Data Breaches&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical data breach incidents affecting healthcare entities and a significant security flaw in the Cursor AI coding tool. Regulatory updates include California’s new CCPA rules, the EHRC’s overhaul at McDonald’s for harassment prevention, and new frozen asset reporting requirements in the Cayman Islands. Policy and governance articles cover the rise of fractional GCs and the regulatory risks of AI in retail investing.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EHR Vendor Identifies Business Associate Data Breach: CareTracker (Amazing Charts) and Marshfield Clinic announce data breaches. &lt;a href=&quot;https://www.hipaajournal.com/caretracker-amazing-charts-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Doctor Alliance Investigating 353 GB Data Theft Claim: HIPAA business associate Doctor Alliance investigates a significant data theft claim. &lt;a href=&quot;https://www.hipaajournal.com/doctor-alliance-data-breach-claim/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Data Breaches Announced by Sun Valley Surgery Center &amp;amp; American Associated Pharmacies: Sun Valley Surgery Center and American Associated Pharmacies report data breaches. &lt;a href=&quot;https://www.hipaajournal.com/data-breach-sun-valley-surgery-center-american-associated-pharmacies/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Nebraska AG’s Lawsuit Against Change Healthcare Survives Motion to Dismiss: Lawsuit over Change Healthcare data breach moves forward. &lt;a href=&quot;https://www.hipaajournal.com/change-healthcare-responding-to-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cursor Issue Paves Way for Credential-Stealing Attacks: Security weakness in AI-powered coding tool Cursor allows credential-stealing attacks. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/cursor-issue-credential-stealing-attacks&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;2026 Deadline Looms for Compliance with Updated Part 2 Regulations Regarding Patient Data Protections: HHS updates to 42 C.F.R. Part 2 align SUD confidentiality requirements with HIPAA, with a 2026 compliance deadline. &lt;a href=&quot;https://www.jdsupra.com/legalnews/2026-deadline-looms-for-compliance-with-1575084/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New California Consumer Privacy Act rules from 1 January 2026: New CCPA regulations introduce regimes for cybersecurity audits. &lt;a href=&quot;https://vinciworks.com/blog/new-california-consumer-privacy-act-rules-from-1-january-2026-what-you-need-to-know-about-ccpa-2026/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EHRC forces major overhaul at McDonald’s: What real harassment prevention now looks like: Equality and Human Rights Commission strengthens agreement with McDonald’s regarding workplace sexual harassment prevention. &lt;a href=&quot;https://vinciworks.com/blog/ehrc-forces-major-overhaul-at-mcdonalds-what-real-harassment-prevention-now-looks-like/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New annual frozen asset reporting requirement: What you need to know: Cayman Islands FRA requires annual reporting of frozen assets under UK sanctions by November 30, 2025. &lt;a href=&quot;https://www.jdsupra.com/legalnews/new-annual-frozen-asset-reporting-6680472/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;General Counsel on Demand: Why High-Risk Sectors Are Embracing the Fractional Model: Fractional GCs embed within businesses to shape strategy and build systems. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/general-counsel-on-demand/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Agentic AI in Retail Investing: Navigating Regulatory and Operational Risk: Discusses the rise of AI in retail finance and its regulatory implications. &lt;a href=&quot;https://wp.nyu.edu/compliance_enforcement/2025/11/17/agentic-ai-in-retail-investing-navigating-regulatory-and-operational-risk/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No More 10% Retainage: California Mandates 5% Retention Cap on Private Construction Projects: California caps retention on private construction projects at 5%, effective January 1, 2026. &lt;a href=&quot;https://www.jdsupra.com/legalnews/no-more-10-retainage-california-4140349/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Artificial Intelligence</category><category>CCPA</category><category>compliance</category><category>Cybersecurity</category><category>Data Breach</category><category>Governance</category><category>Healthcare</category><category>HIPAA</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/healthcare-breaches-ccpa-ai-risk-gc-trends-11-17-2025.webp" length="0" type="image/webp"/></item><item><title>UNC1549 TTPs, Azure DDoS &amp; Data Breaches – 11/17/2025</title><link>https://grabtheaxe.com/news/unc1549-ttps-azure-ddos-data-breaches-11-17-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/unc1549-ttps-azure-ddos-data-breaches-11-17-2025/</guid><description>Analysis of Iran-nexus UNC1549 TTPs in the aerospace sector. Details on a massive 15 Tbps DDoS attack on Azure, plus new data breaches at Logitech and DoorDash.</description><pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/unc1549-ttps-azure-ddos-data-breaches-11-17-2025.webp&quot; alt=&quot;UNC1549 TTPs&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is highlighted by a detailed Mandiant report on the sophisticated espionage tactics of the Iran-nexus group UNC1549 targeting the aerospace sector. This is coupled with a record-breaking 15 Tbps DDoS attack that targeted Microsoft’s Azure infrastructure, demonstrating a massive escalation in botnet capabilities. We are also tracking several significant data breaches, including incidents at Logitech, DoorDash, and the Pennsylvania Attorney General’s office, alongside actively exploited vulnerabilities in Fortinet and XWiki.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem : Mandiant provides a deep-dive analysis of the sophisticated TTPs used by Iran-nexus threat group UNC1549, including custom backdoors and exploiting trusted relationships to target the aerospace and defense industries. &lt;a href=&quot;https://cloud.google.com/blog/topics/threat-intelligence/analysis-of-unc1549-ttps-targeting-aerospace-defense/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Azure hit by 15 Tbps DDoS attack using 500,000 IP addresses : Microsoft reports its Azure cloud platform was targeted by a massive 15.72 Tbps DDoS attack from the Aisuru botnet, which leveraged over 500,000 IP addresses. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-aisuru-botnet-used-500-000-ips-in-15-tbps-azure-ddos-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical Fortinet FortiWeb WAF Bug Exploited in the Wild — A critical vulnerability in Fortinet’s FortiWeb Web Application Firewall (WAF) is being actively exploited, potentially allowing unauthenticated attackers to execute remote administrative commands. &lt;a href=&quot;https://www.darkreading.com/application-security/critical-fortinet-fortiweb-waf-bug-exploited-in-wild&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;RondoDox botnet malware now hacks servers using XWiki flaw — The RondoDox botnet is now exploiting a critical remote code execution (RCE) vulnerability in the XWiki Platform, tracked as CVE-2025-24893, to compromise servers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/rondodox-botnet-malware-now-hacks-servers-using-xwiki-flaw/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pennsylvania attorney general says SSNs stolen during August ransomware attack : Officials in Pennsylvania confirmed that a ransomware attack in August on the attorney general’s office resulted in the theft of sensitive data, including Social Security numbers and medical information. &lt;a href=&quot;https://therecord.media/pennsylvania-attorney-general-office-data-breach-ssns&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;5 plead guilty to laptop farm and ID theft scheme to land North Koreans US IT jobs — Five individuals admitted to running a sophisticated fraud scheme that used stolen US identities and ‘laptop farms’ to help North Korean IT workers secure remote jobs at American companies. &lt;a href=&quot;https://arstechnica.com/security/2025/11/5-plead-guilty-to-laptop-farm-and-id-theft-scheme-to-land-north-koreans-us-it-jobs/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Logitech discloses data breach after Clop claims : Following a claim by the Clop cybercrime group, Logitech has disclosed a data breach, which reportedly stemmed from a zero-day vulnerability in Oracle’s E-Business Suite tool. &lt;a href=&quot;https://therecord.media/logitech-discloses-data-breach-clop&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DoorDash confirms data breach impacting users’ phone numbers and physical addresses : The delivery service DoorDash announced a data breach that exposed customer, delivery worker, and merchant phone numbers and physical addresses. &lt;a href=&quot;https://techcrunch.com/2025/11/17/doordash-confirms-data-breach-impacting-users-phone-numbers-and-physical-addresses/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Princeton University discloses data breach affecting donors, alumni : Princeton University has revealed a cyberattack on a database containing the personal information of its alumni, donors, faculty, and students. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/princeton-university-discloses-data-breach-affecting-donors-alumni/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Surveillance tech provider Protei was hacked, its data stolen, and its website defaced : Russian surveillance tech company Protei, which sells web intercept and surveillance products, was hacked, leading to data theft and a website defacement. &lt;a href=&quot;https://techcrunch.com/2025/11/17/surveillance-tech-provider-protei-was-hacked-its-data-stolen-and-its-website-defaced/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Eurofiber France warns of breach after hacker tries to sell customer data : Eurofiber France has disclosed a data breach after an attacker exploited a vulnerability in its ticket management system and attempted to sell the exfiltrated customer data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/eurofiber-france-warns-of-breach-after-hacker-tries-to-sell-customer-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Malicious NPM packages abuse Adspect redirects to evade security : Researchers have identified seven malicious packages on the npm registry that use the Adspect cloaking service to hide their malicious nature from security tools and researchers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-npm-packages-abuse-adspect-redirects-to-evade-security/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Dutch police seizes 250 servers used by “bulletproof hosting” service : In a major blow to cybercrime infrastructure, Dutch police have seized around 250 servers from a ‘bulletproof hosting’ service that provided anonymous infrastructure for criminal operations. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/dutch-police-seizes-250-servers-used-by-bulletproof-hosting-service/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DoorDash email spoofing vulnerability sparks messy disclosure dispute : A now-patched vulnerability in DoorDash’s systems could have allowed attackers to send phishing emails from the company’s official servers, with a dispute arising over the disclosure process. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/doordash-email-spoofing-vulnerability-sparks-messy-disclosure-dispute/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;MCP AI agent security startup Runlayer launches with 8 unicorns, $11M from Khosla’s Keith Rabois and Felicis : New startup Runlayer has launched with $11 million in funding to address the growing need for securing AI agents used within business environments. &lt;a href=&quot;https://techcrunch.com/2025/11/17/mcp-ai-agent-security-startup-runlayer-lunches-with-8-unicorns-11m-from-khoslas-keith-rabois-and-felicis/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The State of AI: How war will be changed forever : A collaborative piece from the Financial Times and MIT Technology Review explores the profound impact of generative AI on the future of warfare and global power dynamics. &lt;a href=&quot;https://www.technologyreview.com/2025/11/17/1127514/the-state-of-ai-the-new-rules-of-war/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Azure</category><category>Cybersecurity</category><category>Data Breach</category><category>DDoS</category><category>Fortinet</category><category>ransomware</category><category>threat intelligence</category><category>UNC1549</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/unc1549-ttps-azure-ddos-data-breaches-11-17-2025.webp" length="0" type="image/webp"/></item><item><title>Microsoft Zero-Day, Logitech Breach &amp; Patch Tuesday – 11/16/2025</title><link>https://grabtheaxe.com/news/microsoft-zero-day-logitech-breach-patch-tuesday-11-16-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/microsoft-zero-day-logitech-breach-patch-tuesday-11-16-2025/</guid><description>Microsoft&apos;s November Patch Tuesday fixes a critical zero-day under active exploit. Read the latest on the Logitech data breach and Coinbase disclosure claims.</description><pubDate>Sun, 16 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/microsoft-zero-day-logitech-breach-patch-tuesday-11-16-2025.webp&quot; alt=&quot;Microsoft Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This Sunday’s threat summary is led by Microsoft’s November Patch Tuesday release, which includes a patch for a zero-day vulnerability already under active exploitation. We are also tracking significant security incidents, including a reported data breach at Logitech resulting from another zero-day attack and serious allegations regarding Coinbase’s breach disclosure timeline. Stay informed on these critical developments and other emerging threats.&lt;/p&gt;
&lt;h2&gt;Top 3 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Patch Tuesday, November 2025 Edition: Microsoft’s November patches address over 60 flaws, including a zero-day vulnerability that is confirmed to be under active exploitation across all Windows versions. &lt;a href=&quot;https://krebsonsecurity.com/2025/11/microsoft-patch-tuesday-november-2025-edition/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Logitech leaks data after zero-day attack: Tech peripheral giant Logitech has reportedly suffered a significant data leak following a zero-day attack on its systems. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/11/16/infosec_news_in_brief/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;I have recordings proving Coinbase knew about breach months before disclosure: A researcher alleges that cryptocurrency exchange Coinbase was aware of a major security breach for months before notifying the public. &lt;a href=&quot;https://jonathanclark.com/posts/coinbase-breach-timeline.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Finger.exe &amp;amp; ClickFix, (Sun, Nov 16th): The SANS Internet Storm Center reports that the legacy finger.exe command is being utilized in recent ‘ClickFix’ attacks. &lt;a href=&quot;https://isc.sans.edu/diary/rss/32492&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Browser fingerprinting via favicon — A novel tracking technique has emerged that leverages website favicons to create persistent fingerprints of users’ browsers for tracking purposes. &lt;a href=&quot;https://github.com/jonasstrehle/supercookie&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Logitech leaks data after zero-day attack: Tech peripheral giant Logitech has reportedly suffered a significant data leak following a zero-day attack on its systems. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/11/16/infosec_news_in_brief/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;I have recordings proving Coinbase knew about breach months before disclosure: A researcher alleges that cryptocurrency exchange Coinbase was aware of a major security breach for months before notifying the public. &lt;a href=&quot;https://jonathanclark.com/posts/coinbase-breach-timeline.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google to flag Android apps with excessive battery use on the Play Store: Google will now identify and flag Android applications in the Play Store that cause excessive battery drain due to high background activity. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-to-flag-android-apps-with-excessive-battery-use-on-the-play-store/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;DeepEyesV2 outperforms bigger rivals by favoring tools over sheer knowledge: Researchers in China have developed DeepEyesV2, a multimodal AI that intelligently uses external tools to enhance performance and analytical capabilities. &lt;a href=&quot;https://the-decoder.com/deepeyesv2-outperforms-bigger-rivals-by-favoring-tools-over-sheer-knowledge/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Coinbase</category><category>Cybersecurity</category><category>Data Breach</category><category>Logitech</category><category>Microsoft Zero-Day</category><category>Patch Tuesday</category><category>SANS ISC</category><category>threat intelligence</category><category>vulnerability management</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/microsoft-zero-day-logitech-breach-patch-tuesday-11-16-2025.webp" length="0" type="image/webp"/></item><item><title>SFDR 2.0, UK Businesses – 11/16/2025</title><link>https://grabtheaxe.com/news/sfdr-2-0-uk-businesses-11-16-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/sfdr-2-0-uk-businesses-11-16-2025/</guid><description>SFDR 2.0 alert: Understand the implications of the leaked draft proposal for UK businesses. Stay informed on regulatory changes &amp; compliance.</description><pubDate>Sun, 16 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/sfdr-2-0-uk-businesses-11-16-2025.webp&quot; alt=&quot;SFDR 2.0&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s compliance intelligence digest focuses on the implications of the leaked SFDR 2.0 draft proposal for UK businesses, highlighting the need to understand the potential overhaul of the EU’s sustainable finance disclosure regime. Also, a Cybersecurity Outlook 2026 event is mentioned. Here’s what you need to know.&lt;/p&gt;
&lt;h2&gt;Critical Compliance Alert&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SFDR 2.0 Implications for UK Businesses: A leaked draft proposal signals a sweeping overhaul of the EU’s Sustainable Finance Disclosure Regulation (SFDR). This is highly relevant for UK businesses with EU-facing funds or sustainability-linked products. &lt;a href=&quot;https://vinciworks.com/blog/sfdr-2-0-is-coming-what-does-it-mean-for-uk-businesses/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SFDR 2.0 Implications for UK Businesses: A leaked draft proposal signals a sweeping overhaul of the EU’s Sustainable Finance Disclosure Regulation (SFDR). This is highly relevant for UK businesses with EU-facing funds or sustainability-linked products. &lt;a href=&quot;https://vinciworks.com/blog/sfdr-2-0-is-coming-what-does-it-mean-for-uk-businesses/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Cybersecurity</category><category>Environmental Sustainability</category><category>EU Regulation</category><category>Regulatory Compliance</category><category>SFDR</category><category>Sustainable Finance</category><category>UK Businesses</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/sfdr-2-0-uk-businesses-11-16-2025.webp" length="0" type="image/webp"/></item><item><title>Akira, CMMC, Junk Fees &amp; NPM Registry – 11/15/2025</title><link>https://grabtheaxe.com/news/akira-cmmc-junk-fees-npm-registry-11-15-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/akira-cmmc-junk-fees-npm-registry-11-15-2025/</guid><description>Akira ransomware targets Nutanix VMs, CMMC requirements live, plus updates on junk fees laws and NPM registry attack. Stay compliant and secure!</description><pubDate>Sat, 15 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/akira-cmmc-junk-fees-npm-registry-11-15-2025.webp&quot; alt=&quot;Akira Ransomware&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates, focusing on the Akira ransomware’s new targeting of Nutanix VMs and a massive NPM registry attack. We also cover the new Cybersecurity Maturity Model Certification (CMMC) requirements for DoD contractors and expanding state ‘junk fees’ laws. Stay informed about these pressing issues to enhance your organization’s compliance and security posture.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Akira RaaS Targets Nutanix VMs, Threatens Critical Orgs: The Akira ransomware group is actively experimenting with new attack methods, successfully targeting critical sectors through Nutanix VMs. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/akira-raas-nutanix-vms-critical-orgs&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;150,000 Packages Flood NPM Registry in Token Farming Campaign: A self-replicating attack has led to a massive influx of malicious packages in the NPM registry, specifically targeting tokens for the tea.xyz protocol. &lt;a href=&quot;https://www.darkreading.com/application-security/150000-packages-flood-npm-registry-token-farming&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;They’re Here! The Cybersecurity Maturity Model Certification Requirements for DoD Solicitations and Contracts Are Live: Contractors must now adhere to the Cybersecurity Maturity Model Certification (CMMC) requirements for DoD solicitations and contracts. &lt;a href=&quot;https://www.jdsupra.com/legalnews/they-re-here-the-cybersecurity-maturity-9530098/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Expanding Patchwork of State “Junk Fees” Laws Presents Compliance Challenges: Companies face compliance challenges due to expanding state laws regulating fee disclosures and total price advertising, often termed “junk fees” laws. &lt;a href=&quot;https://www.jdsupra.com/legalnews/expanding-patchwork-of-state-junk-fees-1003336/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FERC Staff Audit Report Identifies CIP Standard Compliance Risks in FY2025: A FERC staff audit report highlights risks to electric grid reliability based on Critical Infrastructure Protection (CIP) audits of NERC registered entities. &lt;a href=&quot;https://www.jdsupra.com/legalnews/ferc-staff-audit-report-identifies-cip-5593295/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fall 2025 Financial Conferences Reveal the Rules That Will Shape 2026: Insights from Fall 2025 financial conferences reveal upcoming regulatory changes expected to shape financial services compliance in 2026. &lt;a href=&quot;https://www.smarsh.com/blog/thought-leadership/financial-services-compliance-insights-fall-conferences-2025&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Compliance and Social Media: What You Need to Know About Influencer Content: Companies face growing risks from influencer content, particularly concerning third-party intellectual property rights infringements. &lt;a href=&quot;https://www.jdsupra.com/legalnews/compliance-and-social-media-what-you-5641202/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Preparing for Jersey’s new whistleblowing regime: Key insights and next steps: Insights and practical steps for employers in Jersey and Guernsey to prepare for the forthcoming whistleblowing regime. &lt;a href=&quot;https://www.jdsupra.com/legalnews/preparing-for-jersey-s-new-8797217/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Oregon’s Recycling Modernization Act: What Businesses Need to Know: Businesses need to understand Oregon’s Plastic Pollution and Recycling Modernization Act (RMA), which extends producer responsibility for packaging disposal. &lt;a href=&quot;https://www.jdsupra.com/legalnews/oregon-s-recycling-modernization-act-5374129/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Other&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cybersecurity Outlook 2026: Preview of the Cybersecurity Outlook 2026 virtual event. &lt;a href=&quot;https://www.darkreading.com/events/dark-reading-virtual-event-cybersecurity-outlook-2026&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Healthcare Compliance Essentials Workshop: Announcement for the Healthcare Compliance Essentials Workshop, providing foundational education on compliance program elements. &lt;a href=&quot;https://www.jdsupra.com/legalnews/virtual-event-healthcare-compliance-4304820/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Security Tools Target Growing macOS Threats: New tools aim to combat increasing malware threats targeting macOS, an area researchers say lacks attention. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/new-security-tools-target-growing-macos-threats&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hardened Containers Look to Eliminate Common Source of Vulnerabilities: Companies are working to slim down containers to eliminate common vulnerabilities introduced by the “kitchen-sink” approach to building them. &lt;a href=&quot;https://www.darkreading.com/application-security/hardened-containers-eliminate-common-source-vulnerabilities&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Akira ransomware</category><category>CMMC</category><category>compliance</category><category>Container Security</category><category>Cybersecurity</category><category>Junk Fees</category><category>macOS Threats</category><category>NPM Registry</category><category>Regulatory Updates</category><category>Third-Party Risk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/akira-cmmc-junk-fees-npm-registry-11-15-2025.webp" length="0" type="image/webp"/></item><item><title>GUARD Act, Data Breaches, AI &amp; Privacy – 11/15/2025</title><link>https://grabtheaxe.com/news/guard-act-data-breaches-ai-privacy-11-15-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/guard-act-data-breaches-ai-privacy-11-15-2025/</guid><description>Privacy news: GUARD Act threatens online privacy. Logitech data breach, Tate galleries applicant data leak, &amp; AI-automated attacks. Stay informed!</description><pubDate>Sat, 15 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/guard-act-data-breaches-ai-privacy-11-15-2025.webp&quot; alt=&quot;Data Privacy&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy intelligence digest highlights critical developments, including the GUARD Act’s potential threat to online privacy through mandatory age verification and the data breach at Logitech. Further coverage includes the leak of Tate galleries job applicants’ personal details and Anthropic’s claims regarding AI-automated cyberattacks. Stay informed to navigate the evolving privacy landscape effectively.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GUARD Act Threatens Online Privacy &amp;amp; Safety: The GUARD Act’s age-verification mandates endanger free expression, privacy, and competition by forcing invasive ID checks. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/surveillance-mandate-disguised-child-safety-why-guard-act-wont-keep-us-safe&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Logitech Data Breach Confirmed After Clop Extortion Attack: Hardware giant Logitech confirms a data breach after the Clop extortion gang claimed responsibility. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/logitech-confirms-data-breach-after-clop-extortion-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Personal Details of Tate Galleries Job Applicants Leaked: Sensitive information, including addresses and salaries, of Tate galleries job applicants leaked online. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/14/personal-details-of-tate-galleries-job-applicants-leaked-online&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Anthropic Claims of AI-Automated Cyberattacks Met With Doubt: Anthropic reports Chinese state-sponsored group automated cyber-espionage using Claude Code AI, but claims face skepticism. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/anthropic-claims-of-claude-ai-automated-cyberattacks-met-with-doubt/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://Checkout.com&quot;&gt;Checkout.com&lt;/a&gt; Snubs Hackers After Data Breach: &lt;a href=&quot;http://Checkout.com&quot;&gt;Checkout.com&lt;/a&gt; announces a breach by ShinyHunters, opting to donate ransom instead of paying. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/checkoutcom-snubs-shinyhunters-hackers-to-donate-ransom-instead/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Maryland Privacy Crackdown Raises Bar for Disclosure Compliance: Maryland’s Online Data Privacy Act (MODPA) of 2024 empowers the state to curb exploitative data practices. &lt;a href=&quot;https://pogowasright.org/maryland-privacy-crackdown-raises-bar-for-disclosure-compliance/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;U.S. Senate Introduces the Health Information Privacy Reform Act: HIPRA seeks to extend HIPAA-like protections. &lt;a href=&quot;https://www.insideprivacy.com/health-privacy/u-s-senate-introduces-the-health-information-privacy-reform-act/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Breaches&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Logitech Data Breach Confirmed After Clop Extortion Attack: Hardware giant Logitech confirms a data breach after the Clop extortion gang claimed responsibility. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/logitech-confirms-data-breach-after-clop-extortion-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Personal Details of Tate Galleries Job Applicants Leaked: Sensitive information, including addresses and salaries, of Tate galleries job applicants leaked online. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/14/personal-details-of-tate-galleries-job-applicants-leaked-online&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://Checkout.com&quot;&gt;Checkout.com&lt;/a&gt; Snubs Hackers After Data Breach: &lt;a href=&quot;http://Checkout.com&quot;&gt;Checkout.com&lt;/a&gt; announces a breach by ShinyHunters, opting to donate ransom instead of paying. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/checkoutcom-snubs-shinyhunters-hackers-to-donate-ransom-instead/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Artificial Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GUARD Act Threatens Online Privacy &amp;amp; Safety: The GUARD Act’s age-verification mandates endanger free expression, privacy, and competition by forcing invasive ID checks. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/surveillance-mandate-disguised-child-safety-why-guard-act-wont-keep-us-safe&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Anthropic Claims of AI-Automated Cyberattacks Met With Doubt: Anthropic reports Chinese state-sponsored group automated cyber-espionage using Claude Code AI, but claims face skepticism. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/anthropic-claims-of-claude-ai-automated-cyberattacks-met-with-doubt/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI</category><category>Cybersecurity</category><category>Data Breach</category><category>Data Protection</category><category>GUARD Act</category><category>HIPRA</category><category>MODPA</category><category>Privacy</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/guard-act-data-breaches-ai-privacy-11-15-2025.webp" length="0" type="image/webp"/></item><item><title>XWiki Exploit, FortiWeb Attacks &amp; Finger Malware – 11/15/2025</title><link>https://grabtheaxe.com/news/xwiki-exploit-fortiweb-attacks-finger-malware-11-15-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/xwiki-exploit-fortiweb-attacks-finger-malware-11-15-2025/</guid><description>Critical alert on XWiki vulnerability CVE-2025-24893 (CVSS 9.8) under active exploit by RondoDox. Also covers FortiWeb attacks and new ClickFix malware.</description><pubDate>Sat, 15 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/xwiki-exploit-fortiweb-attacks-finger-malware-11-15-2025.webp&quot; alt=&quot;XWiki Vulnerability&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is highlighted by the active exploitation of a critical remote code execution vulnerability in XWiki servers (CVSS 9.8) by the RondoDox botnet. Security teams are also responding to a novel malware campaign abusing the legacy ‘Finger’ protocol and the massive $220 million financial fallout from the Jaguar Land Rover cyberattack. This report details the key threats and defensive actions required.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet; The RondoDox botnet is actively exploiting a critical RCE vulnerability (CVE-2025-24893, CVSS 9.8) in unpatched XWiki servers. &lt;a href=&quot;https://thehackernews.com/2025/11/rondodox-exploits-unpatched-xwiki.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Honeypot: FortiWeb CVE-2025-64446 Exploits: Active exploitation attempts for the FortiWeb vulnerability CVE-2025-64446 are being widely observed in security honeypots. &lt;a href=&quot;https://isc.sans.edu/diary/rss/32486&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Decades-old ‘Finger’ protocol abused in ClickFix malware attacks: Threat actors are abusing the legacy ‘Finger’ protocol to remotely issue commands and deploy the ClickFix malware on Windows systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jaguar Land Rover cyberattack cost the company over $220 million: A recent cyberattack cost Jaguar Land Rover over $220 million in a single quarter, highlighting the severe financial impact of security incidents. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/jaguar-land-rover-cyberattack-cost-the-company-over-220-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Windows 10 KB5068781 ESU update may fail with 0x800f0922 errors: Microsoft is investigating a bug causing a critical Windows 10 extended security update to fail on corporate devices, posing a patching risk. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-10-kb5068781-esu-update-may-fail-with-0x800f0922-errors/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet; The RondoDox botnet is actively exploiting a critical RCE vulnerability (CVE-2025-24893, CVSS 9.8) in unpatched XWiki servers. &lt;a href=&quot;https://thehackernews.com/2025/11/rondodox-exploits-unpatched-xwiki.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Honeypot: FortiWeb CVE-2025-64446 Exploits: Active exploitation attempts for the FortiWeb vulnerability CVE-2025-64446 are being widely observed in security honeypots. &lt;a href=&quot;https://isc.sans.edu/diary/rss/32486&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Decades-old ‘Finger’ protocol abused in ClickFix malware attacks: Threat actors are abusing the legacy ‘Finger’ protocol to remotely issue commands and deploy the ClickFix malware on Windows systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Jaguar Land Rover cyberattack cost the company over $220 million: A recent cyberattack cost Jaguar Land Rover over $220 million in a single quarter, highlighting the severe financial impact of security incidents. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/jaguar-land-rover-cyberattack-cost-the-company-over-220-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 Companies: Five individuals have pleaded guilty to aiding North Korean IT workers in a fraudulent scheme to infiltrate U.S. companies and generate illicit revenue. &lt;a href=&quot;https://thehackernews.com/2025/11/five-us-citizens-plead-guilty-to.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft: Windows 10 KB5068781 ESU update may fail with 0x800f0922 errors: Microsoft is investigating a bug causing a critical Windows 10 extended security update to fail on corporate devices, posing a patching risk. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-10-kb5068781-esu-update-may-fail-with-0x800f0922-errors/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LeCun accuses Anthropic of exploiting AI cyberattack fears for regulatory capture: AI pioneer Yann LeCun claims AI company Anthropic is exaggerating AI cyberattack risks to influence regulation in its favor. &lt;a href=&quot;https://the-decoder.com/lecun-accuses-anthropic-of-exploiting-ai-cyberattack-fears-for-regulatory-capture/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CVE-2025-24893</category><category>Cyberattack</category><category>Data Breach</category><category>FortiWeb</category><category>Malware</category><category>RondoDox</category><category>threat intelligence</category><category>Windows Security</category><category>XWiki Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/xwiki-exploit-fortiweb-attacks-finger-malware-11-15-2025.webp" length="0" type="image/webp"/></item><item><title>AI Cyberattacks, Fortinet Zero-Day &amp; Akira Ransomware – 11/14/2025</title><link>https://grabtheaxe.com/news/ai-cyberattacks-fortinet-zero-day-akira-ransomware-11-14-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ai-cyberattacks-fortinet-zero-day-akira-ransomware-11-14-2025/</guid><description>Daily threat report: Chinese state actors leverage AI for cyberattacks, a critical Fortinet zero-day is actively exploited, and Akira ransomware targets Nutanix VMs.</description><pubDate>Fri, 14 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ai-cyberattacks-fortinet-zero-day-akira-ransomware-11-14-2025.webp&quot; alt=&quot;AI Cyberattacks&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is defined by a landmark shift in offensive capabilities, as Chinese state actors have been found using AI to automate cyberattacks. This development is coupled with a critical, actively exploited zero-day vulnerability in Fortinet’s FortiWeb products, which demands immediate attention from administrators. Meanwhile, the Akira ransomware group has evolved its tactics to target Nutanix virtual machines, and a massive supply chain attack has flooded the NPM registry with malicious packages. This report details the key threats you need to address now.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fortinet FortiWeb Zero-Day (CVE-2025-64446) Under Active Exploit: Fortinet silently patched a critical path traversal vulnerability in its FortiWeb WAF that is being actively exploited to create unauthorized admin accounts. CISA has added CVE-2025-64446 to its Known Exploited Vulnerabilities (KEV) catalog, requiring immediate patching. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fortinet-confirms-silent-patch-for-fortiweb-zero-day-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chinese State Hackers Automate Attacks Using Anthropic’s AI: A Chinese state-sponsored espionage group reportedly used Anthropic’s AI systems to automate a significant portion of their cyberattacks against approximately 30 entities. This marks a potential turning point in the use of AI for offensive cyber operations, though some researchers question the degree of autonomy. &lt;a href=&quot;https://therecord.media/chinese-hackers-anthropic-cyberattacks&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Akira Ransomware Targets Nutanix Virtual Machines: The Akira ransomware group is now targeting Nutanix AHV hypervisors to encrypt virtual machines, posing a significant threat to critical organizations using this infrastructure. CISA has flagged this as an imminent threat, noting the group has extorted over $244 million since September. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/akira-raas-nutanix-vms-critical-orgs&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Massive Supply Chain Attack Floods NPM Registry with 150,000 Malicious Packages: A self-replicating token farming campaign has inundated the NPM registry with over 150,000 malicious packages. The attack targets tokens for the tea.xyz protocol, highlighting ongoing risks in open-source software supply chains. &lt;a href=&quot;https://www.darkreading.com/application-security/150000-packages-flood-npm-registry-token-farming&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Five Plead Guilty to Aiding North Korean IT Worker Infiltration Schemes: The U.S. DOJ announced that five individuals have pleaded guilty to facilitating schemes that helped North Korean IT workers fraudulently gain employment at U.S. companies. These schemes are a major source of revenue for the North Korean regime, funding its illicit activities through wage and cryptocurrency theft. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/five-plead-guilty-to-helping-north-koreans-infiltrate-us-firms/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence (APT, malware, ransomware)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense &amp;amp; Government Targets: The Iranian state-sponsored group APT42 has launched a new espionage campaign, dubbed SpearSpecter, targeting individuals and organizations of interest to the IRGC. &lt;a href=&quot;https://thehackernews.com/2025/11/iranian-hackers-launch-spearspecter-spy.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;North Korean Hackers Abuse JSON Services for Covert Malware Delivery: Threat actors linked to North Korea are now using legitimate JSON storage services like JSON Keeper and &lt;a href=&quot;http://npoint.io&quot;&gt;npoint.io&lt;/a&gt; to host and deliver malware payloads, evading detection in their campaigns. &lt;a href=&quot;https://thehackernews.com/2025/11/north-korean-hackers-turn-json-services.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ransomware Ecosystem Most Decentralized To Date, LockBit Returns: The ransomware landscape saw 85 active groups in Q3 2025, the most decentralized to date. Despite law enforcement pressure, activity remains high, with 1,590 victims disclosed and the LockBit group re-emerging. &lt;a href=&quot;https://thehackernews.com/2025/11/ransomwares-fragmentation-reaches.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US Establishes New Strike Force to Combat Chinese Crypto Scammers: Federal authorities have created a new task force to disrupt Chinese cryptocurrency scam networks responsible for defrauding Americans of nearly $10 billion annually. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/us-announces-new-strike-force-targeting-chinese-crypto-scammers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Logitech Confirms Data Breach in Clop Extortion Attack: Logitech has confirmed it was breached by the Clop extortion gang, which exploited vulnerabilities in Oracle E-Business Suite to steal data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/logitech-confirms-data-breach-after-clop-extortion-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DoorDash Discloses New Data Breach Exposing User Information: DoorDash has begun notifying customers of a data breach that occurred in October, exposing user information. This is the latest security incident to affect the food delivery platform. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/doordash-hit-by-new-data-breach-in-october-exposing-user-information/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://Checkout.com&quot;&gt;Checkout.com&lt;/a&gt; Breached by ShinyHunters, Donates Ransom Demand to Charity: Financial tech company &lt;a href=&quot;http://Checkout.com&quot;&gt;Checkout.com&lt;/a&gt; announced a breach of a legacy cloud storage system by the ShinyHunters group. The company is refusing to pay the ransom and will donate the equivalent amount to charity instead. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/checkoutcom-snubs-shinyhunters-hackers-to-donate-ransom-instead/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cyberattack on Russian Port Operator Aimed to Disrupt Shipments: A cyberattack targeted Russian port operator Port Alliance, aiming to destabilize operations and disrupt exports of coal and mineral fertilizers across its key seaports. &lt;a href=&quot;https://therecord.media/cyberattack-on-russian-port-operator&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google Reverses Course on New Android Developer Registration Rules: Google is backpedaling on its plan for mandatory identity verification for all developers, now allowing for limited distribution accounts and installation of apps from unverified developers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/google/google-backpedals-on-new-android-developer-registration-rules/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hardened Containers Aim to Reduce Common Vulnerabilities: Several companies are promoting the use of slimmed-down, hardened containers to eliminate the common security vulnerabilities introduced by including unnecessary components. &lt;a href=&quot;https://www.darkreading.com/application-security/hardened-containers-eliminate-common-source-vulnerabilities&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ASUS Warns of Critical Authentication Bypass Flaw in DSL Routers: ASUS has released firmware updates to patch a critical authentication bypass vulnerability affecting several of its DSL series router models, urging users to update immediately. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/asus-warns-of-critical-auth-bypass-flaw-in-dsl-series-routers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies (AI, XDR, CNAPP)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Researchers Uncover Critical Bugs in Major AI Inference Frameworks: Security researchers have found critical remote code execution vulnerabilities in AI inference engines from Meta, Nvidia, and Microsoft. The flaws stem from the unsafe use of ZeroMQ and Python’s pickle deserialization. &lt;a href=&quot;https://thehackernews.com/2025/11/researchers-find-serious-ai-bugs.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Akira ransomware</category><category>CVE-2025-64446</category><category>Cybersecurity</category><category>Data Breach</category><category>Fortinet Vulnerability</category><category>Nation-State Actors</category><category>Supply Chain Attack</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ai-cyberattacks-fortinet-zero-day-akira-ransomware-11-14-2025.webp" length="0" type="image/webp"/></item><item><title>runC Vulnerability, TP-Link Ban &amp; Data Breach – 11/09/2025</title><link>https://grabtheaxe.com/news/runc-vulnerability-tp-link-ban-data-breach-11-09-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/runc-vulnerability-tp-link-ban-data-breach-11-09-2025/</guid><description>Critical alert on runC container escape vulnerability. Analysis of the proposed U.S. ban on TP-Link routers and a major data breach at a Chinese infosec firm.</description><pubDate>Sun, 09 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/runc-vulnerability-tp-link-ban-data-breach-11-09-2025.webp&quot; alt=&quot;runC Vulnerability&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is highlighted by critical vulnerabilities in the runC container runtime, potentially allowing Docker and Kubernetes container escapes. We are also tracking a significant data breach at a Chinese cybersecurity firm that exposed cyber-weapons, and the geopolitical and security implications of a proposed U.S. ban on TP-Link networking gear. This summary provides the essential intelligence you need to understand these developing threats.&lt;/p&gt;
&lt;h2&gt;Top 3 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Dangerous runC flaws could allow hackers to escape Docker containers: Three new vulnerabilities in the runC container runtime could allow attackers to escape Docker and Kubernetes containers, gaining access to the host system. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/dangerous-runc-flaws-could-allow-hackers-to-escape-docker-containers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Data breach at Chinese infosec firm reveals cyber-weapons and target list: A significant data breach at a Chinese information security firm has reportedly exposed its proprietary cyber-weapons and a list of targeted entities. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/11/09/asia_tech_news_roundup/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Drilling Down on Uncle Sam’s Proposed TP-Link Ban: The U.S. government is considering a ban on TP-Link networking equipment due to its ties to China, raising concerns about supply chain security and insecure-by-default products. &lt;a href=&quot;https://krebsonsecurity.com/2025/11/drilling-down-on-uncle-sams-proposed-tp-link-ban/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Data breach at Chinese infosec firm reveals cyber-weapons and target list: A significant data breach at a Chinese information security firm has reportedly exposed its proprietary cyber-weapons and a list of targeted entities. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/11/09/asia_tech_news_roundup/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;NAKIVO Introduces v11.1 with Upgraded Disaster Recovery and MSP Features: NAKIVO has released Backup &amp;amp; Replication v11.1, featuring enhanced disaster recovery options, real-time replication, and improved MSP management tools. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/nakivo-introduces-v111-with-upgraded-disaster-recovery-and-msp-features/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lost iPhone? Don’t fall for phishing texts saying it was found: The Swiss NCSC warns of a phishing scam targeting lost or stolen iPhone owners with fake ‘found’ messages designed to steal Apple ID credentials. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/lost-iphone-dont-fall-for-phishing-texts-saying-it-was-found/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Dangerous runC flaws could allow hackers to escape Docker containers: Three new vulnerabilities in the runC container runtime could allow attackers to escape Docker and Kubernetes containers, gaining access to the host system. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/dangerous-runc-flaws-could-allow-hackers-to-escape-docker-containers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Drilling Down on Uncle Sam’s Proposed TP-Link Ban: The U.S. government is considering a ban on TP-Link networking equipment due to its ties to China, raising concerns about supply chain security and insecure-by-default products. &lt;a href=&quot;https://krebsonsecurity.com/2025/11/drilling-down-on-uncle-sams-proposed-tp-link-ban/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google’s Veo-3 can fake surgical videos but misses every hint of medical sense: Google’s new video AI, Veo-3, can generate realistic-looking surgical videos but lacks any actual understanding of medical procedures, highlighting current AI limitations. &lt;a href=&quot;https://the-decoder.com/googles-veo-3-can-fake-surgical-videos-but-misses-every-hint-of-medical-sense/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>cloud security</category><category>Container Security</category><category>Data Breach</category><category>Docker</category><category>Kubernetes</category><category>Network Security</category><category>runC Vulnerability</category><category>threat intelligence</category><category>TP-Link</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/runc-vulnerability-tp-link-ban-data-breach-11-09-2025.webp" length="0" type="image/webp"/></item><item><title>Mobile Malware, AI Security, Regulatory Compliance – 11/08/2025</title><link>https://grabtheaxe.com/news/mobile-malware-ai-security-regulatory-compliance-11-08-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/mobile-malware-ai-security-regulatory-compliance-11-08-2025/</guid><description>Stay informed on mobile malware targeting Samsung, AI security concerns with Microsoft in UAE, and key regulatory compliance updates. Read the digest now!</description><pubDate>Sat, 08 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/mobile-malware-ai-security-regulatory-compliance-11-08-2025.webp&quot; alt=&quot;Mobile Malware&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical alerts regarding ‘Landfall’ malware targeting Samsung devices and ‘Ransomvibing’ affecting Visual Studio extensions. Key regulatory updates include the FDA’s response to Alvotech’s biosimilar application and California’s upcoming workshop on climate risk reporting. Microsoft’s AI expansion in the UAE also raises third-party security concerns, while forward-thinking compliance strategies for 2026 emphasize fairness and transparency.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;‘Landfall’ Malware Targets Samsung Galaxy Users: New malware can secretly record conversations, track device locations, capture photos, and collect contacts on compromised Samsung devices. &lt;a href=&quot;https://www.darkreading.com/mobile-security/landfall-malware-targeted-samsung-galaxy-users&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;‘Ransomvibing’ Infests Visual Studio Extension Market: A malicious VS Code extension encrypts and exfiltrates data, raising concerns about supply chain security and AI-generated threats. &lt;a href=&quot;https://www.darkreading.com/application-security/ransomvibing-infests-visual-studio-extension-market&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FDA Issues Complete Response Letter for Alvotech’s Simponi® (golimumab) Biosimilar AVT05: The FDA issued a complete response letter (CRL) for Alvotech’s biosimilar application. &lt;a href=&quot;https://www.jdsupra.com/legalnews/fda-issues-complete-response-letter-for-7737977/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California Air Resources Board to Hold Another Public Workshop: The California Air Resources Board will hold a third workshop on greenhouse gas emissions (SB 253) and climate risk reporting (SB 261) mandates. &lt;a href=&quot;https://www.jdsupra.com/legalnews/california-air-resources-board-to-hold-1897154/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Backs Massive AI Push in UAE, Raising Security Concerns: Microsoft’s partnership with Emirates tech company G42 to build a 5-gigawatt AI campus using Nvidia GPUs raises security concerns. &lt;a href=&quot;https://www.darkreading.com/cyber-risk/microsoft-massive-ai-push-uae-security-concerns&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;2026 Compliance Predictions Companies Can’t Afford to Ignore: Embedding fairness, transparency, and accountability into decision-making will provide a competitive advantage in navigating future challenges. &lt;a href=&quot;https://www.traliant.com/blog/2026-compliance-predictions-companies-cant-afford-to-ignore/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Climate Risk</category><category>FDA</category><category>Malware</category><category>Mobile Security</category><category>Ransomvibing</category><category>Regulatory Compliance</category><category>Samsung</category><category>Third-Party Risk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/mobile-malware-ai-security-regulatory-compliance-11-08-2025.webp" length="0" type="image/webp"/></item><item><title>Spyware, Car Surveillance, Firewall Flaws &amp; Breaches – 11/08/2025</title><link>https://grabtheaxe.com/news/spyware-car-surveillance-firewall-flaws-breaches-11-08-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/spyware-car-surveillance-firewall-flaws-breaches-11-08-2025/</guid><description>Privacy alert: New spyware targeting Samsung, car surveillance risks, Cisco firewall flaws exploited, and ID verification fueling data breaches. Stay informed!</description><pubDate>Sat, 08 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/spyware-car-surveillance-firewall-flaws-breaches-11-08-2025.webp&quot; alt=&quot;Car Surveillance&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights critical vulnerabilities and privacy risks. A new LandFall spyware targets Samsung via WhatsApp, while modern cars are increasingly under scrutiny for data collection practices. Additionally, malicious NuGet packages pose a threat with delayed sabotage payloads, and Cisco firewall flaws are being actively exploited for DoS attacks.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New LandFall spyware exploited Samsung zero-day via WhatsApp messages: A new spyware leverages a Samsung zero-day through WhatsApp images. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-landfall-spyware-exploited-samsung-zero-day-via-whatsapp-messages/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Modern cars are spying on you. Here’s what you can do about it.: Cars track data, potentially sharing it with insurers and data brokers; Privacy4Cars offers VIN lookups. &lt;a href=&quot;https://pogowasright.org/modern-cars-are-spying-on-you-heres-what-you-can-do-about-it/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Malicious NuGet packages drop disruptive ‘time bombs’: Packages on NuGet contain sabotage payloads set for 2027-28, targeting databases and Siemens S7 devices. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-nuget-packages-drop-disruptive-time-bombs/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cisco: Actively exploited firewall flaws now abused for DoS attacks: Zero-day vulnerabilities in Cisco firewalls are now being exploited to cause reboot loops. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisco-actively-exploited-firewall-flaws-now-abused-for-dos-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ID verification laws are fueling the next wave of breaches: Laws requiring ID verification lead to large sensitive data stores, increasing breach risks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/id-verification-laws-are-fueling-the-next-wave-of-breaches/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Business&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Modern cars are spying on you. Here’s what you can do about it.: Cars track data, potentially sharing it with insurers and data brokers; Privacy4Cars offers VIN lookups. &lt;a href=&quot;https://pogowasright.org/modern-cars-are-spying-on-you-heres-what-you-can-do-about-it/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Mobile&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New LandFall spyware exploited Samsung zero-day via WhatsApp messages: A new spyware leverages a Samsung zero-day through WhatsApp images. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-landfall-spyware-exploited-samsung-zero-day-via-whatsapp-messages/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Malicious NuGet packages drop disruptive ‘time bombs’: Packages on NuGet contain sabotage payloads set for 2027-28, targeting databases and Siemens S7 devices. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-nuget-packages-drop-disruptive-time-bombs/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;QNAP fixes seven NAS zero-day flaws exploited at Pwn2Own: QNAP patched seven zero-days exploited at Pwn2Own Ireland 2025 to hack NAS devices. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/qnap-fixes-seven-nas-zero-day-vulnerabilities-exploited-at-pwn2own/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cisco: Actively exploited firewall flaws now abused for DoS attacks: Zero-day vulnerabilities in Cisco firewalls are now being exploited to cause reboot loops. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisco-actively-exploited-firewall-flaws-now-abused-for-dos-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ID verification laws are fueling the next wave of breaches: Laws requiring ID verification lead to large sensitive data stores, increasing breach risks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/id-verification-laws-are-fueling-the-next-wave-of-breaches/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Modern cars are spying on you. Here’s what you can do about it.: Cars track data, potentially sharing it with insurers and data brokers; Privacy4Cars offers VIN lookups. &lt;a href=&quot;https://pogowasright.org/modern-cars-are-spying-on-you-heres-what-you-can-do-about-it/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;U.S.&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Modern cars are spying on you. Here’s what you can do about it.: Cars track data, potentially sharing it with insurers and data brokers; Privacy4Cars offers VIN lookups. &lt;a href=&quot;https://pogowasright.org/modern-cars-are-spying-on-you-heres-what-you-can-do-about-it/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Car Surveillance</category><category>Cisco</category><category>Data Breach</category><category>Data Privacy</category><category>Firewall</category><category>ID Verification</category><category>Samsung</category><category>spyware</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/spyware-car-surveillance-firewall-flaws-breaches-11-08-2025.webp" length="0" type="image/webp"/></item><item><title>VSCode Malware, AI Side-Channel &amp; Windows 10 ESU – 11/08/2025</title><link>https://grabtheaxe.com/news/vscode-malware-ai-side-channel-windows-10-esu-11-08-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/vscode-malware-ai-side-channel-windows-10-esu-11-08-2025/</guid><description>Security alert on GlassWorm malware in VSCode extensions. Microsoft reveals &apos;Whisper Leak&apos; AI side-channel attack. Final warning for Windows 10 ESU enrollment.</description><pubDate>Sat, 08 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/vscode-malware-ai-side-channel-windows-10-esu-11-08-2025.webp&quot; alt=&quot;VSCode Malware&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is marked by the re-emergence of the GlassWorm malware, now targeting developers through malicious VSCode extensions on the OpenVSX marketplace. Microsoft has also disclosed a novel side-channel attack, dubbed ‘Whisper Leak,’ capable of compromising encrypted AI chat communications. Furthermore, a critical deadline approaches for Windows 10 users to enroll in Extended Security Updates to avoid exposure. These developments highlight immediate risks to software supply chains, AI privacy, and legacy system security.&lt;/p&gt;
&lt;h2&gt;Top 3 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GlassWorm malware returns on OpenVSX with 3 new VSCode extensions: The GlassWorm malware campaign has resurfaced on the OpenVSX marketplace, infecting three new VSCode extensions that have already been downloaded over 10,000 times. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/glassworm-malware-returns-on-openvsx-with-3-new-vscode-extensions/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic: Researchers have detailed ‘Whisper Leak,’ a novel side-channel attack that can identify conversation topics in encrypted, streaming-mode AI chat traffic, posing significant privacy risks. &lt;a href=&quot;https://thehackernews.com/2025/11/microsoft-uncovers-whisper-leak-attack.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Still on Windows 10? Enroll in free ESU before next week’s Patch Tuesday: Microsoft urges remaining Windows 10 users to enroll in the free Extended Security Updates (ESU) program before the upcoming Patch Tuesday to remain protected against new vulnerabilities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/still-on-windows-10-enroll-in-free-extended-security-updates/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GlassWorm malware returns on OpenVSX with 3 new VSCode extensions: The GlassWorm malware campaign has resurfaced on the OpenVSX marketplace, infecting three new VSCode extensions that have already been downloaded over 10,000 times. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/glassworm-malware-returns-on-openvsx-with-3-new-vscode-extensions/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Honeypot: Requests for (Code) Repositories, (Sat, Nov 8th): SANS ISC honeypots have detected an increase in scanning activity targeting code repositories, indicating active reconnaissance for vulnerable source code by threat actors. &lt;a href=&quot;https://isc.sans.edu/diary/rss/32460&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Still on Windows 10? Enroll in free ESU before next week’s Patch Tuesday: Microsoft urges remaining Windows 10 users to enroll in the free Extended Security Updates (ESU) program before the upcoming Patch Tuesday to remain protected against new vulnerabilities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/still-on-windows-10-enroll-in-free-extended-security-updates/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic: Researchers have detailed ‘Whisper Leak,’ a novel side-channel attack that can identify conversation topics in encrypted, streaming-mode AI chat traffic, posing significant privacy risks. &lt;a href=&quot;https://thehackernews.com/2025/11/microsoft-uncovers-whisper-leak-attack.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Cybersecurity</category><category>GlassWorm</category><category>Malware</category><category>Side-Channel Attack</category><category>threat intelligence</category><category>VSCode</category><category>Windows 10 ESU</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/vscode-malware-ai-side-channel-windows-10-esu-11-08-2025.webp" length="0" type="image/webp"/></item><item><title>AI Ransomware, Cyberattack, Data Privacy – 11/07/2025</title><link>https://grabtheaxe.com/news/ai-ransomware-cyberattack-data-privacy-11-07-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ai-ransomware-cyberattack-data-privacy-11-07-2025/</guid><description>AI ransomware sneaks onto VS Code; US Budget Office hit by cyberattack. Plus, Europol data sharing &amp; student data breach settlement. Stay informed!</description><pubDate>Fri, 07 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ai-ransomware-cyberattack-data-privacy-11-07-2025.webp&quot; alt=&quot;AI Ransomware&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This daily privacy digest highlights critical security threats, including an AI-generated ransomware on the VS Code marketplace and a cyberattack on the U.S. Congressional Budget Office. Also covered are the EU’s move to expand Europol’s data-sharing capabilities and a $5.1 million penalty against Illuminate Education for student data protection failures. Finally, we look at the EFF’s latest findings on the effectiveness of antivirus apps in detecting stalkerware.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI-Slop ransomware test sneaks on to VS Code marketplace. A malicious, AI-created ransomware extension was found on Microsoft’s VS Code marketplace. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/ai-slop-ransomware-test-sneaks-on-to-vs-code-marketplace/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;U.S. Congressional Budget Office hit by suspected foreign cyberattack. CBO confirms a cybersecurity incident, potentially exposing sensitive data to a foreign hacker. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/us-congressional-budget-office-hit-by-suspected-foreign-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How a ransomware gang encrypted Nevada government’s systems. The State of Nevada fully recovered from a ransomware attack impacting 60 agencies. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/how-a-ransomware-gang-encrypted-nevada-governments-systems/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Attorney General James and Multistate Coalition Secure $5.1 Million. Illuminate Education penalized for failing to protect student data. &lt;a href=&quot;https://pogowasright.org/attorney-general-james-and-multistate-coalition-secure-5-1-million-from-education-software-company-for-failing-to-protect-students-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EU Parliament committee votes to advance controversial Europol data sharing proposal. Proposal expands Europol’s data sharing and biometric data collection. &lt;a href=&quot;https://pogowasright.org/eu-parliament-committee-votes-to-advance-controversial-europol-data-sharing-proposal/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New DSK Guidelines Aim to Set the Standard for International Research Collaborations. German authorities release guidelines on international data transfers in medical research. &lt;a href=&quot;https://www.gtlaw-dataprivacydish.com/2025/11/new-dsk-guidelines-aim-to-set-the-standard-for-international-research-collaborations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Attorney General James and Multistate Coalition Secure $5.1 Million. Illuminate Education penalized for failing to protect student data. &lt;a href=&quot;https://pogowasright.org/attorney-general-james-and-multistate-coalition-secure-5-1-million-from-education-software-company-for-failing-to-protect-students-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;AI&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Faking Receipts with AI. AI can now create realistic fake receipts, including paper wrinkles and signatures. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/faking-receipts-with-ai.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The UK’s First Copyright vs. AI Decision: Key Takeaways on a Win for the AI Industry. UK court’s decision favors AI industry, stating AI models aren’t infringing copies. &lt;a href=&quot;https://datamatters.sidley.com/2025/11/06/the-uks-first-copyright-vs-ai-decision-key-takeaways-on-a-win-for-the-ai-industry/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Leak confirms Google Gemini 3 Pro and Nano Banana 2 could launch soon. Google plans to release Gemini 3 for coding and Nano Banana 2 for images. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/leak-confirms-google-gemini-3-pro-and-nano-banana-2-could-launch-soon/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI-Slop ransomware test sneaks on to VS Code marketplace. A malicious, AI-created ransomware extension was found on Microsoft’s VS Code marketplace. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/ai-slop-ransomware-test-sneaks-on-to-vs-code-marketplace/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Government&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;U.S. Congressional Budget Office hit by suspected foreign cyberattack. CBO confirms a cybersecurity incident, potentially exposing sensitive data to a foreign hacker. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/us-congressional-budget-office-hit-by-suspected-foreign-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How a ransomware gang encrypted Nevada government’s systems. The State of Nevada fully recovered from a ransomware attack impacting 60 agencies. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/how-a-ransomware-gang-encrypted-nevada-governments-systems/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EU Parliament committee votes to advance controversial Europol data sharing proposal. Proposal expands Europol’s data sharing and biometric data collection. &lt;a href=&quot;https://pogowasright.org/eu-parliament-committee-votes-to-advance-controversial-europol-data-sharing-proposal/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Stalkerware&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EFF Teams Up With AV Comparatives to Test Android Stalkerware Detection by Major Antivirus Apps. Tests reveal mixed results in stalkerware detection by Android antivirus apps; Malwarebytes scored 100%. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/eff-teams-av-comparatives-test-android-stalkerware-detection-major-antivirus-apps&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI</category><category>Cyberattack</category><category>Data Breach</category><category>Data Privacy</category><category>Europol</category><category>ransomware</category><category>Stalkerware</category><category>Student Data</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ai-ransomware-cyberattack-data-privacy-11-07-2025.webp" length="0" type="image/webp"/></item><item><title>Landfall Spyware, CBO Hack &amp; Cisco Flaws – 11/07/2025</title><link>https://grabtheaxe.com/news/landfall-spyware-cbo-hack-cisco-flaws-11-07-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/landfall-spyware-cbo-hack-cisco-flaws-11-07-2025/</guid><description>Critical security alerts on Landfall spyware exploiting a Samsung zero-day, a major CBO government hack, and active DoS attacks on Cisco firewalls. Stay informed.</description><pubDate>Fri, 07 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/landfall-spyware-cbo-hack-cisco-flaws-11-07-2025.webp&quot; alt=&quot;Landfall Spyware&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is dominated by the discovery of the ‘Landfall’ spyware, which exploited a zero-day in Samsung devices for nearly a year. Other critical threats include actively exploited Cisco firewall vulnerabilities causing DoS attacks and a significant data breach at the U.S. Congressional Budget Office linked to an unpatched device. We are also tracking a supply chain threat involving malicious NuGet packages with dormant ‘time bomb’ payloads set to detonate in the future. This is what you need to know now.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;‘Landfall’ spyware abused zero-day to hack Samsung Galaxy phones: A newly discovered commercial spyware named ‘Landfall’ exploited a zero-day vulnerability for nearly a year to compromise Samsung Galaxy devices, targeting users in the Middle East. &lt;a href=&quot;https://techcrunch.com/2025/11/07/landfall-spyware-abused-zero-day-to-hack-samsung-galaxy-phones/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cisco: Actively exploited firewall flaws now abused for DoS attacks — Cisco warns that two previously disclosed zero-day vulnerabilities in its ASA and FTD firewalls are now being actively used to launch denial-of-service attacks, causing devices to enter a reboot loop. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisco-actively-exploited-firewall-flaws-now-abused-for-dos-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Congressional Budget Office confirms it was hacked: The U.S. Congressional Budget Office (CBO) has confirmed a significant cybersecurity incident, with researchers suggesting the breach may have stemmed from a firewall that remained unpatched for over a year. &lt;a href=&quot;https://techcrunch.com/2025/11/07/congressional-budget-office-confirms-it-was-hacked/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Malicious NuGet packages drop disruptive ‘time bombs’: Malicious packages have been found on the NuGet repository containing hidden payloads scheduled to activate in 2027 and 2028, designed to sabotage databases and Siemens industrial control systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-nuget-packages-drop-disruptive-time-bombs/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Washington Post confirms data breach linked to Oracle hacks — The Washington Post is the latest high-profile victim of the Clop ransomware gang, which breached the newspaper’s network by exploiting vulnerabilities in Oracle software. &lt;a href=&quot;https://techcrunch.com/2025/11/07/washington-post-confirms-data-breach-linked-to-oracle-hacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Russian Hacking Group Sandworm Deploys New Wiper Malware in Ukraine: The Russian state-sponsored group Sandworm has been observed deploying new data-wiping malware against government, energy, and logistics entities in Ukraine. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/russian-sandworm-new-wiper-ukraine/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;From Log4j to IIS, China’s Hackers Turn Legacy Bugs into Global Espionage Tools: A China-linked threat actor is exploiting older vulnerabilities, including Log4j, to target U.S. non-profits involved in policy issues, aiming to establish long-term network persistence for espionage. &lt;a href=&quot;https://thehackernews.com/2025/11/from-log4j-to-iis-chinas-hackers-turn.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities: A malicious Visual Studio Code extension named “susvsex” was discovered with basic ransomware functions, appearing to have been created with AI assistance and making little effort to hide its malicious nature. &lt;a href=&quot;https://thehackernews.com/2025/11/vibe-coded-malicious-vs-code-extension.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How to trade your $214,000 cybersecurity job for a jail cell: An article details a case where incident response experts were arrested by the FBI for allegedly planting ransomware themselves while engaged by victim companies to perform cleanup. &lt;a href=&quot;https://arstechnica.com/security/2025/11/fbi-arrests-ransomware-clean-up-experts-for-planting-ransomware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;QNAP fixes seven NAS zero-day flaws exploited at Pwn2Own — QNAP has released patches for seven zero-day vulnerabilities in its Network-Attached Storage (NAS) devices that were successfully exploited by researchers during the Pwn2Own competition. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/qnap-fixes-seven-nas-zero-day-vulnerabilities-exploited-at-pwn2own/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ID verification laws are fueling the next wave of breaches: An analysis suggests that increasingly strict ID verification laws are forcing companies to store massive amounts of sensitive data, turning compliance efforts into a significant security risk by creating high-value targets. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/id-verification-laws-are-fueling-the-next-wave-of-breaches/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ollama, Nvidia Flaws Put AI Infrastructure at Risk: Researchers have uncovered multiple vulnerabilities in popular AI infrastructure products from Ollama and Nvidia, including a flaw that could permit remote code execution. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/ollama-nvidia-flaws-ai-infrastructure-risk&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;​​Whisper Leak: A novel side-channel attack on remote language models: Microsoft researchers have detailed “Whisper Leak,” a new side-channel attack that can infer the topics of encrypted conversations with remote AI language models by analyzing network traffic patterns. &lt;a href=&quot;https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI Agents Are Going Rogue: Here’s How to Rein Them In: Experts warn that applying human-centric identity frameworks to AI agents is inadequate and creates potential for catastrophic security failures as their use becomes more widespread. &lt;a href=&quot;https://www.darkreading.com/cyber-risk/ai-agents-going-rogue&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Cisco Vulnerability</category><category>Cybersecurity</category><category>Data Breach</category><category>Government Hack</category><category>Landfall Spyware</category><category>ransomware</category><category>Supply Chain Attack</category><category>threat intelligence</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/landfall-spyware-cbo-hack-cisco-flaws-11-07-2025.webp" length="0" type="image/webp"/></item><item><title>DHS, Biometrics, Facial Recognition &amp; Data Breach – 11/06/2025</title><link>https://grabtheaxe.com/news/dhs-biometrics-facial-recognition-data-breach-11-06-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/dhs-biometrics-facial-recognition-data-breach-11-06-2025/</guid><description>DHS biometric data seizure, CBP facial recognition app, &amp; Hyundai data breach. Stay informed on the latest privacy threats and data security news.</description><pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/dhs-biometrics-facial-recognition-data-breach-11-06-2025.webp&quot; alt=&quot;Biometric Seizure&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy intelligence digest highlights concerning developments in data privacy and security. The DHS is under fire for proposed rules allowing the seizure of children’s biometric data, while a CBP app enables local law enforcement to use facial recognition for immigration enforcement. Additionally, a data breach at Hyundai AutoEver America exposed sensitive personal information, underscoring the ever-present threat of data breaches.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;DHS offers “disturbing new excuses” to seize kids’ biometric data, expert says: Civil and digital rights experts are horrified by a proposed rule change allowing DHS to collect biometric data on all immigrants, without age restrictions. &lt;a href=&quot;https://pogowasright.org/dhs-offers-disturbing-new-excuses-to-seize-kids-biometric-data-expert-says/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DHS Gives Local Cops a Facial Recognition App To Find Immigrants: CBP released an app for local law enforcement to scan faces for immigration enforcement, raising privacy concerns. &lt;a href=&quot;https://pogowasright.org/dhs-gives-local-cops-a-facial-recognition-app-to-find-immigrants/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hyundai AutoEver America data breach exposes SSNs, drivers licenses: Hackers breached Hyundai AutoEver America, accessing and exposing personal information, including SSNs and driver’s licenses. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hyundai-autoever-america-data-breach-exposes-ssns-drivers-licenses/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;University of Pennsylvania confirms data stolen in cyberattack: A cyberattack on the University of Pennsylvania resulted in the theft of data related to development and alumni activities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-confirms-data-stolen-in-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California Adds Injunctive Relief to its Right of Publicity Statute and Extends Liability to Digital Replicas: California amended its Right of Publicity statute to include injunctive relief and cover digital replicas. &lt;a href=&quot;https://pogowasright.org/california-adds-injunctive-relief-to-its-right-of-publicity-statute-and-extends-liability-to-digital-replicas/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;California Adds Injunctive Relief to its Right of Publicity Statute and Extends Liability to Digital Replicas: California amended its Right of Publicity statute to include injunctive relief and cover digital replicas. &lt;a href=&quot;https://pogowasright.org/california-adds-injunctive-relief-to-its-right-of-publicity-statute-and-extends-liability-to-digital-replicas/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Rigged Poker Games: The DOJ indicted 31 people for high-tech rigging of poker games using altered shuffling machines and hidden technology. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/rigged-poker-games.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;DHS offers “disturbing new excuses” to seize kids’ biometric data, expert says: Civil and digital rights experts are horrified by a proposed rule change allowing DHS to collect biometric data on all immigrants, without age restrictions. &lt;a href=&quot;https://pogowasright.org/dhs-offers-disturbing-new-excuses-to-seize-kids-biometric-data-expert-says/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DHS Gives Local Cops a Facial Recognition App To Find Immigrants: CBP released an app for local law enforcement to scan faces for immigration enforcement, raising privacy concerns. &lt;a href=&quot;https://pogowasright.org/dhs-gives-local-cops-a-facial-recognition-app-to-find-immigrants/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Biometrics</category><category>CCPA</category><category>Cybersecurity</category><category>Data Breach</category><category>DHS</category><category>Facial recognition</category><category>Privacy</category><category>Surveillance</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/dhs-biometrics-facial-recognition-data-breach-11-06-2025.webp" length="0" type="image/webp"/></item><item><title>Sandworm Wipers, Cisco Flaw, &amp; SonicWall Breach – 11/06/2025</title><link>https://grabtheaxe.com/news/sandworm-wipers-cisco-flaw-sonicwall-breach-11-06-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/sandworm-wipers-cisco-flaw-sonicwall-breach-11-06-2025/</guid><description>Daily security brief on Russia&apos;s Sandworm wiper attacks, a critical Cisco UCCX flaw allowing root access, and SonicWall&apos;s state-sponsored breach confirmation.</description><pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/sandworm-wipers-cisco-flaw-sonicwall-breach-11-06-2025.webp&quot; alt=&quot;Sandworm Wiper Attack&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is defined by aggressive nation-state activity, with Russia’s Sandworm group deploying destructive wiper malware against Ukraine’s critical infrastructure. This summary also covers a critical root-level vulnerability in Cisco’s UCCX software and an official confirmation from SonicWall that state-sponsored hackers were behind its recent cloud backup breach. Additionally, new intelligence from Google confirms that malware leveraging generative AI for evasion is now being actively deployed in the wild.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Wipers from Russia’s Sandworm Hackers Rain Destruction on Ukraine : Russian state-sponsored hackers, including the notorious Sandworm group, are actively deploying destructive data-wiping malware against Ukrainian targets, particularly focusing on the nation’s critical grain industry. &lt;a href=&quot;https://arstechnica.com/security/2025/11/wipers-from-russias-most-cut-throat-hackers-rain-destruction-on-ukraine/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical Cisco UCCX Flaw Lets Attackers Run Commands as Root — Cisco has patched a critical vulnerability in its Unified Contact Center Express (UCCX) software that could allow authenticated, remote attackers to execute arbitrary commands with root privileges. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/critical-cisco-uccx-flaw-lets-hackers-run-commands-as-root/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SonicWall Confirms State-Sponsored Hackers Stole Firewall Backups — SonicWall has officially attributed a September security breach to a nation-state threat actor who gained unauthorized access to firewall configuration backup files from a cloud environment. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/sonicwall-firewall-backups-nation-state-actor&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Warns of Critical Vulnerabilities in ABB FLXeon ICS Controllers — An advisory from CISA details multiple high-severity vulnerabilities (CVSS 8.7) in ABB FLXeon controllers, including hard-coded credentials and improper input validation, which could allow for remote code execution. &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-25-310-03&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Advisory Details RCE Flaws in Advantech DeviceOn/iEdge IoT Platform — CISA has released an advisory for end-of-life Advantech DeviceOn/iEdge products, warning of critical path traversal and XSS vulnerabilities (CVSS 8.7) that could lead to remote code execution. &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-25-310-01&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI-Slop Ransomware Test Sneaks on to VS Code Marketplace : A malicious extension with basic ransomware capabilities, seemingly created with the help of AI, was discovered and removed from Microsoft’s official VS Code marketplace. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/ai-slop-ransomware-test-sneaks-on-to-vs-code-marketplace/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Italian Political Consultant Targeted with Paragon Spyware — A prominent Italian political consultant was notified by WhatsApp that his phone was targeted with sophisticated spyware developed by the commercial surveillance firm Paragon. &lt;a href=&quot;https://techcrunch.com/2025/11/06/italian-political-consultant-says-he-was-targeted-with-paragon-spyware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ClickFix Malware Evolves with Multi-OS Support and Video Tutorials : The ClickFix malware campaign has been updated to include video guides that walk victims through the self-infection process and now automatically detects the OS to provide the correct malicious commands. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/clickfix-malware-attacks-evolve-with-multi-os-support-video-tutorials/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Trojanized ESET Installers Drop Kalambur Backdoor in Attacks on Ukraine : A Russia-aligned threat group is targeting Ukrainian entities with phishing attacks that use trojanized ESET security software installers to deliver the Kalambur backdoor. &lt;a href=&quot;https://thehackernews.com/2025/11/trojanized-eset-installers-drop.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR : Threat actors are now enabling the Windows Hyper-V role on victim systems to deploy a lightweight Linux virtual machine, creating a hidden environment to execute malware and bypass EDR solutions. &lt;a href=&quot;https://thehackernews.com/2025/11/hackers-weaponize-windows-hyper-v-to.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ed Tech Company Fined $5.1 Million for Poor Data Security Practices : An educational technology firm has been fined $5.1 million for failing to implement adequate data security measures, such as monitoring for suspicious activity and securing backups, which led to a major hack. &lt;a href=&quot;https://therecord.media/ed-tech-company-fined-5-million-data-breach-security-practices&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Nevada Government Details Ransomware Attack, Confirms No Ransom Paid : The State of Nevada has released a post-mortem on the August ransomware attack that affected 60 agencies, confirming it did not pay the ransom and that the initial breach occurred in May. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/how-a-ransomware-gang-encrypted-nevada-governments-systems/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Continuous Purple Teaming: Turning Red-Blue Rivalry into Real Defense : An article from Picus Security makes the case for adopting continuous purple teaming and Breach and Attack Simulation (BAS) to proactively validate security controls against real-world attack scenarios. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/continuous-purple-teaming-turning-red-blue-rivalry-into-real-defense/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cloudflare Scrubs Aisuru Botnet from Top Domains List : Cloudflare has taken action to remove domains associated with the massive Aisuru botnet from its public rankings after the botnet was used to manipulate traffic data and attack DNS services. &lt;a href=&quot;https://krebsonsecurity.com/2025/11/cloudflare-scrubs-aisuru-botnet-from-top-domains-list/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cisco Warns of New Attack Variant Battering Firewalls : Cisco is alerting customers to a new attack variant that targets unpatched Secure Firewall devices, exploiting two known vulnerabilities to cause a denial-of-service condition by forcing the device to reload. &lt;a href=&quot;https://thehackernews.com/2025/11/cisco-warns-of-new-firewall-attack.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Releases Four Industrial Control Systems Advisories : CISA has published four new advisories detailing security vulnerabilities in various ICS products from vendors including Advantech, Ubia, ABB, and Hitachi Energy. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/11/06/cisa-releases-four-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Teaching Cybersecurity to AI Systems : A new proof of concept demonstrates how AI agents, using LangChain and OpenAI integrated with the Cisco Umbrella API, can be equipped with real-time threat intelligence to evaluate domain security. &lt;a href=&quot;https://blog.talosintelligence.com/do-robots-dream-of-secure-networking/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google: AI-Enabled Malware is Now Being Actively Deployed : According to Google, threat actors are actively deploying malware that uses ‘just-in-time AI’ and LLMs to generate polymorphic code on-demand, significantly improving its ability to evade detection. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/aienabled-malware-actively/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New IDC Research Highlights a Major Cloud Security Shift : Recent IDC research shows a clear industry trend toward adopting integrated, AI-powered platforms like CNAPP, XDR, and SIEM to reduce complexity and strengthen cloud security resilience. &lt;a href=&quot;https://www.microsoft.com/en-us/security/blog/2025/11/06/new-idc-research-highlights-a-major-cloud-security-shift/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CISA</category><category>Cisco Vulnerability</category><category>ICS security</category><category>Nation-State Actors</category><category>ransomware</category><category>Sandworm</category><category>Security Breach</category><category>threat intelligence</category><category>Wiper Malware</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/sandworm-wipers-cisco-flaw-sonicwall-breach-11-06-2025.webp" length="0" type="image/webp"/></item><item><title>Zero-Day, ChatGPT Bugs, FINRA Fine &amp; Data Breaches – 11/06/2025</title><link>https://grabtheaxe.com/news/zero-day-chatgpt-finra-data-breaches-11-06-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/zero-day-chatgpt-finra-data-breaches-11-06-2025/</guid><description>Zero-day exploit targeting Japan, ChatGPT security bugs, a $10M FINRA fine, and healthcare data breaches lead today&apos;s compliance news. Stay secure and compliant.</description><pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/zero-day-chatgpt-finra-data-breaches-11-06-2025.webp&quot; alt=&quot;Zero-Day Exploit&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical developments, including an APT exploiting a zero-day vulnerability to target Japanese organizations and multiple security flaws in ChatGPT leading to potential data theft. Also covered is a significant FINRA fine for excessive gift spending and recent data breaches in the healthcare sector. Stay informed to strengthen your organization’s security posture and compliance efforts.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;APT ‘Bronze Butler’ Exploits Zero-Day to Root Japan Orgs: A critical security issue in a popular endpoint manager allowed Chinese state-sponsored attackers to backdoor Japanese businesses. &lt;a href=&quot;https://www.darkreading.com/application-security/bronze-butler-apt-exploits-zero-day-vuln-root-japan&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Multiple ChatGPT Security Bugs Allow Rampant Data Theft: Attackers can use them to inject arbitrary prompts, exfiltrate personal user information, bypass safety mechanisms, and take other malicious actions. &lt;a href=&quot;https://www.darkreading.com/application-security/multiple-chatgpt-security-bugs-rampant-data-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Nikkei Suffers Breach Via Slack Compromise: The Japanese media giant said thousands of employee and business partners were impacted by an attack that compromised Slack account data and chat histories. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/nikkei-suffers-breach-slack-compromise&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FINRA Fines Firm $10M on Gift Spending: FINRA fined a financial services firm $10 million for providing clients luxury meals and event tickets in exchange for business deals, and for a weak recordkeeping system. &lt;a href=&quot;https://www.radicalcompliance.com/2025/11/05/finra-fines-firm-10m-on-gift-spending/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tri Century Eye Care &amp;amp; Pittsburgh Gastroenterology Associates Announce Data Breaches: Data breaches have recently been announced by Tri Century Eye Care in Pennsylvania, Pittsburgh Gastroenterology Associates, NAHGA Claims Services. &lt;a href=&quot;https://www.hipaajournal.com/tri-century-eye-care-pittsburgh-gastroenterology-associates-data-breaches/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Threat Intelligence – ISO 27001:2022 Control 5.7 Explained: Cyber attacks evolve faster than traditional security review cycles; organizations need a clearer understanding of relevant threats. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/threat-intelligence-iso-270012022-control-5-7-explained&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pomona Valley Hospital Medical Center Pays $600K to Settle Meta Pixel Lawsuit: Pomona Valley Hospital Medical Center in California has agreed to pay $600,000 to resolve all claims in class action litigation. &lt;a href=&quot;https://www.hipaajournal.com/pomona-valley-hospital-data-breach-settlement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FINRA Fines Firm $10M on Gift Spending: FINRA fined a financial services firm $10 million for providing clients luxury meals and event tickets in exchange for business deals, and for a weak recordkeeping system. &lt;a href=&quot;https://www.radicalcompliance.com/2025/11/05/finra-fines-firm-10m-on-gift-spending/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;December 1, 2025 FCC EEO Deadlines for Stations in AL, GA, CO, MN, MT, ND, SD, CT, ME, MA, NH, RI, and VT: Radio and television stations must prepare an annual EEO Public File Report by December 1, 2025. &lt;a href=&quot;https://www.jdsupra.com/legalnews/december-1-2025-fcc-eeo-deadlines-for-6025546/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Recent DOJ Settlements Highlight Risks for Subcontractors Handling Sensitive Government Information: The DOJ announced an $875,000 settlement with a university over failures to comply with data security obligations in certain contracts. &lt;a href=&quot;https://www.jdsupra.com/legalnews/recent-doj-settlements-highlight-risks-9720959/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Nikkei Suffers Breach Via Slack Compromise: The Japanese media giant said thousands of employee and business partners were impacted by an attack that compromised Slack account data and chat histories. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/nikkei-suffers-breach-slack-compromise&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;No Good Deed: Privilege is at Risk When the Government Directs Your Company’s Internal Investigation: Privilege is at risk when the government directs your company’s internal investigation. &lt;a href=&quot;https://wp.nyu.edu/compliance_enforcement/2025/11/06/no-good-deed-privilege-is-at-risk-when-the-government-directs-your-companys-internal-investigation/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The OIG’s Seven Elements of an Effective Compliance Program: Building an effective compliance program means nurturing a culture of accountability and trust among all staff. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/the-oig-s-seven-elements-of-an-effective-compliance-program&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>ChatGPT</category><category>Cybersecurity</category><category>Data Breach</category><category>FINRA</category><category>HIPAA</category><category>ISO 27001</category><category>Third-Party Risk</category><category>Zero-Day Exploit</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/zero-day-chatgpt-finra-data-breaches-11-06-2025.webp" length="0" type="image/webp"/></item><item><title>Android Malware, Data Breach, EU Surveillance – 11/05/2025</title><link>https://grabtheaxe.com/news/android-malware-data-breach-eu-surveillance-11-05-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/android-malware-data-breach-eu-surveillance-11-05-2025/</guid><description>Android malware impacts millions, California tightens breach notification, and EU officials&apos; surveillance data is for sale. Stay informed on key privacy threats.</description><pubDate>Wed, 05 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/android-malware-data-breach-eu-surveillance-11-05-2025.webp&quot; alt=&quot;Data Breach&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy landscape is marked by critical developments in AI-powered malware, data breach regulations, and surveillance practices. Malicious Android apps are impacting millions, while California tightens data breach notification timelines. Also, the sale of EU officials’ location data raises serious concerns about privacy and security.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Malicious Android apps on Google Play downloaded 42 million times: Hundreds of malicious Android apps were downloaded over 40 million times. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-android-apps-on-google-play-downloaded-42-million-times/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California tightens data breach notification timelines: Covered companies must notify affected California residents within 30 days of a data breach discovery. &lt;a href=&quot;https://www.dataprotectionreport.com/2025/11/california-tightens-data-breach-notification-timelines-imposes-30-day-notice-requirement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phone location data of top EU officials for sale: Journalists found it easy to spy on top EU officials using commercially obtained location histories. &lt;a href=&quot;https://pogowasright.org/phone-location-data-of-top-eu-officials-for-sale-report-finds/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DHS proposes biometrics expansion for immigrants: DHS is looking to increase its collection of biometrics, including from some U.S. citizens. &lt;a href=&quot;https://pogowasright.org/dhs-proposes-biometrics-expansion-for-immigrants-dropping-age-restrictions-and-requiring-biometrics-from-some-us-citizens/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google warns of new AI-powered malware families: Adversaries are using AI to deploy new malware families that integrate LLMs during execution. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-warns-of-new-ai-powered-malware-families-deployed-in-the-wild/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;California Finalizes Updates to Existing CCPA Regulations: Updates to CCPA regulations expand business obligations and cover cybersecurity audits. &lt;a href=&quot;https://www.insideprivacy.com/state-privacy/california-finalizes-updates-to-existing-ccpa-regulations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California tightens data breach notification timelines: Covered companies must notify affected California residents within 30 days of a data breach discovery. &lt;a href=&quot;https://www.dataprotectionreport.com/2025/11/california-tightens-data-breach-notification-timelines-imposes-30-day-notice-requirement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When sharing your info online leads to unwanted telemarketing calls: Learn how companies trick you into sharing info to sell to telemarketers. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?: Amazon agreed to pay $2.5B for enrolling users in Prime without consent, making cancellation hard. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Facebook’s job ads algorithm is sexist: French regulator rules Facebook’s job ad algorithm is discriminatory, skewing ads by gender. &lt;a href=&quot;https://www.theguardian.com/world/2025/nov/05/facebook-job-ads-algorithm-is-sexist-french-equality-watchdog-rules&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US sanctions North Korean bankers linked to cybercrime: The U.S. Treasury Department imposed sanctions on North Korean financial institutions involved in laundering stolen cryptocurrency. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/us-treasury-sanctions-north-korean-bankers-linked-to-cybercrime-it-worker-fraud/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Phone location data of top EU officials for sale: Journalists found it easy to spy on top EU officials using commercially obtained location histories. &lt;a href=&quot;https://pogowasright.org/phone-location-data-of-top-eu-officials-for-sale-report-finds/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DHS proposes biometrics expansion for immigrants: DHS is looking to increase its collection of biometrics, including from some U.S. citizens. &lt;a href=&quot;https://pogowasright.org/dhs-proposes-biometrics-expansion-for-immigrants-dropping-age-restrictions-and-requiring-biometrics-from-some-us-citizens/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Malware</category><category>Android Malware</category><category>Biometrics</category><category>CCPA</category><category>Cybersecurity</category><category>Data Breach</category><category>EU Surveillance</category><category>Privacy Laws</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/android-malware-data-breach-eu-surveillance-11-05-2025.webp" length="0" type="image/webp"/></item><item><title>WordPress Exploit, Ransomware &amp; AI Compliance – 11/05/2025</title><link>https://grabtheaxe.com/news/wordpress-exploit-ransomware-ai-compliance-11-05-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/wordpress-exploit-ransomware-ai-compliance-11-05-2025/</guid><description>Critical WordPress exploit, ransomware surge in Europe, and AI compliance risks. Stay ahead with the latest insights and protect your organization now.</description><pubDate>Wed, 05 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/wordpress-exploit-ransomware-ai-compliance-11-05-2025.webp&quot; alt=&quot;WordPress Vulnerability&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical vulnerabilities, including an active threat targeting 400,000 WordPress sites and a ransomware attack on a New Jersey medical center. We also cover emerging risks in software update tools and the increasing sophistication of ransomware attacks in Europe. Stay informed about key regulatory updates and compliance frameworks to protect your organization.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Critical Site Takeover Flaw Affects 400K WordPress Sites: Attackers are actively exploiting a vulnerability in the Post SMTP plugin, potentially compromising accounts and websites. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/critical-site-takeover-flaw-400k-wordpress-sites&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Jersey Medical Center Suffers Ransomware Attack: Central Jersey Medical Center experienced a ransomware attack, impacting patient data and operations. &lt;a href=&quot;https://www.hipaajournal.com/central-jersey-medical-center-ransomware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Risk ‘Comparable’ to SolarWinds Incident Lurks in Popular Software Update Tool: A widely used software update tool contains a risk that could introduce malware, affecting numerous technology companies. &lt;a href=&quot;https://www.darkreading.com/application-security/risk-solarwinds-popular-software-tool-update&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Europe Sees Increase in Ransomware, Extortion Attacks: European organizations are facing a surge in cyberattacks, with attackers exploiting geopolitical tensions and AI-enhanced social engineering. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/europe-increase-ransomware-extortion&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Federal AI Contracts and the New Era of False Claims Act Enforcement: Increased federal investment in AI contracts is leading to greater scrutiny and enforcement under the False Claims Act. &lt;a href=&quot;https://wp.nyu.edu/compliance_enforcement/2025/11/05/federal-ai-contracts-and-the-new-era-of-false-claims-act-enforcement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;What is SOC2 Audit &amp;amp; Can it Replace a Business Associate Agreement?: An explanation of SOC2 audits and their potential role in fulfilling Business Associate Agreement requirements. &lt;a href=&quot;https://www.totalhipaa.com/what-is-soc2-audit-and-can-it-replace-a-baa/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SOC 2 Compliance Checklist: Why it Doesn’t Exist (And What to Do Instead): Discusses the lack of a definitive SOC 2 checklist and offers alternative approaches to prepare for audits. &lt;a href=&quot;https://linfordco.com/blog/soc-2-compliance-checklist-doesnt-exist/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Michigan Lawmakers Consider Raising MIOSHA Penalties to Match Federal Levels: Legislation is being considered to increase Michigan Occupational Safety and Health Administration (MIOSHA) penalties to align with federal OSHA standards. &lt;a href=&quot;https://www.jdsupra.com/legalnews/michigan-lawmakers-consider-raising-4602689/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Rhode Island’s New Hire Notice Requirements Go Live Jan. 1, Impacting All Employers: Starting January 1, 2026, Rhode Island employers must provide new hires with written notices containing key employment terms. &lt;a href=&quot;https://www.jdsupra.com/legalnews/rhode-island-s-new-hire-notice-7383487/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California Prevailing Wage Compliance: The Three P’s to Know: An overview of California’s prevailing wage requirements for public works projects and how to ensure compliance. &lt;a href=&quot;https://www.jdsupra.com/legalnews/california-prevailing-wage-compliance-4191077/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;December 1, 2025 FCC EEO Deadlines for Stations in AL, GA, CO, MN, MT, ND, SD, CT, ME, MA, NH, RI, and VT: Radio and television stations in specified states must prepare and post an annual EEO Public File Report by December 1, 2025. &lt;a href=&quot;https://www.jdsupra.com/legalnews/december-1-2025-fcc-eeo-deadlines-for-6025546/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Is Supplier–Manufacturer Collaboration Easier with PartnerQuest by CQ?: Explores how PartnerQuest by CQ can streamline collaboration between suppliers and manufacturers. &lt;a href=&quot;https://www.compliancequest.com/blog/easier-supplier-manufacturer-collaboration-with-partnerquest/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>ai compliance</category><category>Exploit</category><category>HIPAA</category><category>ransomware</category><category>Regulatory Compliance</category><category>SOC2</category><category>Vulnerability</category><category>WordPress</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/wordpress-exploit-ransomware-ai-compliance-11-05-2025.webp" length="0" type="image/webp"/></item><item><title>ICS Vulnerabilities, WordPress Exploit &amp; Russian Malware – 11/04/2025</title><link>https://grabtheaxe.com/news/ics-vulnerabilities-wordpress-exploit-russian-malware-11-04-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ics-vulnerabilities-wordpress-exploit-russian-malware-11-04-2025/</guid><description>Critical ICS vulnerabilities (CVSS 10.0) and an actively exploited WordPress flaw lead today&apos;s threats. Get details on new Russian malware tactics and data breaches.</description><pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ics-vulnerabilities-wordpress-exploit-russian-malware-11-04-2025.webp&quot; alt=&quot;ICS Vulnerabilities&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is dominated by critical vulnerabilities in Industrial Control Systems (ICS), with CISA issuing alerts for aviation weather and surveillance systems carrying a CVSS score of 10.0. Concurrently, threat actors are actively exploiting a widespread vulnerability in a popular WordPress plugin to hijack administrator accounts. This summary also covers a novel malware evasion technique used by Russian hackers and the concerning merger of three major cybercrime groups into a unified collective.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Radiometrics VizAir Vulnerabilities: CISA warns of multiple critical vulnerabilities (CVSS 10.0) in aviation weather systems, allowing remote, unauthenticated attackers to manipulate weather data and disrupt airport operations. &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-25-308-04&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Adds Two Known Exploited Vulnerabilities to Catalog: CISA has added vulnerabilities in Gladinet CentreStack/Triofox (CVE-2025-11371) and CWP Control Web Panel (CVE-2025-48703) to its KEV catalog, indicating active exploitation. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/11/04/cisa-adds-two-known-exploited-vulnerabilities-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hackers Exploit WordPress Post SMTP Plugin: Threat actors are actively exploiting a critical vulnerability in the Post SMTP plugin, affecting over 400,000 sites, to hijack administrator accounts and gain full control. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-exploit-wordpress-plugin-post-smtp-to-hijack-admin-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Russian Hackers Abuse Hyper-V to Hide Malware in Linux VMs: The Russian-aligned group ‘Curly COMrades’ is using a novel technique, hiding malware in a hidden Alpine Linux VM on Windows systems to bypass EDR solutions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/russian-hackers-abuse-hyper-v-to-hide-malware-in-linux-vms/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Survision LPR Camera Lacks Authentication: A critical vulnerability (CVSS 9.3) in Survision’s License Plate Recognition cameras allows attackers full system access without authentication due to password protection being off by default. &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-25-308-02&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A Cybercrime Merger Like No Other: Scattered Spider, LAPSUS$, and ShinyHunters Join Forces: Three notorious cybercrime groups have reportedly merged, forming a powerful collective for coordinated extortion and data theft operations. &lt;a href=&quot;https://thehackernews.com/2025/11/a-cybercrime-merger-like-no-other.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SesameOp Backdoor Uses OpenAI API for Covert C2: A novel backdoor named ‘SesameOp’ has been discovered using OpenAI’s Assistants API for stealthy command-and-control communications, evading traditional detection methods. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/sesameop-backdoor-openai-api-covert-c2&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;U.S. Prosecutors Indict Insiders for BlackCat Ransomware Attacks: Federal prosecutors have indicted three individuals for allegedly using BlackCat ransomware to attack and extort five U.S. companies, including a medical device manufacturer. &lt;a href=&quot;https://thehackernews.com/2025/11/us-prosecutors-indict-cybersecurity.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Malicious Android Apps on Google Play Downloaded 42 Million Times: A Zscaler report reveals that hundreds of malicious Android applications available on the official Google Play Store have been downloaded over 42 million times in the past year. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-android-apps-on-google-play-downloaded-42-million-times/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical React Native CLI Flaw Exposed Developers to Remote Attacks: A now-patched critical vulnerability in a popular React Native npm package could have allowed remote unauthenticated attackers to execute arbitrary OS commands on developer machines. &lt;a href=&quot;https://thehackernews.com/2025/11/critical-react-native-cli-flaw-exposed.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Teams Bugs Let Attackers Impersonate Colleagues: Check Point disclosed four security flaws in Microsoft Teams that could allow attackers to manipulate conversations, impersonate users, and exploit notifications for social engineering. &lt;a href=&quot;https://thehackernews.com/2025/11/microsoft-teams-bugs-let-attackers.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Data Breach at Major Swedish Software Supplier Impacts 1.5 Million: Swedish IT supplier Miljödata suffered a cyberattack that exposed the personal data of 1.5 million people, prompting an investigation by the country’s privacy authority. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/data-breach-at-major-swedish-software-supplier-impacts-15-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phone Location Data of Top EU Officials for Sale: A new report reveals that commercially available location data from data brokers can be easily used to track the movements of high-ranking European Union officials. &lt;a href=&quot;https://techcrunch.com/2025/11/04/phone-location-data-of-top-eu-officials-for-sale-report-finds/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Media Giant Nikkei Reports Data Breach Impacting 17,000 People: Japanese publisher Nikkei disclosed that its Slack platform was compromised, exposing the personal information of more than 17,000 employees and business partners. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/media-giant-nikkei-reports-data-breach-impacting-17-000-people/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Apache OpenOffice Disputes Data Breach Claims by Ransomware Gang: The Apache Software Foundation is disputing claims made by the Akira ransomware gang that they successfully breached the OpenOffice project and stole 23 GB of documents. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/apache-openoffice-disputes-data-breach-claims-by-ransomware-gang/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Polish Loan Platform Hacked; Multiple Businesses Disrupted: A series of cyberattacks in Poland have disrupted a loan platform, a mobile payment system, and other businesses, with officials calling such incidents ‘commonplace’. &lt;a href=&quot;https://therecord.media/poland-hacks-loan-platform-mobile-payments-system-travel-agency&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Removing Defender Application Guard from Office: Microsoft has announced plans to deprecate and eventually remove the Defender Application Guard sandboxing feature from Microsoft Office, with removal set for December 2027. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-removing-defender-application-guard-from-office/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Top 3 Browser Sandbox Threats That Slip Past Modern Security Tools: Attackers are increasingly exploiting browsers’ built-in behaviors to steal credentials and move laterally, bypassing traditional security defenses that lack browser-layer visibility. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/the-top-3-browser-sandbox-threats-that-slip-past-modern-security-tools/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Identity Is Now the Top Source of Cloud Risk: According to ReliaQuest data from Q3, identity-related issues were the root cause of 44% of all cloud security alerts, making it the primary source of risk in cloud environments. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/identity-is-now-the-top-cloud-risk/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Releases Five Industrial Control Systems Advisories: CISA has published five new ICS advisories detailing vulnerabilities in products from Fuji Electric, Survision, Delta Electronics, Radiometrics, and IDIS. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/11/04/cisa-releases-five-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google’s AI ‘Big Sleep’ Finds 5 New Vulnerabilities in Apple’s Safari WebKit: Google’s AI-powered security agent, ‘Big Sleep,’ has discovered five security flaws in Apple’s WebKit browser engine, highlighting the potential of AI in vulnerability research. &lt;a href=&quot;https://thehackernews.com/2025/11/googles-ai-big-sleep-finds-5-new.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CISA</category><category>cloud security</category><category>Critical Vulnerabilities</category><category>Cybercrime</category><category>Data Breach</category><category>ICS security</category><category>Malware</category><category>threat intelligence</category><category>WordPress Security</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ics-vulnerabilities-wordpress-exploit-russian-malware-11-04-2025.webp" length="0" type="image/webp"/></item><item><title>OpenAI Backdoor, Healthcare Breach &amp; Ransomware – 11/04/2025</title><link>https://grabtheaxe.com/news/openai-backdoor-healthcare-breach-ransomware-11-04-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/openai-backdoor-healthcare-breach-ransomware-11-04-2025/</guid><description>Compliance digest: OpenAI backdoor malware, healthcare data breach, and ransomware indictments. Stay informed on critical security &amp; regulatory updates.</description><pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/openai-backdoor-healthcare-breach-ransomware-11-04-2025.webp&quot; alt=&quot;OpenAI Backdoor&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s compliance intelligence digest highlights critical security and regulatory updates. Key alerts include a new malware campaign leveraging the OpenAI API, a significant healthcare data breach affecting over 92,000 patients, and indictments related to BlackCat ransomware attacks. Also covered are regulatory updates from the FCA and new compliance requirements in Rhode Island.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SesameOp Backdoor Uses OpenAI API for Covert C2: New malware campaign uses OpenAI API for command and control, demonstrating misuse of generative AI services. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/sesameop-backdoor-openai-api-covert-c2&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Oglethorpe Hacking Incident Affects More Than 92,000 Patients: A Tampa, FL-based mental health network disclosed a security incident affecting over 92,000 patients. &lt;a href=&quot;https://www.hipaajournal.com/oglethorpe-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;U.S. Nationals Indicted for BlackCat Ransomware Attacks on Healthcare Organizations: Two U.S. nationals have been indicted for using BlackCat ransomware to target healthcare organizations. &lt;a href=&quot;https://www.hipaajournal.com/u-s-nationals-indicted-blackcat-ransomware-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Android Malware Mutes Alerts, Drains Crypto Wallets: New Android malware, BankBot-YNRK, targets Indonesian users by masquerading as legitimate applications to steal cryptocurrency. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/android-malware-mutes-alerts-drains-crypto-wallets&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Training failures leave UK firms exposed under new data law: VinciWorks survey reveals that fewer than 2% of organizations are fully ready for the Data Use and Access Act, with staff training emerging as the single biggest compliance gap. &lt;a href=&quot;https://vinciworks.com/blog/training-failures-leave-uk-firms-exposed-under-new-data-law/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How DORA fits with ISO 27001, NIS2 and the GDPR: Article discusses how DORA builds on existing frameworks like ISO 27001, NIS2, and GDPR for ICT risk governance in the EU financial sector. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/how-dora-fits-with-iso-27001-nis2-and-the-gdpr&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AML in practice: What the Law Society’s SARs review means for Scottish legal firms: The Law Society of Scotland’s SARs Thematic Review examines AML reporting obligations for Scottish legal practices. &lt;a href=&quot;https://vinciworks.com/blog/aml-in-practice-what-the-law-societys-sars-review-means-for-scottish-legal-firms/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FCA Updates Treasury Select Committee on Non-Financial Misconduct: Now is The Time to Take Action: The FCA updates its approach to non-financial misconduct, emphasizing it as a regulatory issue. &lt;a href=&quot;https://www.jdsupra.com/legalnews/fca-updates-treasury-select-committee-3890504/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Rhode Island’s New Hire Notice Requirements Go Live Jan. 1, Impacting All Employers: Effective Jan. 1, 2026, Rhode Island employers must provide new hires with written notice of employment terms. &lt;a href=&quot;https://www.jdsupra.com/legalnews/rhode-island-s-new-hire-notice-7383487/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On the Road Again: Hackers Hijack Physical Cargo Freight: Attackers are using remote monitoring tools to steal physical cargo in the trucking and freight supply chain. &lt;a href=&quot;https://www.darkreading.com/identity-access-management-security/hackers-weaponize-remote-tools-hijack-cargo-freight&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AdvaMed modernizes its code of ethics for the digital era: AdvaMed updates its Code of Ethics on Interactions with US Health Care Professionals. &lt;a href=&quot;https://www.jdsupra.com/legalnews/advamed-modernizes-its-code-of-ethics-5188566/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Bermuda: New Beneficial Ownership Framework: Bermuda implements a new beneficial ownership framework with the Beneficial Ownership Act 2025. &lt;a href=&quot;https://www.jdsupra.com/legalnews/bermuda-new-beneficial-ownership-7140027/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AML</category><category>Backdoor</category><category>compliance</category><category>Data Breach</category><category>DORA</category><category>FCA</category><category>Healthcare</category><category>Malware</category><category>OpenAI</category><category>ransomware</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/openai-backdoor-healthcare-breach-ransomware-11-04-2025.webp" length="0" type="image/webp"/></item><item><title>Racist Policing, Ring Privacy, App Censorship &amp; Payroll Scams – 11/04/2025</title><link>https://grabtheaxe.com/news/racist-policing-ring-privacy-app-censorship-payroll-scams-11-04-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/racist-policing-ring-privacy-app-censorship-payroll-scams-11-04-2025/</guid><description>Privacy threats today: Racist policing via surveillance, Ring&apos;s privacy risks, app censorship concerns, &amp; payroll scams. Stay secure with our analysis.</description><pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/racist-policing-ring-privacy-app-censorship-payroll-scams-11-04-2025.webp&quot; alt=&quot;Racist Policing&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy and security landscape is marked by significant threats, including racist policing practices enabled by surveillance technology and the concerning privacy implications of Amazon Ring’s facial recognition features. The increasing control over app availability by governments and platforms raises censorship alarms, while cybercriminals are actively targeting payroll systems. Stay informed to protect your data and digital rights.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;License Plate Surveillance Logs Reveal Racist Policing Against Romani People: EFF uncovers racist policing practices using license plate readers, targeting Romani people based on harmful stereotypes. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/license-plate-surveillance-logs-reveal-racist-policing-against-romani-people&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Legal Case Against Ring’s Face Recognition Feature: Amazon Ring’s face recognition tool raises privacy concerns, potentially violating biometric privacy laws with mass surveillance risks. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/legal-case-against-rings-face-recognition-feature&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Application Gatekeeping: An Ever-Expanding Pathway to Internet Censorship: Governments and platforms are increasingly controlling app availability, raising censorship concerns and impacting developer freedom. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/application-gatekeeping-ever-expanding-pathway-internet-censorship&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cybercriminals Targeting Payroll Sites: Microsoft warns of payroll scams using social engineering to steal credentials and divert direct deposits into attacker-controlled accounts. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/cybercriminals-targeting-payroll-sites.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hacker steals over $120 million from Balancer DeFi crypto protocol: Hackers targeted Balancer Protocol’s v2 pools, resulting in losses estimated to be over $128 million. &lt;a href=&quot;https://www.bleepingcomputer.com/news/cryptocurrency/hacker-steals-over-120-million-from-balancer-defi-crypto-protocol/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;CryptoCurrency&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hacker steals over $120 million from Balancer DeFi crypto protocol: Hackers targeted Balancer Protocol’s v2 pools, resulting in losses estimated to be over $128 million. &lt;a href=&quot;https://www.bleepingcomputer.com/news/cryptocurrency/hacker-steals-over-120-million-from-balancer-defi-crypto-protocol/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;HIPAA&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HIPAA Security Rule: Still on Track for Finalization: Despite criticisms, the proposed HIPAA Security Rule overhaul is still progressing, raising concerns and hopes within the healthcare community. &lt;a href=&quot;https://www.alstonprivacy.com/hipaa-security-rule-still-on-track-for-finalization/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Health Information Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HIPAA Security Rule: Still on Track for Finalization: Despite criticisms, the proposed HIPAA Security Rule overhaul is still progressing, raising concerns and hopes within the healthcare community. &lt;a href=&quot;https://www.alstonprivacy.com/hipaa-security-rule-still-on-track-for-finalization/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Health Privacy&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HIPAA Security Rule: Still on Track for Finalization: Despite criticisms, the proposed HIPAA Security Rule overhaul is still progressing, raising concerns and hopes within the healthcare community. &lt;a href=&quot;https://www.alstonprivacy.com/hipaa-security-rule-still-on-track-for-finalization/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Microsoft&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Windows 10 update bug triggers incorrect end-of-support alerts: Microsoft acknowledges that October 2025 updates are causing false end-of-support warnings on active Windows 10 systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/windows-10-update-bug-triggers-incorrect-end-of-support-alerts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: SesameOp malware abuses OpenAI Assistants API in attacks: New backdoor malware, SesameOp, uses OpenAI Assistants API as a covert command-and-control channel, discovered by Microsoft. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-sesameop-malware-abuses-openai-assistants-api-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Patch for WSUS flaw disabled Windows Server hotpatching: An update for a WSUS vulnerability has broken hotpatching on some Windows Server 2025 devices, according to Microsoft. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-patch-for-wsUS-flaw-disabled-windows-server-hotpatching/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HIPAA Security Rule: Still on Track for Finalization: Despite criticisms, the proposed HIPAA Security Rule overhaul is still progressing, raising concerns and hopes within the healthcare community. &lt;a href=&quot;https://www.alstonprivacy.com/hipaa-security-rule-still-on-track-for-finalization/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Russian hackers abuse Hyper-V to hide malware in Linux VMs: Curly COMrades are using Microsoft Hyper-V to hide malware in Linux VMs, bypassing endpoint detection solutions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/russian-hackers-abuse-hyper-v-to-hide-malware-in-linux-vms/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hackers exploit critical auth bypass flaw in JobMonster WordPress theme: A critical vulnerability in the JobMonster WordPress theme allows hackers to hijack administrator accounts under specific conditions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-auth-bypass-flaw-in-jobmonster-wordpress-theme/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fake Solidity VSCode extension on Open VSX backdoors developers: A malicious Solidity VSCode extension, SleepyDuck, uses an Ethereum smart contract to communicate with attackers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fake-solidity-vscode-extension-on-open-vsx-backdoors-developers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: SesameOp malware abuses OpenAI Assistants API in attacks: New backdoor malware, SesameOp, uses OpenAI Assistants API as a covert command-and-control channel, discovered by Microsoft. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-sesameop-malware-abuses-openai-assistants-api-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US cybersecurity experts indicted for BlackCat ransomware attacks: Former cybersecurity employees are indicted for allegedly hacking networks in BlackCat ransomware attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/us-cybersecurity-experts-indicted-for-blackcat-ransomware-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hackers use RMM tools to breach freighters and steal cargo shipments: Threat actors are deploying RMM tools via malicious links to hijack cargo and steal physical goods from freight brokers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-use-rmm-tools-to-breach-freighters-and-steal-cargo-shipments/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Patch for WSUS flaw disabled Windows Server hotpatching: An update for a WSUS vulnerability has broken hotpatching on some Windows Server 2025 devices, according to Microsoft. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-patch-for-wsus-flaw-disabled-windows-server-hotpatching/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OAuth Device Code Phishing: Azure vs. Google Compared: Device code phishing abuses the OAuth device flow, with different attack surfaces on Google and Azure platforms. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/oauth-device-code-phishing-azure-vs-google-compared/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Uncategorized&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Get a credit freeze to stop identity thieves: Freezing your credit is a great way to help protect yourself from identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/get-credit-freeze-stop-identity-thieves&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam: Learn how to identify phony business opportunities, work-at-home scams, and shady employment agencies. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams: Prepare for emergencies and learn how to spot disaster-related scams to protect yourself and older adults. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to help protect foster youth from identity theft: Foster youth are at greater risk of identity theft; learn how to protect them. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone: Scammers impersonate FTC officials to try to get your money; the FTC will never ask you to move your money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?: Amazon will pay $2.5 billion to settle FTC charges of enrolling people in Prime without consent; $1.5B goes to consumers. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls: Learn how sharing your information online can lead to unwanted telemarketing calls and how to reduce them. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams: Protect yourself from scams during Medicare Open Enrollment by learning to spot them. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams: Take key steps to avoid scams when selling your timeshare. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going: The FTC says &lt;a href=&quot;http://Kars-R-Us.com&quot;&gt;Kars-R-Us.com&lt;/a&gt; lied about how donated money would be spent on a breast cancer charity. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Football Manager 26 review –a modern sim for the modern game: A review of Football Manager 26, highlighting its upgraded graphics and data-driven gameplay. &lt;a href=&quot;https://www.theguardian.com/games/2025/nov/04/football-manager-26-review-sports-interactive-sega&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Rise of the ‘porno-trolls’: how one porn platform made millions suing its viewers: Strike 3, a porn platform owner, has clogged US courts with copyright lawsuits against porn watchers. &lt;a href=&quot;https://www.theguardian.com/society/ng-interactive/2025/nov/04/strike-3-porn-copyright-lawsuits&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cybercriminals Targeting Payroll Sites: Microsoft warns of payroll scams using social engineering to steal credentials and divert direct deposits into attacker-controlled accounts. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/cybercriminals-targeting-payroll-sites.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI firm wins high court ruling after photo agency’s copyright claim: Stability AI wins a high court case against Getty Images over the use of copyrighted data for AI models. &lt;a href=&quot;https://www.theguardian.com/media/2025/nov/04/stabilty-ai-high-court-getty-images-copyright&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Elon Musk’s $1tn Tesla pay deal to be rejected by huge Norway wealth fund: Norway’s sovereign wealth fund will vote against Elon Musk’s $1tn pay package at Tesla’s annual shareholder meeting. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/04/elon-musk-tesla-pay-deal-norway-wealth-fund-annual-shareholder-meeting&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;European Commission launches a call for evidence on the impact assessment for the forthcoming EU Quantum Act: The European Commission seeks evidence on the impact assessment for the upcoming EU Quantum Act. &lt;a href=&quot;https://www.insideprivacy.com/uncategorized/european-commission-launches-a-call-for-evidence-on-the-impact-assessment-for-the-forthcoming-eu-quantum-act/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Apple Watch SE 3 review: the bargain smartwatch for iPhone: A review of the Apple Watch SE 3, highlighting its features and affordability for iPhone users. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/04/apple-watch-se-3-review-bargain-smartwatch-iphone-screen-watchos-26&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Legal Case Against Ring’s Face Recognition Feature: Amazon Ring’s face recognition tool raises privacy concerns, potentially violating biometric privacy laws with mass surveillance risks. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/legal-case-against-rings-face-recognition-feature&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pornography depicting strangulation to become criminal offence in the UK: Possessing or publishing porn featuring strangulation will become a criminal offence in the UK. &lt;a href=&quot;https://www.theguardian.com/society/2025/nov/03/pornography-depicting-strangulation-to-become-criminal-offence-in-the-uk&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;License Plate Surveillance Logs Reveal Racist Policing Against Romani People: EFF uncovers racist policing practices using license plate readers, targeting Romani people based on harmful stereotypes. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/license-plate-surveillance-logs-reveal-racist-policing-against-romani-people&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Application Gatekeeping: An Ever-Expanding Pathway to Internet Censorship: Governments and platforms are increasingly controlling app availability, raising censorship concerns and impacting developer freedom. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/application-gatekeeping-ever-expanding-pathway-internet-censorship&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The best meditation apps to quit doomscrolling and find peace instead: A guide to the best meditation apps for reducing stress and improving focus. &lt;a href=&quot;https://www.theguardian.com/thefilter-us/2025/nov/03/best-meditation-apps&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EFF Stands With Tunisian Media Collective Nawaat: EFF supports Nawaat, a Tunisian media collective, after the government suspended its activities, citing concerns over press freedom. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/eff-stands-tunisian-media-collective-nawaat&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;What EFF Needs in a New Executive Director: EFF seeks a visionary and collaborative executive director to lead the organization in its mission. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/11/what-eff-needs-new-executive-director&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI signs $38bn cloud computing deal with Amazon: OpenAI signs a $38 billion deal with Amazon to use AWS infrastructure for its AI products. &lt;a href=&quot;https://www.theguardian.com/technology/2025/nov/03/openai-cloud-computing-deal-amazon-aws-datacentres-nvidia-chips&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;banking&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cybercriminals Targeting Payroll Sites: Microsoft warns of payroll scams using social engineering to steal credentials and divert direct deposits into attacker-controlled accounts. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/cybercriminals-targeting-payroll-sites.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;credentials&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cybercriminals Targeting Payroll Sites: Microsoft warns of payroll scams using social engineering to steal credentials and divert direct deposits into attacker-controlled accounts. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/cybercriminals-targeting-payroll-sites.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;scams&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cybercriminals Targeting Payroll Sites: Microsoft warns of payroll scams using social engineering to steal credentials and divert direct deposits into attacker-controlled accounts. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/cybercriminals-targeting-payroll-sites.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;social engineering&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cybercriminals Targeting Payroll Sites: Microsoft warns of payroll scams using social engineering to steal credentials and divert direct deposits into attacker-controlled accounts. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/cybercriminals-targeting-payroll-sites.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>App Censorship</category><category>Cybercrime</category><category>Data Security</category><category>Facial recognition</category><category>Payroll Scams</category><category>Privacy</category><category>Racist Policing</category><category>Surveillance</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/racist-policing-ring-privacy-app-censorship-payroll-scams-11-04-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breaches, AI Manipulation &amp; User Consent – 11/03/2025</title><link>https://grabtheaxe.com/news/data-breaches-ai-manipulation-user-consent-11-03-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breaches-ai-manipulation-user-consent-11-03-2025/</guid><description>Privacy threats today: University of Pennsylvania data breach, AI manipulation tactics, and user consent guidance. Stay informed and protect your data!</description><pubDate>Mon, 03 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breaches-ai-manipulation-user-consent-11-03-2025.webp&quot; alt=&quot;Data Breaches&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy digest highlights critical data breaches, including a significant incident at the University of Pennsylvania, and supply chain attacks via Open VSX. We also cover the arrest of an alleged Jabber Zeus coder and explore the manipulation of AI summarization tools. Finally, we provide essential guidance on protecting personal data and avoiding scams, emphasizing user consent and data minimization.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Penn hacker claims 1.2 million donor data breach; A hacker claims responsibility for the University of Pennsylvania data breach, exposing 1.2 million donor records. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-hacker-claims-1.2-million-donor-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Open VSX rotates access tokens after supply-chain malware attack; Open VSX rotated access tokens after a leak allowed attackers to publish malicious extensions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/open-vsx-rotates-tokens-used-in-supply-chain-malware-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Alleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody: Yuriy Igorevich Rybtsov, aka MrICQ, a developer for the Jabber Zeus cybercrime group, is now in U.S. custody. &lt;a href=&quot;https://krebsonsecurity.com/2025/11/alleged-jabber-zeus-coder-mricq-in-u-s-custody/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI Summarization Optimization: Meeting attendees may manipulate AI notetakers by using specific language to be captured in summaries. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/11/ai-summarization-optimization.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Windows Task Manager won’t quit after KB5067036 update: A known issue prevents users from quitting Windows 11 Task Manager after installing the October 2025 update. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-task-manager-wont-quit-after-kb5067036-update/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Get a credit freeze to stop identity thieves: Freezing your credit is a great way to protect yourself from identity theft; here’s what to know. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/get-credit-freeze-stop-identity-thieves&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to help protect foster youth from identity theft: Foster youth are at greater risk of identity theft; learn how to help protect them. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone: Scammers pretend to be FTC officials to get your money; the FTC will never ask you to move your money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going: The FTC says &lt;a href=&quot;http://Kars-R-Us.com&quot;&gt;Kars-R-Us.com&lt;/a&gt; lied about how vehicle donations would be spent on a breast cancer charity. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam: Learn how to identify phony business opportunities, work-at-home scams, and shady employment agencies. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams: Have a plan and know how to spot disaster-related scams to protect yourself during emergencies. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams: Scammers become more active during Medicare Open Enrollment; learn how to spot and avoid them. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams: Be cautious when selling your timeshare; learn how to avoid scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?: Amazon agreed to pay $2.5 billion for enrolling people in Prime without consent; $1.5 billion will go back to consumers. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls: Companies trick you into sharing info, then sell it to telemarketers; learn how to cut down on unwanted calls. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Manipulation</category><category>Data Breach</category><category>Identity Theft</category><category>Jabber Zeus</category><category>Privacy</category><category>Scams</category><category>Supply Chain Attack</category><category>User Consent</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breaches-ai-manipulation-user-consent-11-03-2025.webp" length="0" type="image/webp"/></item><item><title>DeFi Heist, Insider Threats &amp; AI Malware – 11/03/2025</title><link>https://grabtheaxe.com/news/defi-heist-insider-threats-ai-malware-11-03-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/defi-heist-insider-threats-ai-malware-11-03-2025/</guid><description>Daily threat report: Over $120M stolen in a DeFi heist, DOJ indicts ransomware negotiators in an insider plot, and new AI-powered malware uses OpenAI for C2.</description><pubDate>Mon, 03 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/defi-heist-insider-threats-ai-malware-11-03-2025.webp&quot; alt=&quot;Insider Threats&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is marked by audacious insider threats, including the indictment of US ransomware negotiators for conducting their own attacks and an executive selling zero-day exploits to Russia. A massive $128 million DeFi heist highlights ongoing risks in the cryptocurrency space. Additionally, a novel malware campaign has been discovered using OpenAI’s API for covert command-and-control, showcasing the evolving abuse of emerging technologies by threat actors.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hacker steals over $120 million from Balancer DeFi crypto protocol: A major DeFi exploit on the Balancer Protocol has resulted in the theft of over $128 million in cryptocurrency, marking a significant financial breach. &lt;a href=&quot;https://www.bleepingcomputer.com/news/cryptocurrency/hacker-steals-over-120-million-from-balancer-defi-crypto-protocol/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How an ex-L3Harris Trenchant boss stole and sold cyber exploits to Russia: A former executive at defense contractor L3Harris Trenchant, Peter Williams, has been exposed for stealing and selling eight zero-day exploits to a Russian broker. &lt;a href=&quot;https://techcrunch.com/2025/11/03/how-an-ex-l3-harris-trenchant-boss-stole-and-sold-cyber-exploits-to-russia/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DOJ accuses US ransomware negotiators of launching their own ransomware attacks: The DOJ has indicted three individuals, including two US ransomware negotiators, for allegedly conducting ALPHV/BlackCat ransomware attacks themselves in an unprecedented insider plot. &lt;a href=&quot;https://techcrunch.com/2025/11/03/doj-accuses-us-ransomware-negotiators-of-launching-their-own-ransomware-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: SesameOp malware abuses OpenAI Assistants API in attacks: Microsoft has identified a new backdoor malware, SesameOp, which cleverly uses the OpenAI Assistants API for its command-and-control communications to evade detection. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-sesameop-malware-abuses-openai-assistants-api-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fake Solidity VSCode extension on Open VSX backdoors developers: A malicious VSCode extension for Solidity developers, named SleepyDuck, has been found on the Open VSX registry, using an Ethereum smart contract for C2 communications. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fake-solidity-vscode-extension-on-open-vsx-backdoors-developers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea: The Kimsuky APT group is using a new backdoor called HttpTroy, disguised as a VPN invoice, in targeted spear-phishing attacks against entities in South Korea. &lt;a href=&quot;https://thehackernews.com/2025/11/new-httptroy-backdoor-poses-as-vpn.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Android Malware Mutes Alerts, Drains Crypto Wallets: A new Android banking trojan, BankBot-YNRK, is targeting users in Indonesia by masquerading as legitimate applications to mute security alerts and steal from crypto wallets. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/android-malware-mutes-alerts-drains-crypto-wallets&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Researchers Uncover BankBot-YNRK and DeliveryRAT Android Trojans Stealing Financial Data: Analysis reveals two Android trojans, BankBot-YNRK and DeliveryRAT, are actively harvesting sensitive financial data from compromised mobile devices. &lt;a href=&quot;https://thehackernews.com/2025/11/researchers-uncover-bankbot-ynrk-and.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Data breach costs lead to 90% drop in operating profit at South Korean telecom giant: SK Telecom’s operating profit plummeted by 90% due to the high costs of compensating customers and recovery efforts after a massive data breach affecting 27 million people. &lt;a href=&quot;https://therecord.media/data-breach-costs-lead-to-profit-decline-south-korea-telecom&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cargo theft gets a boost from hackers using remote monitoring tools: Threat actors are using Remote Monitoring and Management (RMM) tools to infiltrate trucking and logistics companies, enabling them to hijack and steal physical cargo shipments. &lt;a href=&quot;https://therecord.media/cargo-theft-hackers-remote-monitoring-tools&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Japanese retailer Askul confirms data leak after cyberattack claimed by Russia-linked group: Online retailer Askul has confirmed a data breach exposing customer and supplier information following a cyberattack attributed to a Russia-linked threat group. &lt;a href=&quot;https://therecord.media/askul-confirms-data-breach-ransomware-incident&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ground zero: 5 things to do after discovering a cyberattack: An essential guide outlines the first five critical steps an organization should take immediately after discovering a cyberattack to contain the threat and mitigate damage. &lt;a href=&quot;https://www.welivesecurity.com/en/business-security/ground-zero-5-things-discovering-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI Developed Code: 5 Critical Security Checkpoints for Human Oversight: Experts outline five essential security checkpoints where human developers must review AI-generated code to prevent introducing vulnerabilities. &lt;a href=&quot;https://www.darkreading.com/application-security/ai-code-security-checkpoints&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft: Patch for WSUS flaw disabled Windows Server hotpatching: A recent Microsoft out-of-band patch for an actively exploited Windows Server Update Service (WSUS) vulnerability has inadvertently broken the hotpatching feature. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-patch-for-wsus-flaw-disabled-windows-server-hotpatching/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OAuth Device Code Phishing: Azure vs. Google Compared: A technical comparison explores the different attack surfaces and risks for OAuth device code phishing when targeting Microsoft Azure versus Google Cloud environments. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/oauth-device-code-phishing-azure-vs-google-compared/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Lawmakers ask FTC to probe Flock Safety’s cybersecurity practices: US lawmakers are urging the Federal Trade Commission to investigate surveillance tech provider Flock Safety’s security measures, citing concerns over weak account protection. &lt;a href=&quot;https://therecord.media/wyden-letter-ftc-flock-safety-investigate-cybersecurity-practices&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA and NSA Outline Best Practices to Secure Exchange Servers: CISA and the NSA have jointly released a new blueprint with best practices and guidelines to help organizations harden their Microsoft Exchange Servers against attacks. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/cisa-nsa-secure-exchange-servers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A self-rewriting AI from KAUST revives Jürgen Schmidhuber’s vision of a Gödel Machine: Researchers have developed the Huxley-Gödel Machine (HGM), an AI agent capable of evolving by rewriting and improving its own source code. &lt;a href=&quot;https://the-decoder.com/a-self-rewriting-ai-from-kaust-revives-jurgen-schmidhubers-vision-of-a-godel-machine/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>ALPHV</category><category>BlackCat</category><category>Cyber Espionage</category><category>Data Breach</category><category>DeFi</category><category>insider threat</category><category>Malware</category><category>ransomware</category><category>threat intelligence</category><category>Zero-Day Exploit</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/defi-heist-insider-threats-ai-malware-11-03-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breach, AML Reform, &amp; AI Governance – 10/28/2025</title><link>https://grabtheaxe.com/news/data-breach-aml-reform-ai-governance-10-28-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breach-aml-reform-ai-governance-10-28-2025/</guid><description>Key compliance updates: Major data breach, UK AML reform details, and AI governance insights. Stay informed on critical risks &amp; regulatory changes.</description><pubDate>Tue, 28 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breach-aml-reform-ai-governance-10-28-2025.webp&quot; alt=&quot;Data Breach&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights a concerning data breach affecting over 10 million patients, alongside growing threats from North Korean crypto heists and increasing scrutiny of tax advisors. UK’s AML reforms and FCA’s expanded supervisory role are also key developments. Additionally, boards are urged to prioritize cyber security and understand the implications of agentic AI, while UK employers face evolving sexual harassment compliance laws.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;More Than 10 Million Patients Affected by Conduent Business Solutions Data Breach: A data breach at a business associate of several HIPAA-covered entities has resulted in the exposure of over 10 million patient records. &lt;a href=&quot;https://www.hipaajournal.com/conduent-business-solutions-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;North Korea’s BlueNoroff Expands Scope of Crypto Heists: Campaigns targeting fintech and Web3 developers use fake business collaboration and job recruitment lures. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/north-korea-bluenoroff-expands-crypto-heists&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tax advisor crackdowns are coming and the new rules and risks leave no room for error: HMRC is increasing scrutiny and accountability for tax professionals, with prosecutors targeting firms that fail to prevent tax evasion. &lt;a href=&quot;https://vinciworks.com/blog/tax-advisor-crackdowns-are-coming-and-the-new-rules-and-risks-leave-no-room-for-error/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cyber Security Must Be a Board Priority – And It Starts With Cyber Essentials: Senior ministers and national security officials urge boards to strengthen cyber resilience, starting with Cyber Essentials. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/cyber-security-must-be-a-board-priority-and-it-starts-with-cyber-essentials&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Memento Spyware Tied to Chrome Zero-Day Attacks: Researchers uncovered a new spyware product from Memento Labs linked to Chrome zero-day exploits. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/memento-spyware-chrome-zero-day-attacks&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HIPAA Compliance Team: Choosing the Right Compliance Professionals for Your Organization: Guidance on selecting the appropriate compliance professionals for your organization to ensure HIPAA compliance. &lt;a href=&quot;https://www.totalhipaa.com/hipaa-compliance-team/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;UK AML Reform in 2025: A Public Recalibration of Risk and Responsibility: Major developments including the national risk assessment and draft regulatory amendments mark a strategic shift in UK AML efforts. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/uk-aml-reform-2025-recalibration-risk-responsibility/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FCA to Become UK’s Sole AML/CTF Supervisor for Professional Services Firms: The Financial Conduct Authority (FCA) will assume sole responsibility for supervising AML/CTF for legal, accountancy, and trust service providers in the UK. &lt;a href=&quot;https://www.jdsupra.com/legalnews/fca-to-become-uk-s-sole-aml-ctf-5365136/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Asia-Pacific compliance outlook: Are you ready for 2026 regulations?: Overview of major compliance reforms coming online in Asia-Pacific in 2026, covering AML, data protection, AI governance, and more. &lt;a href=&quot;https://vinciworks.com/blog/the-asia-pacific-compliance-outlook-are-you-ready-for-2026-regulations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;What Boards Need to Know (and Ask) About Agentic AI: Strategic questions for board directors and senior leadership to understand the implications of agentic AI. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/what-boards-need-know-agentic-ai/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sexual harassment compliance in the UK: Your essential FAQ for the Worker Protection Act and Employment Rights Act: Essential information on the evolving sexual harassment laws in the UK, including the Worker Protection Act and Employment Rights Act. &lt;a href=&quot;https://vinciworks.com/blog/sexual-harassment-compliance-in-the-uk-your-essential-faq-for-the-worker-protection-act-and-employment-rights-act/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>ai governance</category><category>AML</category><category>Crypto Heist</category><category>Cybersecurity</category><category>Data Breach</category><category>HIPAA</category><category>Tax Evasion</category><category>UK Regulation</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breach-aml-reform-ai-governance-10-28-2025.webp" length="0" type="image/webp"/></item><item><title>Social Engineering, Malware, 2FA &amp; AI Strategy – 10/28/2025</title><link>https://grabtheaxe.com/news/social-engineering-malware-2fa-ai-strategy-10-28-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/social-engineering-malware-2fa-ai-strategy-10-28-2025/</guid><description>Stay ahead of privacy threats: Social engineering credit card scams, Android malware, 2FA re-enrollment on X, and the EU&apos;s new AI strategy. Read the details!</description><pubDate>Tue, 28 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/social-engineering-malware-2fa-ai-strategy-10-28-2025.webp&quot; alt=&quot;Social Engineering&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy digest highlights critical threats including social engineering attacks via credit card scams originating from China, and the need for X users to re-enroll 2FA keys. Also covered are the EU’s AI strategy, Android malware mimicking human typing, and the exploitation of Chrome zero-day vulnerabilities by Italian spyware vendors. Stay informed to protect your data and systems.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Social Engineering Credit Card Details: Criminal gangs in China are scamming people out of credit card information via texts, amassing over $1 billion. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/social-engineering-peoples-credit-card-details.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;X: Re-enroll 2FA Security Keys: Users must re-enroll their security keys/passkeys for 2FA by Nov 10 or be locked out. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/x-re-enroll-2fa-security-keys-by-november-10-or-get-locked-out/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Herodotus Android Malware: This malware family mimics human typing to evade detection by security software. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-herodotus-android-malware-fakes-human-typing-to-avoid-detection/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;BiDi Swap URL Phishing: Attackers are using bidirectional text to make fake URLs look real, exploiting a browser flaw. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/bidi-swap-the-bidirectional-text-trick-that-makes-fake-urls-look-real/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Italian Spyware Chrome Zero-Day: An Italian spyware vendor is linked to Chrome zero-day attacks via Operation ForumTroll. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/italian-spyware-vendor-linked-to-chrome-zero-day-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;European Commission AI Strategy: The EU aims to accelerate AI adoption across sectors with a comprehensive policy framework. &lt;a href=&quot;https://www.insideprivacy.com/artificial-intelligence/european-commission-p%0Ablishes-apply-ai-strategy-to-accelerate-sectoral-ai-adoption-across-the-eu/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US Law &amp;amp; Medical Debt Reporting: Federal law overrides state bans on medical debt reporting, according to the CFPB. &lt;a href=&quot;https://pogowasright.org/us-law-overrides-state-bans-on-medical-debt-reporting-cfpb-says/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UN Cyber Crime Treaty: Despite privacy concerns, a UN cyber crime treaty wins support from 72 nations. &lt;a href=&quot;https://pogowasright.org/despite-privacy-concerns-un-cyber-crime-treaty-wins-support-from-72-nations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>2FA</category><category>AI Strategy</category><category>Chrome Zero-Day</category><category>Credit Card Fraud</category><category>Cybercrime</category><category>Malware</category><category>Privacy Laws</category><category>social engineering</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/social-engineering-malware-2fa-ai-strategy-10-28-2025.webp" length="0" type="image/webp"/></item><item><title>TEE.Fail Attack, Qilin Ransomware, CISA Alerts &amp; BlueNoroff – 10/28/2025</title><link>https://grabtheaxe.com/news/tee-fail-attack-qilin-ransomware-cisa-alerts-bluenoroff-10-28-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/tee-fail-attack-qilin-ransomware-cisa-alerts-bluenoroff-10-28-2025/</guid><description>Critical TEE.Fail attack extracts secrets from Intel, AMD, and NVIDIA CPUs. CISA adds exploited Dassault flaws to KEV catalog. Read today&apos;s top security threats.</description><pubDate>Tue, 28 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/tee-fail-attack-qilin-ransomware-cisa-alerts-bluenoroff-10-28-2025.webp&quot; alt=&quot;TEE.Fail Attack&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is highlighted by the disclosure of TEE.Fail, a severe side-channel attack capable of compromising secure enclaves in modern CPUs from Intel, AMD, and NVIDIA. CISA has also issued an urgent warning, adding two actively exploited Dassault Systèmes vulnerabilities to its KEV catalog. Meanwhile, threat actors continue to innovate, with the Qilin ransomware gang now using WSL for evasive attacks and the BlueNoroff APT deploying new multi-platform malware.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Adds Two Actively Exploited Dassault Vulnerabilities to KEV Catalog: CISA warns that two vulnerabilities in Dassault Systèmes’ DELMIA Apriso (CVE-2025-6204 &amp;amp; CVE-2025-6205) are being actively exploited, requiring immediate patching by federal agencies. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-warns-of-two-more-actively-exploited-dassault-vulnerabilities/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;TEE.Fail Attack Breaks Confidential Computing on Intel, AMD, NVIDIA CPUs: Researchers have developed a new side-channel attack named TEE.Fail, capable of extracting secrets from the Trusted Execution Environment (TEE) in modern CPUs from major vendors. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/teefail-attack-breaks-confidential-computing-on-intel-amd-nvidia-cpus/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Qilin Ransomware Abuses WSL to Run Linux Encryptors in Windows: The Qilin ransomware group is leveraging the Windows Subsystem for Linux (WSL) to execute its Linux-based encryptors on Windows systems, a novel technique designed to evade detection. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/qilin-ransomware-abuses-wsl-to-run-linux-encryptors-in-windows/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;BlueNoroff APT Unveils New Malware Campaigns Targeting macOS and Windows: The North Korean APT group BlueNoroff is behind the ‘GhostCall’ and ‘GhostHire’ campaigns, using sophisticated, multi-stage malware to target cryptocurrency and Web3 sectors. &lt;a href=&quot;https://securelist.com/bluenoroff-apt-campaigns-ghostcall-and-ghosthire/117842/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New ‘Herodotus’ Android Malware Mimics Human Typing to Evade Detection: A new Android banking trojan, Herodotus, uses randomized delays to mimic human input, allowing it to bypass behavioral biometric security and perform device takeover attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-herodotus-android-malware-fakes-human-typing-to-avoid-detection/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Researchers Warn of Prolific Qilin Ransomware Gang: The Qilin ransomware group has intensified its attacks, adding over 185 victims to its leak site in October alone and targeting major organizations across various sectors. &lt;a href=&quot;https://therecord.media/qilin-ransomware-gang-hits-hundreds-of-orgs-2025&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;‘BiDi Swap’ Phishing Trick Makes Fake URLs Look Authentic: Attackers are reviving a decade-old browser flaw using bidirectional text to create deceptive URLs for phishing campaigns, making it difficult for users to spot malicious links. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/bidi-swap-the-bidirectional-text-trick-that-makes-fake-urls-look-real/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Atroposia MaaS Platform Includes Local Vulnerability Scanner: A new Malware-as-a-Service (MaaS) named Atroposia offers a remote access trojan (RAT) equipped with data theft capabilities and a built-in local vulnerability scanner to find additional exploits. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-atroposia-malware-comes-with-a-local-vulnerability-scanner/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Advertising Giant Dentsu Reports Data Breach at Subsidiary Merkle: Dentsu has disclosed a cybersecurity incident at its US subsidiary Merkle, which resulted in the exposure of both employee and client data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/advertising-giant-dentsu-reports-data-breach-at-subsidiary-merkle/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Keys to the Kingdom: A Defender’s Guide to Privileged Account Monitoring: A comprehensive guide from Google Cloud’s threat intelligence team details strategies for preventing, detecting, and responding to intrusions that target privileged accounts. &lt;a href=&quot;https://cloud.google.com/blog/topics/threat-intelligence/privileged-account-monitoring/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Windows 11 Update Rolls Out New ‘Administrator Protection’ Feature: Microsoft’s latest preview update for Windows 11 (KB5067036) introduces Administrator Protection, a new feature designed to enhance system security against unauthorized changes. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5067036-update-rolls-out-administrator-protection-feature/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google Chrome to Warn Users Before Opening Insecure HTTP Sites: Starting in October 2026 with version 154, Google Chrome will require user permission before connecting to insecure HTTP websites, aiming to further push the web towards HTTPS. &lt;a href=&quot;https://www.bleepingcomputer.com/news/google/google-chrome-to-warn-users-before-opening-insecure-http-sites/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CyDeploy Offers ‘Digital Twin’ System for Secure Update Testing: Startup CyDeploy is developing a platform that uses machine learning to create a replica of a company’s system, allowing for safe testing of patches and updates before deployment. &lt;a href=&quot;https://techcrunch.com/2025/10/28/cydeploy-wants-to-create-a-replica-of-a-companys-system-to-help-it-test-updates-before-pushing-them-out-catch-it-at-disrupt-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Releases Three Industrial Control Systems (ICS) Advisories: CISA has published advisories for vulnerabilities in Schneider Electric EcoStruxure and Vertikal Systems Hospital Manager, urging critical infrastructure operators to apply mitigations. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/10/28/cisa-releases-three-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Sued in Australia Over Deceptive Copilot Subscriptions: The ACCC is suing Microsoft for allegedly misleading 2.7 million Australians into paying for Copilot AI subscriptions within the Microsoft 365 service. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-sued-for-allegedly-tricking-millions-into-copilot-m365-subscriptions/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI Restructures, Microsoft Increases Stake to 27 Percent: OpenAI has completed a major corporate restructuring under a new foundation, with Microsoft solidifying its partnership by taking a nearly one-third stake in the AI company. &lt;a href=&quot;https://the-decoder.com/openai-restructures-under-new-foundation-microsoft-takes-27-percent-stake/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>BlueNoroff APT</category><category>CISA</category><category>Cybersecurity</category><category>KEV Catalog</category><category>Qilin Ransomware</category><category>Side-Channel Attack</category><category>TEE.Fail</category><category>threat intelligence</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/tee-fail-attack-qilin-ransomware-cisa-alerts-bluenoroff-10-28-2025.webp" length="0" type="image/webp"/></item><item><title>Ransomware, Data Breach, &amp; FATF Updates – 10/27/2025</title><link>https://grabtheaxe.com/news/ransomware-data-breach-fatf-updates-10-27-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ransomware-data-breach-fatf-updates-10-27-2025/</guid><description>Stay ahead of compliance threats: Linux ransomware targets Windows, HIPAA breach settlement, and FATF AML updates. Expert analysis for October 27, 2025.</description><pubDate>Mon, 27 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ransomware-data-breach-fatf-updates-10-27-2025.webp&quot; alt=&quot;Ransomware Attack&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates in regulatory enforcement, data security, and policy governance. Key alerts include a Linux-based ransomware targeting Windows hosts, a significant HIPAA data breach settlement, and multiple healthcare data breaches. Stay informed on FATF’s updated AML guidance and strategies for effective compliance incentives.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Qilin Targets Windows Hosts With Linux-Based Ransomware: Attack demonstrates evasion strategy that can stump defenses not equipped to detect cross-platform threats. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/qilin-targets-windows-hosts-linux-based-ransomware&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Yale New Haven Health Agrees to $18 Million Data Breach Settlement: An $18 million settlement proposed to resolve claims stemming from a 2025 data breach. &lt;a href=&quot;https://www.hipaajournal.com/yale-new-haven-health-system-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Data Breaches Announced by ModMed, LifeBridge Health &amp;amp; Right at Home: Data breaches announced by EHR provider Modernizing Medicine (ModMed), Baltimore healthcare provider LifeBridge Health, and Right at Home. &lt;a href=&quot;https://www.hipaajournal.com/data-breache-modmed-lifebridge-health-right-at-home/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FATF October 2025 plenary: Newly updated guide to every high risk jurisdiction for money laundering: Four countries exited the FATF Grey List reflecting strengthened AML/CFT controls. &lt;a href=&quot;https://vinciworks.com/blog/fatf-october-2025-plenary-newly-updated-guide-to-every-high-risk-jurisdiction-for-money-laundering/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FATF October 2025 plenary: Newly updated guide to every high risk jurisdiction for money laundering: Four countries exited the FATF Grey List reflecting strengthened AML/CFT controls. &lt;a href=&quot;https://vinciworks.com/blog/fatf-october-2025-plenary-newly-updated-guide-to-every-high-risk-jurisdiction-for-money-laundering/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Do the Enforcement Choices Match the “America First” Antitrust Rhetoric?: Analysis suggests antitrust laws have been underenforced for decades. &lt;a href=&quot;https://wp.nyu.edu/compliance_enforcement/2025/10/27/do-the-enforcement-choices-match-the-america-first-antitrust-rhetoric/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Yale New Haven Health Agrees to $18 Million Data Breach Settlement: An $18 million settlement proposed to resolve claims stemming from a 2025 data breach. &lt;a href=&quot;https://www.hipaajournal.com/yale-new-haven-health-system-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Data Breaches Announced by ModMed, LifeBridge Health &amp;amp; Right at Home: Data breaches announced by EHR provider Modernizing Medicine (ModMed), Baltimore healthcare provider LifeBridge Health, and Right at Home. &lt;a href=&quot;https://www.hipaajournal.com/data-breache-modmed-lifebridge-health-right-at-home/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Holiday Housekeeping: 4 Employee Handbook Policies to Make Sure You’ve Got Right Before 2026: Employee handbook is key for setting workplace expectations and staying compliant. &lt;a href=&quot;https://trustmineral.com/managing-employees/holiday-handbook-policies-2026/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Getting Started on Compliance Incentives: Structuring and using incentives in an ethics and compliance program can be tricky but beneficial. &lt;a href=&quot;https://www.radicalcompliance.com/2025/10/27/getting-started-on-compliance-incentives/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AML</category><category>compliance</category><category>Cybersecurity</category><category>Data Breach</category><category>FATF</category><category>HIPAA</category><category>ransomware</category><category>Regulatory Enforcement</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ransomware-data-breach-fatf-updates-10-27-2025.webp" length="0" type="image/webp"/></item><item><title>Spyware, AI Strategy, Data Privacy – 10/27/2025</title><link>https://grabtheaxe.com/news/spyware-ai-strategy-data-privacy-10-27-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/spyware-ai-strategy-data-privacy-10-27-2025/</guid><description>Stay informed: Spyware attacks, EU AI strategy &amp; data privacy tips. Get the latest on critical privacy threats and regulations in our daily summary.</description><pubDate>Mon, 27 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/spyware-ai-strategy-data-privacy-10-27-2025.webp&quot; alt=&quot;Spyware Attacks&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy digest highlights critical alerts, including a Chrome zero-day linked to an Italian spyware vendor and CISA’s order to patch a Windows Server flaw. Also covered are NYDFS guidance on third-party service provider risks, EFF’s stance against the UN Cybercrime Convention, and a deep dive into First Wap’s global surveillance operations. Stay informed on the latest threats and regulatory actions.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Italian spyware vendor linked to Chrome zero-day attacks: Malware linked to Memento Labs exploited a Chrome zero-day. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/italian-spyware-vendor-linked-to-chrome-zero-day-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA orders feds to patch Windows Server WSUS flaw used in attacks: CISA mandates patching a critical Windows Server vulnerability exploited in attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-windows-server-wsus-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NYDFS Issues Guidance on Managing Risks Related to Third-Party Service Providers: NYDFS outlines guidance on managing risks from third-party service providers. &lt;a href=&quot;https://www.alstonprivacy.com/nydfs-issues-guidance-on-managing-risks-related-to-third-party-service-providers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Joint Statement on the UN Cybercrime Convention: EFF and Global Partners Urge Governments Not to Sign: EFF urges governments not to sign the UN Cybercrime Convention due to human rights concerns. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-windows-server-wsus-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;First Wap: A Surveillance Computer You’ve Never Heard Of: Surveillance firm First Wap’s phone-tracking empire extends globally. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/first-wap-a-surveillance-computer-you-ve-never-heard-of.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EU Member States Begin Rolling Out New Product Liability Rules: EU states update product liability laws to align with the new Product Liability Directive. &lt;a href=&quot;https://www.insideprivacy.com/european-union-2/eu-member-states-begin-rolling-out-new-product-liability-rules/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;European Commission Publishes Apply AI Strategy to Accelerate Sectoral AI Adoption Across the EU: The EU Commission releases its AI Strategy to boost AI adoption across sectors. &lt;a href=&quot;https://www.insideprivacy.com/artificial-intelligence/european-commission-publishes-apply-ai-strategy-to-accelerate-sectoral-ai-adoption-across-the-eu/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Opt Out October: Daily Tips to Protect Your Privacy and Security: EFF shares daily tips on opting out of tech giants’ surveillance. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Strategy</category><category>Cybercrime Convention</category><category>Data Privacy</category><category>Product Liability</category><category>spyware</category><category>Surveillance</category><category>Third-Party Risk</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/spyware-ai-strategy-data-privacy-10-27-2025.webp" length="0" type="image/webp"/></item><item><title>WSUS Flaw, Qilin Ransomware &amp; Italian Spyware – 10/27/2025</title><link>https://grabtheaxe.com/news/wsus-flaw-qilin-ransomware-italian-spyware-10-27-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/wsus-flaw-qilin-ransomware-italian-spyware-10-27-2025/</guid><description>CISA orders immediate patching for a critical WSUS vulnerability under active exploit. Get the latest intelligence on Qilin ransomware TTPs and new spyware.</description><pubDate>Mon, 27 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/wsus-flaw-qilin-ransomware-italian-spyware-10-27-2025.webp&quot; alt=&quot;WSUS Vulnerability&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s top threat is a critical Windows Server Update Services (WSUS) vulnerability under active exploit, prompting an emergency directive from CISA for federal agencies to patch immediately. We are also tracking a detailed analysis of the sophisticated Qilin ransomware group’s attack methods and the discovery of a new Italian spyware linked to a Google Chrome zero-day. These events highlight the urgent need for robust patch management and heightened awareness of evolving espionage and extortion tactics.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA orders feds to patch Windows Server WSUS flaw used in attacks; CISA has added a critical WSUS vulnerability to its KEV catalog, mandating federal agencies to patch immediately due to active exploitation. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-windows-server-wsus-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Italian spyware vendor linked to Chrome zero-day attacks — A Google Chrome zero-day vulnerability exploited earlier this year has been linked to malware from Italian spyware vendor Memento Labs, the successor to Hacking Team. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/italian-spyware-vendor-linked-to-chrome-zero-day-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Uncovering Qilin attack methods exposed through multiple cases — Cisco Talos details the TTPs of the Qilin ransomware group, noting its focus on the manufacturing sector and use of legitimate tools for evasion and persistence. &lt;a href=&quot;https://blog.talosintelligence.com/uncovering-qilin-attack-methods-exposed-through-multiple-cases/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;QNAP warns of critical &lt;a href=&quot;http://ASP.NET&quot;&gt;ASP.NET&lt;/a&gt; flaw in its Windows backup software — QNAP urges customers to patch a critical &lt;a href=&quot;http://ASP.NET&quot;&gt;ASP.NET&lt;/a&gt; Core vulnerability impacting its NetBak PC Agent, a utility for backing up Windows data to NAS devices. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/qnap-warns-its-windows-backup-software-is-also-affected-by-critical-aspnet-flaw/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands — A vulnerability in OpenAI’s ChatGPT Atlas browser allows attackers to inject malicious instructions via specially crafted URLs, potentially leading to code execution. &lt;a href=&quot;https://thehackernews.com/2025/10/new-chatgpt-atlas-browser-exploit-lets.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence (APT, malware, ransomware)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Mem3nt0 mori – The Hacking Team is back!: Kaspersky researchers link new ‘Dante’ spyware from Memento Labs (formerly Hacking Team) to the ForumTroll APT attacks, which exploited a Chrome zero-day. &lt;a href=&quot;https://securelist.com/forumtroll-apt-hacking-team-dante-spyware/117851/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Italian-made spyware spotted in breaches of Russian, Belarusian systems — The Dante spyware from Memento Labs was reportedly used in cyber-espionage operations targeting entities in Russia and Belarus. &lt;a href=&quot;https://therecord.media/memento-labs-formerly-hacking-team-dante-spyware-russia-kaspersky&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ransomware profits drop as victims stop paying hackers — Ransomware payment rates have fallen to a new low of 23%, indicating a shift in how organizations respond to extortion demands. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/ransomware-profits-drop-as-victims-stop-paying-hackers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Sweden’s power grid operator confirms data breach claimed by ransomware gang — Sweden’s power grid operator is investigating a data breach after a ransomware group threatened to leak hundreds of gigabytes of stolen data. &lt;a href=&quot;https://therecord.media/sweden-power-grid-operator-data&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google disputes false claims of massive Gmail data breach — Google has refuted widespread reports of a massive data breach, stating that claims of 183 million exposed accounts are false. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-disputes-false-claims-of-massive-gmail-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;X: Re-enroll 2FA security keys by November 10 or get locked out: X (formerly Twitter) is requiring users with security keys or passkeys for 2FA to re-enroll them by November 10 to avoid account lockout. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/x-re-enroll-2fa-security-keys-by-november-10-or-get-locked-out/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The State of Exposure Management in 2025: Insights From 3,000+ Organizations — A new report highlights how organizations are adapting to an expanding attack surface and AI-weaponized vulnerabilities by improving exposure management. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/the-state-of-exposure-management-in-2025-insights-from-3-000-plus-organizations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: New policy removes pre-installed Microsoft Store apps — A new Microsoft policy allows IT administrators to remove pre-installed Microsoft Store applications, providing greater control over system configurations. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-now-lets-admins-remove-pre-installed-microsoft-store-apps-via-policy/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks (NIST, MITRE ATT&amp;amp;CK, CIS)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;US declines to join more than 70 countries in signing UN cybercrime treaty — The United States has opted not to sign the UN Convention against Cybercrime, a global treaty aimed at creating a unified mechanism to combat digital crime. &lt;a href=&quot;https://therecord.media/us-declines-signing-cybercrime-treaty&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies (AI, XDR, CNAPP)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI fuels a new wave of fake receipts, according to SAP Concur — SAP Concur warns that generative AI is driving a significant increase in expense fraud through the creation of highly convincing fake receipts. &lt;a href=&quot;https://the-decoder.com/ai-fuels-a-new-wave-of-fake-receipts-according-to-sap-concur/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Reuters: Deepseek emerges as key AI partner in China’s military research — A report indicates that China’s military is utilizing domestic AI models from companies like Deepseek and Alibaba for developing autonomous weapons systems. &lt;a href=&quot;https://the-decoder.com/reuters-deepseek-emerges-as-key-ai-partner-in-chinas-military-research/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;What brain privacy will look like in the age of neurotech — Experts discuss the future of brain data privacy, including the potential for commodification and the role of AI in decoding internal speech. &lt;a href=&quot;https://therecord.media/what-brain-privacy-will-look-like&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CISA</category><category>Cybersecurity</category><category>Data Breach</category><category>Patch Management</category><category>Qilin Ransomware</category><category>spyware</category><category>threat intelligence</category><category>WSUS Vulnerability</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/wsus-flaw-qilin-ransomware-italian-spyware-10-27-2025.webp" length="0" type="image/webp"/></item><item><title>CoPhish, Hospital Breach &amp; FTC Scams – 10/26/2025</title><link>https://grabtheaxe.com/news/cophish-hospital-breach-ftc-scams-10-26-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cophish-hospital-breach-ftc-scams-10-26-2025/</guid><description>Privacy alert: New CoPhish attack, hospital breach exposes patients. Plus, FTC warns of Amazon scams and identity theft risks. Stay protected!</description><pubDate>Sun, 26 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cophish-hospital-breach-ftc-scams-10-26-2025.webp&quot; alt=&quot;CoPhish Attack&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights several critical threats, including a novel ‘CoPhish’ attack exploiting Microsoft Copilot, a disturbing hospital breach involving patient photos, and a range of identity theft scams targeting vulnerable populations. We also cover new privacy regulations in New Zealand and FTC warnings about Amazon Prime subscriptions and charity scams. Stay informed to protect your data and avoid becoming a victim.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New CoPhish attack steals OAuth tokens via Copilot Studio agents: A phishing technique uses Microsoft Copilot Studio agents to deliver fraudulent OAuth consent requests. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-cophish-attack-steals-oauth-tokens-via-copilot-studio-agents/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jay Hospital employees fired over ‘horrible’ pictures of sleeping, medicated patients: Hospital staff took and posted pictures of sleeping patients on social media, leading to their termination. &lt;a href=&quot;https://pogowasright.org/jay-hospital-employees-fired-over-horrible-pictures-of-sleeping-medicated-patients/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Get a credit freeze to stop identity thieves: Freezing your credit is a great way to help protect yourself from identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/get-credit-freeze-stop-identity-thieves&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to help protect foster youth from identity theft: Foster youth are at greater risk of identity theft because they often move more often and more people have access to their info. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams: Scammers get more active around Medicare Open Enrollment Period, trying to get your money, information, or both. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New Zealand passed The Privacy Amendment Act in September. Learn about the IPP3A: New Zealand’s government passed The Privacy Amendment Act, adding Information Privacy Principle (IPP) 3A, effective May 1, 2026. &lt;a href=&quot;https://pogowasright.org/new-zealand-passed-the-privacy-amendment-act-in-september-learn-about-the-ipp3a/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?: Amazon agreed to pay $2.5 billion for enrolling people in Prime subscriptions without consent and making cancellation difficult. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Labor rules out giving tech giants free rein to mine copyright content to train AI: The Albanese government has ruled out granting copyright exemption for AI models training. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/27/labor-rules-out-giving-tech-giants-free-rein-to-mine-copyright-content-to-train-ai&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Scams &amp;amp; Identity Theft&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How to spot a job scam: Learn how to spot phony business opportunities, work-at-home scams, shady employment agencies, and scammy multi-level marketing schemes. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams: Learn how to spot disaster-related scams and find free tools to help you get started on a plan that includes fraud prevention. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone: Scammers pretend to be FTC officials to try to get your money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls: Companies trick you into sharing your information so they can sell it to telemarketers. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams: Learn key steps to avoid scams when selling your timeshare. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going: The FTC says &lt;a href=&quot;http://Kars-R-Us.com&quot;&gt;Kars-R-Us.com&lt;/a&gt;, Inc. lied about how the money would be spent when it collected vehicle donations. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Amazon Prime</category><category>CoPhish</category><category>FTC</category><category>Healthcare Breach</category><category>Identity Theft</category><category>New Zealand</category><category>Phishing</category><category>Privacy Laws</category><category>Scams</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/cophish-hospital-breach-ftc-scams-10-26-2025.webp" length="0" type="image/webp"/></item><item><title>CIPA, Biometrics, UN Cybercrime &amp; Privacy Tips – 10/25/2025</title><link>https://grabtheaxe.com/news/cipa-biometrics-un-cybercrime-privacy-tips-10-25-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cipa-biometrics-un-cybercrime-privacy-tips-10-25-2025/</guid><description>Privacy news: CIPA faces criticism, Philippines bans biometric data sales, EFF warns on UN Cybercrime Convention. Plus, tips to boost your privacy today!</description><pubDate>Sat, 25 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cipa-biometrics-un-cybercrime-privacy-tips-10-25-2025.webp&quot; alt=&quot;Biometric Data&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights critical developments in data protection and digital rights. Key articles include a critique of California’s CIPA law, the Philippines’ stance against selling biometric data, and warnings against the UN Cybercrime Convention due to human rights concerns. Also featured are practical tips to enhance personal privacy and a report on AI models developing ‘survival drives’.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;“Untenable.” Federal California District Court Calls for Legislative Action on CIPA: A federal court criticizes California’s Invasion of Privacy Act (CIPA), urging legislative reform due to its broad interpretation. &lt;a href=&quot;https://www.globalprivacywatch.com/2025/10/untenable-federal-california-district-court-calls-for-legislative-action-on-cipa/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Philippines Data Protection Authority: Biometric Data Is Not for Sale: Lessons for U.S. Privacy Law: The Philippines’ NPC directs Worldcoin to cease biometric data processing, asserting biometric information is not a commodity for trade. &lt;a href=&quot;https://pogowasright.org/philippines-data-protection-authority-biometric-data-is-not-for-sale-lessons-for-u-s-privacy-law/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Joint Statement on the UN Cybercrime Convention: EFF and Global Partners Urge Governments Not to Sign: EFF and partners warn against signing the UN Cybercrime Convention due to its lack of human rights safeguards and potential for abuse. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/joint-statement-un-cybercrime-convention-eff-and-global-partners-urge-governments&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Opt Out October: Daily Tips to Protect Your Privacy and Security: EFF provides daily tips for opting out of tech giants’ surveillance, including disabling ad tracking and using privacy-protective browsers. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI models may be developing their own ‘survival drive’, researchers say. AI safety research company has said that AI models may be developing their own “survival drive”. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/25/ai-models-may-be-developing-their-own-survival-drive-researchers-say&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;“Untenable.” Federal California District Court Calls for Legislative Action on CIPA: A federal court criticizes California’s Invasion of Privacy Act (CIPA), urging legislative reform due to its broad interpretation. &lt;a href=&quot;https://www.globalprivacywatch.com/2025/10/untenable-federal-california-district-court-calls-for-legislative-action-on-cipa/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Philippines Data Protection Authority: Biometric Data Is Not for Sale: Lessons for U.S. Privacy Law: The Philippines’ NPC directs Worldcoin to cease biometric data processing, asserting biometric information is not a commodity for trade. &lt;a href=&quot;https://pogowasright.org/philippines-data-protection-authority-biometric-data-is-not-for-sale-lessons-for-u-s-privacy-law/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Opt Out October: Daily Tips to Protect Your Privacy and Security: EFF provides daily tips for opting out of tech giants’ surveillance, including disabling ad tracking and using privacy-protective browsers. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cross-Border Data Transfers&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Joint Statement on the UN Cybercrime Convention: EFF and Global Partners Urge Governments Not to Sign: EFF and partners warn against signing the UN Cybercrime Convention due to its lack of human rights safeguards and potential for abuse. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/joint-statement-un-cybercrime-convention-eff-and-global-partners-urge-governments&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Biometric Data</category><category>CIPA</category><category>Data Minimization</category><category>Data Protection</category><category>EFF</category><category>Privacy</category><category>Surveillance</category><category>UN Cybercrime Convention</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/cipa-biometrics-un-cybercrime-privacy-tips-10-25-2025.webp" length="0" type="image/webp"/></item><item><title>CoPhish Attack, AI Browser Risks &amp; OAuth Threats – 10/25/2025</title><link>https://grabtheaxe.com/news/cophish-attack-ai-browser-risks-oauth-threats-10-25-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cophish-attack-ai-browser-risks-oauth-threats-10-25-2025/</guid><description>Daily security brief on the new &apos;CoPhish&apos; attack stealing OAuth tokens, major security risks in AI browser agents, and growing AI-powered surveillance threats.</description><pubDate>Sat, 25 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cophish-attack-ai-browser-risks-oauth-threats-10-25-2025.webp&quot; alt=&quot;CoPhish Attack&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is highlighted by a novel phishing technique dubbed ‘CoPhish,’ which leverages Microsoft Copilot agents to steal valuable OAuth tokens. This new attack vector underscores the growing security risks at the intersection of AI and user identity. We are also tracking significant vulnerabilities introduced by emerging AI browser agents and the privacy implications of expanding AI-powered government surveillance. This is what you need to know now.&lt;/p&gt;
&lt;h2&gt;Top 2 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New CoPhish attack steals OAuth tokens via Copilot Studio agents: A novel phishing technique weaponizes Microsoft Copilot Studio agents to steal OAuth tokens by delivering fraudulent consent requests through trusted Microsoft domains. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-cophish-attack-steals-oauth-tokens-via-copilot-studio-agents/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The glaring security risks with AI browser agents: New AI-powered browsers from OpenAI and Perplexity, while boosting productivity, introduce significant security vulnerabilities like data leakage and prompt injection attacks. &lt;a href=&quot;https://techcrunch.com/2025/10/25/the-glaring-security-risks-with-ai-browser-agents/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New CoPhish attack steals OAuth tokens via Copilot Studio agents: A novel phishing technique weaponizes Microsoft Copilot Studio agents to steal OAuth tokens by delivering fraudulent consent requests through trusted Microsoft domains. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-cophish-attack-steals-oauth-tokens-via-copilot-studio-agents/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ICE is building a social media panopticon: U.S. Immigration and Customs Enforcement (ICE) is reportedly expanding a massive AI-powered surveillance system to monitor social media and track millions of web users. &lt;a href=&quot;https://www.theverge.com/policy/806425/ice-social-media-surveillance-free-speech-assault&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ChatGPT’s memory could turn personal details into ads OpenAI CEO Altman once called dystopian: Concerns are rising that ChatGPT’s new memory features could be used to harvest personal user details for advertising, a practice previously criticized by OpenAI’s CEO. &lt;a href=&quot;https://the-decoder.com/chatgpts-memory-could-turn-personal-details-into-ads-altman-once-called-dystopian/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;MPs urge government to stop Britain’s phone theft wave through tech: UK Members of Parliament are pushing the government to implement technological solutions to combat the rising wave of phone theft across the country. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/10/25/uk_committee_phone_theft/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The glaring security risks with AI browser agents: New AI-powered browsers from OpenAI and Perplexity, while boosting productivity, introduce significant security vulnerabilities like data leakage and prompt injection attacks. &lt;a href=&quot;https://techcrunch.com/2025/10/25/the-glaring-security-risks-with-ai-browser-agents/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Junk data from X makes large language models lose reasoning skills, researchers show: Research shows that training large language models on low-quality data can permanently degrade their reasoning capabilities, posing a long-term risk to AI integrity. &lt;a href=&quot;https://the-decoder.com/junk-data-from-x-makes-large-language-models-lose-reasoning-skills-researchers-show/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>CoPhish Attack</category><category>Cybersecurity</category><category>Data Privacy</category><category>Microsoft Copilot</category><category>OAuth</category><category>Phishing</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/cophish-attack-ai-browser-risks-oauth-threats-10-25-2025.webp" length="0" type="image/webp"/></item><item><title>Windows Patch, Pay Transparency, AI Act &amp; FCPA – 10/25/2025</title><link>https://grabtheaxe.com/news/windows-patch-pay-transparency-ai-act-fcpa-10-25-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/windows-patch-pay-transparency-ai-act-fcpa-10-25-2025/</guid><description>Critical Windows patch, NJ pay transparency rules, AI Innovation Act impact, &amp; FCPA updates. Stay ahead of compliance challenges. Read more!</description><pubDate>Sat, 25 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/windows-patch-pay-transparency-ai-act-fcpa-10-25-2025.webp&quot; alt=&quot;Windows Patch&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates, including an emergency patch for a Windows Server bug under active attack. We also cover proposed rules for pay transparency in New Jersey, California’s labor enforcement bill, and the potential impact of the AI Innovation Act on financial services. Stay informed on flood insurance compliance challenges, enterprise risk management, and upcoming anti-corruption events.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Issues Emergency Patch for Critical Windows Server Bug: Microsoft has released an out-of-band update to address CVE-2025-59287, a flaw under active attack. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/microsoft-emergency-patch-windows-server-bug&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Proposed Rules for NJ Pay Transparency Clarify Employer Scope + Applicability: New Jersey’s proposed rules clarify the scope of the Pay Transparency Act, requiring employers to include wage ranges in job ads. &lt;a href=&quot;https://www.jdsupra.com/legalnews/proposed-rules-for-nj-pay-transparency-7607110/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California’s AB 288: A New Era of State Labor Enforcement and Legal Uncertainty: California’s Assembly Bill 288 seeks to fill gaps left by a lack of quorum at the National Labor Relations Board (NLRB). &lt;a href=&quot;https://www.jdsupra.com/legalnews/california-s-ab-288-a-new-era-of-1345446/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;AI &amp;amp; Financial Services&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI Innovation Act Would Bring New Era to Financial Services Industry: The Unleashing AI Innovation in Financial Services Act proposes AI Innovation Labs for supervised AI tool testing in finance. &lt;a href=&quot;https://www.jdsupra.com/legalnews/ai-innovation-act-would-bring-new-era-6652806/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Flood remains compliance challenge: Financial institutions struggle with flood insurance compliance due to unclear regulations and inconsistent interpretations. &lt;a href=&quot;https://www.jdsupra.com/legalnews/flood-remains-compliance-challenge-91413/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Enterprise Risk Management Explained: The (In)Complete Guide: Many organizations lack visibility into their vendor evaluations and AI governance, leading to escalating risks. &lt;a href=&quot;https://www.jdsupra.com/legalnews/enterprise-risk-management-explained-9099089/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;[Event] 42nd Annual Conference on FCPA and Global Anti-Corruption – December 3rd – 4th, National Harbor, MD: ACI’s conference explores the future of FCPA and anti-corruption strategy. &lt;a href=&quot;https://www.jdsupra.com/legalnews/event-42nd-annual-conference-on-fcpa-5109120/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Innovation Act</category><category>Anti-Corruption</category><category>Emergency Patch</category><category>Enterprise Risk Management</category><category>FCPA</category><category>Financial Services</category><category>Flood Insurance</category><category>New Jersey</category><category>Pay Transparency</category><category>Windows Server</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/windows-patch-pay-transparency-ai-act-fcpa-10-25-2025.webp" length="0" type="image/webp"/></item><item><title>AI, Surveillance, Data Brokers &amp; Breach Laws – 10/24/2025</title><link>https://grabtheaxe.com/news/ai-surveillance-data-breach-laws-10-24-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ai-surveillance-data-breach-laws-10-24-2025/</guid><description>AI surveillance in schools, data broker expansions, &amp; breach notification law updates. Stay informed on key privacy threats and regulations.</description><pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ai-surveillance-data-breach-laws-10-24-2025.webp&quot; alt=&quot;AI Surveillance&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy landscape is marked by increasing concerns over AI’s role in surveillance and data access, notably in schools and secure communications. Key developments include a LastPass phishing campaign, updates to breach notification laws in California and Oklahoma, and the Philippines’ stance against selling biometric data. These issues underscore the importance of robust privacy measures and user control.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LastPass Phishing Campaign: LastPass warns of phishing emails requesting password vault access via fake inheritance processes. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fake-lastpass-death-claims-used-to-breach-password-vaults/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California &amp;amp; Oklahoma Breach Notification Updates: New legislation updates breach notification requirements in CA and OK, impacting businesses operating in those states. &lt;a href=&quot;https://www.alstonprivacy.com/key-breach-notification-updates-in-california-and-oklahoma-for-2026/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI Classroom Surveillance Concerns: NYCLU raises concerns over AI-powered classroom surveillance in Long Island, citing privacy risks. &lt;a href=&quot;https://pogowasright.org/ny-school-districts-ai-powered-classroom-surveillance-worries-civil-liberties-advocates/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ICE Mass Surveillance Campaign: ICE is reportedly using surveillance technology to investigate protesters, originally intended for undocumented immigrants. &lt;a href=&quot;https://pogowasright.org/ice-is-mounting-a-mass-surveillance-campaign-on-american-citizens/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI Access &amp;amp; Secure Chat Risks: EFF highlights privacy risks with AI features accessing secure chats, urging stronger user controls. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/when-ai-and-secure-chat-meet-users-deserve-strong-controls-over-how-they-interact&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;California Enacts Digital Age Verification Law: California’s Digital Age Assurance Act requires device-based age verification, creating safer digital environments for children. &lt;a href=&quot;https://www.alstonprivacy.com/california-enacts-digital-age-verification-law/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Philippines DPA: Biometric Data Not for Sale: The Philippines DPA halts Worldcoin’s biometric data processing, emphasizing that such data is not a commodity. &lt;a href=&quot;https://dataprivacy.foxrothschild.com/2025/10/articles/general-privacy-data-security-news-developments/philippines-data-protection-authority-biometric-data-is-not-for-sale-lessons-for-u-s-privacy-law/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Retail CCTV &amp;amp; GDPR Compliance: Bavarian court allows store security guards to use body cameras, citing GDPR compliance measures. &lt;a href=&quot;https://dataprivacy.foxrothschild.com/2025/10/articles/general-privacy-data-security-news-developments/smile-youre-on-camera-meets-gdpr-and-u-s-privacy-law-in-the-retail-context/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;NY School District’s AI Surveillance: NYCLU is concerned about a Long Island school district using AI-powered classroom surveillance. &lt;a href=&quot;https://pogowasright.org/ny-school-districts-ai-powered-classroom-surveillance-worries-civil-liberties-advocates/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ICE Mass Surveillance: ICE is using surveillance technology to investigate protesters, raising concerns about civil liberties. &lt;a href=&quot;https://pogowasright.org/ice-is-mounting-a-mass-surveillance-campaign-on-american-citizens/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Breaches&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Toys “R” Us Canada Data Breach: Toys “R” Us Canada warns customers about leaked information from a previous data theft. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/toys-r-us-canada-warns-customers-info-leaked-in-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;AI &amp;amp; Privacy&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI Access &amp;amp; Secure Chat Controls: EFF emphasizes the need for strong user controls over AI’s access to secure chat data. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/when-ai-and-secure-chat-meet-users-deserve-strong-controls-over-how-they-interact&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Surveillance</category><category>Biometrics</category><category>Breach Notification</category><category>CCPA</category><category>Data Brokers</category><category>Data Minimization</category><category>GDPR</category><category>Privacy Laws</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ai-surveillance-data-breach-laws-10-24-2025.webp" length="0" type="image/webp"/></item><item><title>Cyber Risk, HIPAA &amp; AI Policy Updates – 10/24/2025</title><link>https://grabtheaxe.com/news/cyber-risk-hipaa-ai-policy-10-24-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cyber-risk-hipaa-ai-policy-10-24-2025/</guid><description>Stay ahead: Cyber risk guidance, HIPAA breach, and AI policy updates. Key compliance insights for October 24, 2025. Protect your organization now.</description><pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cyber-risk-hipaa-ai-policy-10-24-2025.webp&quot; alt=&quot;Cyber Risk&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates, including a hospital firing employees for HIPAA violations and a severe Adobe Commerce flaw under active attack. New York’s DFS issued guidance on third-party cyber risk, while a $14 billion crypto bust offers hope against cybercrime. Stay informed with these key insights to safeguard your organization.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Florida Hospital Fires Employees for Taking Unauthorized Photographs of Sedated Patients: Four employees were terminated for allegedly taking unauthorized photographs of patients. &lt;a href=&quot;https://www.hipaajournal.com/florida-hospital-fires-employees-unauthorized-photographs-patients/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fear the ‘SessionReaper’: Adobe Commerce Flaw Under Attack: CVE-2025-54236 is a critical flaw in Adobe Commerce (formerly Magento) that allows attackers to remotely take over sessions. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/sessionreaper-adobe-commerce-flaw-under-attack&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Good Guidance on Third-Party Cyber Risk: New York regulators released guidance about managing cybersecurity risks of third-party technology providers. &lt;a href=&quot;https://www.radicalcompliance.com/2025/10/23/good-guidance-on-third-party-cyber-risk/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US Crypto Bust Offers Hope in Battle Against Cybercrime Syndicates: A $14 billion seizure by US investigators warns cybercriminals relying on bitcoin. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/us-crypto-bust-hope-battle-against-cybercrime-syndicates&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tired of Unpaid Toll Texts? Blame the ‘Smishing Triad’: Chinese smishers shift to lower-frequency, higher-impact government impersonation attacks. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/unpaid-toll-texts-smishing-triad&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Florida Hospital Fires Employees for Taking Unauthorized Photographs of Sedated Patients: Four employees were terminated for allegedly taking unauthorized photographs of patients, raising HIPAA concerns. &lt;a href=&quot;https://www.hipaajournal.com/florida-hospital-fires-employees-unauthorized-photographs-patients/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Good Guidance on Third-Party Cyber Risk: New York regulators released guidance about managing cybersecurity risks of third-party technology providers. &lt;a href=&quot;https://www.radicalcompliance.com/2025/10/23/good-guidance-on-third-party-cyber-risk/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Expired Federal Telehealth Waivers: Key Changes in Medicare Reimbursement Requirements for Telehealth Providers: Federal government telehealth flexibilities expired, impacting Medicare reimbursement. &lt;a href=&quot;https://www.jdsupra.com/legalnews/expired-federal-telehealth-waivers-key-5601022/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Audit &amp;amp; Monitoring Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AuditBoard to Acquire AI Governance Platform FairNow: AuditBoard will acquire FairNow, an AI governance platform with AI registry, risk assessments, and compliance features. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/auditboard-to-acquire-ai-governance-platform-fairnow/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Optera Adds AI-Powered Data Ingestion to Emissions Platform: Optera added AI-powered data ingestion to its emissions platform, converting raw energy bills into auditable emissions data. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/optera-adds-ai-powered-data-ingestion-to-emissions-platform/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FlexTecs Launches Inbox Automation Tool for AP Teams: FlexTecs launched AP Inbox Assist, using AI to automate accounts payable inbox management. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/flextecs-launches-inbox-automation-tool-for-ap-teams/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Good Guidance on Third-Party Cyber Risk: New York regulators released guidance about managing cybersecurity risks of third-party technology providers. &lt;a href=&quot;https://www.radicalcompliance.com/2025/10/23/good-guidance-on-third-party-cyber-risk/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI Innovation Act Would Bring New Era to Financial Services Industry: The Unleashing AI Innovation in Financial Services Act aims to accelerate responsible AI experimentation. &lt;a href=&quot;https://www.jdsupra.com/legalnews/ai-innovation-act-would-bring-new-era-6652806/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI in Employment-Related Decisions Part 2: State Strategies to Address Pressure and What It Means for Employers: State lawmakers recalibrate approaches to regulating AI use in employment decisions. &lt;a href=&quot;https://www.jdsupra.com/legalnews/ai-in-employment-related-decisions-part-9836182/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>ai governance</category><category>Cybersecurity</category><category>Data Protection</category><category>HIPAA</category><category>Regulatory Compliance</category><category>Smishing</category><category>Third-Party Risk</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/cyber-risk-hipaa-ai-policy-10-24-2025.webp" length="0" type="image/webp"/></item><item><title>WSUS Vulnerability, WordPress Exploits &amp; GlassWorm Worm – 10/24/2025</title><link>https://grabtheaxe.com/news/wsus-vulnerability-wordpress-exploits-glassworm-worm-10-24-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/wsus-vulnerability-wordpress-exploits-glassworm-worm-10-24-2025/</guid><description>Critical WSUS vulnerability (CVE-2025-59287) is actively exploited, prompting emergency Microsoft patches. Also covers WordPress plugin attacks and a new worm.</description><pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/wsus-vulnerability-wordpress-exploits-glassworm-worm-10-24-2025.webp&quot; alt=&quot;WSUS Vulnerability&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s top threat is a critical Windows Server (WSUS) vulnerability now under active exploitation, prompting an emergency out-of-band patch from Microsoft and a CISA alert. Security teams are also contending with mass attacks on outdated WordPress plugins and a novel self-spreading worm targeting VS Code extensions. This summary covers the essential details you need to secure your systems against these immediate threats.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Critical WSUS flaw in Windows Server now exploited in attacks: A critical remote code execution vulnerability in Windows Server Update Service (WSUS) is now under active exploitation in the wild, with a proof-of-concept exploit publicly available. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-now-exploiting-critical-windows-server-wsus-flaw-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Releases Out-of-Band Security Update to Mitigate Windows Server Update Service Vulnerability, CVE-2025-59287: Microsoft and CISA are urging organizations to immediately apply an emergency out-of-band patch for the actively exploited WSUS vulnerability (CVE-2025-59287) to prevent remote code execution. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/10/24/microsoft-releases-out-band-security-update-mitigate-windows-server-update-service-vulnerability-cve&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Adds Two Known Exploited Vulnerabilities to Catalog — CISA has added the critical Microsoft WSUS flaw (CVE-2025-59287) and an Adobe Commerce vulnerability (CVE-2025-54236) to its Known Exploited Vulnerabilities (KEV) catalog, requiring immediate federal agency action. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/10/24/cisa-adds-two-known-exploited-vulnerabilities-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hackers launch mass attacks exploiting outdated WordPress plugins — A widespread campaign is actively targeting WordPress websites by exploiting old, critical remote code execution vulnerabilities in the GutenKit and Hunk Companion plugins. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-launch-mass-attacks-exploiting-outdated-wordpress-plugins/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Self-Spreading ‘GlassWorm’ Infects VS Code Extensions in Widespread Supply Chain Attack: A sophisticated, self-propagating worm dubbed ‘GlassWorm’ is spreading through Visual Studio Code extensions, representing a significant new software supply chain threat to developers. &lt;a href=&quot;https://thehackernews.com/2025/10/self-spreading-glassworm-infects-vs.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;North Korean hacking group targeting European drone maker with ScoringMathTea malware — The North Korean Lazarus APT group is targeting a European drone manufacturer with ScoringMathTea malware as part of its ongoing ‘Operation DreamJob’ espionage campaign. &lt;a href=&quot;https://therecord.media/north-korea-hackers-target-europe-drone-makers&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This browser claims “perfect privacies protection,” but it acts like malware: Security researchers warn that the ‘Universe Browser,’ which advertises strong privacy, behaves like malware and shows connections to Asian cybercrime and illegal gambling networks. &lt;a href=&quot;https://arstechnica.com/security/2025/10/this-browser-claims-perfect-privacies-protection-but-it-acts-like-malware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign — The Pakistan-linked APT36 group is targeting Indian government entities with spear-phishing attacks to deliver ‘DeskRAT,’ a new malware written in Golang. &lt;a href=&quot;https://thehackernews.com/2025/10/apt36-targets-indian-government-with.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New LockBit Ransomware Victims Identified by Security Researchers — Check Point researchers have identified a dozen new attacks attributed to the LockBit ransomware group, with several utilizing a new version of the malware. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/new-lockbit-ransomware-victims/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fake LastPass death claims used to breach password vaults: A new phishing campaign is targeting LastPass users with fraudulent emails about legacy inheritance requests in an attempt to gain unauthorized access to their password vaults. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fake-lastPass-death-claims-used-to-breach-password-vaults/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cyberattack on Russia’s food safety agency reportedly disrupts product shipments: A reported DDoS attack against Russia’s food safety watchdog has disrupted critical systems, including its veterinary certification platform, impacting product shipments. &lt;a href=&quot;https://therecord.media/russia-food-safety-agency-rosselkhoznadzor-ddos-attack&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How to reduce costs with self-service password resets — Implementing secure self-service password reset tools with multi-factor authentication can significantly reduce IT help desk calls, which account for nearly 40% of their workload. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/how-to-reduce-costs-with-self-service-password-resets/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Mozilla: New Firefox extensions must disclose data collection practices — Mozilla will soon require all Firefox extension developers to clearly disclose if their add-ons collect user data or share it with third parties, enhancing user transparency. &lt;a href=&quot;https://www.bleepingcomputer.com/news/software/mozilla-new-firefox-extensions-must-disclose-data-collection-practices/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Amazon: This week’s AWS outage caused by major DNS failure: Amazon has attributed the massive AWS outage that affected numerous online services on Monday to a significant failure within its DNS infrastructure. &lt;a href=&quot;https://www.bleepingcomputer.com/news/technology/amazon-this-weeks-aws-outage-caused-by-major-dns-failure/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Counter Ransomware Initiative stresses importance of supply-chain security — A global coalition is urging companies to improve their software supply-chain security as threat actors increasingly use third-party products to launch ransomware attacks. &lt;a href=&quot;https://therecord.media/counter-ransomware-initiative-software-supply-chain-guidance&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Sneaky Mermaid attack in Microsoft 365 Copilot steals data: A novel indirect prompt injection technique, the ‘Mermaid attack,’ has been demonstrated to successfully exfiltrate data from Microsoft 365 Copilot, posing a new threat to AI assistants. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/10/24/m365_copilot_mermaid_indirect_prompt_injection/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI positions ChatGPT as a search engine for work data with Company Knowledge: OpenAI’s new ‘Company Knowledge’ feature for ChatGPT Enterprise allows it to index and search data from internal tools, raising important data security and governance questions. &lt;a href=&quot;https://the-decoder.com/openai-positions-chatgpt-as-a-search-engine-for-work-data-with-company-knowledge/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CISA</category><category>CVE-2025-59287</category><category>Cybersecurity</category><category>Malware</category><category>Microsoft</category><category>Supply Chain Attack</category><category>threat intelligence</category><category>WordPress</category><category>WSUS Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/wsus-vulnerability-wordpress-exploits-glassworm-worm-10-24-2025.webp" length="0" type="image/webp"/></item><item><title>F5 Breach, AI Spoofing, Data Transparency – 10/23/2025</title><link>https://grabtheaxe.com/news/f5-breach-ai-spoofing-data-transparency-10-23-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/f5-breach-ai-spoofing-data-transparency-10-23-2025/</guid><description>F5 breach alert: Nation-state attack compromises updates. Plus, AI spoofing risks and health app data transparency issues. Stay informed and secure!</description><pubDate>Thu, 23 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/f5-breach-ai-spoofing-data-transparency-10-23-2025.webp&quot; alt=&quot;F5 Breach&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy landscape is marked by critical vulnerabilities and evolving threats. A significant breach at F5 highlights the risks of nation-state actors, while AI spoofing attacks target browser users. Additionally, health apps continue to struggle with data transparency, emphasizing the need for robust user consent mechanisms and better transparency controls.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Serious F5 Breach: F5 disclosed a breach by a sophisticated nation-state group with long-term access, compromising update distribution. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/serious-f5-breach.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Spoofed AI Sidebars: Atlas and Comet browser users are vulnerable to AI sidebar spoofing attacks leading to dangerous actions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/spoofed-ai-sidebars-can-trick-atlas-comet-users-into-dangerous-actions/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Health Apps Data Transparency: Study reveals health apps transmit personal data before consent, raising data transparency and user control concerns. &lt;a href=&quot;https://pogowasright.org/study-finds-health-apps-still-struggle-with-data-transparency/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lanscope Endpoint Manager Flaw: CISA warns of hackers exploiting a critical vulnerability in the Motex Lanscope Endpoint Manager. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-warns-of-lanscope-endpoint-manager-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Iranian Hackers &amp;amp; Phoenix Backdoor: MuddyWater group targeted 100+ government entities, deploying Phoenix backdoor. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/iranian-hackers-targeted-over-100-govt-orgs-with-phoenix-backdoor/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;“Smile, You’re on Camera” &amp;amp; GDPR: Bavarian court’s GDPR ruling on body-worn cameras in retail offers insights for U.S. retailers. &lt;a href=&quot;https://dataprivacy.foxrothschild.com/2025/10/articles/general-privacy-data-security-news-developments/smile-youre-on-camera-meets-gdpr-and-u-s-privacy-law-in-the-retail-context/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California Data Broker Requirements: California expands data broker rules impacting companies selling data of consumers without direct relationships. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/california-continues-to-expand-data-broker-requirements/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;“Smile, You’re on Camera” &amp;amp; GDPR: Bavarian court’s GDPR ruling on body-worn cameras in retail offers insights for U.S. retailers. &lt;a href=&quot;https://dataprivacy.foxrothschild.com/2025/10/articles/general-privacy-data-security-news-developments/smile-youre-on-camera-meets-gdpr-and-u-s-privacy-law-in-the-retail-context/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Health Apps Data Transparency: Study reveals health apps transmit personal data before consent, raising data transparency and user control concerns. &lt;a href=&quot;https://pogowasright.org/study-finds-health-apps-still-struggle-with-data-transparency/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI &amp;amp; Secure Chat Controls: Google and Apple must offer better user controls over AI access to personal data in secure chat apps. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/when-ai-and-secure-chat-meet-users-deserve-strong-controls-over-how-they-interact&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Spoofing</category><category>CCPA</category><category>Cybersecurity</category><category>Data Brokers</category><category>Data Security</category><category>Data Transparency</category><category>F5 Breach</category><category>GDPR</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/f5-breach-ai-spoofing-data-transparency-10-23-2025.webp" length="0" type="image/webp"/></item><item><title>Lanscope Flaw, Adobe Exploits &amp; Lazarus Group – 10/23/2025</title><link>https://grabtheaxe.com/news/lanscope-flaw-adobe-exploits-lazarus-group-10-23-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/lanscope-flaw-adobe-exploits-lazarus-group-10-23-2025/</guid><description>Critical alert on an exploited Lanscope flaw. Analysis of active Adobe Commerce attacks, Lazarus Group&apos;s defense targets, and new ICS advisories from CISA.</description><pubDate>Thu, 23 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/lanscope-flaw-adobe-exploits-lazarus-group-10-23-2025.webp&quot; alt=&quot;Actively Exploited Vulnerabilities&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is marked by urgent alerts from CISA regarding an actively exploited vulnerability in Lanscope Endpoint Manager. Concurrently, a critical flaw in Adobe Commerce is being leveraged to attack hundreds of e-commerce sites, while the North Korean Lazarus Group continues its espionage campaign against European defense firms. This summary also covers new advisories for Industrial Control Systems and emerging threats targeting AI-powered browsers.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA warns of Lanscope Endpoint Manager flaw exploited in attacks: CISA has added a critical vulnerability (CVE-2025-61932) in Motex Lanscope Endpoint Manager to its Known Exploited Vulnerabilities catalog, confirming it is under active attack. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-warns-of-lanscope-endpoint-manager-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Over 250 Magento Stores Hit Overnight as Hackers Exploit New Adobe Commerce Flaw: A critical improper input validation flaw in Adobe Commerce and Magento (CVE-2025-54236), dubbed ‘SessionReaper’, is being actively exploited to take over e-commerce sessions, with over 250 stores already targeted. &lt;a href=&quot;https://thehackernews.com/2025/10/over-250-magento-stores-hit-overnight.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;North Korean Lazarus hackers targeted European defense companies: The North Korean Lazarus Group is conducting a sophisticated cyber-espionage campaign, ‘Operation DreamJob,’ using fake job lures to compromise European defense companies, particularly those involved in drone technology. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/north-korean-lazarus-hackers-targeted-european-defense-companies/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Releases Eight Industrial Control Systems Advisories: CISA has published eight new advisories detailing multiple critical vulnerabilities in ICS/SCADA products from vendors including AutomationDirect, ASKI Energy, Veeder-Root, and Delta Electronics, some with CVSS scores as high as 9.9. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/10/23/cisa-releases-eight-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;“Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards: A cybercriminal group named ‘Jingle Thief’ is targeting and exploiting the cloud environments of retail organizations to conduct widespread gift card fraud. &lt;a href=&quot;https://thehackernews.com/2025/10/jingle-thief-hackers-exploit-cloud.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid response: Cisco Talos reports a surge in attacks on public-facing applications for initial access in Q3 2025, with ToolShell exploits against SharePoint being the most prevalent tactic. &lt;a href=&quot;https://blog.talosintelligence.com/ir-trends-q3-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials: Google’s Threat Intelligence Group is tracking a Vietnamese threat cluster (UNC6229) that uses fake job postings on legitimate platforms to deliver malware and phish for credentials to hijack corporate advertising accounts. &lt;a href=&quot;https://cloud.google.com/blog/topics/threat-intelligence/vietnamese-actors-fake-job-posting-campaigns/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phishing campaign across Mideast, North Africa is attributed to Iranian group: The Iranian state-sponsored group MuddyWater has been linked to a recent phishing campaign that spreads backdoor malware to targets in the Middle East and North Africa. &lt;a href=&quot;https://therecord.media/iran-muddywater-phishing-campaign-north-africa-middle-east&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hackers posing as Kyrgyz officials target Russian agencies in cyber espionage campaign: The ‘Cavalry Werewolf’ hacking group is targeting Russian public sector, energy, and manufacturing companies in a prolonged cyber-espionage campaign using lures that impersonate Kyrgyz officials. &lt;a href=&quot;https://therecord.media/hackers-pose-kyrgyz-officials-russia-cyber-espionage&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Toys “R” Us Canada warns customers’ info leaked in data breach: Toys “R” Us Canada has notified customers of a data breach after threat actors stole and subsequently leaked customer records online. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/toys-r-us-canada-warns-customers-info-leaked-in-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US accuses former L3Harris cyber boss of stealing and selling secrets to Russian buyer: The US DOJ has charged a former general manager of L3Harris’s hacking division, Trenchant, with stealing trade secrets and selling them to a buyer in Russia. &lt;a href=&quot;https://techcrunch.com/2025/10/23/u-s-government-accuses-former-l3harris-cyber-boss-of-stealing-trade-secrets/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft disables File Explorer preview for downloads to block attacks: To mitigate credential theft risks, Microsoft is now automatically blocking the File Explorer preview pane for files downloaded from the internet to prevent attacks leveraging malicious documents. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-preview-pane-for-downloads-to-block-ntlm-theft-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;HP pulls update that broke Microsoft Entra ID auth on some AI PCs: HP has retracted a faulty HP OneAgent software update that deleted Microsoft certificates on some Windows 11 AI PCs, preventing users from logging into Microsoft Entra ID. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/hp-pulls-update-that-broke-microsoft-entra-id-auth-on-some-ai-pcs/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Spoofed AI sidebars can trick Atlas, Comet users into dangerous actions: Security researchers have found that OpenAI’s Atlas and Perplexity’s Comet AI browsers are vulnerable to sidebar spoofing attacks, which can trick users into following malicious, AI-generated instructions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/spoofed-ai-sidebars-can-trick-atlas-comet-users-into-dangerous-actions/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ChatGPT Atlas carries significant security risks, OpenAI warns: OpenAI’s own head of security has publicly warned that the company’s new browser, ChatGPT Atlas, could introduce significant security vulnerabilities for its users. &lt;a href=&quot;https://the-decoder.com/chatgpt-atlas-carries-significant-security-risks-openai-warns/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Zero Trust Has a Blind Spot: Your AI Agents. A new report highlights how autonomous AI agents are creating significant security blind spots that traditional Zero Trust architectures are not equipped to handle. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/zero-trust-has-a-blind-spot-your-ai-agents/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Active Exploit</category><category>Adobe Commerce</category><category>AI security</category><category>CISA Alert</category><category>Data Breach</category><category>endpoint security</category><category>ICS security</category><category>Lazarus Group</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/lanscope-flaw-adobe-exploits-lazarus-group-10-23-2025.webp" length="0" type="image/webp"/></item><item><title>Privacy Laws, Data Breach, Meta Bots – 10/18/2025</title><link>https://grabtheaxe.com/news/privacy-laws-data-breach-meta-bots-10-18-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/privacy-laws-data-breach-meta-bots-10-18-2025/</guid><description>Privacy updates: California&apos;s new laws, ICO&apos;s Capita fine, Meta&apos;s bot safeguards, &amp; EFF&apos;s privacy tips. Stay informed on data protection and online safety.</description><pubDate>Sat, 18 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/privacy-laws-data-breach-meta-bots-10-18-2025.webp&quot; alt=&quot;Data Protection&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights critical developments in data protection and online safety. Key stories include California’s enactment of new privacy laws, the ICO’s significant fine against Capita for a major data breach, and Meta’s new parental controls for AI chatbots. Also featured are practical tips from EFF on minimizing your digital footprint and a warning from UK MPs regarding online misinformation.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;California Enacts New Privacy Laws: Governor Newsom signed privacy proposals into law, including those for browser opt-outs, social media account deletion, and data brokers. &lt;a href=&quot;https://www.insideprivacy.com/state-privacy/california-enacts-new-privacy-laws/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ICO Fines Capita £14 Million Over 2023 Data Breach: The ICO fined Capita £14 million under the UK GDPR after a 2023 data breach affected over 6 million people. &lt;a href=&quot;https://www.insideprivacy.com/data-privacy/ico-fines-capita-14-million-over-2023-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Parents will be able to block Meta bots from talking to their children under new safeguards: Meta is adding safeguards to teen accounts, letting parents turn off chats with AI characters due to inappropriate conversations. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/18/parents-will-be-able-to-block-meta-bots-from-talking-to-their-children-under-new-safeguards&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Opt Out October: Daily Tips to Protect Your Privacy and Security: EFF provides daily tips for October on opting out of tech giant surveillance, covering passwords, data brokers, ad tracking, and app decluttering. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK MPs warn of repeat of 2024 riots unless online misinformation is tackled: UK MPs warn that failures to tackle online misinformation could trigger a repeat of the 2024 summer riots. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/17/uks-riots-of-2024-will-repeat-unless-misinformation-is-tackled-mps-warn&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;California Enacts New Privacy Laws: Governor Newsom signed privacy proposals into law, including those for browser opt-outs, social media account deletion, and data brokers. &lt;a href=&quot;https://www.insideprivacy.com/state-privacy/california-enacts-new-privacy-laws/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ICO Fines Capita £14 Million Over 2023 Data Breach: The ICO fined Capita £14 million under the UK GDPR after a 2023 data breach affected over 6 million people. &lt;a href=&quot;https://www.insideprivacy.com/data-privacy/ico-fines-capita-14-million-over-2023-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Opt Out October: Daily Tips to Protect Your Privacy and Security: EFF provides daily tips for October on opting out of tech giant surveillance, covering passwords, data brokers, ad tracking, and app decluttering. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Parents will be able to block Meta bots from talking to their children under new safeguards: Meta is adding safeguards to teen accounts, letting parents turn off chats with AI characters due to inappropriate conversations. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/18/parents-will-be-able-to-block-meta-bots-from-talking-to-their-children-under-new-safeguards&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI</category><category>California Privacy</category><category>Data Breach</category><category>Data Protection</category><category>GDPR</category><category>Meta</category><category>Online Safety</category><category>Parental Controls</category><category>Privacy Laws</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/privacy-laws-data-breach-meta-bots-10-18-2025.webp" length="0" type="image/webp"/></item><item><title>Surveillance, Data Breach &amp; EFF Lawsuit – 10/17/2025</title><link>https://grabtheaxe.com/news/online-surveillance-data-breach-eff-lawsuit-10-17-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/online-surveillance-data-breach-eff-lawsuit-10-17-2025/</guid><description>EFF sues over online surveillance, Zendesk email bombs, unencrypted satellite data &amp; more. Stay informed about today&apos;s critical privacy threats.</description><pubDate>Fri, 17 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/online-surveillance-data-breach-eff-lawsuit-10-17-2025.webp&quot; alt=&quot;Online Surveillance&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy digest highlights the concerning trend of increased surveillance and data breaches. Key stories include the EFF’s lawsuit against the Trump administration’s ideological surveillance program, the exploitation of lax authentication in Zendesk leading to ’email bombs’, and the surprising revelation of unencrypted satellite traffic. Additionally, a data breach at Sotheby’s exposed financial information, and a breach at Prosper impacted over 17 million accounts.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Labor Unions, EFF Sue Trump Administration to Stop Ideological Surveillance of Free Speech Online: Lawsuit challenges the U.S. government’s online surveillance program targeting noncitizens. &lt;a href=&quot;https://www.eff.org/press/releases/labor-unions-eff-sue-trump-administration-stop-surveillance-free-speech-online&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Email Bombs Exploit Lax Authentication in Zendesk: Cybercriminals are flooding inboxes using Zendesk’s lax authentication to send menacing messages. &lt;a href=&quot;https://krebsonsecurity.com/2025/10/email-bombs-exploit-lax-authentication-in-zendesk/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A Surprising Amount of Satellite Traffic Is Unencrypted: Study reveals sensitive data including critical infrastructure and personal communications are broadcast unencrypted. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/a-surprising-amount-of-satellite-traffic-is-unencrypted.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Auction giant Sotheby’s says data breach exposed financial information: Sotheby’s is notifying individuals of a data breach where threat actors stole sensitive financial details. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/auction-giant-sothebys-says-data-breach-exposed-financial-information/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Have I Been Pwned: Prosper data breach impacts 17.6 million accounts: Hackers stole personal information of over 17.6 million people after breaching Prosper’s systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/have-i-been-pwned-warns-of-prosper-data-breach-impacting-176-million-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Recapping CMMC Level 3: Considerations for Government Contractors: DoD issued a final rule implementing the Cybersecurity Maturity Model Certification (CMMC) program for government contractors. &lt;a href=&quot;https://www.gtlaw-dataprivacydish.com/2025/10/recapping-cmmc-level-3-considerations-for-government-contractors/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Leveling Up: Will CMMC Contract Obligations Impact Your Organization?: New rule impacts how defense contractors engage with the Department of Defense regarding Cybersecurity Maturity Model Certification. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/leveling-up-will-cmmc-contract-obligations-impact-your-organization/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Opt Out October: Daily Tips to Protect Your Privacy and Security: Series of daily tips to help users take control of their online privacy and limit tech giant surveillance. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Claro and Town of Dover, NJ Launch AI Video Analytics to Transform Public Safety: Dover, NJ partners with Claro to deploy AI-driven surveillance tech across municipal buildings. &lt;a href=&quot;https://pogowasright.org/claro-and-town-of-dover-nj-launch-ai-video-analytics-to-transform-public-safety/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Labor Unions, EFF Sue Trump Administration to Stop Ideological Surveillance of Free Speech Online: Lawsuit challenges the U.S. government’s online surveillance program targeting noncitizens. &lt;a href=&quot;https://www.eff.org/press/releases/labor-unions-eff-sue-trump-administration-stop-surveillance-free-speech-online&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CMMC</category><category>Data Breach</category><category>EFF</category><category>Online Surveillance</category><category>Privacy Laws</category><category>Satellite Traffic</category><category>Zendesk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/online-surveillance-data-breach-eff-lawsuit-10-17-2025.webp" length="0" type="image/webp"/></item><item><title>Ransomware, Data Breach, NY DFS, &amp; Password Risks – 10/17/2025</title><link>https://grabtheaxe.com/news/ransomware-data-breach-ny-dfs-password-risks-10-17-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ransomware-data-breach-ny-dfs-password-risks-10-17-2025/</guid><description>Ransomware surge, data breach settlements, and NY DFS cybersecurity fines lead today&apos;s compliance news. Password managers under attack. Stay informed and secure!</description><pubDate>Fri, 17 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ransomware-data-breach-ny-dfs-password-risks-10-17-2025.webp&quot; alt=&quot;Ransomware Attacks&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s compliance threat summary highlights the increasing risk of ransomware attacks and data breaches, particularly within the healthcare sector. New York regulators are cracking down on insurance firms with poor cybersecurity, while phishing campaigns are targeting password managers. Additionally, new regulations are impacting data transfers and federal grant processes, demanding increased vigilance.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cyberattackers Target LastPass, Top Password Managers: Phishing campaigns are exploiting employee trust in password vaults. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/cyberattackers-target-lastpass-password-managers&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Kettering Health Confirmed Patient Data Compromised in May 2025 Ransomware Attack: Investigation confirms patient data was compromised in a ransomware attack. &lt;a href=&quot;https://www.hipaajournal.com/kettering-health-ransomware-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NY DFS Nails Insurance Firms on Cyber Fails: New York regulators fined insurance firms for poor cybersecurity practices leading to privacy breaches. &lt;a href=&quot;https://www.radicalcompliance.com/2025/10/16/ny-dfs-nails-insurance-firms-on-cyber-fails/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cybersecurity Firm Reports 36% YOY Increase in Ransomware Attacks: Black Fog’s Q3 2025 report shows a significant rise in ransomware attacks. &lt;a href=&quot;https://www.hipaajournal.com/q3-2025-ransomware-report/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ITRC: 23 Million Individuals Affected by Data Breaches in Q3, 2025: System compromises and data breaches continue to affect millions. &lt;a href=&quot;https://www.hipaajournal.com/itrc-23-million-individuals-affected-data-breaches-q3-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Eastern Radiologists Agrees to $3.35 Million Data Breach Settlement: Settlement reached over a 2023 data breach impacting patient data. &lt;a href=&quot;https://www.hipaajournal.com/eastern-radiologists-data-breach-settlement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;California Restricts Use of Common Pricing Algorithms, Reforms the Pleading Standard for Certain Antitrust Claims, and Increases Penalties: California enacted AB 325 and SB 763, amending the Cartwright Act. &lt;a href=&quot;https://wp.nyu.edu/compliance_enforcement/2025/10/17/california-restricts-use-of-common-pricing-algorithms-reforms-the-pleading-standard-for-certain-antitrust-claims-and-increases-penalties/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NY DFS Nails Insurance Firms on Cyber Fails: New York regulators fined insurance firms for poor cybersecurity practices leading to privacy breaches. &lt;a href=&quot;https://www.radicalcompliance.com/2025/10/16/ny-dfs-nails-insurance-firms-on-cyber-fails/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Sensitive Data Bulk Transfer Rule: What You Need to Know: The U.S. Department of Justice’s Sensitive Data Bulk Transfer Rule is now in effect, impacting due diligence and compliance requirements. &lt;a href=&quot;https://www.jdsupra.com/legalnews/the-sensitive-data-bulk-transfer-rule-8594212/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Executive Order Reshapes Federal Grants Process: An executive order aims to improve federal grantmaking oversight and accountability. &lt;a href=&quot;https://www.jdsupra.com/legalnews/executive-order-reshapes-federal-grants-8459845/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Executive Order 14331: Navigating the New Era of Fair Banking: The Consumer Finance Podcast: Discusses implications of President Trump’s Executive Order 14331, “Guaranteeing Fair Banking for All Americans.” &lt;a href=&quot;https://www.jdsupra.com/legalnews/executive-order-14331-navigating-the-ne-05232/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When Supplier Data Lives in Silos, Risk Lives Everywhere: Fragmented supplier data across different sites poses a significant risk to manufacturers. &lt;a href=&quot;https://www.compliancequest.com/blog/supplier-data-silos-and-srm-risk-management/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Background Check Software Buyer’s Guide: Guide to researching background check software based on size, structure, and risk profile. &lt;a href=&quot;https://www.jdsupra.com/legalnews/background-check-software-buyer-s-guide-5036717/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Leaks in Microsoft VS Code Marketplace Put Supply Chain at Risk: Secrets exposed in Visual Studio Code marketplaces put supply chains at risk. &lt;a href=&quot;https://www.darkreading.com/application-security/leaks-microsoft-vs-code-marketplaces-supply-chain-risks&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When national cyber incidents break records, CEOs can’t stay outsiders: UK government demands action from CEOs on cyber threats. &lt;a href=&quot;https://vinciworks.com/blog/when-national-cyber-incidents-break-records-ceos-cant-stay-outsiders/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI Agent Security: Whose Responsibility Is It?: The shared responsibility model is key to agentic services, but awareness and risk management are challenging. &lt;a href=&quot;https://www.darkreading.com/cybersecurity-operations/ai-agent-security-awareness-responsibility&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI Chat Data Is History’s Most Thorough Record of Enterprise Secrets, Secure it Wisely: AI interactions are revealing records of human thinking, impacting law enforcement, accountability, and privacy. &lt;a href=&quot;https://www.darkreading.com/application-security/ai-chat-data-is-history-s-most-thorough-record-of-enterprise-secrets-secure-it-accordingly&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;From Capital to Clinics: California Reins in Private Equity Power to Address Corporate Practice of Medicine (CPOM) Concerns: California enacts bills impacting private equity firms and physician practices. &lt;a href=&quot;https://www.jdsupra.com/legalnews/from-capital-to-clinics-california-1679478/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>compliance</category><category>Cybersecurity</category><category>Data Breach</category><category>HIPAA</category><category>NY DFS</category><category>password manager</category><category>ransomware</category><category>Third-Party Risk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ransomware-data-breach-ny-dfs-password-risks-10-17-2025.webp" length="0" type="image/webp"/></item><item><title>Cyber Threats, Healthcare Breach, &amp; AML Updates – 10/16/2025</title><link>https://grabtheaxe.com/news/cyber-threats-healthcare-breach-aml-updates-10-16-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cyber-threats-healthcare-breach-aml-updates-10-16-2025/</guid><description>Stay ahead of cybersecurity threats with updates on healthcare breaches, AML regulation changes, and key compliance alerts. Read our summary now!</description><pubDate>Thu, 16 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cyber-threats-healthcare-breach-aml-updates-10-16-2025.webp&quot; alt=&quot;Cybersecurity Threats&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s compliance landscape is marked by significant cybersecurity threats, particularly in the healthcare sector, and evolving regulatory scrutiny across various industries. A major breach at F5 and widespread healthcare disruptions highlight the urgent need for robust cybersecurity measures. Simultaneously, regulatory updates like AIFMD 2.0 and Australia’s AML regulations demand proactive compliance efforts, while the EU’s crackdown on resale price fixing underscores the importance of fair competition.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;F5 BIG-IP Breach by Nation-State Actor: F5 disclosed a breach including zero-day bugs, source code, and customer information. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/f5-big-ip-environment-breached-nation-state-actor&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Healthcare Cyberattacks Disrupt Patient Care: 72% of healthcare organizations report disruptions to patient care due to cyberattacks. &lt;a href=&quot;https://www.hipaajournal.com/healthcare-cyberattacks-disrupt-patient-care/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Australia’s AML Penalties Signal Tranche 2 Readiness: ANZ faces a record penalty, signaling the importance of AML/CTF compliance under Tranche 2. &lt;a href=&quot;https://vinciworks.com/blog/australias-aml-reckoning-what-the-anz-240m-penalty-signals-ahead-of-tranche-2/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EU Fines Fashion Brands for Resale Price Fixing: Gucci, Chloé, and Loewe fined over $182 million for engaging in resale price maintenance. &lt;a href=&quot;https://www.jdsupra.com/legalnews/resale-price-fixing-in-fashion-eu-9745317/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI-Optimized Attack Chains Tested by China Hackers: Chinese hackers are testing AI to optimize attack chains in Taiwan, revealing the evolving cyber threat landscape. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/china-hackers-ai-optimized-attack-taiwan&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Risk Management Software for Medical Device Regulatory Compliance: Ensuring quality, safety, and FDA readiness with risk management software. &lt;a href=&quot;https://www.compliancequest.com/bloglet/risk-management-software-for-medical-device-regulatory-compliance/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AIFMD 2.0: What’s To Come With Six Months To Go: Fund managers should prepare for compliance with AIFMD 2.0, effective April 2026. &lt;a href=&quot;https://www.regulatoryandcompliance.com/2025/10/aifmd-2-0-whats-to-come-with-six-months-to-go/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Australia’s AML Reckoning: What the ANZ $240m penalty signals ahead of Tranche 2: Largest corporate misconduct penalty signals what’s coming under Tranche 2 of AML/CTF regime. &lt;a href=&quot;https://vinciworks.com/blog/australias-aml-reckoning-what-the-anz-240m-penalty-signals-ahead-of-tranche-2/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California Strengthens Privacy Protections for Individuals Visiting Family Planning Centers: New bill strengthens privacy for those seeking or receiving family planning services. &lt;a href=&quot;https://www.hipaajournal.com/califonria-strengthens-privacy-family-planning-centers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New CRS Regulations – What UK Investment Managers Need To Know: HMRC issued the International Tax Compliance (Amendment) Regulations 2025, introducing significant changes to the UK’s Common Reporting Standard (CRS) regime. &lt;a href=&quot;https://www.jdsupra.com/legalnews/new-crs-regulations-what-uk-investment-6820662/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Executive Order Reshapes Federal Grants Process: Signed to improve grantmaking, end waste, and ensure accountability for public funds. &lt;a href=&quot;https://www.jdsupra.com/legalnews/executive-order-reshapes-federal-grants-8459845/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Audit &amp;amp; Monitoring Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Jscrambler Launches AI Assistant for PCI DSS Script Authorization: New AI assistant provides risk-based insights for script authorization decisions and compliance justifications. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/jscrambler-launches-ai-assistant-for-pci-dss-script-authorization/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EcoVadis Launches Anonymous Reporting Tool for Supply Chain Workers: Worker Voice Connect helps organizations address worker concerns in global supply chains. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/ecovadis-launches-anonymous-reporting-tool-for-supply-chain-workers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI Compliance Tips for Advisers: Investment advisers are exploring ways to leverage AI in their operations, introducing complex legal, regulatory, and fiduciary challenges. &lt;a href=&quot;https://www.jdsupra.com/legalnews/ai-compliance-tips-for-advisers-9709449/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;PCCE Welcomes Two Members to its Board of Advisors: Courtney Colligan and Marshall Miller join NYU School of Law Program on Corporate Compliance and Enforcement (PCCE)’s Board of Advisors. &lt;a href=&quot;https://wp.nyu.edu/compliance_enforcement/2025/10/16/pcce-welcomes-two-members-to-its-board-of-advisors/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Healthcare Compliance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Five Healthcare Providers Warn Patients About Cyberattacks &amp;amp; Data Breaches: Cyberattacks and data breaches announced by multiple healthcare providers. &lt;a href=&quot;https://www.hipaajournal.com/five-healthcare-providers-cyberattacks-data-breaches-oct-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;72% of Healthcare Orgs Report Disruption to Patient Care Due to Cyberattacks: Survey finds most healthcare organizations experienced disruptions due to cyberattacks. &lt;a href=&quot;https://www.hipaajournal.com/healthcare-cyberattacks-disrupt-patient-care/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Orthopedics Rhode Island Agrees to Pay $2.9 Million to Settle Class Action Data Breach Lawsuit: Ortho RI settles class action lawsuit stemming from a data breach. &lt;a href=&quot;https://www.hipaajournal.com/orthopedics-rhode-island-class-action-data-breach-settlement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AIFMD</category><category>AML</category><category>compliance</category><category>Cybersecurity</category><category>Data Breach</category><category>Healthcare</category><category>Regulatory Updates</category><category>Third-Party Risk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/cyber-threats-healthcare-breach-aml-updates-10-16-2025.webp" length="0" type="image/webp"/></item><item><title>EtherHiding, Phishing, Adobe Flaw &amp; Data Breach – 10/16/2025</title><link>https://grabtheaxe.com/news/etherhiding-phishing-adobe-flaw-data-breach-10-16-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/etherhiding-phishing-adobe-flaw-data-breach-10-16-2025/</guid><description>Privacy threats today: North Korean hackers use EtherHiding, phishing targets password managers, Adobe flaw exploited, and Capita fined for data breach. Stay informed!</description><pubDate>Thu, 16 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/etherhiding-phishing-adobe-flaw-data-breach-10-16-2025.webp&quot; alt=&quot;EtherHiding Malware&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy briefing highlights critical threats, including North Korean hackers employing ‘EtherHiding’ tactics and an ongoing phishing campaign targeting password manager users. CISA warns of active exploitation of a maximum-severity Adobe flaw, while Capita faces a hefty fine for a significant data breach. Scams involving cryptocurrency ATMs continue to pose a risk to consumers.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;North Korean hackers use EtherHiding to hide malware on the blockchain: Hackers are using a new tactic to deliver malware, steal cryptocurrency, and perform espionage. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-etherhiding-to-hide-malware-on-the-blockchain/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fake LastPass, Bitwarden breach alerts lead to PC hijacks: Phishing campaign targets password manager users, urging them to download a malicious desktop version. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fake-lastpass-bitwarden-breach-alerts-lead-to-pc-hijacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: Maximum-severity Adobe flaw now exploited in attacks: Attackers are actively exploiting a maximum-severity vulnerability in Adobe Experience Manager to execute code. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-maximum-severity-adobe-flaw-now-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Capita to pay £14 million for data breach impacting 6.6 million people: The ICO has fined Capita £14 million for a 2023 data breach exposing millions of people’s data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/capita-to-pay-14-million-for-data-breach-impacting-66-million-people/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cryptocurrency ATMs: Cryptocurrency ATMs are used to scam people out of their money, with usurious fees and a common place for scammers. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/cryptocurrency-atms.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;ATMs&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cryptocurrency ATMs: Cryptocurrency ATMs are used to scam people out of their money, with usurious fees and a common place for scammers. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/cryptocurrency-atms.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cybersecurity&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Incident Response Defenses: Can You Take Advantage of a Cyber Program Safe Harbor?: Organizations can take advantage of states’ safe harbor provisions for data incident preparedness. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/incident-response-defenses-can-you-take-advantage-of-a-cyber-program-safe-harbor/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Breach&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Incident Response Defenses: Can You Take Advantage of a Cyber Program Safe Harbor?: Organizations can take advantage of states’ safe harbor provisions for data incident preparedness. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/incident-response-defenses-can-you-take-advantage-of-a-cyber-program-safe-harbor/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Incident Response Defenses: Can You Take Advantage of a Cyber Program Safe Harbor?: Organizations can take advantage of states’ safe harbor provisions for data incident preparedness. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/incident-response-defenses-can-you-take-advantage-of-a-cyber-program-safe-harbor/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;General Privacy &amp;amp; Data Security News &amp;amp; Developments&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Sensitive Data Bulk Transfer Rule: What You Need to Know: The U.S. Department of Justice’s Sensitive Data Bulk Transfer Rule is in effect, including due diligence and compliance requirements. &lt;a href=&quot;https://dataprivacy.foxrothschild.com/2025/10/articles/united-states/the-sensitive-data-bulk-transfer-rule-what-you-need-to-know/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Google&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;YouTube is down worldwide with playback error: YouTube is facing a global outage, with users reporting playback errors on both the website and mobile apps. &lt;a href=&quot;https://www.bleepingcomputer.com/news/google/youtube-is-down-worldwide-with-playback-error/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Legal&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Capita to pay £14 million for data breach impacting 6.6 million people: The ICO has fined Capita £14 million for a 2023 data breach exposing millions of people’s data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/capita-to-pay-14-million-for-data-breach-impacting-66-million-people/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Microsoft&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft debuts Copilot Actions for agentic AI-driven Windows tasks: Microsoft announced Copilot Actions, enabling AI agents to perform real tasks on local files and applications. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-debuts-copilot-actions-for-agentic-ai-driven-windows-tasks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Sept Windows Server updates cause Active Directory issues: Microsoft confirmed that the September 2025 security updates are causing Active Directory issues on Windows Server 2025 systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2025-windows-server-updates-cause-active-directory-issues/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA: Maximum-severity Adobe flaw now exploited in attacks: Attackers are actively exploiting a maximum-severity vulnerability in Adobe Experience Manager to execute code. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-maximum-severity-adobe-flaw-now-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Unified Exposure Management Platforms: The Future of Preemptive Cyber Defense: Unified Exposure Management Platforms continuously identifies, validates, and fixes exploitable risks before adversaries strike. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/unified-exposure-management-platforms-the-future-of-preemptive-cyber-defense/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;North Korean hackers use EtherHiding to hide malware on the blockchain: Hackers are using a new tactic to deliver malware, steal cryptocurrency, and perform espionage. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-etherhiding-to-hide-malware-on-the-blockchain/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft adds Copilot voice activation on Windows 11 PCs: Windows 11 users can start a conversation with Copilot by saying the “Hey Copilot” wake word. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-adds-hey-copilot-wake-word-to-windows-11-pcs/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft debuts Copilot Actions for agentic AI-driven Windows tasks: Microsoft announced Copilot Actions, enabling AI agents to perform real tasks on local files and applications. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-debuts-copilot-actions-for-agentic-ai-driven-windows-tasks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Capita to pay £14 million for data breach impacting 6.6 million people: The ICO has fined Capita £14 million for a 2023 data breach exposing millions of people’s data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/capita-to-pay-14-million-for-data-breach-impacting-66-million-people/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;PowerSchool hacker gets sentenced to four years in prison: A college student was sentenced to four years in prison for a cyberattack on PowerSchool in December 2024. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/powerschool-hacker-gets-sentenced-to-four-years-in-prison/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fake LastPass, Bitwarden breach alerts lead to PC hijacks: Phishing campaign targets password manager users, urging them to download a malicious desktop version. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fake-lastpass-bitwarden-breach-alerts-lead-to-pc-hijacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;F5 releases BIG-IP patches for stolen security vulnerabilities: F5 has released security updates to address BIG-IP vulnerabilities stolen in a breach detected on August 9, 2025. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/f5-releases-big-ip-patches-for-stolen-security-vulnerabilities/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Clothing giant MANGO discloses data breach exposing customer info: Spanish fashion retailer MANGO is sending notices of a data breach to its customers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/clothing-giant-mango-discloses-data-breach-exposing-customer-info/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Software&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;YouTube is down worldwide with playback error: YouTube is facing a global outage, with users reporting playback errors on both the website and mobile apps. &lt;a href=&quot;https://www.bleepingcomputer.com/news/google/youtube-is-down-worldwide-with-playback-error/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Uncategorized&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Get a credit freeze to stop identity thieves: Freezing your credit is a great place to start to help protect yourself from identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/get-credit-freeze-stop-identity-thieves&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam: There are some ways to spot phony business opportunities, work-at-home scams, shady employment agencies, and scammy multi-level marketing schemes. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams: Having a plan and knowing how to spot disaster-related scams can make a difference to anyone recovering from a disaster. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to help protect foster youth from identity theft: Foster youth are at greater risk of identity theft, so here are ways to help protect them. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone: Nobody who works at the FTC will ever tell you to move your money to protect it. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls: Learn how to cut down on the number of unwanted telemarketing calls you get. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams: Learn to spot the scams that get more active around Medicare Open Enrollment Period. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams: Key steps to avoid scams when selling your timeshare. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going: Find out where the money is going before you donate to a cause. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?: Amazon agreed to pay $2.5 billion to settle the FTC’s charges, so who gets a refund? &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Barrister found to have used AI to prepare for hearing after citing ‘fictitious’ cases: An immigration barrister was found to be using AI to do his work for a tribunal hearing. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/16/barrister-found-to-have-used-ai-to-prepare-for-hearing-after-citing-fictitious-cases&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ROG Xbox Ally X review – like nothing handheld gaming has seen before, for better or worse: The ROG Xbox Ally X is an impressive, yet expensive, piece of gaming tech. &lt;a href=&quot;https://www.theguardian.com/games/2025/oct/16/rog-xbox-ally-x-review-like-nothing-handheld-gaming-has-seen-before&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Italian news publishers demand investigation into Google’s AI Overviews: Italian news publishers are calling for an investigation into Google’s AI Overviews. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/16/google-ai-overviews-italian-news-publishers-demand-investigation&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Spotify partnering with multinational music companies to develop ‘responsible’ AI products: Spotify is teaming up with the world’s biggest music companies to develop “responsible” artificial intelligence products. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/16/spotify-ai-products-partnering-multinational-music-companies&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cryptocurrency ATMs: Cryptocurrency ATMs are used to scam people out of their money, with usurious fees and a common place for scammers. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/cryptocurrency-atms.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Plug-in hybrids pollute almost as much as petrol cars, report finds: Plug-in hybrid electric vehicles (PHEVs) pump out nearly five times more planet-heating pollution than official figures show. &lt;a href=&quot;https://www.theguardian.com/environment/2025/oct/16/plug-in-hybrids-pollute-almost-as-much-as-petrol-cars-report-finds&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;🎃 A Full Month of Privacy Tips from EFF | EFFector 37.14: EFF is helping you take control of your online privacy with Opt Out October. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/full-month-privacy-tips-eff-effector-3714&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Opt Out October: Daily Tips to Protect Your Privacy and Security: EFF provides daily tips to protect your privacy and security during Opt Out October. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;United States&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Sensitive Data Bulk Transfer Rule: What You Need to Know: The U.S. Department of Justice’s Sensitive Data Bulk Transfer Rule is in effect, including due diligence and compliance requirements. &lt;a href=&quot;https://dataprivacy.foxrothschild.com/2025/10/articles/united-states/the-sensitive-data-bulk-transfer-rule-what-you-need-to-know/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;cryptocurrency&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cryptocurrency ATMs: Cryptocurrency ATMs are used to scam people out of their money, with usurious fees and a common place for scammers. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/cryptocurrency-atms.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;data breach&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Incident Response Defenses: Can You Take Advantage of a Cyber Program Safe Harbor?: Organizations can take advantage of states’ safe harbor provisions for data incident preparedness. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/incident-response-defenses-can-you-take-advantage-of-a-cyber-program-safe-harbor/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;scams&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cryptocurrency ATMs: Cryptocurrency ATMs are used to scam people out of their money, with usurious fees and a common place for scammers. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/cryptocurrency-atms.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Adobe Flaw</category><category>CISA</category><category>Cryptocurrency Scams</category><category>Data Breach</category><category>EtherHiding</category><category>North Korean Hackers</category><category>Password Managers</category><category>Phishing</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/etherhiding-phishing-adobe-flaw-data-breach-10-16-2025.webp" length="0" type="image/webp"/></item><item><title>Apple Bounty, Android Attack, Surveillance &amp; MANGO Breach – 10/15/2025</title><link>https://grabtheaxe.com/news/apple-bounty-android-attack-surveillance-mango-breach-10-15-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/apple-bounty-android-attack-surveillance-mango-breach-10-15-2025/</guid><description>Apple enhances bug bounty, Android &apos;Pixnapping&apos; steals MFA, surveillance empire exposed &amp; MANGO data breach. Stay informed on top privacy threats.</description><pubDate>Wed, 15 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/apple-bounty-android-attack-surveillance-mango-breach-10-15-2025.webp&quot; alt=&quot;Bug Bounty&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy landscape is marked by both proactive security measures and emerging threats. Apple’s enhanced bug bounty program highlights the industry’s focus on combating sophisticated spyware, while a novel Android attack demonstrates the evolving tactics of data extraction. Additionally, revelations about a global surveillance empire and a data breach at fashion retailer MANGO underscore the persistent challenges in safeguarding personal information.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Apple’s Bug Bounty Program: Apple is offering a $2M bounty for zero-click exploits, aiming to combat mercenary spyware attacks. The program includes increased rewards for Lockdown Mode bypasses and iCloud access exploits. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/apples-bug-bounty-program.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Android Pixnapping attack steals MFA codes pixel-by-pixel: A malicious Android app can extract sensitive data by stealing pixels and reconstructing them. This side-channel attack requires no permissions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-android-pixnapping-attack-steals-mfa-codes-pixel-by-pixel/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Surveillance Empire That Tracked World Leaders, a Vatican Enemy, and Maybe You: First Wap’s European founders built a phone-tracking empire operating from Jakarta. Their reach extends from the Vatican to the Middle East to Silicon Valley. &lt;a href=&quot;https://pogowasright.org/the-surveillance-empire-that-tracked-world-leaders-a-vatican-enemy-and-maybe-you/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Clothing giant MANGO discloses data breach exposing customer info: Spanish fashion retailer MANGO warns customers of a data breach at its marketing vendor. The breach exposed personal data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/clothing-giant-mango-discloses-data-breach-exposing-customer-info/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;F5 says hackers stole undisclosed BIG-IP flaws, source code: Nation-state hackers breached F5 and stole undisclosed BIG-IP security vulnerabilities and source code. Patches have been released to address the stolen vulnerabilities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-breach-f5-to-steal-undisclosed-big-ip-flaws-source-code/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Apple&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Apple’s Bug Bounty Program: Apple is offering a $2M bounty for zero-click exploits, aiming to combat mercenary spyware attacks. The program includes increased rewards for Lockdown Mode bypasses and iCloud access exploits. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/apples-bug-bounty-program.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cybersecurity&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Incident Response Defenses: Can You Take Advantage of a Cyber Program Safe Harbor?: Many organizations are budgeting and planning for data incident preparedness. Several states have safe harbor provisions for organizations with cyber programs. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/incident-response-defenses-can-you-take-advantage-of-a-cyber-program-safe-harbor/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Breach&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Incident Response Defenses: Can You Take Advantage of a Cyber Program Safe Harbor?: Many organizations are budgeting and planning for data incident preparedness. Several states have safe harbor provisions for organizations with cyber programs. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/incident-response-defenses-can-you-take-advantage-of-a-cyber-program-safe-harbor/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Incident Response Defenses: Can You Take Advantage of a Cyber Program Safe Harbor?: Many organizations are budgeting and planning for data incident preparedness. Several states have safe harbor provisions for organizations with cyber programs. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/incident-response-defenses-can-you-take-advantage-of-a-cyber-program-safe-harbor/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Microsoft&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft: Sept Windows Server updates cause Active Directory issues: Microsoft confirms that the September 2025 security updates are causing Active Directory issues on Windows Server 2025 systems. Details are emerging. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2025-windows-server-updates-cause-active-directory-issues/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Final Windows 10 Patch Tuesday update rolls out as support ends: Microsoft released the final free update for Windows 10 as it reaches the end of its support lifecycle. This marks the end of an era. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/final-windows-10-patch-tuesday-update-rolls-out-as-support-ends/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Exchange 2016 and 2019 have reached end of support: Microsoft reminds that Exchange Server 2016 and 2019 have reached the end of support. IT admins should upgrade to Exchange Server SE or migrate to Exchange Online. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-and-2019-have-reached-end-of-support/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Mobile&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New Android Pixnapping attack steals MFA codes pixel-by-pixel: A malicious Android app can extract sensitive data by stealing pixels and reconstructing them. This side-channel attack requires no permissions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-android-pixnapping-attack-steals-mfa-codes-pixel-by-pixel/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;F5 releases BIG-IP patches for stolen security vulnerabilities: F5 released security updates to address BIG-IP vulnerabilities stolen in a breach detected on August 9, 2025. Apply the patches immediately. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/f5-releases-big-ip-patches-for-stolen-security-vulnerabilities/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Clothing giant MANGO discloses data breach exposing customer info: Spanish fashion retailer MANGO warns customers of a data breach at its marketing vendor. The breach exposed personal data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/clothing-giant-mango-discloses-data-breach-exposing-customer-info/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot dark web threats on your network using NDR: Dark web activity can hide in plain sight within network traffic. Corelight’s NDR platform provides visibility and AI-driven detection. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/how-to-spot-dark-web-threats-on-your-network-using-ndr/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;F5 says hackers stole undisclosed BIG-IP flaws, source code: Nation-state hackers breached F5 and stole undisclosed BIG-IP security vulnerabilities and source code. Patches have been released to address the stolen vulnerabilities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-breach-f5-to-steal-undisclosed-big-ip-flaws-source-code/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Malicious crypto-stealing VSCode extensions resurface on OpenVSX: A threat actor is targeting developers with malicious VSCode extensions to steal cryptocurrency and plant backdoors. Be cautious when installing extensions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-crypto-stealing-vscode-extensions-resurface-on-openvsx/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Android Pixnapping attack steals MFA codes pixel-by-pixel: A malicious Android app can extract sensitive data by stealing pixels and reconstructing them. This side-channel attack requires no permissions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-android-pixnapping-attack-steals-mfa-codes-pixel-by-pixel/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Surveillance Empire That Tracked World Leaders, a Vatican Enemy, and Maybe You: First Wap’s European founders built a phone-tracking empire operating from Jakarta. Their reach extends from the Vatican to the Middle East to Silicon Valley. &lt;a href=&quot;https://pogowasright.org/the-surveillance-empire-that-tracked-world-leaders-a-vatican-enemy-and-maybe-you/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Uncategorized&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Opt Out October: Daily Tips to Protect Your Privacy and Security: EFF provides daily tips to protect your privacy and security during Opt Out October. Learn how to opt out of tech giant surveillance. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Digital ID: Danes and Estonians find it ‘pretty uncontroversial’: Citizens in Denmark and Estonia have enrolled in digital ID systems with little opposition. The UK is planning a similar system. &lt;a href=&quot;https://www.theguardian.com/politics/2025/10/15/digital-id-denmark-estonia-uncontroversial-concerns-security-privacy&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI will allow verified adults to use ChatGPT to generate erotic content: OpenAI plans to relax restrictions on ChatGPT, allowing erotic content for verified adult users. Age verification methods are forthcoming. &lt;a href=&quot;https://www.theguardian.com/technology/2025/10/14/openai-chatgpt-adult-erotic-content&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Exploits&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Apple’s Bug Bounty Program: Apple is offering a $2M bounty for zero-click exploits, aiming to combat mercenary spyware attacks. The program includes increased rewards for Lockdown Mode bypasses and iCloud access exploits. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/apples-bug-bounty-program.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Spyware&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Apple’s Bug Bounty Program: Apple is offering a $2M bounty for zero-click exploits, aiming to combat mercenary spyware attacks. The program includes increased rewards for Lockdown Mode bypasses and iCloud access exploits. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/apples-bug-bounty-program.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Vulnerabilities&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Apple’s Bug Bounty Program: Apple is offering a $2M bounty for zero-click exploits, aiming to combat mercenary spyware attacks. The program includes increased rewards for Lockdown Mode bypasses and iCloud access exploits. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/apples-bug-bounty-program.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Android</category><category>Apple</category><category>Bug Bounty</category><category>Data Breach</category><category>Exploit</category><category>MFA</category><category>spyware</category><category>Surveillance</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/apple-bounty-android-attack-surveillance-mango-breach-10-15-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breach, CCPA, Oracle Attack &amp; Patch Update – 10/15/2025</title><link>https://grabtheaxe.com/news/data-breach-ccpa-oracle-attack-patch-update-10-15-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breach-ccpa-oracle-attack-patch-update-10-15-2025/</guid><description>Data breach at Harvard, new CCPA rules, and a massive Microsoft patch update lead today&apos;s compliance news. Stay informed on the latest threats and regulations.</description><pubDate>Wed, 15 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breach-ccpa-oracle-attack-patch-update-10-15-2025.webp&quot; alt=&quot;Data Breaches&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s compliance digest features critical updates on data breaches, ransomware attacks, and evolving regulatory landscapes. Harvard University suffered a significant breach due to an Oracle zero-day, while Microsoft issued a massive patch update addressing actively exploited vulnerabilities. New CCPA risk assessment requirements and restrictions on private equity involvement in healthcare practices highlight the increasing complexity of compliance.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Harvard University Breached in Oracle Zero-Day Attack: The Clop ransomware group claimed responsibility for stealing Harvard’s data as part of a broader campaign against Oracle customers. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/harvard-breached-oracle-zero-day-attack&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Drops Terrifyingly Large October Patch Update: October 2025’s Patch Tuesday includes actively exploited zero-days and privilege-escalation bugs, ending Windows 10 updates. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/microsoft-october-patch-update&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;China’s Flax Typhoon Turns Geo-Mapping Server into a Backdoor: Chinese APT threat actors compromised an organization’s ArcGIS server, modifying the geospatial mapping software for stealth access. &lt;a href=&quot;https://www.darkreading.com/application-security/chinas-flax-typhoon-geo-mapping-server-backdoor&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pixnapping Attack Lets Attackers Steal 2FA on Android: A proof-of-concept exploit allows an attacker to steal sensitive data from Gmail, Google Accounts, Google Authenticator, Google Maps, Signal, and Venmo. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/pixnapping-attack-attackers-2fa-android&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;$49.99M Settlement Agreed to Resolve Class Action Data Breach Lawsuit Against Heritage Provider Network et al: A $49.99 million settlement has received preliminary approval from the court to resolve class action litigation against Heritage Provider Network. &lt;a href=&quot;https://www.hipaajournal.com/multiple-lawsuits-regal-medical-group-ransomware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;What Is ISO/IEC 27006-1:2024 &amp;amp; What Changed in the 2024 (2025 Transition) Edition?: This standard governs how certification bodies (CBs) operate when auditing and certifying organizations for ISO 27001. &lt;a href=&quot;https://linfordco.com/blog/iso-iec-27006-updates-guidance/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ISO 27001 for Non-IT Roles: A Beginner’s Guide: Understanding ISO 27001 is no longer optional for IT teams alone, as non-technical roles are increasingly involved in projects handling sensitive data. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/iso-27001-for-non-it-roles-a-beginners-guide&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New CRS Regulations – What UK Investment Managers Need To Know: HMRC issued the International Tax Compliance (Amendment) Regulations 2025, introducing significant changes to the UK’s Common Reporting Standard (CRS) regime. &lt;a href=&quot;https://www.jdsupra.com/legalnews/new-crs-regulations-what-uk-investment-6820662/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California Enacts SB 351: New Restrictions on Private Equity and Hedge Fund Involvement in Physician and Dental Practices: California Governor Gavin Newsom signed into law Senate Bill 351, strengthening restrictions on the corporate practice of medicine and dentistry in California. &lt;a href=&quot;https://www.jdsupra.com/legalnews/california-enacts-sb-351-new-5228882/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Understanding the CCPA’s New Risk Assessment Requirements – Part 2: The California Privacy Protection Agency (CPPA) has approved significant updates to CCPA regulations, including a new obligation to conduct risk assessments. &lt;a href=&quot;https://www.jdsupra.com/legalnews/understanding-the-ccpa-s-new-risk-1476576/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI Compliance Tips for Advisers: Investment advisers are exploring ways to leverage AI, introducing complex legal, regulatory, and fiduciary challenges. &lt;a href=&quot;https://www.jdsupra.com/legalnews/ai-compliance-tips-for-advisers-9709449/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Risk Management Software for Semiconductor Supply Chain Compliance: Ensuring Resilience and Regulatory Alignment: Semiconductor manufacturers face numerous risks due to the globally integrated and complex nature of their supply chains. &lt;a href=&quot;https://www.compliancequest.com/bloglet/risk-management-software-for-semiconductor-supply-chain-compliance/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Yes, You Can Fire an Employee for a Problematic Post, but Should You?: Considerations around firing an employee for problematic social media posts are discussed. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/yes-you-probably-can-fire-employee-troubling-tweet-should-you/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Are Your Hotline Metrics Telling the Board a Compelling Story?: Compliance leaders can use data visualization and storytelling to help boards grasp the significance of trends in hotline metrics. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/are-your-hotline-metrics-telling-board-compelling-story/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CCPA</category><category>Cybersecurity</category><category>Data Breach</category><category>ISO 27001</category><category>Microsoft Patch</category><category>Oracle</category><category>ransomware</category><category>Regulatory Compliance</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breach-ccpa-oracle-attack-patch-update-10-15-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breach, AI Surveillance &amp; Student Tracking – 10/14/2025</title><link>https://grabtheaxe.com/news/data-breach-ai-surveillance-student-tracking-10-14-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breach-ai-surveillance-student-tracking-10-14-2025/</guid><description>Privacy alert: Data breaches impact healthcare, LinkedIn lawsuits, AI surveillance, &amp; Microsoft student tracking. Stay informed on key privacy developments.</description><pubDate>Tue, 14 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breach-ai-surveillance-student-tracking-10-14-2025.webp&quot; alt=&quot;Student Tracking&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights critical breaches affecting healthcare and online platforms, alongside regulatory scrutiny of Microsoft’s educational tracking. We also cover the implications of AI in surveillance and the evolving landscape of US privacy laws. Stay informed about the key developments shaping data protection and cybersecurity.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft ‘illegally’ tracked students via 365 Education: Austrian data protection regulator ruled Microsoft illegally tracked students and used their data. &lt;a href=&quot;https://pogowasright.org/microsoft-illegally-tracked-students-via-365-education-says-data-watchdog/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SimonMed says 1.2 million patients impacted in January data breach: Medical imaging provider SimonMed Imaging is notifying over 1.2 million individuals of a data breach. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/simonmed-says-12-million-patients-impacted-in-january-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Secure Boot bypass risk threatens nearly 200,000 Linux Framework laptops: Signed UEFI shell components could be exploited to bypass Secure Boot protections. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/secure-boot-bypass-risk-on-nearly-200-000-linux-framework-sytems/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SonicWall VPN accounts breached using stolen creds: Threat actors compromised over a hundred SonicWall SSLVPN accounts via stolen credentials. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/sonicwall-vpn-accounts-breached-using-stolen-creds-in-widespread-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;LinkedIn Stuck With Three Lawsuits Over Online Data Tracking: LinkedIn faces lawsuits over collecting sensitive information without consent, violating California privacy laws. &lt;a href=&quot;https://pogowasright.org/linkedin-stuck-with-three-lawsuits-over-online-data-tracking/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;2025 Brought Us Eight US “Comprehensive” Privacy Laws: Maryland law (MODPA) went into effect Oct 1st, bringing the US total to 17 (or 16). &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/2025-brought-us-eight-us-comprehensive-privacy-laws-whats-next/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California’s Latest Trio of Privacy Bills: New laws give consumers greater control over personal info, impacting businesses and data brokers. &lt;a href=&quot;https://www.bytebacklaw.com/2025/10/californias-latest-trio-of-privacy-bills-what-businesses-and-consumers-need-to-know/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LinkedIn Stuck With Three Lawsuits Over Online Data Tracking: LinkedIn faces lawsuits over collecting sensitive information without consent, violating California privacy laws. &lt;a href=&quot;https://pogowasright.org/linkedin-stuck-with-three-lawsuits-over-online-data-tracking/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft ‘illegally’ tracked students via 365 Education: Austrian data protection regulator ruled Microsoft illegally tracked students and used their data. &lt;a href=&quot;https://pogowasright.org/microsoft-illegally-tracked-students-via-365-education-says-data-watchdog/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft ‘illegally’ tracked students via 365 Education: Austrian data protection regulator ruled Microsoft illegally tracked students and used their data. &lt;a href=&quot;https://pogowasright.org/microsoft-illegally-tracked-students-via-365-education-says-data-watchdog/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;AI&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Trump Administration’s Increased Use of Social Media Surveillance: Trump administration uses AI to monitor public speech of foreign nationals and revoke visas. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/the-trump-administrations-increased-use-of-social-media-surveillance.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When AI Agents Join the Teams: The Hidden Security Shifts No One Expects: Autonomous AI agents now open tickets, fix incidents, and make decisions faster than humans. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/when-ai-agents-join-the-teams-the-hidden-security-shifts-no-one-expects/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Breaches&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LinkedIn Stuck With Three Lawsuits Over Online Data Tracking: LinkedIn faces lawsuits over collecting sensitive information without consent, violating California privacy laws. &lt;a href=&quot;https://pogowasright.org/linkedin-stuck-with-three-lawsuits-over-online-data-tracking/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SimonMed says 1.2 million patients impacted in January data breach: Medical imaging provider SimonMed Imaging is notifying over 1.2 million individuals of a data breach. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/simonmed-says-12-million-patients-impacted-in-january-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cybersecurity&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Happy Cyber Awareness Month: October is Cyber Awareness Month, dedicated to raising awareness of cyber security incidents. &lt;a href=&quot;https://www.dataprotectionreport.com/2025/10/happy-cyber-awareness-month/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Recapping CMMC Level 2: Considerations for Government Contractors: Contractors handling CUI may need CMMC Level 2 self-assessment for new contracts starting Nov 10, 2025. &lt;a href=&quot;https://www.gtlaw-dataprivacydish.com/2025/10/recapping-cmmc-level-2-considerations-for-government-contractors/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Secure Boot bypass risk threatens nearly 200,000 Linux Framework laptops: Signed UEFI shell components could be exploited to bypass Secure Boot protections. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/secure-boot-bypass-risk-on-nearly-200-000-linux-framework-sytems/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chinese hackers abuse geo-mapping tool for year-long persistence: Chinese hackers used a geo-mapping tool as a web shell for over a year. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/chinese-hackers-abuse-geo-mapping-tool-for-year-long-persistence/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft restricts IE mode access in Edge after zero-day attacks: Microsoft restricts IE mode access in Edge after zero-day attacks in Chakra JavaScript engine. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-restricts-ie-mode-access-in-edge-after-zero-day-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Massive multi-country botnet targets RDP services in the US: A large-scale botnet is targeting Remote Desktop Protocol (RDP) services in the United States. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/massive-multi-country-botnet-targets-rdp-services-in-the-us/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SonicWall VPN accounts breached using stolen creds: Threat actors compromised over a hundred SonicWall SSLVPN accounts via stolen credentials. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/sonicwall-vpn-accounts-breached-using-stolen-creds-in-widespread-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Microsoft&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft warns that Windows 10 reaches end of support today: Windows 10 will no longer receive patches for newly discovered security vulnerabilities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-that-windows-10-reaches-end-of-support-today/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft restricts IE mode access in Edge after zero-day attacks: Microsoft restricts IE mode access in Edge after zero-day attacks in Chakra JavaScript engine. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-restricts-ie-mode-access-in-edge-after-zero-day-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft ‘illegally’ tracked students via 365 Education: Austrian data protection regulator ruled Microsoft illegally tracked students and used their data. &lt;a href=&quot;https://pogowasright.org/microsoft-illegally-tracked-students-via-365-education-says-data-watchdog/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Healthcare&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SimonMed says 1.2 million patients impacted in January data breach: Medical imaging provider SimonMed Imaging is notifying over 1.2 million individuals of a data breach. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/simonmed-says-12-million-patients-impacted-in-january-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Trump Administration’s Increased Use of Social Media Surveillance: Trump administration uses AI to monitor public speech of foreign nationals and revoke visas. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/the-trump-administrations-increased-use-of-social-media-surveillance.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Protecting Privacy to Combat Authoritarianism: Surveillance is a powerful tool for authoritarian governments to stifle dissent. &lt;a href=&quot;https://pogowasright.org/protecting-privacy-to-combat-authoritarianism/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Surveillance</category><category>Cybersecurity</category><category>Data Breach</category><category>Healthcare</category><category>LinkedIn</category><category>Microsoft</category><category>Privacy Laws</category><category>Student Tracking</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breach-ai-surveillance-student-tracking-10-14-2025.webp" length="0" type="image/webp"/></item><item><title>Sanctions, Data Breach, Warfare &amp; UK Policy – 10/14/2025</title><link>https://grabtheaxe.com/news/sanctions-data-breach-warfare-uk-policy-10-14-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/sanctions-data-breach-warfare-uk-policy-10-14-2025/</guid><description>Stay compliant: UK sanctions list update, healthcare data breach settlements, Russian hybrid warfare risks, &amp; new UK pension policy. Read the full summary.</description><pubDate>Tue, 14 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/sanctions-data-breach-warfare-uk-policy-10-14-2025.webp&quot; alt=&quot;Data Breach&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates, including the UK’s move to a single sanctions list, significant healthcare data breaches, and the risks posed by Russian hybrid warfare. Additionally, upcoming identity verification requirements for UK pension scheme directors and the expiration of Medicare telehealth flexibilities demand immediate attention. Stay informed to navigate the evolving regulatory landscape and protect your organization from emerging threats.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Time to Switch: UK Moves to a Single Sanctions List by January 2026: The UK Sanctions List (UKSL) will be the single official source of UK sanctions designations starting January 2026, replacing the OFSI Consolidated List. &lt;a href=&quot;https://www.regulatoryandcompliance.com/2025/10/time-to-switch-uk-moves-to-a-single-sanctions-list-by-january-2026/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fort Wayne Medical Education Program Data Breach Affects Almost 30,000 Individuals: A data breach at the Fort Wayne Medical Education Program has compromised the data of nearly 30,000 individuals. &lt;a href=&quot;https://www.hipaajournal.com/fort-wayne-medical-education-program-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;$30 Million Settlement Agreed to Resolve Integris Health Class Action Data Breach Lawsuit: Integris Health settles a class action lawsuit for $30 million following a data breach. &lt;a href=&quot;https://www.hipaajournal.com/integris-health-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Russia’s Hybrid Warfare Triggers Logistics, Comms &amp;amp; Operational Disruption: US companies supporting Ukraine face increased risk of sabotage targeting logistics and communications. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/russia-hybrid-warfare-triggers-disruption/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FREE WEBINAR NEXT WEEK: Building a Compliant Workforce: A free webinar will be held next week focusing on how to build a compliant workforce. &lt;a href=&quot;https://www.hipaajournal.com/free-live-webinar/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FREE WEBINAR NEXT WEEK: Building a Compliant Workforce: A free webinar will be held next week focusing on how to build a compliant workforce. &lt;a href=&quot;https://www.hipaajournal.com/free-live-webinar/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Time to Switch: UK Moves to a Single Sanctions List by January 2026: The UK Sanctions List (UKSL) will be the single official source of UK sanctions designations starting January 2026, replacing the OFSI Consolidated List. &lt;a href=&quot;https://www.regulatoryandcompliance.com/2025/10/time-to-switch-uk-moves-to-a-single-sanctions-list-by-january-2026/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NY Lobbying and Ethics Commission Weighs Regulations Changes: The New York State Commission on Ethics and Lobbying in Government is considering several proposed changes to its regulations. &lt;a href=&quot;https://www.jdsupra.com/legalnews/ny-lobbying-and-ethics-commission-6967968/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Medicare Telehealth Flexibilities Expire: Temporary Medicare telehealth flexibilities implemented during the COVID-19 pandemic have expired, impacting service delivery. &lt;a href=&quot;https://www.jdsupra.com/legalnews/medicare-telehealth-flexibilities-expire-2640842/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Russia’s Hybrid Warfare Triggers Logistics, Comms &amp;amp; Operational Disruption: US companies supporting Ukraine face increased risk of sabotage targeting logistics and communications. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/russia-hybrid-warfare-triggers-disruption/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pension Scheme Trustee Directors – Identity Verification Requirements: New requirements for individual directors of UK companies, including pension scheme trustee directors, to verify their identity starting November 18, 2025. &lt;a href=&quot;https://www.jdsupra.com/legalnews/pension-scheme-trustee-directors-2344523/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Cyber Risk</category><category>Data Breach</category><category>Healthcare Compliance</category><category>Medicare</category><category>Sanctions</category><category>Telehealth</category><category>Third-Party Risk</category><category>UK Regulation</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/sanctions-data-breach-warfare-uk-policy-10-14-2025.webp" length="0" type="image/webp"/></item><item><title>Windows Zero-Days, Patch Tuesday &amp; Android Attacks – 10/14/2025</title><link>https://grabtheaxe.com/news/windows-zero-days-patch-tuesday-android-attacks-10-14-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/windows-zero-days-patch-tuesday-android-attacks-10-14-2025/</guid><description>Critical Patch Tuesday alert: Microsoft fixes 172 flaws and 6 zero-days as Windows 10 support ends. Get analysis on new Android attacks and CISA KEV updates.</description><pubDate>Tue, 14 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/windows-zero-days-patch-tuesday-android-attacks-10-14-2025.webp&quot; alt=&quot;Patch Tuesday&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is dominated by Microsoft’s October Patch Tuesday, which addresses a massive 172 flaws, including six zero-days under active exploitation. This release coincides with the final security update for Windows 10, officially marking its end-of-life. We are also tracking a novel ‘Pixnapping’ attack against Android devices capable of stealing MFA codes, a silent Oracle zero-day patch, and CISA’s addition of five new actively exploited vulnerabilities to its KEV catalog. Here is the critical intelligence you need to stay ahead of today’s threats.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws; Microsoft’s massive October Patch Tuesday addresses 172 vulnerabilities, including six zero-days that are already being actively exploited in the wild. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2025-patch-tuesday-fixes-6-zero-days-172-flaws/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Adds Five Known Exploited Vulnerabilities to Catalog: CISA has added five new vulnerabilities to its KEV catalog, including flaws in Microsoft Windows, requiring federal agencies to patch them immediately due to active exploitation. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/10/14/cisa-adds-five-known-exploited-vulnerabilities-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Android Pixnapping attack steals MFA codes pixel-by-pixel: A novel side-channel attack on Android, named Pixnapping, allows malicious apps without any special permissions to steal sensitive data like MFA codes by reconstructing screen pixels. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-android-pixnapping-attack-steals-mfa-codes-pixel-by-pixel/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Oracle silently fixes zero-day exploit leaked by ShinyHunters: Oracle has quietly patched a zero-day vulnerability in its E-Business Suite that was actively exploited after the ShinyHunters extortion group publicly leaked a proof-of-concept. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/oracles-silently-fixes-zero-day-exploit-leaked-by-shinyhunters/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chinese hackers abuse geo-mapping tool for year-long persistence: Chinese state-sponsored hackers (Flax Typhoon) maintained undetected access to a target’s network for over a year by turning a component of the ArcGIS geo-mapping tool into a persistent web shell. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/chinese-hackers-abuse-geo-mapping-tool-for-year-long-persistence/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence (APT, malware, ransomware)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;US seizes $15 billion in crypto from ‘pig butchering’ kingpin: The US Department of Justice has seized a staggering $15 billion in bitcoin from the leader of the Prince Group, a criminal organization behind widespread ‘pig butchering’ crypto scams. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/us-seizes-15-billion-in-crypto-from-pig-butchering-kingpin/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Taiwan reports surge in Chinese cyber activity and disinformation efforts: Taiwan’s National Security Bureau reports a significant increase in network intrusions and influence operations from China this year, with a strong focus on critical infrastructure. &lt;a href=&quot;https://therecord.media/taiwan-nsb-report-china-surge-cyberattacks-influence-operations&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Malicious crypto-stealing VSCode extensions resurface on OpenVSX: A threat actor is persistently targeting developers by publishing malicious Visual Studio Code extensions on multiple marketplaces to steal cryptocurrency and install backdoors. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-crypto-stealing-vscode-extensions-resurface-on-openvsx/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Signal in the noise: what hashtags reveal about hacktivism in 2025: Kaspersky researchers analyzed over 11,000 hacktivist posts to identify trends in how campaigns are organized and targeted, using hashtag data from the surface and dark web. &lt;a href=&quot;https://securelist.com/dfi-meta-hacktivist-report/117708/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Indiana city confirms ransomware hackers behind September incident: Officials in Michigan City, Indiana, have confirmed that a damaging cyber incident in September that crippled government systems was a ransomware attack. &lt;a href=&quot;https://therecord.media/michigan-indiana-city-ransomware&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Feds sanction Cambodian conglomerate over cyber scams, seize $15 billion from chairman: The U.S. Treasury Department has sanctioned the Prince Group and its chairman, seizing $15 billion in assets for its role in large-scale cyber scam operations. &lt;a href=&quot;https://therecord.media/feds-sanction-cambodian-conglomerate-scams-seize-15-billion&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Final Windows 10 Patch Tuesday update rolls out as support ends: Microsoft has released the final free cumulative security update for Windows 10, marking the official end of its support lifecycle and urging users to upgrade. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/final-windows-10-patch-tuesday-update-rolls-out-as-support-ends/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The king is dead, long live the king! Windows 10 EOL and Windows 11 forensic artifacts: With Windows 10 support ending, security experts are detailing the new and changed forensic artifacts in Windows 11 that will be critical for future incident response investigations. &lt;a href=&quot;https://securelist.com/forensic-artifacts-in-windows-11/117680/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Secure Boot bypass risk threatens nearly 200,000 Linux Framework laptops: A significant vulnerability was discovered in nearly 200,000 Framework laptops running Linux, where signed UEFI components could be exploited to bypass Secure Boot protections. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/secure-boot-bypass-risk-on-nearly-200-000-linux-framework-sytems/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Satellites found exposing unencrypted data, including phone calls and some military comms: Researchers have discovered satellites exposing large volumes of unencrypted data, including sensitive phone calls and military communications from providers like T-Mobile and AT&amp;amp;T. &lt;a href=&quot;https://techcrunch.com/2025/10/14/satellites-found-exposing-unencrypted-data-including-phone-calls-and-some-military-comms/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;California passes first U.S. law regulating AI companion chatbots: California has enacted the first law in the United States requiring safety measures for AI companion chatbots, prompted by tragic events involving young users. &lt;a href=&quot;https://the-decoder.com/california-passes-first-u-s-law-regulating-ai-companion-chatbots/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When AI Agents Join the Teams: The Hidden Security Shifts No One Expects: The increasing use of autonomous AI agents in IT operations is creating a ‘Shadow AI’ problem, introducing new security risks that require governing these agents as powerful identities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/when-ai-agents-join-the-teams-the-hidden-security-shifts-no-one-expects/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Android Security</category><category>CISA</category><category>Cybersecurity</category><category>Patch Tuesday</category><category>threat intelligence</category><category>vulnerability management</category><category>Windows 10 EOL</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/windows-zero-days-patch-tuesday-android-attacks-10-14-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breaches, Quantum Threat &amp; DC BEST Act – 10/13/2025</title><link>https://grabtheaxe.com/news/data-breaches-quantum-threat-dc-best-act-10-13-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breaches-quantum-threat-dc-best-act-10-13-2025/</guid><description>Compliance digest: Data breach settlements, quantum computing threats, D.C.&apos;s BEST Act, &amp; critical infrastructure data sprawl. Stay informed on key risks.</description><pubDate>Mon, 13 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breaches-quantum-threat-dc-best-act-10-13-2025.webp&quot; alt=&quot;Data Sprawl&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical data breach settlements and the growing threat landscape impacting various sectors. Key updates include a $4 million settlement for ALN Medical Management, a significant data breach at SimonMed Imaging affecting 1.27 million individuals, and warnings about the vulnerability of critical infrastructure due to unmonitored data. Additionally, the digest covers the long-term risks associated with quantum computing and new identity verification requirements for UK pension scheme directors.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SimonMed Imaging Data Breach: SimonMed Imaging is notifying 1.27M individuals affected by a January 2025 cyberattack. &lt;a href=&quot;https://www.hipaajournal.com/simonmed-imaging-confirms-january-2025-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ALN Medical Management Data Breach Settlement: ALN Medical Management to pay $4 million to settle class action data breach lawsuit. &lt;a href=&quot;https://www.hipaajournal.com/aln-medical-management-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical Infrastructure Data Sprawl: Critical infrastructure CISOs must address unmonitored back-office data to defend against nation-state actors. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/critical-infrastructure-back-office-data&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Quantum Computing Threat: Financial and other industries are urged to prepare for the potential of quantum computers breaking current encryption. &lt;a href=&quot;https://www.darkreading.com/cybersecurity-operations/financial-industries-urged-prepare-quantum-computers&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK Pension Scheme Identity Verification: New identity verification requirements coming into force for individual directors of UK companies, including pension scheme trustee directors. &lt;a href=&quot;https://www.jdsupra.com/legalnews/pension-scheme-trustee-directors-2344523/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HIPAA Data Breach Settlement: ALN Medical Management to pay $4 million to settle class action data breach lawsuit. &lt;a href=&quot;https://www.hipaajournal.com/aln-medical-management-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;DC’s BEST Act: Understanding D.C.’s New BEST Act and What It Means for Your Business. &lt;a href=&quot;https://www.harborcompliance.com/blog/understanding-d-c-s-new-best-act-and-what-it-means-for-your-business/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NY Lobbying and Ethics Commission: The New York State Commission on Ethics and Lobbying in Government is weighing regulations changes. &lt;a href=&quot;https://www.jdsupra.com/legalnews/ny-lobbying-and-ethics-commission-6967968/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Foreign Ownership Mitigation: Navigating Foreign Ownership Mitigation in the Commercial Space Era. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/navigating-foreign-ownership-mitigation-commercial-space-era/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;2025 Code of Conduct Report: Review of the 2025 Code of Conduct Report. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/lrn-2025-code-conduct-report/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Importance of ‘Feeling Heard’: Analysis of the importance of ‘feeling heard’ within organizations. &lt;a href=&quot;https://www.radicalcompliance.com/2025/10/13/importance-of-feeling-heard-yet-again/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>BEST Act</category><category>compliance</category><category>critical infrastructure</category><category>Data Breach</category><category>HIPAA</category><category>Quantum Computing</category><category>Regulatory Compliance</category><category>Third-Party Risk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breaches-quantum-threat-dc-best-act-10-13-2025.webp" length="0" type="image/webp"/></item><item><title>Oracle Zero-Day, Android 2FA Theft &amp; IE Exploit – 10/13/2025</title><link>https://grabtheaxe.com/news/oracle-zero-day-android-2fa-theft-ie-exploit-10-13-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/oracle-zero-day-android-2fa-theft-ie-exploit-10-13-2025/</guid><description>Daily security brief on a critical Oracle zero-day flaw requiring an emergency patch, a new &apos;Pixnapping&apos; attack stealing Android 2FA codes, and MS IE mode exploits.</description><pubDate>Mon, 13 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/oracle-zero-day-android-2fa-theft-ie-exploit-10-13-2025.webp&quot; alt=&quot;Oracle Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is dominated by critical, actively exploited vulnerabilities. Oracle has released an emergency patch for a zero-day flaw in its E-Business Suite, while Microsoft is forced to lock down IE Mode in Edge due to separate zero-day attacks. A novel ‘Pixnapping’ attack on Android devices can steal 2FA codes without permissions, and a massive botnet is targeting RDP services across the US. Here is what you need to know to stay protected.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Oracle releases emergency patch for new E-Business Suite flaw: Oracle has issued an out-of-band patch for a critical, unauthenticated remote execution vulnerability in its E-Business Suite. Immediate patching is required. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/oracle-releases-emergency-patch-for-new-e-business-suite-flaw/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft restricts IE mode access in Edge after zero-day attacks: Microsoft is locking down Internet Explorer mode in Edge after discovering active zero-day attacks exploiting the Chakra JavaScript engine for remote access. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-restricts-ie-mode-access-in-edge-after-zero-day-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hackers can steal 2FA codes and private messages from Android phones: A novel ‘Pixnapping’ side-channel attack allows a malicious Android app, requiring no permissions, to steal 2FA codes and private messages from the screen. &lt;a href=&quot;https://arstechnica.com/security/2025/10/no-fix-yet-for-attack-that-lets-hackers-pluck-2fa-codes-from-android-phones/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Massive multi-country botnet targets RDP services in the US: A large-scale botnet, originating from over 100,000 unique IP addresses, is actively conducting brute-force attacks against Remote Desktop Protocol (RDP) services in the U.S. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/massive-multi-country-botnet-targets-rdp-services-in-the-us/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SonicWall VPN accounts breached using stolen creds in widespread attacks: Threat actors have compromised over a hundred SonicWall SSLVPN accounts in a large-scale campaign using valid, stolen credentials to gain network access. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/sonicwall-vpn-accounts-breached-using-stolen-creds-in-widespread-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SimonMed says 1.2 million patients impacted in January data breach: U.S. medical imaging provider SimonMed is notifying 1.2 million individuals that their sensitive information was exposed in a data breach earlier this year. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/simonmed-says-12-million-patients-impacted-in-january-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Harvard investigating breach linked to Oracle zero-day exploit: Following its appearance on the Clop ransomware leak site, Harvard University is investigating a data breach linked to the newly disclosed Oracle E-Business Suite zero-day. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/harvard-investigating-breach-linked-to-oracle-zero-day-exploit/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK hit by record number of ‘nationally significant’ cyberattacks: The UK government reports a record number of major cyberattacks, prompting a direct appeal to business leaders to strengthen their enterprise security posture. &lt;a href=&quot;https://therecord.media/uk-hit-by-record-number-significant-cyberattacks&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors: The RondoDox botnet has significantly expanded its attack surface, now leveraging over 50 vulnerabilities in products from more than 30 vendors to compromise infrastructure. &lt;a href=&quot;https://thehackernews.com/2025/10/researchers-warn-rondodox-botnet-is.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs: A new backdoor written in Rust, named ChaosBot, is using Discord channels for command-and-control to execute commands and conduct reconnaissance on compromised systems. &lt;a href=&quot;https://thehackernews.com/2025/10/new-rust-based-malware-chaosbot-hijacks.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns: The Astaroth banking trojan is now using GitHub repositories to host its malware, making its C2 infrastructure more resilient against takedown efforts. &lt;a href=&quot;https://thehackernews.com/2025/10/astaroth-banking-trojan-abuses-github.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hackers Target ScreenConnect Features For Network Intrusions: Attackers are increasingly exploiting features within the ScreenConnect RMM tool, often via phishing, to gain unauthorized control over target systems and networks. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/hackers-target-screenconnects/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Why Signal’s post-quantum makeover is an amazing engineering achievement: Signal’s implementation of the ML-KEM algorithm sets a new, high standard for post-quantum readiness, protecting user communications from future cryptographic threats. &lt;a href=&quot;https://arstechnica.com/security/2025/10/why-signals-post-quantum-makeover-is-an-amazing-engineering-achievement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Meet Varonis Interceptor: AI-Native Email Security: Varonis has launched Interceptor, an AI-native email security platform that uses multimodal AI to detect and stop zero-hour phishing and social engineering attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/meet-varonis-interceptor-ai-native-email-security/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Building a lasting security culture at Microsoft: Microsoft outlines its internal strategy for creating a durable security culture, emphasizing that every employee has a critical role in protecting the company and its customers. &lt;a href=&quot;https://www.microsoft.com/en-us/security/blog/2025/10/13/building-a-lasting-security-culture-at-microsoft/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Netherlands invokes special powers against Chinese-owned semiconductor company Nexperia: Citing national security risks and ‘serious governance shortcomings,’ the Dutch government has taken control of the Chinese-owned chipmaker Nexperia. &lt;a href=&quot;https://therecord.media/netherlands-special-powers-chinese-owned-semiconductor&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Android Security</category><category>Botnet</category><category>Cybersecurity</category><category>Data Breach</category><category>Microsoft</category><category>Oracle Zero-Day</category><category>threat intelligence</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/oracle-zero-day-android-2fa-theft-ie-exploit-10-13-2025.webp" length="0" type="image/webp"/></item><item><title>Student Data, AI Ethics, Data Breaches &amp; Regulations – 10/13/2025</title><link>https://grabtheaxe.com/news/student-data-ai-ethics-breaches-regulations-10-13-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/student-data-ai-ethics-breaches-regulations-10-13-2025/</guid><description>Privacy alert: Microsoft student data tracking, AI ethics concerns, data breach impacts, and new privacy regulations. Stay informed and secure your data.</description><pubDate>Mon, 13 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/student-data-ai-ethics-breaches-regulations-10-13-2025.webp&quot; alt=&quot;Student Tracking&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights critical breaches affecting healthcare and education, alongside growing concerns about AI’s role in politics and liability. Microsoft faces scrutiny over student data tracking and its involvement in international conflicts. Additionally, vulnerabilities in Oracle and Microsoft products demand immediate attention to safeguard sensitive data.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft ‘illegally’ tracked students via 365 Education: Austrian data protection regulator ruled Microsoft illegally tracked students and used their data via 365 Education. &lt;a href=&quot;https://pogowasright.org/microsoft-illegally-tracked-students-via-365-education-says-data-watchdog/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SimonMed says 1.2 million patients impacted in January data breach: U.S. medical imaging provider SimonMed Imaging is notifying over 1.2 million individuals of a data breach. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/simonmed-says-12-million-patients-impacted-in-january-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SonicWall VPN accounts breached using stolen creds: Threat actors compromised more than a hundred SonicWall SSLVPN accounts in a large-scale campaign using stolen credentials. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/sonicwall-vpn-accounts-breached-using-stolen-creds-in-widespread-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Harvard investigating breach linked to Oracle zero-day exploit: Harvard University is investigating a data breach after the Clop ransomware gang listed the school on its data leak site. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/harvard-investigating-breach-linked-to-oracle-zero-day-exploit/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EFF urges action around Microsoft’s role in Israel’s War on Gaza: EFF and other organizations call on Microsoft to cease involvement in providing AI and cloud computing technologies for use in Israel’s actions. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/eff-and-five-human-rights-organizations-urge-action-around-microsofts-role-israels&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;California’s Latest Trio of Privacy Bills: New laws in California allow consumers greater control over their personal information. &lt;a href=&quot;https://www.bytebacklaw.com/2025/10/californias-latest-trio-of-privacy-bills-what-businesses-and-consumers-need-to-know/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;2025 Brought Us Eight US “Comprehensive” Privacy Laws: Maryland law went into effect on October 1st, bringing the total to 17 US state privacy laws in 2025. &lt;a href=&quot;https://www.eyeonprivacy.com/2025/10/2025-brought-us-eight-us-comprehensive-privacy-laws-whats-next/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Breaches&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SimonMed says 1.2 million patients impacted in January data breach: U.S. medical imaging provider SimonMed Imaging is notifying over 1.2 million individuals of a data breach that exposed their sensitive information. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/simonmed-says-12-million-patients-impacted-in-january-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Harvard investigating breach linked to Oracle zero-day exploit: Harvard University is investigating a data breach after the Clop ransomware gang listed the school on its data leak site. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/harvard-investigating-breach-linked-to-oracle-zero-day-exploit/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;AI&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI and the Future of American Politics: AI is poised to play a volatile role in America’s next federal election in 2026, with potential impacts for democracy. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/ai-and-the-future-of-american-politics.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Meet Varonis Interceptor: AI-Native Email Security: Varonis’ new Interceptor platform uses multimodal AI to detect zero-hour phishing and social engineering attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/meet-varonis-interceptor-ai-native-email-security/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Equity threatens mass direct action over use of actors’ images in AI content: Equity threatens action over use of members’ likenesses, images and voices in AI content without permission. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/13/equity-threatens-mass-direct-action-over-use-of-actors-images-in-ai-content&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI could make it harder to establish blame for medical failings: Experts warn AI in healthcare could create a legally complex blame game for medical failings. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/13/ai-tools-medical-health-liability-artificial-intelligence&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Microsoft&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft ‘illegally’ tracked students via 365 Education: Austrian data protection regulator ruled Microsoft illegally tracked students and used their data via 365 Education. &lt;a href=&quot;https://pogowasright.org/microsoft-illegally-tracked-students-via-365-education-says-data-watchdog/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft restricts IE mode access in Edge after zero-day attacks: Microsoft is restricting access to Internet Explorer mode in Edge browser after zero-day exploits. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-restricts-ie-mode-access-in-edge-after-zero-day-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft investigates outage affecting Microsoft 365 apps: Microsoft is investigating an ongoing incident preventing some customers from accessing Microsoft 365 applications. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-investigates-outage-affecting-microsoft-365-apps/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft: Windows 11 Media Creation Tool broken on Windows 10 PCs: The latest version of the Windows 11 Media Creation Tool (MCT) no longer works correctly on Windows 10 22H2 computers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-11-media-creation-tool-broken-on-windows-10-pcs/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EFF urges action around Microsoft’s role in Israel’s War on Gaza: EFF and other organizations call on Microsoft to cease involvement in providing AI and cloud computing technologies for use in Israel’s actions. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/eff-and-five-human-rights-organizations-urge-action-around-microsofts-role-israels&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Vulnerabilities&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft restricts IE mode access in Edge after zero-day attacks: Microsoft is restricting access to Internet Explorer mode in Edge browser after zero-day exploits. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-restricts-ie-mode-access-in-edge-after-zero-day-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Oracle releases emergency patch for new E-Business Suite flaw: Oracle has issued an emergency security update to patch another E-Business Suite (EBS) vulnerability. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/oracle-releases-emergency-patch-for-new-e-business-suite-flaw/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Harvard investigating breach linked to Oracle zero-day exploit: Harvard University is investigating a data breach after the Clop ransomware gang listed the school on its data leak site. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/harvard-investigating-breach-linked-to-oracle-zero-day-exploit/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI ethics</category><category>Data Breaches</category><category>Healthcare Data</category><category>Microsoft</category><category>Privacy Regulations</category><category>Student Data</category><category>VPN security</category><category>Zero-Day Exploit</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/student-data-ai-ethics-breaches-regulations-10-13-2025.webp" length="0" type="image/webp"/></item><item><title>Edge Vulns, Botnet Exploits, &amp; Regulations – 10/11/2025</title><link>https://grabtheaxe.com/news/edge-vulns-botnet-exploits-regulations-10-11-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/edge-vulns-botnet-exploits-regulations-10-11-2025/</guid><description>Edge vulns exploited by RondoDox botnet &amp; AI browser agent security gaps addressed. Plus: Victorian psychosocial regulations &amp; NCAA gambling policy updates.</description><pubDate>Sat, 11 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/edge-vulns-botnet-exploits-regulations-10-11-2025.webp&quot; alt=&quot;Edge Vulns&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance digest highlights critical security vulnerabilities and important regulatory updates. The RondoDox botnet’s exploit of edge device vulnerabilities and the AI browser agent security gaps addressed by 1Password are key concerns. Additionally, changes to Victorian psychosocial regulations, NCAA gambling policies, and H-2A wage rules demand immediate attention for compliance professionals.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;RondoDox Botnet: an ‘Exploit Shotgun’ for Edge Vulns: RondoDox takes a hit-and-run, shotgun approach to exploiting bugs in consumer edge devices around the world. &lt;a href=&quot;https://www.darkreading.com/endpoint-security/rondodox-botnet-exploit-edge-vulns&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1Password Addresses Critical AI Browser Agent Security Gap: The security company looks to tackle new authentication challenges that could lead to credential leakage, as enterprises increasingly leverage AI browser agents. &lt;a href=&quot;https://www.darkreading.com/identity-access-management-security/1password-addresses-critical-ai-browser-agent-security-gap&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ready or Not, Here They Come: The Victorian Psychosocial Regulations and Compliance Code Explained: On 30 September 2025, the Victorian Minister for WorkSafe and TAC made: The Occupational Health and Safety (Psychological Health) Regulations 2025 (the Victorian Regulations). &lt;a href=&quot;https://www.jdsupra.com/legalnews/ready-or-not-here-they-come-the-5077874/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NCAA Takes Steps to Permit Gambling on Professional Sports While Continuing to Crack Down on College Sports Betting: On October 8, 2025, the NCAA Division I Administrative Committee adopted a proposal that would allow for student-athletes and athletics department staff members to bet on professional sports. &lt;a href=&quot;https://www.jdsupra.com/legalnews/ncaa-takes-steps-to-permit-gambling-on-4357113/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Harvesting Change: the New H-2A Wage Rule for Agricultural Employers: The Department of Labor (DOL) recently issued an Interim Final Rule (IFR) that significantly revises the methodology for determining the Adverse Effect Wage Rates (AEWRs) for H-2A nonimmigrant workers in non-range occupations across the United States. &lt;a href=&quot;https://www.jdsupra.com/legalnews/harvesting-change-the-new-h-2a-wage-9387784/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Order in the HOA: Tips for Conducting Compliant and Transparent Board Meetings: Compliance with an HOA’s governing documents helps avoid legal liabilities and ensures decisions are made consistent with North Carolina law. &lt;a href=&quot;https://www.jdsupra.com/legalnews/order-in-the-hoa-tips-for-conducting-1232400/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Audit &amp;amp; Monitoring Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Legal Tech Audits: Improve Your Law Firm’s Efficiency and Security: As the legal industry becomes increasingly defined by the integration of advancing technologies, many law firms today are learning that having top legal talent is no longer enough to continue growing and remain competitive. &lt;a href=&quot;https://www.jdsupra.com/legalnews/legal-tech-audits-improve-your-law-firm-2520391/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Compliance Tip of the Day – Compliance Lessons from Wells Fargo’s AI-Assisted Whistleblower Program: Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. &lt;a href=&quot;https://www.jdsupra.com/legalnews/compliance-tip-of-the-day-compliance-l-92547/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Botnet</category><category>compliance</category><category>Edge Vulns</category><category>H-2A Wage Rule</category><category>NCAA</category><category>Regulations</category><category>RondoDox</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/edge-vulns-botnet-exploits-regulations-10-11-2025.webp" length="0" type="image/webp"/></item><item><title>SonicWall VPN Attacks, LockBit Tactics &amp; Apple Bounties – 10/11/2025</title><link>https://grabtheaxe.com/news/sonicwall-vpn-attacks-lockbit-tactics-apple-bounties-10-11-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/sonicwall-vpn-attacks-lockbit-tactics-apple-bounties-10-11-2025/</guid><description>Critical alert on widespread SonicWall VPN compromise. Analysis of LockBit ransomware weaponizing DFIR tools and Apple&apos;s increased bug bounty rewards for exploits.</description><pubDate>Sat, 11 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/sonicwall-vpn-attacks-lockbit-tactics-apple-bounties-10-11-2025.webp&quot; alt=&quot;SonicWall VPN Compromise&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s critical threat landscape is dominated by a widespread compromise of SonicWall SSL VPNs, where attackers are leveraging valid credentials for broad access. We are also tracking the evolution of ransomware tactics, as LockBit operators are now weaponizing the legitimate DFIR tool Velociraptor in their attacks. Additional intelligence covers Apple’s significant increase in bug bounty rewards and emerging developments in AI governance and research. Stay informed on these key issues.&lt;/p&gt;
&lt;h2&gt;Top 2 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Experts Warn of Widespread SonicWall VPN Compromise Impacting Over 100 Accounts: Huntress warns of a widespread compromise affecting SonicWall SSL VPN devices, where attackers are using valid credentials for rapid, large-scale access to customer environments. &lt;a href=&quot;https://thehackernews.com/2025/10/experts-warn-of-widespread-sonicwall.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacks — Threat actors associated with the LockBit ransomware are abusing the open-source digital forensics and incident response (DFIR) tool Velociraptor to facilitate their attacks. &lt;a href=&quot;https://thehackernews.com/2025/10/hackers-turn-velociraptor-dfir-tool.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Apple ups the reward for finding major exploits to $2 million — To incentivize security research, Apple has increased its maximum bug bounty reward to $2 million for major exploits, with potential bonuses pushing the total payout to $5 million. &lt;a href=&quot;https://arstechnica.com/security/2025/10/apple-ups-the-reward-for-finding-major-exploits-to-2-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google Deepmind’s “Vibe Checker” aims to rate AI code by human standards — A new study from Google DeepMind proposes a new benchmark to evaluate AI-generated code based on human developer preferences rather than just functional correctness. &lt;a href=&quot;https://the-decoder.com/google-deepminds-vibe-checker-aims-to-rate-ai-code-by-human-standards/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI accused of pressuring AI regulation advocates with subpoenas — Reports indicate OpenAI has served subpoenas to civil society groups and individuals advocating for stricter AI regulations, raising concerns about corporate influence on policy. &lt;a href=&quot;https://the-decoder.com/openai-accused-of-pressuring-ai-regulation-advocates-with-subpoenas/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A new information-theory framework reveals when multi-agent AI systems truly work as a team — Researchers have developed a new framework to measure genuine teamwork in multi-agent AI systems, helping to distinguish collaborative intelligence from simple parallel task execution. &lt;a href=&quot;https://the-decoder.com/a-new-information-theory-framework-reveals-when-multi-agent-ai-systems-truly-work-as-a-team/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Apple security</category><category>Bug Bounty</category><category>Cybersecurity</category><category>DFIR</category><category>LockBit</category><category>ransomware</category><category>SonicWall</category><category>threat intelligence</category><category>VPN security</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/sonicwall-vpn-attacks-lockbit-tactics-apple-bounties-10-11-2025.webp" length="0" type="image/webp"/></item><item><title>Zero-Day Exploit, Data Scraping &amp; Foster Youth Risks – 10/11/2025</title><link>https://grabtheaxe.com/news/zero-day-exploit-data-scraping-foster-youth-risks-10-11-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/zero-day-exploit-data-scraping-foster-youth-risks-10-11-2025/</guid><description>Zero-day exploit in Gladinet, data scraping privacy clash, and identity theft risks for foster youth. Stay informed on today&apos;s top privacy threats.</description><pubDate>Sat, 11 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/zero-day-exploit-data-scraping-foster-youth-risks-10-11-2025.webp&quot; alt=&quot;Data Scraping&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights the exploitation of a zero-day vulnerability in Gladinet file sharing software, posing a significant risk to system files. We also examine the privacy implications of data scraping for AI, the risks of identity theft for foster youth, and ongoing scams targeting consumers. Stay informed to protect your data and privacy.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hackers exploiting zero-day in Gladinet file sharing software: Threat actors are exploiting a zero-day vulnerability (CVE-2025-11371) in Gladinet CentreStack and Triofox products. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-exploiting-zero-day-in-gladinet-file-sharing-software/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Article: The Great Scrape: The Clash Between Scraping and Privacy: AI systems depend on scraped data, often containing personal information, impacting tools like facial recognition. &lt;a href=&quot;https://pogowasright.org/article-the-great-scrape-the-clash-between-scraping-and-privacy-2/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to help protect foster youth from identity theft: Foster youth are at greater risk of identity theft due to frequent moves and increased access to their information. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone: Scammers impersonate FTC officials to steal money; the FTC will never ask you to move your money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?: Amazon is refunding consumers who were enrolled in Prime subscriptions without their consent and then made it difficult to cancel. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls: Sharing your information online can lead to unwanted telemarketing calls, which are illegal if you’re on the Do Not Call Registry. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon?: Amazon is refunding consumers who were enrolled in Prime subscriptions without their consent and then made it difficult to cancel. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Uncategorized&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams: Having a plan and knowing how to spot disaster-related scams can make a difference to anyone recovering from a disaster. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to help protect foster youth from identity theft: Foster youth are at greater risk of identity theft due to frequent moves and increased access to their information. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone: Scammers impersonate FTC officials to steal money; the FTC will never ask you to move your money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Get a credit freeze to stop identity thieves: Freezing your credit is a great way to protect yourself from identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/get-credit-freeze-stop-identity-thieves&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams: Scammers are active during Medicare Open Enrollment, so learn to spot the scams to protect your money and information. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams: Be cautious when selling your timeshare, as there are many scams to watch out for. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going: Ensure that the fundraiser is legitimate and that your money will be spent as promised. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam: Learn how to identify phony business opportunities, work-at-home scams, and shady employment agencies. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tony Blair and Nick Clegg hosted dinner giving tech bosses access to UK minister: Tony Blair and Nick Clegg hosted a private dinner for tech leaders to meet with a UK minister. &lt;a href=&quot;https://www.theguardian.com/politics/2025/oct/11/tony-blair-and-nick-clegg-hosted-dinner-giving-tech-bosses-access-to-uk-minister&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Using a swearword in your Google search can stop the AI answer. But should you?: Using a swear word in your Google search can stop the AI answer from popping up. &lt;a href=&quot;https://www.theguardian.com/technology/2025/oct/11/using-a-swearword-in-your-google-search-can-stop-the-ai-answer-but-should-you&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Watch Now: Navigating Surveillance with EFF Members: EFF partnered with WISP to discuss online behavioral tracking and the data broker industry. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/watch-now-navigating-surveillance-eff-members&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EFF Austin: Organizing and Making a Difference in Central Texas: EFF-Austin advocates for digital rights and educates the public about emerging technologies. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/eff-austin-organizing-and-making-difference-central-texas&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Cybersecurity</category><category>Data Scraping</category><category>FTC Scams</category><category>Identity Theft</category><category>Online Surveillance</category><category>Privacy</category><category>Zero-Day Exploit</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/zero-day-exploit-data-scraping-foster-youth-risks-10-11-2025.webp" length="0" type="image/webp"/></item><item><title>AML Failures, AI Law, Data Breach, FCA Scheme – 10/08/2025</title><link>https://grabtheaxe.com/news/aml-failures-ai-law-data-breach-fca-scheme-10-08-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/aml-failures-ai-law-data-breach-fca-scheme-10-08-2025/</guid><description>AML failures in Europe, Vietnam&apos;s AI law, data breach at Harris Health, &amp; FCA redress scheme. Stay compliant with the latest security updates.</description><pubDate>Wed, 08 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/aml-failures-ai-law-data-breach-fca-scheme-10-08-2025.webp&quot; alt=&quot;AML Failures&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates, including Varengold Bank’s AML failures and the FCA’s consultation on UK motor finance. We also cover a 10-year insider data breach at Harris Health, along with active exploitation of vulnerabilities in Oracle E-Business Suite and Fortra’s GoAnywhere. Stay informed on key regulatory changes and emerging cyber threats impacting compliance.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Varengold Bank’s AML failures: A cautionary tale for Europe’s financial sector: Germany’s financial regulator BaFin fined Varengold Bank AG €3.3 million for AML control weaknesses stemming from systemic governance failures. &lt;a href=&quot;https://vinciworks.com/blog/varengold-banks-aml-failures-a-cautionary-tale-for-europes-financial-sector/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FCA Starts Consultation on UK Motor Finance Consumer Redress Scheme: The FCA published a consultation paper on an industry-wide scheme to compensate motor finance customers who were treated unfairly between 2007 and 2024. &lt;a href=&quot;https://www.regulatoryandcompliance.com/2025/10/fca-starts-consultation-on-uk-motor-finance-consumer-redress-scheme/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Harris Health Notifies Patients About 10-Year Insider Data Breach: Harris Health in Texas notified over 5,000 patients about a potential data breach where electronic health records may have been compromised. &lt;a href=&quot;https://www.hipaajournal.com/harris-health-10-year-insider-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cl0p Mass Exploiting Zero-day Vulnerability in Oracle E-Business Suite: A zero-day vulnerability in Oracle E-Business Suite is under active exploitation by the Cl0p ransomware group. &lt;a href=&quot;https://www.hipaajournal.com/cl0p-mass-exploiting-zero-day-vulnerability-oracle-e-business-suite/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical GoAnywhere Vulnerability Exploited in Medusa Ransomware Attacks: A critical vulnerability in Fortra’s GoAnywhere MFT secure web-based file transfer tool is being actively exploited in Medusa ransomware attacks. &lt;a href=&quot;https://www.hipaajournal.com/critical-goanywhere-vulnerability-medusa-ransomware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Vietnam: Releasing draft AI Law for comprehensive AI governance framework: Vietnam’s draft AI Law aims to establish a comprehensive AI governance framework by January 2026, introducing phased implementation, risk-based classification, and strict penalties for violations. &lt;a href=&quot;https://www.globalcompliancenews.com/2025/10/08/https-insightplus-bakermckenzie-com-bm-data-technology-vietnam-releasing-draft-ai-law-for-comprehensive-ai-governance-framework_10032025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Brazil: Data Protection Authority becomes a regulatory agency and assumes new responsibilities for the digital protection of children and adolescents: The Brazilian Data Protection Authority (ANPD) now oversees digital protections for children and adolescents, including enforcing court orders and setting security standards. &lt;a href=&quot;https://www.globalcompliancenews.com/2025/10/08/https-insightplus-bakermckenzie-com-bm-data-technology-brazil-data-protection-authority-becomes-a-regulatory-agency-and-assumes-new-responsibilities-for-the-digital-protection-of-children-and-adoles/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;United States: White House publishes plan for the taxation of cryptocurrencies and other digital assets: The US Administration’s Working Group on Digital Asset Markets published recommendations for revising legislation and IRS guidance regarding cryptocurrency taxation. &lt;a href=&quot;https://www.globalcompliancenews.com/2025/10/08/https-insightplus-bakermckenzie-com-bm-financial-institutions_1-united-states-white-house-p/a_1-united-states-white-house-publishes-plan-for-the-taxation-of-cryptocurrencies-and-other-digital-assets_09302025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ukraine: Approval of Defence City regime for arms manufacturers including tax and customs incentives: Ukraine’s Defence City regime offers tax, customs, and regulatory incentives to defence-related enterprises, effective from October 2025. &lt;a href=&quot;https://www.globalcompliancenews.com/2025/10/08/https-insightplus-bakermckenzie-com-bm-industrials-manufacturing-transportation-kyiv-ukraine-approves-defence-city-regime-for-arms-manufacturers-including-tax-and-customs-incentives_09222025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Why Are Your Policies Yelling at Me? It’s Time to Rethink Tone in Rules. — Policy-writing expert Lewis Eisen examines how corporate policies are often worded more harshly than laws governing serious crimes, undermining positive relationships and cooperative workplaces. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/why-are-your-policies-yelling-at-me/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Why Letting Go of Control Can Strengthen Your E&amp;amp;C Program: Smart governance builds processes that feel natural; bureaucracy multiplies steps until employees seek workarounds. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/letting-go-control-can-strengthen-program/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Colombia adopts the first certifiable international standard for AI systems: ISO/IEC 42001:2023: Organizations in Colombia can now adopt ISO/IEC 42001:2023, becoming among the first in Latin America with a certifiable standard for responsible AI management. &lt;a href=&quot;https://www.globalcompliancenews.com/2025/10/08/https-insightplus-bakermckenzie-com-bm-technology-media-telecommunications_1-colombia-adopts-the-first-certifiable-international-standard-for-ai-systems-isoiec-420012023_09292025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Audit &amp;amp; Monitoring Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Types of Penetration Tests: A Look at Different Pentest Techniques &amp;amp; Tools: A blog post discussing penetration testing techniques and tools, including their relation to SOC 2 requirements and comparison to vulnerability assessments. &lt;a href=&quot;https://linfordco.com/blog/types-penetration-tests-tools/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Incident Response Management Best Practices for Financial Services Compliance Executives — No content available. &lt;a href=&quot;https://www.smarsh.com/blog/thought-leadership/incident-response-management-best-practices-financial-services-compliance&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Calling All Influencers: Spear-Phishers Dangle Tesla, Red Bull Jobs: Cyberattackers are using impersonation campaigns aimed at stealing résumés from social media pros. &lt;a href=&quot;https://www.darkreading.com/remote-workforce/influencers-phishers-tesla-red-bull-jobs&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;2025 Asia-Pacific Community Meeting Agenda Highlights: The 2025 PCI SSC Asia-Pacific Community Meeting will take place in Bangkok, Thailand on 5-6 November. &lt;a href=&quot;https://blog.pcisecuritystandards.org/2025-asia-pacific-community-meeting-agenda-highlights&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Law</category><category>AML</category><category>Cybersecurity</category><category>Data Breach</category><category>FCA</category><category>Financial Regulation</category><category>Healthcare</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/aml-failures-ai-law-data-breach-fca-scheme-10-08-2025.webp" length="0" type="image/webp"/></item><item><title>ALPR Abuse, AI Influence, Discord Breach – 10/07/2025</title><link>https://grabtheaxe.com/news/alpr-abuse-ai-influence-discord-breach-10-07-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/alpr-abuse-ai-influence-discord-breach-10-07-2025/</guid><description>Privacy alert: ALPR misuse in Texas, AI influence campaign, &amp; Discord data breach exposing IDs. Plus, spyware in UAE &amp; CISA guidance updates.</description><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/alpr-abuse-ai-influence-discord-breach-10-07-2025.webp&quot; alt=&quot;Data Misuse&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy intelligence digest reveals critical privacy threats, including the misuse of ALPR data by law enforcement in Texas, a sophisticated AI-driven influence operation targeting Iran, and a significant data breach at Discord exposing user IDs. We also cover spyware campaigns targeting messaging app users in the UAE and updated guidance from CISA for government contractors on SBOM. Here’s your concise update to stay informed and prepared.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Flock Safety ALPR Abuse: Texas sheriff misused license plate reader data in an abortion investigation, contradicting initial claims. The investigation involved accessing data across state lines. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/flock-safety-and-texas-sheriff-claimed-license-plate-search-was-missing-person-it&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI-Enabled Influence Operation: Citizen Lab uncovers an AI-driven influence campaign against Iran, likely conducted by Israel, using inauthentic X profiles. The operation aimed to incite revolt against the Iranian government. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/ai-enabled-influence-operation-against-iran.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Discord Data Breach: Proof-of-age IDs, including driver’s licenses and passports, were leaked in a Discord data breach via a third-party customer service provider. Users who contacted customer service or trust and safety teams were affected. &lt;a href=&quot;https://www.theguardian.com/games/2025/10/07/discord-data-breach-proof-of-age-id-leaked&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Spyware Targeting UAE Messaging App Users: Researchers discovered spyware embedded in fake messaging apps targeting users in the United Arab Emirates. The spyware campaigns, ProSpy and ToSpy, pose as Signal and ToTok. &lt;a href=&quot;https://pogowasright.org/researchers-uncover-spyware-targeting-messaging-app-users-in-the-uae/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Software Bill of Materials Guidance: CISA issued updated guidance for government contractors on Software Bill of Materials (SBOM), following NTIA’s 2021 publication. The guidance responds to Executive Order 14028 on improving cybersecurity. &lt;a href=&quot;https://www.gtlaw-dataprivacydish.com/2025/10/software-bill-of-materials-guidance-for-government-contractors/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Opt Out October: Daily Tips to Protect Your Privacy and Security: EFF provides daily tips throughout October to help users opt out of tech giants’ surveillance practices. Tips include establishing digital hygiene, learning about data brokers, and disabling ad tracking. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FTC Consumer Alerts: The FTC warns consumers about various scams, including impersonating FTC officials, fake job opportunities, and disaster-related schemes. The alerts also cover refunds from Amazon and protecting foster youth from identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Influence</category><category>ALPR</category><category>CISA</category><category>Data Breach</category><category>Data Privacy</category><category>Discord</category><category>Government Contractors</category><category>SBOM</category><category>spyware</category><category>Surveillance</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/alpr-abuse-ai-influence-discord-breach-10-07-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breach, GDPR, Cyber Tech &amp; FinCrime – 10/06/2025</title><link>https://grabtheaxe.com/news/data-breach-gdpr-cyber-fincrime-10-06-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breach-gdpr-cyber-fincrime-10-06-2025/</guid><description>Stay ahead: Data breach settlement, GDPR training insights, Chinese cyber tech exploitation, and AI in FinCrime prevention. Read the full compliance digest.</description><pubDate>Mon, 06 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breach-gdpr-cyber-fincrime-10-06-2025.webp&quot; alt=&quot;GDPR Training&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates, including a $5 million settlement in an EyeMed data breach case and key insights into GDPR compliance training. We also cover the rise of self-propagating malware targeting WhatsApp users in Brazil and the concerning trend of Chinese government fronts exploiting Western cyber tech. Stay informed on these pressing issues to enhance your organization’s risk management and compliance strategies.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EyeMed Vision Care Agrees to Pay $5 Million to Settle Class Action Data Breach Lawsuit: EyeMed Vision Care settles a class action lawsuit stemming from a June 2020 data breach for $5 million. &lt;a href=&quot;https://www.hipaajournal.com/eyemed-vision-care-class-action-data-breach-settlement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;5 common GDPR mistakes – and how training can fix them: Common GDPR breaches arise from everyday slip-ups; training can mitigate risks of complaints, investigations, and fines. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/5-common-gdpr-mistakes-and-how-training-can-fix-them&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Self-Propagating Malware Hits WhatsApp Users in Brazil: The Water Saci campaign spreads Sorvepotel malware, stealing credentials and monitoring browser activity to defraud financial institutions. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/self-propagating-malware-hits-whatsapp-users-brazil&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chinese Gov’t Fronts Trick the West to Obtain Cyber Tech: Outwardly neutral Chinese institutions collaborate with Western organizations and researchers for PRC state intelligence. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/chinese-govt-fronts-cyber-tech&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Why Most Banks Are Not Ready for Agentic AI in FinCrime Prevention (and How to Get There): Readiness assessments and strategic guardrails separate transformative adoption from costly failures in FinCrime prevention using Agentic AI. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/why-most-banks-are-not-ready-agentic-ai/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EyeMed Vision Care Agrees to Pay $5 Million to Settle Class Action Data Breach Lawsuit: EyeMed Vision Care settles a class action lawsuit stemming from a June 2020 data breach for $5 million. &lt;a href=&quot;https://www.hipaajournal.com/eyemed-vision-care-class-action-data-breach-settlement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FinReg Monthly Update: Highlights the latest developments in UK and EU financial services regulation for September 2025, including FCA priorities. &lt;a href=&quot;https://www.regulatoryandcompliance.com/2025/10/finreg-monthly-update-september-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Streamlining Consumer Duty – A Welcome Update from the FCA: Discusses the challenges and updates regarding the implementation of the FCA Consumer Duty regime. &lt;a href=&quot;https://www.regulatoryandcompliance.com/2025/10/streamlining-consumer-duty-a-welcome-update-from-the-fca/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Chinese Gov’t Fronts Trick the West to Obtain Cyber Tech: Outwardly neutral Chinese institutions collaborate with Western organizations and researchers for PRC state intelligence. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/chinese-govt-fronts-cyber-tech&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New Presidential Memo: Why Federal Grantees Should Engage in Byrd Watching: A Presidential Memorandum addresses the Attorney General regarding the use of appropriated funds for illegal lobbying and partisan political activity by federal grantees. &lt;a href=&quot;https://www.jdsupra.com/legalnews/new-presidential-memo-why-federal-6848189/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Between Silence &amp;amp; Oversharing: Navigating Tariff Disclosure in a Shifting Trade Environment: Discusses navigating tariff disclosure in a shifting trade environment. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/navigating-tariff-disclosure-shifting-trade-environment/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;5 common GDPR mistakes – and how training can fix them: Common GDPR breaches arise from everyday slip-ups; training can mitigate risks of complaints, investigations, and fines. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/5-common-gdpr-mistakes-and-how-training-can-fix-them&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Cybersecurity</category><category>Data Breach</category><category>Financial Regulation</category><category>FinCrime</category><category>GDPR</category><category>HIPAA</category><category>Malware</category><category>Third-Party Risk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breach-gdpr-cyber-fincrime-10-06-2025.webp" length="0" type="image/webp"/></item><item><title>Oracle Zero-Day, Clop Attacks &amp; GoAnywhere Exploit – 10/06/2025</title><link>https://grabtheaxe.com/news/oracle-zero-day-clop-attacks-goanywhere-exploit-10-06-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/oracle-zero-day-clop-attacks-goanywhere-exploit-10-06-2025/</guid><description>Critical Oracle zero-day (CVE-2025-61882) actively exploited by Clop ransomware. Get details on the GoAnywhere MFT bug, Red Hat data breach, and other top threats.</description><pubDate>Mon, 06 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/oracle-zero-day-clop-attacks-goanywhere-exploit-10-06-2025.webp&quot; alt=&quot;Oracle Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is dominated by a critical Oracle E-Business Suite zero-day vulnerability being actively exploited by the Clop ransomware gang for data theft, prompting urgent patch advisories from the FBI and CISA. Additionally, a severe GoAnywhere MFT bug is being used to deploy Medusa ransomware, and the Red Hat data breach has escalated with the involvement of the ShinyHunters extortion group. This summary covers the essential details you need to know to protect your organization.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Oracle E-Business Suite Zero-Day Under Active Exploit by Clop: A critical unauthenticated RCE vulnerability (CVE-2025-61882) in Oracle’s E-Business Suite is being actively exploited by the Clop ransomware gang for data theft attacks, prompting an emergency patch. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/oracle-patches-ebs-zero-day-exploited-in-clop-data-theft-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FBI and UK Gov Issue Urgent Warning on Oracle Vulnerability: The FBI and UK’s NCSC are urging all organizations to patch the Oracle EBS zero-day immediately, describing it as a ‘stop-what-you’re-doing’ level threat due to widespread exploitation by Clop. &lt;a href=&quot;https://therecord.media/fbi-uk-urge-orgs-to-patch-after-clop-campaign&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical GoAnywhere MFT Bug Exploited in Medusa Ransomware Attacks: Microsoft reports that cybercrime group Storm-1175 is exploiting a maximum severity vulnerability (CVE-2025-10035) in Fortra’s GoAnywhere MFT to deploy Medusa ransomware. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-critical-goanywhere-bug-exploited-in-ransomware-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Red Hat Data Breach Escalates as ShinyHunters Joins Extortion: The data breach impacting enterprise software giant Red Hat has worsened, with the ShinyHunters extortion group now leaking stolen customer data and demanding a ransom. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/red-hat-data-breach-escalates-as-shinyhunters-joins-extortion/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Redis Warns of Critical RCE Flaw Impacting Thousands of Instances: Redis has patched a maximum severity vulnerability that could allow unauthenticated attackers to achieve remote code execution on thousands of internet-exposed instances. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/redis-warns-of-max-severity-flaw-impacting-thousands-of-instances/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;XWorm Malware Resurfaces with Ransomware Module and 35+ Plugins: The XWorm backdoor is being distributed in new phishing campaigns, now upgraded with a ransomware module and over 35 plugins for enhanced malicious capabilities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/xworm-malware-resurfaces-with-ransomware-module-over-35-plugins/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Malware Leverages WhatsApp to Target Brazilian Organizations: A self-propagating malware is targeting Brazilian government and business users via WhatsApp, hijacking contact lists to spread and steal financial data. &lt;a href=&quot;https://therecord.media/brazil-malware-whatsapp-sorvepotel&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Suspected Chinese Cyber Spies Targeted Serbian Aviation Agency: A hacking group believed to be linked to China has targeted a Serbian government aviation department and other European institutions in a cyberespionage campaign. &lt;a href=&quot;https://therecord.media/suspected-chinese-spies-serbia&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Zimbra Zero-Day Exploited to Target Brazilian Military: A now-patched XSS zero-day vulnerability (CVE-2025-27915) in Zimbra Collaboration was used in attacks against the Brazilian military via malicious ICS calendar files. &lt;a href=&quot;https://thehackernews.com/2025/10/zimbra-zero-day-exploited-to-target.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Steam and Microsoft Warn of Unity Flaw Exposing Gamers to Attacks: A code execution vulnerability in the popular Unity game engine could be exploited by attackers to compromise gamers’ systems on both Android and Windows. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/steam-and-microsoft-warn-of-unity-flaw-exposing-gamers-to-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How We Trained an ML Model to Detect DLL Hijacking: Kaspersky researchers provide a detailed breakdown of how they developed and trained a machine learning model to effectively identify and prevent DLL hijacking attacks. &lt;a href=&quot;https://securelist.com/building-ml-model-to-detect-dll-hijacking/117565/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Zeroday Cloud Hacking Contest Offers $4.5 Million in Bounties: A new bug bounty competition, Zeroday Cloud, has been launched with a $4.5 million prize pool to encourage researchers to find and report exploits in open-source cloud and AI tools. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/zeroday-cloud-hacking-contest-offers-45-million-in-bounties/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Adds Seven Known Exploited Vulnerabilities to Catalog: CISA has added seven vulnerabilities to its KEV catalog, including the critical Oracle EBS flaw (CVE-2025-61882), mandating immediate patching for federal agencies. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/10/06/cisa-adds-seven-known-exploited-vulnerabilities-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;California Passes First Sweeping AI Safety Law: California has enacted SB 53, the first broad AI safety law in the U.S., which mandates that major AI developers adhere to strict safety protocols to prevent catastrophic risks. &lt;a href=&quot;https://the-decoder.com/california-passes-first-sweeping-ai-safety-law/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Role of Artificial Intelligence in Today’s Cybersecurity Landscape: An analysis of how AI is transforming cybersecurity by enhancing threat detection, accelerating incident response, and enabling smarter threat hunting in XDR and SIEM platforms. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/the-role-of-artificial-intelligence-in-todays-cybersecurity-landscape/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Clop Ransomware</category><category>CVE-2025-61882</category><category>Cybersecurity</category><category>Data Breach</category><category>GoAnywhere MFT</category><category>Medusa Ransomware</category><category>Oracle Zero-Day</category><category>threat intelligence</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/oracle-zero-day-clop-attacks-goanywhere-exploit-10-06-2025.webp" length="0" type="image/webp"/></item><item><title>Cybercriminal Tactics, Nation-State Hackers – 10/05/2025</title><link>https://grabtheaxe.com/news/cybercriminal-tactics-nation-state-hackers-10-05-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cybercriminal-tactics-nation-state-hackers-10-05-2025/</guid><description>Understand cybercriminal and nation-state hacker tactics. Learn how they operate in this Dark Reading virtual event. Stay ahead of threats! - 10/05/2025</description><pubDate>Sun, 05 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cybercriminal-tactics-nation-state-hackers-10-05-2025.webp&quot; alt=&quot;Cybercriminal Tactics&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s compliance digest highlights the critical need to understand the evolving tactics of cybercriminals and nation-state actors. A Dark Reading virtual event focuses on providing insights into how these adversaries operate. Understanding these methods is crucial for developing effective defense strategies and maintaining robust security postures.&lt;/p&gt;
&lt;h2&gt;Critical Compliance Alert&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;[Dark Reading Virtual Event] Know Your Enemy: How cybercriminals and nation-state hackers operate: Learn about the tactics and strategies employed by cybercriminals and nation-state actors in this Dark Reading virtual event. &lt;a href=&quot;https://www.darkreading.com/events/-dark-reading-virtual-event-know-your-enemy-how-cybercriminals-and-nation-state-hackers-operate&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Cybercriminals</category><category>Cybersecurity</category><category>Dark Reading</category><category>Incident Response</category><category>Nation-State Hackers</category><category>threat intelligence</category><category>vulnerability management</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/cybercriminal-tactics-nation-state-hackers-10-05-2025.webp" length="0" type="image/webp"/></item><item><title>Zimbra Flaw, ParkMobile Breach &amp; Data Scams – 10/05/2025</title><link>https://grabtheaxe.com/news/zimbra-flaw-parkmobile-breach-data-scams-10-05-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/zimbra-flaw-parkmobile-breach-data-scams-10-05-2025/</guid><description>Zimbra zero-day exploit, ParkMobile&apos;s breach settlement, and a rise in data scams. Stay informed about today&apos;s top privacy threats and how to protect yourself.</description><pubDate>Sun, 05 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/zimbra-flaw-parkmobile-breach-data-scams-10-05-2025.webp&quot; alt=&quot;Data Scams&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights critical security flaws, data breach settlements, and a surge in scams targeting consumers. A zero-day vulnerability in Zimbra is being actively exploited, while ParkMobile’s settlement for a 2021 data breach offers minimal compensation. Additionally, the FTC warns of scammers impersonating officials and provides guidance on avoiding job, timeshare, and donation scams. Stay informed to protect your data and finances.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hackers exploited Zimbra flaw as zero-day using iCalendar files : A flaw in Zimbra Collaboration Suite was exploited in zero-day attacks. Researchers found the attacks while monitoring .ICS calendar attachments. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-exploited-zimbra-flaw-as-zero-day-using-icalendar-files/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ParkMobile pays… $1 each for 2021 data breach that hit 22 million : ParkMobile settles class action over 2021 data breach affecting 22 million users, offering a mere $1 in-app credit as compensation. Victims must manually claim it before it expires. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/parkmobile-pays-1-each-for-2021-data-breach-that-hit-22-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone : Scammers impersonate FTC officials to steal money, urging victims to move funds. The FTC never tells people to move money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to help protect foster youth from identity theft : Foster youth are at higher risk of identity theft due to frequent moves and multiple access points to their information. Learn how to protect them. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls : Companies trick users into sharing data, then sell it to telemarketers, resulting in illegal calls. Learn to reduce unwanted telemarketing. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon? : Amazon agreed to pay $2.5 billion for enrolling users in Prime without consent and making cancellation difficult. Find out who gets a refund. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ParkMobile pays… $1 each for 2021 data breach that hit 22 million : ParkMobile settles class action over 2021 data breach affecting 22 million users, offering a mere $1 in-app credit as compensation. Victims must manually claim it before it expires. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/parkmobile-pays-1-each-for-2021-data-breach-that-hit-22-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;AI &amp;amp; Chatbots&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ChatGPT social could be a thing, as leak shows direct messages support : Leaks suggest OpenAI plans to add direct messaging support to ChatGPT, expanding its functionality beyond a chatbot. It could become a social platform. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-social-could-be-a-thing-as-leak-shows-direct-messages-support/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI rolls out GPT Codex Alpha with early access to new models : OpenAI releases GPT Codex Alpha, offering early access to new models and improvements for vibe coding. Codex is making waves in the industry. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/openai-rolls-out-gpt-codex-alpha-with-early-access-to-new-models/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI wants ChatGPT to be your emotional support : OpenAI aims to enhance ChatGPT’s emotional support capabilities, improving beyond GPT-4o. The goal is for ChatGPT to offer better emotional assistance. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/openai-wants-chatgpt-to-be-your-emotional-support/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI prepares $4 ChatGPT Go for several new countries : OpenAI is expanding its cheaper ChatGPT “Go” plan to more countries after initial testing. This provides a more affordable option. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/openai-prepares-4-chatgpt-go-for-several-new-countries/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Scams &amp;amp; Fraud&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone : Scammers impersonate FTC officials to steal money, urging victims to move funds. The FTC never tells people to move money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam : Learn how to identify fake job opportunities, work-at-home scams, and shady employment agencies. Watch FTC Chairman Andrew Ferguson’s video. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams : Plan for emergencies and learn to spot disaster-related scams. Free tools are available to help with fraud prevention. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams : Learn how to avoid scams when selling your timeshare. Be cautious of easy ways to sell that sound too good to be true. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going : Ensure donations go to legitimate causes. The FTC says &lt;a href=&quot;http://Kars-R-Us.com&quot;&gt;Kars-R-Us.com&lt;/a&gt;, Inc. lied about where vehicle donations were going. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams : Protect yourself from scams during Medicare Open Enrollment. Scammers become more active during this period. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Identity Theft&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Get a credit freeze to stop identity thieves : Freeze your credit to protect against identity theft. Learn the steps to freeze your credit. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/get-credit-freeze-stop-identity-thieves&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to help protect foster youth from identity theft : Foster youth are at higher risk of identity theft due to frequent moves and multiple access points to their information. Learn how to protect them. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-thieft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Collection&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls : Companies trick users into sharing data, then sell it to telemarketers, resulting in illegal calls. Learn to reduce unwanted telemarketing. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Data Breach</category><category>Data Privacy</category><category>FTC</category><category>Identity Theft</category><category>ParkMobile</category><category>Scams</category><category>Zero-Day Exploit</category><category>Zimbra</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/zimbra-flaw-parkmobile-breach-data-scams-10-05-2025.webp" length="0" type="image/webp"/></item><item><title>Zimbra Zero-Day, Gov Cloud Loss, &amp; ParkMobile Breach – 10/05/2025</title><link>https://grabtheaxe.com/news/zimbra-zero-day-gov-cloud-loss-parkmobile-breach-10-05-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/zimbra-zero-day-gov-cloud-loss-parkmobile-breach-10-05-2025/</guid><description>Critical alert on Zimbra zero-day exploit using iCalendar files. Analysis of the ParkMobile data breach settlement and a catastrophic government cloud data loss.</description><pubDate>Sun, 05 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/zimbra-zero-day-gov-cloud-loss-parkmobile-breach-10-05-2025.webp&quot; alt=&quot;Zimbra Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is highlighted by the active exploitation of a Zimbra zero-day vulnerability using malicious calendar files. A catastrophic fire has also led to the complete loss of a South Korean government cloud system due to a lack of backups, serving as a stark reminder of disaster recovery’s importance. Additionally, we cover the minimal compensation offered to 22 million users in the ParkMobile data breach settlement and advancements in AI for vulnerability detection.&lt;/p&gt;
&lt;h2&gt;Top 3 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hackers exploited Zimbra flaw as zero-day using iCalendar files: A vulnerability in the Zimbra Collaboration Suite was actively exploited as a zero-day using malicious iCalendar (.ICS) files to compromise systems before a patch was available. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-exploited-zimbra-flaw-as-zero-day-using-icalendar-files/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fire destroys S. Korean government’s cloud storage system, no backups available: A catastrophic incident in South Korea resulted in a fire destroying a government cloud storage system, leading to total data loss due to the lack of available backups. &lt;a href=&quot;https://koreajoongangdaily.joins.com/news/2025-10-01/national/socialAffairs/NIRS-fire-destroys-governments-cloud-storage-system-no-backups-available/2412936&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ParkMobile pays… $1 each for 2021 data breach that hit 22 million: Following a class-action lawsuit for its 2021 data breach, ParkMobile is compensating 22 million affected users with a manually claimed, expiring $1 in-app credit. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/parkmobile-pays-1-each-for-2021-data-breach-that-hit-22-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hackers exploited Zimbra flaw as zero-day using iCalendar files: A vulnerability in the Zimbra Collaboration Suite was actively exploited as a zero-day using malicious iCalendar (.ICS) files to compromise systems before a patch was available. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-exploited-zimbra-flaw-as-zero-day-using-icalendar-files/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fire destroys S. Korean government’s cloud storage system, no backups available: A catastrophic incident in South Korea resulted in a fire destroying a government cloud storage system, leading to total data loss due to the lack of available backups. &lt;a href=&quot;https://koreajoongangdaily.joins.com/news/2025-10-01/national/socialAffairs/NIRS-fire-destroying-governments-cloud-storage-system-no-backups-available/2412936&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ParkMobile pays… $1 each for 2021 data breach that hit 22 million: Following a class-action lawsuit for its 2021 data breach, ParkMobile is compensating 22 million affected users with a manually claimed, expiring $1 in-app credit. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/parkmobile-pays-1-each-for-2021-data-breach-that-hit-22-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Reasoning models like Claude Sonnet 4.5 are getting better at spotting security flaws: Anthropic reports that advanced AI reasoning models like Claude Sonnet 4.5 are demonstrating a growing potential for effectively identifying complex cybersecurity flaws. &lt;a href=&quot;https://the-decoder.com/reasoning-models-like-claude-sonnet-4-5-are-getting-better-at-spotting-security-flaws/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>cloud security</category><category>Cybersecurity</category><category>Data Breach</category><category>Incident Response</category><category>threat intelligence</category><category>Zero-Day</category><category>Zimbra</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/zimbra-zero-day-gov-cloud-loss-parkmobile-breach-10-05-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breaches, Tile Vulnerability &amp; AI Risks – 10/04/2025</title><link>https://grabtheaxe.com/news/data-breaches-tile-vulnerability-ai-risks-10-04-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breaches-tile-vulnerability-ai-risks-10-04-2025/</guid><description>Critical data breaches at Discord &amp; Renault/Dacia, Tile tracker vulnerabilities exposed. Plus, AI risks &amp; FTC scam warnings. Stay secure!</description><pubDate>Sat, 04 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breaches-tile-vulnerability-ai-risks-10-04-2025.webp&quot; alt=&quot;Data Breaches&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights critical data breaches affecting Discord and Renault/Dacia customers, alongside vulnerabilities in Tile trackers that enable stalking. The launch of OpenAI’s Sora video app raises concerns about violent and racist content, while the FTC warns about online scams and telemarketing. Stay informed to protect your data and privacy.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hackers steal identifiable Discord user data in third-party breach : Partial payment and personal data stolen from Discord users due to a third-party breach. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-steal-identifiable-discord-user-data-in-third-party-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Renault and Dacia UK warn of data breach impacting customers : Sensitive customer information compromised at a third-party provider. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/renault-and-dacia-uk-warn-of-data-breach-impacting-customers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tile’s Lack of Encryption Is a Danger for Users Everywhere : Vulnerabilities in Tile trackers allow easy location tracking by stalkers and the company. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/tiles-lack-encryption-danger-users-everywhere&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI launch of video app Sora plagued by violent and racist images : New AI video generator quickly populated with harmful content due to inadequate guardrails. &lt;a href=&quot;https://www.theguardian.com/us-news/2025/oct/04/openai-sora-violence-racism&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When sharing your info online leads to unwanted and unlawful telemarketing calls : Learn how companies trick users into sharing data, leading to illegal telemarketing. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/when-sharing-your-info-online-leads-unwanted-and-unlawful-telemarketing-calls&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Artificial Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Opera wants you to pay $19.90 per month for its new AI browser : Opera Neon puts AI in control of browsing, but comes with a monthly fee. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/opera-wants-you-to-pay-1990-per-month-for-its-new-ai-browser/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Privacy&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Flo Health, Google Settle Class Action Privacy Lawsuit for $56 Million : Settlement over Flo app’s alleged unlawful sharing of health data with Google. &lt;a href=&quot;https://www.insideprivacy.com/health-privacy/flo-health-google-settle-class-action-privacy-lawsuit-for-56-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Health Privacy&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Flo Health, Google Settle Class Action Privacy Lawsuit for $56 Million : Settlement over Flo app’s alleged unlawful sharing of health data with Google. &lt;a href=&quot;https://www.insideprivacy.com/health-privacy/flo-health-google-settle-class-action-privacy-lawsuit-for-56-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Signal adds new cryptographic defense against quantum attacks : Signal introduces SPQR, a new cryptographic component to defend against quantum computing threats. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/signal-adds-new-cryptographic-defense-against-quantum-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Technology&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Opera wants you to pay $19.90 per month for its new AI browser : Opera Neon puts AI in control of browsing, but comes with a monthly fee. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/opera-wants-you-to-pay-1990-per-month-for-its-new-ai-browser/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Uncategorized&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How to help protect foster youth from identity theft : Tips for foster parents and service providers to protect foster youth from identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone : FTC warns of scammers impersonating FTC officials to steal money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Get a credit freeze to stop identity thieves : Steps to freeze your credit to protect against identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/get-credit-freeze-stop-identity-thieves&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams : Tips to avoid scams during Medicare Open Enrollment. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams : Advice on avoiding scams when selling a timeshare. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going : FTC warns about a charity scam involving vehicle donations. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-the-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam : FTC shares tips on identifying fake job opportunities and employment scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams : Planning tips and scam avoidance during emergencies. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Who’s eligible for a refund from Amazon? : Details on Amazon’s $2.5 billion settlement and consumer refunds. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;‘Delivery robots will happen’: Skype co-founder on his fast-growing venture Starship : Ahti Heinla discusses Starship Technologies and the future of delivery robots. &lt;a href=&quot;https://www.theguardian.com/business/2025/oct/04/delivery-robots-skype-co-founder-ahti-heinla-starship&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to live a good life in difficult times: Yuval Noah Harari, Rory Stewart and Maria Ressa in conversation : Discussion on navigating the future with AI, climate change, and democracy. &lt;a href=&quot;https://www.theguardian.com/books/2025/oct/04/how-to-live-a-good-life-in-difficult-times-yuval-noah-harari-rory-stewart-and-maria-ressa-in-conversation&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Friday Squid Blogging: Squid Overfishing in the Southwest Atlantic : Article and report on squid overfishing. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/friday-squid-blogging-squid-overfishing-in-the-southwest-atlantic.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;What Europe’s New Gig Work Law Means for Unions and Technology : Analysis of the EU’s Platform Work Directive and its impact on worker’s rights. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/what-europes-new-gig-work-law-means-unions-and-technology&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Opt Out October: Daily Tips to Protect Your Privacy and Security : Daily tips for opting out of tech giant surveillance. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hey, San Francisco, There Should be Consequences When Police Spy Illegally : EFF argues for consequences when police violate surveillance oversight laws. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/hey-san-francisco-there-should-be-consequences-when-police-spy-illegally&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Stalin, Putin and an enduring obsession with immortality | Letter : Readers respond to an article about dictators and tech billionaires wanting to ‘solve the problem’ of ageing. &lt;a href=&quot;https://www.theguardian.com/society/2025/oct/03/stalin-putin-and-an-enduring-obsessed-with-immortality&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Wiretap Litigation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Flo Health, Google Settle Class Action Privacy Lawsuit for $56 Million : Settlement over Flo app’s alleged unlawful sharing of health data with Google. &lt;a href=&quot;https://www.insideprivacy.com/health-privacy/flo-health-google-settle-class-action-privacy-lawsuit-for-56-million/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;reports&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Friday Squid Blogging: Squid Overfishing in the Southwest Atlantic : Article and report on squid overfishing. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/friday-squid-blogging-squid-overfishing-in-the-southwest-atlantic.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;squid&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Friday Squid Blogging: Squid Overfishing in the Southwest Atlantic : Article and report on squid overfishing. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/10/friday-squid-blogging-squid-overfishing-in-the-southwest-atlantic.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI</category><category>Dacia</category><category>Data Breach</category><category>Discord</category><category>Privacy</category><category>Renault</category><category>Scams</category><category>security</category><category>Telemarketing</category><category>Tile Tracker</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breaches-tile-vulnerability-ai-risks-10-04-2025.webp" length="0" type="image/webp"/></item><item><title>Export Controls, AI Safety, Lapsus$ &amp; Cybersecurity – 10/04/2025</title><link>https://grabtheaxe.com/news/export-controls-ai-safety-lapsus-cybersecurity-10-04-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/export-controls-ai-safety-lapsus-cybersecurity-10-04-2025/</guid><description>Export control expansion, CA&apos;s AI safety law, and Lapsus$’s return highlight today&apos;s compliance risks. Plus, cybersecurity protection expiration analysis.</description><pubDate>Sat, 04 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/export-controls-ai-safety-lapsus-cybersecurity-10-04-2025.webp&quot; alt=&quot;Export Controls&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s compliance intelligence digest highlights critical developments in regulatory and third-party risk landscapes. Lapsus$ has resurfaced, threatening Salesforce customers, while new US Commerce Department rules expand export controls. California’s AI safety legislation sets a precedent, and the expiration of cybersecurity information-sharing protections marks a significant shift in policy.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Lapsus$ Returns With Salesforce Leak Site : The cybercriminal collective Lapsus$ has reemerged and is threatening to publish stolen data from Salesforce customers by Oct. 10 if their demands are not met. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/scattered-lapsus-hunters-returns-salesforce-leak-site&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New US Commerce Department Global License Requirements : BIS released the Affiliates Rule, drawing unnamed entities into entity-specific controls to close paths of diversion to blacklisted entities. &lt;a href=&quot;https://www.jdsupra.com/legalnews/new-us-commerce-department-global-3905372/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;BIS Expands Export Controls to Affiliates : BIS issued an interim final rule expanding export controls to foreign affiliates of parties already subject to restrictions. &lt;a href=&quot;https://www.jdsupra.com/legalnews/bis-closes-loophole-new-rule-expands-4752934/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California AI Safety Legislation : California Governor Gavin Newsom signed into law Senate Bill 53 (SB 53), known as the Transparency in Frontier Artificial Intelligence Act (TFAIA). &lt;a href=&quot;https://www.jdsupra.com/legalnews/landmark-california-ai-safety-2500298/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cybersecurity Protections Expire : The legal protections for sharing of cyber threat information among private sector entities and with the federal government were not renewed by Congress and have expired. &lt;a href=&quot;https://www.jdsupra.com/legalnews/the-end-of-an-era-a-decade-of-7994095/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New US Commerce Department Global License Requirements : BIS released the Affiliates Rule, drawing unnamed entities into entity-specific controls to close paths of diversion to blacklisted entities. &lt;a href=&quot;https://www.jdsupra.com/legalnews/new-us-commerce-department-global-3905372/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;BIS Closes Loophole: New Rule Expands Export Controls to Affiliates : BIS issued an interim final rule expanding export controls to foreign affiliates of parties already subject to restrictions. &lt;a href=&quot;https://www.jdsupra.com/legalnews/bis-closes-loophole-new-rule-expands-4752934/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Broadcast Station Filings Due on October 10, 2025 : All radio and television broadcast stations must prepare a list of important issues facing their communities of license and the programs aired during July, August, and September dealing with those issues. &lt;a href=&quot;https://www.jdsupra.com/legalnews/broadcast-station-filings-due-on-9044472/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The End of an Era: A Decade of Cybersecurity Protections Expire : The legal protections for sharing of cyber threat information among private sector entities and with the federal government were not renewed by Congress and have expired. &lt;a href=&quot;https://www.jdsupra.com/legalnews/the-end-of-an-era-a-decade-of-7994095/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Landmark California AI Safety Legislation : California Governor Gavin Newsom signed into law Senate Bill 53 (SB 53), known as the Transparency in Frontier Artificial Intelligence Act (TFAIA). &lt;a href=&quot;https://www.jdsupra.com/legalnews/landmark-california-ai-safety-2500298/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Lapsus$ Returns With Salesforce Leak Site : The cybercriminal collective Lapsus$ has reemerged and is threatening to publish stolen data from Salesforce customers by Oct. 10 if their demands are not met. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/scattered-lapsus-hunters-returns-salesforce-leak-site&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Dutch Authorities Arrest Two Teens for Alleged Pro-Russian Espionage : Dutch Prime Minister Dick Schoof described the incident as part of a broader pattern of Russian hybrid attacks against Europe. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/dutch-authorities-arrest-teens-pro-russian-espionage&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Affiliates Rule</category><category>AI Safety</category><category>BIS</category><category>Cybersecurity</category><category>Data Leak</category><category>Export Controls</category><category>Lapsus$</category><category>Regulatory Compliance</category><category>Third-Party Risk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/export-controls-ai-safety-lapsus-cybersecurity-10-04-2025.webp" length="0" type="image/webp"/></item><item><title>Palo Alto Scans, Discord Breach &amp; AI CometJacking – 10/04/2025</title><link>https://grabtheaxe.com/news/palo-alto-scans-discord-breach-ai-cometjacking-10-04-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/palo-alto-scans-discord-breach-ai-cometjacking-10-04-2025/</guid><description>Critical alert on massive Palo Alto Networks scans indicating reconnaissance. Details on the Discord data breach, new AI CometJacking attack, and other key security risks.</description><pubDate>Sat, 04 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/palo-alto-scans-discord-breach-ai-cometjacking-10-04-2025.webp&quot; alt=&quot;Palo Alto Networks Scans&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This daily threat summary highlights a significant surge in reconnaissance scans targeting Palo Alto Networks portals, signaling potential future attacks. Additionally, Discord has disclosed a data breach exposing user information via a third-party compromise, and a novel ‘CometJacking’ attack demonstrates new risks in AI-powered browsers. These incidents underscore the evolving threats to network infrastructure, user data, and emerging technologies.&lt;/p&gt;
&lt;h2&gt;Top 3 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Massive surge in scans targeting Palo Alto Networks login portals: Threat actors are conducting widespread reconnaissance against Palo Alto Networks login portals, with scanning activity increasing by 500%, indicating preparation for potential attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/massive-surge-in-scans-targeting-palo-alto-networks-login-portals/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Discord discloses data breach after hackers steal support tickets: Discord has confirmed a data breach originating from a compromised third-party support agent, exposing user PII, partial payment info, and government-issued IDs from support tickets. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/discord-discloses-data-breach-after-hackers-steal-support-tickets/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CometJacking: One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief: Researchers have detailed a new prompt injection attack, “CometJacking,” that can compromise Perplexity’s Comet AI browser with a single malicious link to steal sensitive data from connected services. &lt;a href=&quot;https://thehackernews.com/2025/10/cometjacking-one-click-can-turn.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Event startup Partiful wasn’t stripping GPS locations from user-uploaded photos: The event planning app Partiful exposed granular GPS location data from user-uploaded photos, a privacy flaw that has since been fixed after being reported. &lt;a href=&quot;https://techcrunch.com/2025/10/04/event-startup-partiful-wasnt-stripping-gps-locations-from-user-uploaded-photos/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A breach every month raises doubts about South Korea’s digital defenses: A consistent string of data breaches in South Korea is raising significant concerns about the nation’s cybersecurity posture and its ability to protect its advanced digital infrastructure. &lt;a href=&quot;https://techcrunch.com/2025/10/04/a-breach-every-month-raises-doubts-about-south-koreas-digital-defenses/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Massive surge in scans targeting Palo Alto Networks login portals: Threat actors are conducting widespread reconnaissance against Palo Alto Networks login portals, with scanning activity increasing by 500%, indicating preparation for potential attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/massive-surge-in-scans-targeting-palo-alto-networks-login-portals/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CometJacking: One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief: Researchers have detailed a new prompt injection attack, “CometJacking,” that can compromise Perplexity’s Comet AI browser with a single malicious link to steal sensitive data from connected services. &lt;a href=&quot;https://thehackernews.com/2025/10/cometjacking-one-click-can-turn.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Anker offered Eufy camera owners $2 per video for AI training: Anker’s Eufy brand solicited customer videos for AI training in exchange for a small payment, raising privacy concerns about how user surveillance data is collected and utilized. &lt;a href=&quot;https://techcrunch.com/2025/10/04/anker-offered-to-pay-eufy-camera-owners-to-share-videos-for-training-its-ai/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ICE wants to build a 24/7 social media surveillance team: U.S. Immigration and Customs Enforcement (ICE) is planning to hire contractors for round-the-clock social media surveillance to identify individuals for deportation, expanding its digital monitoring capabilities. &lt;a href=&quot;https://arstechnica.com/security/2025/10/ice-wants-to-build-a-24-7-social-media-surveillance-team/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>CometJacking</category><category>Cybersecurity Alert</category><category>Data Breach</category><category>Discord</category><category>Network Security</category><category>Palo Alto Networks</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/palo-alto-scans-discord-breach-ai-cometjacking-10-04-2025.webp" length="0" type="image/webp"/></item><item><title>Salesforce Leak, Cyberattacks &amp; FTC Shutdown – 10/04/2025</title><link>https://grabtheaxe.com/news/salesforce-leak-cyberattacks-ftc-shutdown-10-04-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/salesforce-leak-cyberattacks-ftc-shutdown-10-04-2025/</guid><description>Salesforce leak threat, rising cyberattack costs, &amp; FTC shutdown plan: Stay ahead of critical compliance issues with our intelligence digest. Read more now!</description><pubDate>Sat, 04 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/salesforce-leak-cyberattacks-ftc-shutdown-10-04-2025.webp&quot; alt=&quot;Salesforce Leak&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical compliance alerts, including the Lapsus$ group’s return threatening a Salesforce leak, new US Commerce Department global license requirements, and the rising costs of healthcare cyberattacks. Also covered are ISO 27001 implementation challenges, FTC shutdown plans, and third-party risks related to tariff transactions. Stay informed to protect your organization from emerging threats and regulatory shifts.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Scattered Lapsus$ Hunters Returns With Salesforce Leak Site: The cybercriminal collective reemerged and threatened to publish the stolen data of Salesforce customers by Oct. 10 if its demands are not met. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/scattered-lapsus-hunters-returns-salesforce-leak-site&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New US Commerce Department Global License Requirements for Transactions Involving Affiliates of Listed Entities: BIS released the Affiliates Rule, which draws unnamed entities around the world into BIS’s entity-specific controls to close paths of diversion to blacklisted entities. &lt;a href=&quot;https://www.jdsupra.com/legalnews/new-us-commerce-department-global-3905372/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business: The company likely failed to completely clean out attackers from a previous breach and now is a case study for the high cost of ransomware. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/jaguar-land-rover-cyberattacks-bad-business&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;PHI Potentially Stolen in Phishing Attack on Superior Vision Service: Protected health information has been compromised in a phishing attack on Superior Vision Service. &lt;a href=&quot;https://www.hipaajournal.com/superior-vision-service-people-encouraging-people-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Healthcare Cyberattacks Costing $200K+ Rise 400% in a Year: Almost half of healthcare organizations experienced at least one data breach between March 2024 and March 2025. &lt;a href=&quot;https://www.hipaajournal.com/healthcare-cyberattacks-200k-increase-400pc/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;5 Reasons ISO 27001 Implementations Fail (and How to Avoid Them): Most ISMS implementation projects fail because of poor planning and execution, requiring leadership, integration, and discipline across the business. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/5-reasons-iso-27001-implementations-fail-and-how-to-avoid-them&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FTC Releases Shutdown Plan, Will Continue to Accept HSR Filings: The FTC released a shutdown plan outlining operations during the lapse in appropriations; FTC Commissioners are excepted from furlough. &lt;a href=&quot;https://www.regulatoryandcompliance.com/2025/10/ftc-releases-shutdown-plan-will-continue-to-accept-hsr-filings/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New SEC No-Action Letter on Crypto Custody: What It Means for Advisers &amp;amp; Funds: A new SEC no-action letter addresses custody of crypto assets for regulated advisers and funds. &lt;a href=&quot;https://compliance-risk.com/new-sec-no-action-letter-on-crypto-custody-what-it-means-for-advisers-funds/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CFTC Proposes Revisions to Business Conduct and Swap Documentation Requirements for Swap Dealers and Major Swap Participants: The CFTC issued a proposal to revise external business conduct standards and swap documentation requirements for Swap Entities, removing unnecessary burdens. &lt;a href=&quot;https://www.jdsupra.com/legalnews/cftc-proposes-revisions-to-business-1185926/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Beware the Tariff DDP Trap: Managing Hidden Import Liabilities Before They Bite: Companies using Duty Paid transactions face exposure; the importer remains legally responsible for accurate customs declarations, tariff payments, and regulatory compliance. &lt;a href=&quot;https://wp.nyu.edu/compliance_enforcement/2025/10/03/beware-the-tariff-ddp-trap-managing-hidden-import-liabilities-before-they-bite/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Cybersecurity</category><category>Data Breach</category><category>FTC</category><category>Healthcare Cybersecurity</category><category>ISO 27001</category><category>Lapsus$</category><category>Salesforce</category><category>Tariff Compliance</category><category>Third-Party Risk</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/salesforce-leak-cyberattacks-ftc-shutdown-10-04-2025.webp" length="0" type="image/webp"/></item><item><title>ICE Tracking, CometJacking, Salesforce Leak – 10/03/2025</title><link>https://grabtheaxe.com/news/ice-tracking-commetjacking-salesforce-leak-10-03-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ice-tracking-commetjacking-salesforce-leak-10-03-2025/</guid><description>Privacy threats today: ICE&apos;s mass phone tracking, CometJacking email theft, Salesforce data leak, &amp; FTC action on child data. Stay secure &amp; informed.</description><pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ice-tracking-commetjacking-salesforce-leak-10-03-2025.webp&quot; alt=&quot;Phone Tracking&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This privacy digest highlights critical developments, including ICE’s acquisition of a mass phone tracking tool and the ‘CommetJacking’ attack stealing emails via AI browsers. We also cover a significant Salesforce data leak, a ransomware attack on Asahi, and the FTC’s crackdown on child data exploitation. Stay informed to navigate these evolving privacy threats effectively.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ICE to Buy Tool that Tracks Locations of Hundreds of Millions of Phones Every Day: ICE acquired a surveillance tool updated daily with location data from millions of phones. &lt;a href=&quot;https://pogowasright.org/ice-to-buy-tool-that-tracks-locations-of-hundreds-of-millions-of-phones-every-day/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CommetJacking attack tricks Comet browser into stealing emails: A new attack exploits URL parameters to steal sensitive data from connected services. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/commetjacking-attack-tricks-comet-browser-into-stealing-emails/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ShinyHunters launches Salesforce data leak site to extort 39 victims: An extortion group leaks data stolen in Salesforce attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/shinyhunters-starts-leaking-data-stolen-in-salesforce-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Japanese beer giant Asahi confirms ransomware attack: A ransomware attack caused IT disruptions and factory shutdowns. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/japanese-beer-giant-asahi-confirms-ransomware-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FTC Cracks Down on Messaging App Operator on Child Data Exploitation: The FTC announced legal action against Sendit for violations of consumer protection and privacy laws. &lt;a href=&quot;https://www.alstonprivacy.com/ftc-cracks-down-on-messaging-app-operator-on-child-data-exploitation/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Brazil Adopts Law Protecting Minors Online — Brazil enacted the Digital Statute of the Child and Adolescent, establishing a regulatory framework for protecting children online. &lt;a href=&quot;https://www.insideprivacy.com/childrens-privacy/brazil-adopts-law-protecting-minors-online/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FTC Cracks Down on Messaging App Operator on Child Data Exploitation: The FTC announced legal action against Sendit for violations of consumer protection and privacy laws. &lt;a href=&quot;https://www.alstonprivacy.com/ftc-cracks-down-on-messaging-app-operator-on-child-data-exploitation/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Gmail business users can now send encrypted emails to anyone — Google says that Gmail enterprise users can now send end-to-end encrypted emails to people who use any email service. &lt;a href=&quot;https://www.bleepingcomputer.com/news/google/gmail-business-users-can-now-send-encrypted-emails-to-anyone/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Surveillance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ICE to Buy Tool that Tracks Locations of Hundreds of Millions of Phones Every Day: ICE acquired a surveillance tool updated daily with location data from millions of phones. &lt;a href=&quot;https://pogowasright.org/ice-to-buy-tool-that-tracks-locations-of-hundreds-of-millions-of-phones-every-day/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cybersecurity&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Incoming Deadlines and Requirements for DOJ’s Data Security Program on Oct. 6, 2025: Starting Oct. 6, U.S. entities handling bulk sensitive data must implement a written data compliance program. &lt;a href=&quot;https://www.gtlaw-dataprivacydish.com/2025/10/incoming-deadlines-and-requirements-for-dojs-data-security-program-on-oct-6-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Japanese beer giant Asahi confirms ransomware attack: A ransomware attack caused IT disruptions and factory shutdowns. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/japanese-beer-giant-asahi-confirms-ransomware-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ShinyHunters launches Salesforce data leak site to extort 39 victims: An extortion group leaks data stolen in Salesforce attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/shinyhunters-starts-leaking-data-stolen-in-salesforce-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CommetJacking attack tricks Comet browser into stealing emails: A new attack exploits URL parameters to steal sensitive data from connected services. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/commetjacking-attack-tricks-comet-browser-into-stealing-emails/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Oracle links Clop extortion attacks to July 2025 vulnerabilities: Oracle linked Clop ransomware attacks to E-Business Suite vulnerabilities patched in July 2025. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/oracle-links-clop-extortion-attacks-to-july-security-flaws/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Outlook stops displaying inline SVG images used in attacks: Outlook will no longer display risky inline SVG images used in attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-outlook-stops-displaying-inline-svg-images-used-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DrayTek warns of remote code execution bug in Vigor routers: DrayTek warned of a security vulnerability in Vigor routers allowing remote code execution. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/draytek-warns-of-remote-code-execution-bug-in-vigor-routers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Child Privacy</category><category>CometJacking</category><category>Cybersecurity</category><category>Data Leak</category><category>FTC</category><category>ICE</category><category>Phone Tracking</category><category>ransomware</category><category>Salesforce</category><category>Surveillance</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ice-tracking-commetjacking-salesforce-leak-10-03-2025.webp" length="0" type="image/webp"/></item><item><title>Salesforce Breach, Oracle Flaw &amp; CISA Alert – 10/03/2025</title><link>https://grabtheaxe.com/news/salesforce-breach-oracle-flaw-cisa-alert-10-03-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/salesforce-breach-oracle-flaw-cisa-alert-10-03-2025/</guid><description>Daily security summary on the massive Salesforce breach by Scattered Spider, Oracle EBS flaws exploited by Clop, and a new CISA KEV alert. Stay informed.</description><pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/salesforce-breach-oracle-flaw-cisa-alert-10-03-2025.webp&quot; alt=&quot;Salesforce Breach&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is dominated by a massive data extortion campaign targeting Salesforce customers, allegedly orchestrated by the Scattered Spider group. This summary details the breach, an active Clop ransomware campaign exploiting Oracle vulnerabilities, and a new CISA alert for an actively exploited flaw. We also cover significant breaches at Discord and Renault, and emerging threats like self-spreading WhatsApp malware.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hacking group claims theft of 1 billion records from Salesforce customer databases: The Scattered Spider (aka ShinyHunters) group claims a massive data theft from Salesforce customers like FedEx and TransUnion, launching a new leak site for extortion. &lt;a href=&quot;https://techcrunch.com/2025/10/03/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Oracle links Clop extortion attacks to July 2025 vulnerabilities — Oracle has connected an ongoing extortion campaign by the Clop ransomware gang to E-Business Suite (EBS) vulnerabilities that were patched in July. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/oracle-links-clop-extortion-attacks-to-july-security-flaws/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild — CISA has added a high-severity command injection vulnerability in Smartbedded Meteobridge to its Known Exploited Vulnerabilities (KEV) catalog, indicating active attacks. &lt;a href=&quot;https://thehackernews.com/2025/10/cisa-flags-meteobridge-cve-2025-4008.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Japanese beer giant Asahi confirms ransomware attack — Asahi has confirmed that a ransomware attack was the cause of recent IT disruptions that forced it to shut down its factories. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/japanese-beer-giant-asahi-confirms-ransomware-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL — A new self-propagating malware targeting Brazilian users is spreading rapidly via WhatsApp to infect Windows systems, engineered for speed and propagation. &lt;a href=&quot;https://thehackernews.com/2025/10/researchers-warn-of-self-spreading.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Rhadamanthys Stealer Evolves: Adds Device Fingerprinting, PNG Steganography Payloads: The Rhadamanthys info-stealer has been updated to support device fingerprint collection and can now hide malicious payloads within PNG image files. &lt;a href=&quot;https://thehackernews.com/2025/10/rhadamanthys-stealer-evolves-adds.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New “Cavalry Werewolf” Attack Hits Russian Agencies with FoalShell and StallionRAT: A threat actor linked to the YoroTrooper hacking group is targeting the Russian public sector with malware families including FoalShell and StallionRAT. &lt;a href=&quot;https://thehackernews.com/2025/10/new-cavalry-werewolf-attack-hits.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Renault and Dacia UK warn of data breach impacting customers — The car manufacturer has notified UK customers that their sensitive information was compromised following a data breach at a third-party provider. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/renault-and-dacia-uk-warn-of-data-breach-impacting-customers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Discord customer service data breach leaks user info and scanned photo IDs — A third-party customer service provider for Discord was breached, leading to the exposure of user data, including names, emails, and a small number of government IDs. &lt;a href=&quot;https://www.theverge.com/news/792032/discord-customer-service-data-breach-hack&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Gmail business users can now send encrypted emails to anyone — Google has enabled Gmail enterprise users to send end-to-end encrypted emails to individuals using any email service or platform. &lt;a href=&quot;https://www.bleepingcomputer.com/news/google/gmail-business-users-can-now-send-encrypted-emails-to-anyone/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Presenting AI to the Board as a CISO? Here’s a Template. — A new template is available to help CISOs clearly communicate GenAI adoption strategies, associated risks, and governance controls to company leadership. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/presenting-ai-to-the-board-as-a-ciso-heres-a-template/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CommetJacking attack tricks Comet browser into stealing emails: A new attack called ‘CometJacking’ exploits URL parameters in Perplexity’s Comet AI browser to execute hidden instructions and access sensitive data from connected services. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/commetjacking-attack-tricks-comet-browser-into-stealing-emails/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Signal adds new cryptographic defense against quantum attacks: The secure messaging app has implemented a new cryptographic component, Sparse Post-Quantum Ratchet (SPQR), to defend against future threats from quantum computing. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/signal-adds-new-cryptographic-defense-against-quantum-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CISA</category><category>Clop</category><category>Cybersecurity</category><category>Data Breach</category><category>Oracle</category><category>ransomware</category><category>Salesforce Breach</category><category>Scattered Spider</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/salesforce-breach-oracle-flaw-cisa-alert-10-03-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breaches, Apple Backdoor &amp; Android Spyware – 10/02/2025</title><link>https://grabtheaxe.com/news/data-breaches-apple-backdoor-android-spyware-10-02-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breaches-apple-backdoor-android-spyware-10-02-2025/</guid><description>Major data breaches at WestJet &amp; Motility, UK demands Apple backdoor, &amp; new Android spyware. Stay informed about today&apos;s top privacy threats.</description><pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breaches-apple-backdoor-android-spyware-10-02-2025.webp&quot; alt=&quot;Data Breaches&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest reveals significant data breaches, including a major incident at WestJet affecting 1.2 million customers and a ransomware attack on Motility Software impacting 766,000 clients. The UK government’s renewed push for an Apple backdoor raises encryption concerns, while new Android spyware campaigns highlight ongoing mobile security threats. Stay informed to protect your data and privacy.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;WestJet Data Breach Exposes Travel Details of 1.2 Million Customers: Canadian airline WestJet reports a cyberattack compromised personal information, including passports and ID documents, of 1.2 million customers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/westjet-data-breach-exposes-travel-details-of-12-million-customers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Data Breach at Dealership Software Provider Impacts 766k Clients: A ransomware attack at Motility Software Solutions exposed the sensitive data of 766,000 customers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/data-breach-at-dealership-software-provider-impacts-766k-clients/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Red Hat Confirms Security Incident After Hackers Claim GitHub Breach: The Crimson Collective claims to have breached Red Hat’s private GitHub repositories, stealing nearly 570GB of data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/red-hat-confirms-security-incident-after-hackers-claim-github-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK Government Demands Apple Backdoor for British Users’ Data: The UK government is again demanding Apple create a backdoor into its encrypted backup services, now limited to British users. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/10/uk-still-trying-backdoor-encryption-apple-users&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Android Spyware Campaigns Impersonate Signal and ToTok Messengers: New spyware campaigns, ProSpy and ToSpy, target Android users with fake upgrades for Signal and ToTok to steal data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/android-spyware-campaigns-impersonate-signal-and-totok-messengers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Navigating California’s New and Emerging AI Employment Regulations: New regulations in California impose requirements on employers using automated-decision systems in employment decisions. &lt;a href=&quot;https://www.insideprivacy.com/artificial-intelligence/navigating-californias-new-and-emerging-ai-employment-regulations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Who’s Eligible for a Refund from Amazon?: Amazon agreed to pay $2.5 billion to settle FTC charges of enrolling millions in Prime subscriptions without consent. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/whos-eligible-refund-amazon&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cybersecurity&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA 2015 Sunsets: Cyber Threat Sharing Without a Net?: The Cybersecurity Information Sharing Act of 2015 expired, removing the legal framework for cyber threat information sharing. &lt;a href=&quot;https://www.dataprotectionreport.com/2025/10/cisa-2015-sunsets-cyber-threat-sharing-without-a-net/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;China Issues Measures for the Administration of National Cybersecurity Incident Reporting: China issued measures for national cybersecurity incident reporting, effective November 1, 2025. &lt;a href=&quot;https://www.dataprotectionreport.com/2025/10/china-issues-measures-for-the-administration-of-national-cybersecurity-incident-reporting-published-in-collaboration-with-shanghai-pacific-legal/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Breaches &amp;amp; Leaks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;WestJet Data Breach Exposes Travel Details of 1.2 Million Customers: Canadian airline WestJet reports a cyberattack compromised personal information, including passports and ID documents, of 1.2 million customers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/westjet-data-breach-exposes-travel-details-of-12-million-customers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Data Breach at Dealership Software Provider Impacts 766k Clients: A ransomware attack at Motility Software Solutions exposed the sensitive data of 766,000 customers. [Read more](&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/data-breach-at-dealership-software-provider-im&quot;&gt;https://www.bleepingcomputer.com/news/security/data-breach-at-dealership-software-provider-im&lt;/a&gt;
pacts-766k-clients/)&lt;/li&gt;
&lt;li&gt;Red Hat Confirms Security Incident After Hackers Claim GitHub Breach: The Crimson Collective claims to have breached Red Hat’s private GitHub repositories, stealing nearly 570GB of data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/red-hat-confirms-security-incident-after-hackers-claim-github-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Adobe Analytics Bug Leaked Customer Tracking Data to Other Tenants: Adobe warns Analytics customers of an ingestion bug that caused data from some organizations to appear in others’ instances. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/adobe-analytics-bug-leaked-customer-tracking-data-to-other-tenants/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Android</category><category>Apple</category><category>Cybersecurity</category><category>Data Breach</category><category>Encryption</category><category>Privacy</category><category>ransomware</category><category>spyware</category><category>UK Government</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breaches-apple-backdoor-android-spyware-10-02-2025.webp" length="0" type="image/webp"/></item><item><title>Oracle Extortion, Red Hat Breach &amp; CISA KEVs – 10/02/2025</title><link>https://grabtheaxe.com/news/oracle-extortion-red-hat-breach-cisa-kevs-10-02-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/oracle-extortion-red-hat-breach-cisa-kevs-10-02-2025/</guid><description>Daily threat report on the Clop-linked Oracle extortion campaign, Red Hat&apos;s GitLab breach, CISA&apos;s new KEVs, and a critical RCE bug in DrayTek Vigor routers.</description><pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/oracle-extortion-red-hat-breach-cisa-kevs-10-02-2025.webp&quot; alt=&quot;Oracle Extortion&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is dominated by a new extortion campaign linked to the Clop ransomware gang targeting Oracle E-Business Suite users and a significant security breach at Red Hat involving a compromised GitLab instance. CISA has also issued critical alerts, adding five actively exploited vulnerabilities to its KEV catalog that require immediate attention. This summary covers these top threats, along with new malware campaigns and critical hardware vulnerabilities you need to know about.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Adds Five Known Exploited Vulnerabilities to Catalog: CISA has added five actively exploited vulnerabilities to its KEV catalog, including flaws in GNU Bash, Juniper ScreenOS, and Jenkins, requiring federal agencies to patch immediately. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/10/02/cisa-adds-five-known-exploited-vulnerabilities-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Clop Ransomware Gang Linked to Oracle E-Business Suite Extortion Campaign: Google and Mandiant are tracking a new extortion campaign, likely by the Clop gang, targeting executives with emails claiming data theft from their Oracle E-Business Suite systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/clop-extortion-emails-claim-theft-of-oracle-e-business-suite-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Red Hat Confirms Security Breach of GitLab Instance: Red Hat is investigating a security incident after an extortion group breached one of its GitLab instances, claiming to have stolen nearly 570GB of data from 28,000 internal repositories. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/red-hat-confirms-security-incident-after-hackers-breach-gitlab-instance/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DrayTek Warns of Critical Remote Code Execution Bug in Vigor Routers: A critical vulnerability has been disclosed in several DrayTek Vigor router models that could allow remote, unauthenticated attackers to execute arbitrary code. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/draytek-warns-of-remote-code-execution-bug-in-vigor-routers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Warns of Critical Flaw in Raise3D Pro2 Series 3D Printers: An ICS advisory from CISA highlights a critical (CVSS 8.8) authentication bypass vulnerability in Raise3D Pro2 printers, which could allow for data exfiltration. &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-25-275-01&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Android Spyware Campaigns Impersonate Signal and ToTok Messengers: New spyware campaigns dubbed ProSpy and ToSpy are luring Android users with fake Signal and ToTok messaging app plugins to steal sensitive data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/android-spyware-campaigns-impersonate-signal-and-totok-messengers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chinese-Speaking Cybercrime Group UAT-8099 Targets IIS for SEO Fraud: Cisco Talos reports on UAT-8099, a cybercrime group focused on SEO fraud and stealing credentials and configuration data from high-value Microsoft IIS servers. &lt;a href=&quot;https://blog.talosintelligence.com/uat-8099-chinese-speaking-cybercrime-group-seo-fraud/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Confucius APT Deploys New Malware in Attacks on Pakistan: The Confucius cyber-espionage group has launched a new phishing campaign against Pakistani targets, utilizing malware such as WooperStealer and the Anondoor backdoor. &lt;a href=&quot;https://thehackernews.com/2025/10/confucius-hackers-hit-pakistan-with-new.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Malicious PyPI Package ‘soopsocks’ Delivered Backdoor to Windows Systems: A deceptive Python package named ‘soopsocks’ was downloaded over 2,600 times, installing a stealthy backdoor on Windows systems before being removed from the repository. &lt;a href=&quot;https://thehackernews.com/2025/10/alert-malicious-pypi-package-soopsocks.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Japanese Brewer Asahi Halts Production After Cyberattack: Beverage giant Asahi is facing production and delivery disruptions following a significant cyberattack, leading to fears of shortages of its top-selling beer. &lt;a href=&quot;https://therecord.media/japan-asahi-delay-cyberattack&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Georgia Tech Settles with DOJ Over Lax Cybersecurity Allegations: The Georgia Institute of Technology will pay $875,000 to resolve a False Claims Act lawsuit alleging it failed to meet cybersecurity requirements for federal defense contracts. &lt;a href=&quot;https://therecord.media/georgia-tech-gtrc-cybersecurity-false-claims-act-settlement&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Outlook to Block Inline SVG Images Used in Attacks: To counter emerging threats, Outlook for Web and the new Outlook for Windows will no longer render inline SVG images, which have been exploited by attackers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-outlook-stops-displaying-inline-svg-images-used-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Defender Bug Causes Erroneous BIOS Update Alerts: Microsoft is addressing a bug in Defender for Endpoint that incorrectly flags BIOS firmware as outdated, causing false security alerts for system administrators. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-bug-triggers-erroneous-bios-update-alerts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Your Service Desk is the New Attack Vector: Here’s How to Defend It. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/your-service-desk-is-the-new-attack-vector-heres-how-to-defend-it/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Releases Two Industrial Control Systems Advisories: CISA published advisories for vulnerabilities in Raise3D Pro2 Series 3D Printers (CVE-2025-10653) and the Hitachi Energy MSM Product (CVE-2023-53155, CVE-2024-53429). &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/10/02/cisa-releases-two-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CISA</category><category>Clop</category><category>Data Breach</category><category>KEV</category><category>Oracle</category><category>ransomware</category><category>Red Hat</category><category>threat intelligence</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/oracle-extortion-red-hat-breach-cisa-kevs-10-02-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breach, GDPR, &amp; SEC Compliance – 10/01/2025</title><link>https://grabtheaxe.com/news/data-breach-gdpr-sec-compliance-10-01-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breach-gdpr-sec-compliance-10-01-2025/</guid><description>Stay ahead of compliance: Data breach in Florida, GDPR updates, SEC guidance, and China&apos;s new cyber incident reporting rules. Read the latest now!</description><pubDate>Wed, 01 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breach-gdpr-sec-compliance-10-01-2025.webp&quot; alt=&quot;Data Breach&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance digest highlights critical breaches and regulatory shifts impacting organizations globally. A Florida medication management provider disclosed a significant data breach due to phishing, while the UK grapples with financial crime reforms. Jaguar Land Rover faced a major cyber attack, and China implemented strict cyber incident reporting rules. Stay informed to enhance your compliance posture and mitigate emerging risks.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Florida Medication Management Provider Discloses 150K-record Data Breach: Outcomes One, a Florida-based business associate, disclosed a phishing incident affecting almost 150,000 individuals. &lt;a href=&quot;https://www.hipaajournal.com/outcomes-one-phishing-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Human Error and Accidental Data Breaches: Lessons from Recent Cases: Verizon’s 2025 DBIR indicates 60% of breaches involve human error, including misconfigured AWS buckets and incorrect email practices. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/human-error-and-accidental-data-breaches-lessons-from-recent-cases&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK Financial Crime Reform: What Firms Need to Know: The private wealth management sector is highly susceptible to financial crime risks, including fraud, money laundering and sanctions breaches. &lt;a href=&quot;https://www.regulatoryandcompliance.com/2025/10/uk-financial-crime-reform-what-firms-need-to-know/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Our Experts’ Views on the Jaguar Land Rover Cyber Attack: JLR halted production across three UK plants following a major cyber attack, impacting 30,000 employees and its supply chain. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/our-experts-views-on-the-jaguar-land-rover-cyber-attack&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;China Imposes One-Hour Reporting Rule for Major Cyber Incidents: New regulations in China mandate reporting major cyber incidents within one hour, signaling a focus on hardening networks. &lt;a href=&quot;https://www.darkreading.com/cybersecurity-operations/china-one-hour-reporting-rule-major-cyber-incidents&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Compliance Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HIPAA Risk Assessment – Is this required?: A reminder about the importance of HIPAA risk assessments. &lt;a href=&quot;https://www.totalhipaa.com/hipaa-risk-assessment-is-this-required/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Achieving CJIS Compliance in the Cloud Era: A Strategic Imperative for State and Local Agencies: Considerations for achieving CJIS compliance when using cloud services. &lt;a href=&quot;https://www.smarsh.com/blog/thought-leadership/achieving-cjis-compliance-in-the-cloud-era-for-state-local-agencies&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Who Needs ISO 27001 Foundation Training?: Discusses the roles that benefit from ISO 27001 training, emphasizing its value beyond auditors and security consultants. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/who-needs-iso-27001-foundation-training&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SEC Guidance on the Government Shutdown: Guidance on potential delays in SEC interactions due to the government shutdown. &lt;a href=&quot;https://www.regulatoryandcompliance.com/2025/10/sec-guidance-on-the-government-shutdown/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EIOPA Raises Concerns Over Proposed European Union Climate-Reporting Scope Reduction: EIOPA cautions against scaling back mandatory sustainability disclosures in the EU. &lt;a href=&quot;https://www.regulatoryandcompliance.com/2025/10/eiopa-raises-concerns-over-proposed-european-union-climate-reporting-scope-reduction/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A Guide to the EU GDPR’s Requirements for an EU Representative: Explanation of the EU GDPR requirements for non-EEA organizations to appoint an EU representative. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/a-guide-to-the-gdprs-eu-representative-requirements&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;BIS Ratchets Up Export Controls, Adopts 50 Percent Affiliate Rule: BIS expands the Entity List to include foreign subsidiaries and affiliates of listed companies. &lt;a href=&quot;https://www.jdsupra.com/legalnews/bis-ratchets-up-export-controls-adopts-5099356/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Audit &amp;amp; Monitoring Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The AI Exchange: Innovators in Payment Security Featuring Elavon Inc.: A blog series from PCI Security Standards Council on adopting AI in payment security. &lt;a href=&quot;https://blog.pcisecuritystandards.org/the-ai-exchange-innovators-in-payment-security-featuring-elavon-inc&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Decoding BIS’s New 50 Percent Rule: End-User Controls Extended to Affiliates: Analysis of BIS’s interim final rule expanding end-user controls to cover affiliates. &lt;a href=&quot;https://www.jdsupra.com/legalnews/decoding-bis-s-new-50-percent-rule-end-7763895/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Deregulation Déjà Vu: 3 Cycles Every Compliance Leader Should Remember: Wolters Kluwer’s Elaine Duffus discusses cycles of deregulation, risk-taking, and crisis in financial services. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/deregulation-deja-vu/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CJIS</category><category>Cyber Attack</category><category>Data Breach</category><category>Export Controls</category><category>Financial Crime</category><category>GDPR</category><category>HIPAA</category><category>SEC</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breach-gdpr-sec-compliance-10-01-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breaches, OpenShift Flaw &amp; China APT – 10/01/2025</title><link>https://grabtheaxe.com/news/data-breaches-openshift-flaw-china-apt-10-01-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breaches-openshift-flaw-china-apt-10-01-2025/</guid><description>Daily security report: Major data breaches at WestJet and Allianz impact millions. A critical Red Hat OpenShift AI flaw allows full takeover. New China APT found.</description><pubDate>Wed, 01 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breaches-openshift-flaw-china-apt-10-01-2025.webp&quot; alt=&quot;Critical Data Breaches&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is defined by several massive data breaches, with incidents at Allianz Life and WestJet impacting a combined 2.7 million people. A critical vulnerability in Red Hat’s OpenShift AI platform poses a severe risk, potentially allowing a full infrastructure takeover. Additionally, a new China-aligned APT group, Phantom Taurus, has been identified targeting government and telecom sectors, while a new Android banking trojan called Klopatra is gaining traction in Europe. Here is the critical intelligence you need to know.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Red Hat OpenShift AI Flaw Exposes Hybrid Cloud Infrastructure to Full Takeover: A severe security flaw has been disclosed in Red Hat OpenShift AI that could allow attackers to escalate privileges and gain control of the entire infrastructure. &lt;a href=&quot;https://thehackernews.com/2025/10/critical-red-hat-openshift-ai-flaw.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Allianz Life says July data breach impacts 1.5 million people: Insurance giant Allianz Life has confirmed that a cyberattack in July compromised the personal information of nearly 1.5 million individuals. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/allianz-life-says-july-data-breach-impacts-15-million-people/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;WestJet data breach exposes travel details of 1.2 million customers: Canadian airline WestJet has disclosed that a June cyberattack, attributed to the Scattered Spider group, compromised the personal data of 1.2 million customers, including passports. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/westjet-data-breach-exposes-travel-details-of-12-million-customers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;China-linked hacking group Phantom Taurus targeting embassies, foreign ministries: A newly identified espionage group, Phantom Taurus, aligned with China, is actively targeting foreign ministries, embassies, and telecommunication companies across multiple continents. &lt;a href=&quot;https://therecord.media/china-linked-phantom-taurus-hacking&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Android Banking Trojan “Klopatra” Uses Hidden VNC to Control Infected Smartphones: A new Android banking trojan named Klopatra is infecting devices across Europe, using hidden VNC capabilities to give attackers remote control and steal financial data. &lt;a href=&quot;https://thehackernews.com/2025/10/new-android-banking-trojan-klopatra.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;That annoying SMS phish you just got may have come from a box like this: Security researchers are highlighting the creative infrastructure used by smishing operators, including specialized hardware for sending mass phishing text messages. &lt;a href=&quot;https://arstechnica.com/security/2025/10/that-annoying-sms-phish-you-just-got-may-have-come-from-a-box-like-this/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Seniors targeted in global Facebook scam spreading new Android malware: A global scam campaign on Facebook is targeting senior citizens with a new strain of Android malware, originating in Australia and now seen worldwide. &lt;a href=&quot;https://therecord.media/seniors-targeted-facebook-android-malware-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Nvidia and Adobe vulnerabilities: Cisco Talos has disclosed five vulnerabilities in Nvidia products and one in Adobe Acrobat, with patches now available from the vendors. &lt;a href=&quot;https://blog.talosintelligence.com/nvidia-and-adobe-vulnerabilities/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Millions impacted by data breaches at insurance giant, auto dealership software firm: In addition to the Allianz breach, auto dealership software developer Motility suffered a ransomware attack, leading to significant data exposure. &lt;a href=&quot;https://therecord.media/millions-impacted-by-data-breaches-insurance-car-dealership-software&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Adobe Analytics bug leaked customer tracking data to other tenants: Adobe has warned Analytics customers of an ingestion bug that caused some organizations’ tracking data to be exposed to other tenants for approximately one day. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/adobe-analytics-bug-leaked-customer-tracking-data-to-other-tenants/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Forensic journey: hunting evil within AmCache: Kaspersky provides a deep dive into using the AmCache artifact for incident investigation and has released a command-line tool for data extraction. &lt;a href=&quot;https://securelist.com/amcache-forensic-artifact/117622/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hackers Exploit Milesight Routers to Send Phishing SMS to European Users: Threat actors are abusing APIs in Milesight industrial cellular routers to send smishing messages with phishing links to users across Europe. &lt;a href=&quot;https://thehackernews.com/2025/10/hackers-exploit-milesight-routers-to.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;UK government tries again to access encrypted Apple customer data: Report: The U.K. Home Office is reportedly making a second attempt to compel Apple to provide access to users’ encrypted iCloud backups. &lt;a href=&quot;https://techcrunch.com/2025/10/01/uk-government-tries-again-to-access-encrypted-apple-customer-data-report/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How To Simplify CISA’s Zero Trust Roadmap with Modern Microsegmentation: This article explores how modern, automated, and agentless microsegmentation can help organizations meet CISA’s Zero Trust foundational requirements. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/how-to-simplify-cisas-zero-trust-roadmap-with-modern-microsegmentation/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google Drive for desktop gets AI-powered ransomware detection: Google is rolling out an AI-powered feature for Google Drive that automatically detects ransomware attacks and pauses file syncing to minimize damage. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-drive-for-desktop-gets-ai-powered-ransomware-detection/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Anker offered to pay Eufy camera owners to share videos for training its AI: Raising privacy concerns, Anker offered compensation to Eufy smart camera owners in exchange for their video footage to be used for training AI systems. &lt;a href=&quot;https://techcrunch.com/2025/10/01/anker-offered-to-pay-eufy-camera-owners-to-share-videos-for-training-its-ai/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Android Malware</category><category>APT</category><category>cloud security</category><category>Cybersecurity</category><category>Data Breach</category><category>ransomware</category><category>Red Hat OpenShift</category><category>threat intelligence</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breaches-openshift-flaw-china-apt-10-01-2025.webp" length="0" type="image/webp"/></item><item><title>VMware Exploit, Linux Flaw, EU Chat Control – 09/30/2025</title><link>https://grabtheaxe.com/news/vmware-exploit-linux-flaw-eu-chat-control-09-30-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/vmware-exploit-linux-flaw-eu-chat-control-09-30-2025/</guid><description>VMware zero-day exploit and Linux Sudo flaw require immediate attention. EU&apos;s Chat Control proposal sparks privacy concerns. CCPA updates included.</description><pubDate>Tue, 30 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/vmware-exploit-linux-flaw-eu-chat-control-09-30-2025.webp&quot; alt=&quot;VMware Exploit&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy digest highlights critical vulnerabilities and cyberattacks, with a focus on VMware and Linux systems exploited by malicious actors. The EU’s proposed ‘Chat Control’ measures are raising significant privacy concerns, while new CCPA regulations are set to take effect in California. Stay informed to protect your data and systems from emerging threats.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Chinese hackers exploiting VMware zero-day since October 2024: Broadcom patched a high-severity vulnerability in VMware, exploited in zero-day attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-vmware-zero-day-since-october-2024/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA warns of critical Linux Sudo flaw exploited in attacks: Hackers are exploiting a critical vulnerability in the sudo package, enabling root-level command execution. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-linux-sudo-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Broadcom fixes high-severity VMware NSX bugs reported by NSA: Security updates patch VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA). &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/broadcom-fixes-high-severity-vmware-nsx-bugs-reported-by-nsa/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Japan’s largest brewer suspends operations due to cyberattack: Asahi Group Holdings, Ltd (Asahi) disclosed a cyberattack disrupting operations. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/japans-largest-brewer-suspends-operations-due-to-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chat Control Is Back on the Menu in the EU. It Still Must Be Stopped: EU Council debates “Chat Control,” scanning private conversations, raising privacy concerns. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/chat-control-back-menu-eu-it-still-must-be-stopped-0&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Revised and New CCPA Regulations Set to Take Effect on Jan. 1, 2026 – Summary of Near-Term Action Items: California Privacy Protection Agency (CPPA) regulations are approved, effective January 1, 2026. &lt;a href=&quot;https://www.gtlaw-dataprivacydish.com/2025/09/revised-and-new-ccpa-regulations-set-to-take-effect-on-jan-1-2026-summary-of-near-term-action-items/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK Clinical Trial Regulatory Updates for Sponsors: The UK Parliament approved amendments to clinical trial regulations, the most significant update in two decades. &lt;a href=&quot;https://verasafe.com/blog/uk-clinical-trial-regulatory-updates-for-sponsors/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Chinese hackers exploiting VMware zero-day since October 2024: Broadcom patched a high-severity vulnerability in VMware, exploited in zero-day attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/chinese-hackers-exploring-vmware-zero-day-since-october-2024/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;VMware Certification Is Surging in a Shifting IT Landscape: VMware certification surges due to hybrid infrastructure, cloud complexity, and rising security risks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/vmware-certification-is-surging-in-a-shifting-it-landscape/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA warns of critical Linux Sudo flaw exploited in attacks: Hackers are exploiting a critical vulnerability in the sudo package, enabling root-level command execution. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-linux-sudo-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Broadcom fixes high-severity VMware NSX bugs reported by NSA: Security updates patch VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA). &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/broadcom-fixes-high-severity-vmware-nsx-bugs-reported-by-nsa/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK convicts “Bitcoin Queen” in world’s largest cryptocurrency seizure: The Metropolitan Police secured a conviction in the world’s largest cryptocurrency seizure. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/uk-convicts-bitcoin-queen-in-worlds-largest-cryptocurrency-seizure/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Japan’s largest brewer suspends operations due to cyberattack: Asahi Group Holdings, Ltd (Asahi) disclosed a cyberattack disrupting operations. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/japans-largest-brewer-suspends-operations-due-to-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ransomware gang sought BBC reporter’s help in hacking media giant: Medusa ransomware gang tempted a BBC correspondent to become an insider threat. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/ransomware-gang-sought-bbc-reporters-help-in-hacking-media-giant/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK govt backs JLR with £1.5 billion loan guarantee after cyberattack: The UK Government is providing Jaguar Land Rover (JLR) with a £1.5 billion loan guarantee after a cyberattack. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/uk-govt-backs-jlr-with-15-billion-loan-guarantee-after-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Scams &amp;amp; Social Engineering&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Details of a Scam: A personal experience details an attempted scam, highlighting social engineering tactics. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/09/details-of-a-scam.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to help protect foster youth from identity theft: The FTC provides guidance on protecting foster youth from identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone: The FTC warns of scammers impersonating FTC officials to steal money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Get a credit freeze to stop identity thieves: The FTC advises freezing credit to protect against identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/get-credit-freeze-stop-identity-thieves&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Scammers are impersonating the United States Patent and Trademark Office: Scammers impersonate the USPTO to steal money from business owners. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/scammers-are-impersonating-united-states-patent-and-trademark-office&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams: The FTC provides steps to avoid scams when selling a timeshare. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going: The FTC warns against donating to causes where fundraisers lie about fund usage. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam: The FTC provides tips on identifying and avoiding job scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams: The FTC advises on preparing for emergencies and avoiding related scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This Medicare Open Enrollment season, learn how to protect yourself from scams: The FTC advises on protecting against scams during Medicare Open Enrollment. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/medicare-open-enrollment-season-learn-how-protect-yourself-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Privacy&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Text messages and the new Texas registration requirement: Texas amended its telephone solicitation law to include text messages and registration requirements. &lt;a href=&quot;https://www.dataprotectionreport.com/2025/09/text-messages-and-the-new-texas-registration-requirement/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EFF Urges Virgina Court of Appeals to Require Search Warrants to Access ALPR Databases: EFF urges Virginia court to require warrants for ALPR data access, citing privacy concerns. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/eff-urges-virgina-court-appeals-require-search-warrants-access-alpr-databases&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chat Control Is Back on the Menu in the EU. It Still Must Be Stopped: EU Council debates “Chat Control,” scanning private conversations, raising privacy concerns. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/chat-control-back-menu-eu-it-still-must-be-stopped-0&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Artificial Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Brave launches ‘Ask Brave’ feature to fuse AI with traditional search: Brave integrates AI chat with search in a new feature called Ask Brave. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/brave-launches-ask-brave-feature-to-fuse-ai-with-traditional-search/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;It’s time to prepare for AI personhood | Jacy Reese Anthis: An article discussing the social upheaval that will come with technological advances in AI. &lt;a href=&quot;https://www.theguardian.com/commentisfree/2025/sep/30/artificial-intelligence-personhood&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Protecting Access to the Law—and Beneficial Uses of AI: EFF supports AI for legal research in Thomson Reuters v. ROSS Intelligence copyright case. &lt;a href=&quot;https://www.eff.org/deeplinks/2025/09/protecting-access-law-and-beneficial-uses-ai&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CCPA</category><category>Chat Control</category><category>Cybersecurity</category><category>Data Privacy</category><category>Linux</category><category>ransomware</category><category>VMware</category><category>Vulnerability</category><category>Zero-Day Exploit</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/vmware-exploit-linux-flaw-eu-chat-control-09-30-2025.webp" length="0" type="image/webp"/></item><item><title>VMware Zero-Day, CISA Alerts &amp; Cisco Flaws – 09/30/2025</title><link>https://grabtheaxe.com/news/vmware-zero-day-cisa-alerts-cisco-flaws-09-30-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/vmware-zero-day-cisa-alerts-cisco-flaws-09-30-2025/</guid><description>Critical VMware zero-day exploited by Chinese hackers since Oct 2024. CISA issues urgent patch orders for Fortra and Sudo flaws. 50k Cisco firewalls at risk.</description><pubDate>Tue, 30 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/vmware-zero-day-cisa-alerts-cisco-flaws-09-30-2025.webp&quot; alt=&quot;VMware Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is dominated by the active exploitation of critical vulnerabilities, including a VMware zero-day leveraged by Chinese hackers for nearly a year. CISA has issued urgent directives for flaws in Fortra and Linux Sudo, while nearly 50,000 Cisco firewalls remain exposed to ongoing attacks. This summary also covers a disruptive cyberattack on Japanese brewer Asahi and new threat intelligence on North Korean cyber operations and emerging malware toolkits.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA orders federal gov to patch critical Fortra file transfer bug: With a CVSS score of 10/10, CISA has issued an emergency directive for a critical vulnerability in Fortra’s file transfer solution, highlighting significant risk. &lt;a href=&quot;https://therecord.media/cisa-orders-federal-gov-patch-fortra-bug&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chinese hackers exploiting VMware zero-day since October 2024: A high-severity privilege escalation flaw (CVE-2025-41244) in VMware products has been actively exploited by a China-linked APT group for nearly a year before being patched. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-vmware-zero-day-since-october-2024/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA warns of critical Linux Sudo flaw exploited in attacks: CISA has added a critical Sudo vulnerability (CVE-2025-32463) to its Known Exploited Vulnerabilities catalog, as attackers are actively using it to gain root-level privileges on Linux systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-linux-sudo-flaw-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Nearly 50,000 Cisco firewalls vulnerable to actively exploited flaws: Tens of thousands of publicly exposed Cisco ASA and FTD appliances remain vulnerable to two actively exploited vulnerabilities, posing a significant risk to networks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/nearly-50-000-cisco-firewalls-vulnerable-to-actively-exploited-flaws/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical WD My Cloud bug allows remote command injection: Western Digital has patched a critical vulnerability in multiple My Cloud NAS devices that could allow remote attackers to execute arbitrary system commands. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/critical-wd-my-cloud-bug-allows-remote-command-injection/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;North Korea IT worker scheme expanding to more industries, countries outside of US tech sector: Research from Okta reveals that North Korean IT workers are expanding their infiltration efforts beyond the US tech sector into dozens of other countries and industries. &lt;a href=&quot;https://therecord.media/north-korea-it-worker-scheme-expands-outisde-us-tech&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New MatrixPDF toolkit turns PDFs into phishing and malware lures: A new toolkit named MatrixPDF enables attackers to weaponize standard PDF files, turning them into interactive lures designed to bypass email security for phishing and malware delivery. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-matrixpdf-toolkit-turns-pdfs-into-phishing-and-malware-lures/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New China APT Strikes With Precision and Persistence: A newly identified China-linked APT group, Phantom Taurus, is targeting government and telecom sectors using advanced, fileless backdoors to evade detection. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/new-china-apt-strikes-precision-persistence&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;‘Klopatra’ Trojan Makes Bank Transfers While You Sleep: A sophisticated new Android banking trojan, ‘Klopatra,’ is targeting users in Italy and Spain with advanced techniques to steal financial data and execute fraudulent transfers. &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/klopatra-trojan-bank-transfers-sleep&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events: The ‘Datzbro’ Android banking trojan is targeting elderly users by using AI-generated Facebook events to lure victims into installing malware capable of device takeover. &lt;a href=&quot;https://thehackernews.com/2025/09/new-android-trojan-datzbro-tricking.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Japan’s beer-making giant Asahi stops production after cyberattack : Asahi Group, a major Japanese brewer, has suspended production and has no recovery timeline after a significant cyberattack disrupted its systems. &lt;a href=&quot;https://techcrunch.com/2025/09/30/japans-beer-making-giant-asahi-stops-production-after-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A breach every month raises doubts about South Korea’s digital defenses: A consistent string of data breaches and security incidents in South Korea is raising serious questions about the nation’s cybersecurity posture despite its advanced digital infrastructure. &lt;a href=&quot;https://techcrunch.com/2025/09/30/a-breach-every-month-raises-doubts-about-south-koreas-digital-defenses/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;WestJet confirms recent breach exposed customers’ passports: Canadian airline WestJet has confirmed that a June cyberattack resulted in the compromise of sensitive customer data, including passport details and other ID documents. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/westjet-confirms-recent-breach-exposed-customers-passports/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations: Google’s Threat Intelligence Group provides a detailed defensive framework with proactive hardening measures to protect SaaS platforms like Salesforce from vishing and data theft campaigns. &lt;a href=&quot;https://cloud.google.com/blog/topics/threat-intelligence/unc6040-proactive-hardening-recommendations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Intel and AMD trusted enclaves, the backbone of network security, fall to physical attacks: Researchers have demonstrated that physical attacks can defeat the security of Intel SGX and AMD SEV trusted enclaves, a threat vector chipmakers claim is outside their model. &lt;a href=&quot;https://arstechnica.com/security/2025/09/intel-and-amd-trusted-enclaves-the-backbone-of-network-security-fall-to-physical-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Broadcom fixes high-severity VMware NSX bugs reported by NSA: Following a report from the NSA, Broadcom has released patches for two high-severity vulnerabilities in its VMware NSX network virtualization and security platform. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/broadcom-fixes-high-severity-vmware-nsx-bugs-reported-by-nsa/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CPPA fines Tractor Supply Company $1.4 million for privacy violations: Tractor Supply Company faces a $1.4 million fine for allegedly failing to provide a compliant privacy policy and sharing personal data without proper consent. &lt;a href=&quot;https://therecord.media/ccpa-tractor-supply-privacy-fine&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cyber information-sharing law and state grants set to go dark as Congress stalls over funding: Key cybersecurity initiatives, including a vital information-sharing law and state grant programs, are at risk of lapsing as Congress has yet to renew their funding. &lt;a href=&quot;https://therecord.media/cisa-2015-state-cyber-grants-lapse-congress-government-shutdown&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FTC alleges messaging app violated child privacy law, duped users into subscriptions: The FTC has filed a complaint against the Sendit app for allegedly collecting data from users under 13 and using deceptive subscription practices. &lt;a href=&quot;https://therecord.media/ftc-alleges-sendit-app-violated-children-privacy-rule&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Releases Ten Industrial Control Systems Advisories: CISA has published ten new advisories detailing vulnerabilities and security issues in various Industrial Control Systems (ICS) from vendors like Festo, MegaSys, and LG. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/30/cisa-releases-ten-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OpenAI unveils Sora 2 video model with realistic physics, high-quality audio, and a new social app: OpenAI’s new Sora 2 model advances AI video generation and is launching with a social app, raising concerns about the potential for sophisticated deepfakes and misinformation. &lt;a href=&quot;https://the-decoder.com/openai-unveils-sora-2-video-model-with-realistic-physics-high-quality-audio-and-a-new-social-app/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The US may be heading toward a drone-filled future: The increasing use of drones by private sector companies like Flock Safety for tracking shoplifters highlights growing concerns around surveillance and privacy. &lt;a href=&quot;https://www.technologyreview.com/2025/09/30/1124470/the-us-may-be-heading-toward-a-drone-filled-future/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI-Powered Voice Cloning Raises Vishing Risks: A new research framework demonstrates how AI voice cloning can be used in real-time conversations, significantly increasing the threat of sophisticated vishing attacks. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/ai-voice-cloning-vishing-risks&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Actively Exploited</category><category>APT</category><category>CISA</category><category>Cisco Firewall</category><category>Cybersecurity</category><category>Fortra</category><category>Sudo Vulnerability</category><category>threat intelligence</category><category>VMware Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/vmware-zero-day-cisa-alerts-cisco-flaws-09-30-2025.webp" length="0" type="image/webp"/></item><item><title>AI Vulnerability, Data Breach &amp; Ransomware – 09/29/2025</title><link>https://grabtheaxe.com/news/ai-vulnerability-data-breach-ransomware-09-29-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ai-vulnerability-data-breach-ransomware-09-29-2025/</guid><description>AI vulnerability in Notion, Harrods data breach, &amp; Akira ransomware bypass MFA. Stay informed about the latest privacy threats and security breaches.</description><pubDate>Mon, 29 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ai-vulnerability-data-breach-ransomware-09-29-2025.webp&quot; alt=&quot;AI Vulnerability&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s privacy briefing highlights a critical vulnerability in Notion’s AI agent, making it susceptible to data theft via prompt injection. We also cover a significant data breach at Harrods, affecting 430,000 customers, and Akira ransomware’s ability to bypass MFA on SonicWall VPNs. Stay informed about these pressing security threats and how to protect your data.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Abusing Notion’s AI Agent for Data Theft: Notion’s new AI agent is vulnerable to data theft via prompt injection due to access to private data and external communication capabilities. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/09/abusing-notions-ai-agent-for-data-theft.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Harrods suffers new data breach exposing 430,000 customer records: Hackers compromised a third-party supplier, stealing sensitive e-commerce customer information. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/harrods-suffers-new-data-breach-exposing-430-000-customer-records/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Akira ransomware breaching MFA-protected SonicWall VPN accounts: Threat actors are successfully logging in despite MFA, possibly via stolen OTP seeds. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/akira-ransomware-breaching-mfa-protected-sonicwall-vpn-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;12 Myths About Automated Decision-Making Systems, per the EDPS: The EDPS issued a TechDispatch addressing common misconceptions about ADM systems. &lt;a href=&quot;https://dataprivacy.foxrothschild.com/2025/09/articles/artificial-intelligence/12-myths-about-automated-decision-making-systems-per-the-edps/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;12 Myths About Automated Decision-Making Systems, per the EDPS: The EDPS issued a TechDispatch addressing common misconceptions about ADM systems. &lt;a href=&quot;https://dataprivacy.foxrothschild.com/2025/09/articles/artificial-intelligence/12-myths-about-automated-decision-making-systems-per-the-edps/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ChatGPT tests free trial for paid plans, rolls out cheaper Go in more regions: OpenAI is offering free trials for ChatGPT Plus and a cheaper GPT Go in Indonesia. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-tests-free-trial-for-paid-plans-rolls-out-cheaper-go-in-more-regions/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Protecting kids and adults online: The FTC and Utah Division of Consumer Protection announced a settlement with Aylo over distribution of child sex abuse materials. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/protecting-kids-and-adults-online&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Harrods suffers new data breach exposing 430,000 customer records: Hackers compromised a third-party supplier, stealing sensitive e-commerce customer information. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/harrods-suffers-new-data-breach-exposing-430-000-customer-records/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Can We Trust AI To Write Vulnerability Checks? Here’s What We Found: Intruder tested AI’s ability to write vulnerability checks, finding it helpful but requiring human oversight. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/can-we-trust-ai-to-write-vulnerability-checks-heres-what-we-found/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Akira ransomware breaching MFA-protected SonicWall VPN accounts: Threat actors are successfully logging in despite MFA, possibly via stolen OTP seeds. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/akira-ransomware-breaching-mfa-protected-sonicwall-vpn-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;AI Vulnerabilities&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Abusing Notion’s AI Agent for Data Theft: Notion’s new AI agent is vulnerable to data theft via prompt injection due to access to private data and external communication capabilities. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/09/abusing-notions-ai-agent-for-data-theft.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI is routing GPT-4o to safety models when it detects harmful activities: GPT-4o is routing requests to a safety model when harmful activities are detected. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-routing-gpt-4o-to-safety-models-when-it-detects-harmful-activities/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Phishing &amp;amp; Scams&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ignore unexpected calls about loans you didn’t apply for: Scammers are sending voicemails about loans you didn’t apply for, hoping you’ll respond. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/ignore-unexpected-calls-about-loans-you-didnt-apply&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;No, that’s not an FTC commissioner on the phone: Scammers impersonate FTC officials to get your money, but the FTC will never tell you to move your money. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/no-thats-not-ftc-commissioner-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Scammers are impersonating the United States Patent and Trademark Office: Scammers are impersonating the USPTO to steal money from business owners. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/scammers-are-impersonating-united-states-patent-and-trademark-office&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thinking about selling your timeshare? Key steps to avoid scams: Be cautious of easy ways to sell your timeshare, as they could be scams. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/thinking-about-selling-your-timeshare-key-steps-avoid-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Before you donate, find out where the money is going: The FTC says &lt;a href=&quot;http://Kars-R-Us.com&quot;&gt;Kars-R-Us.com&lt;/a&gt;, Inc. lied about how donated money would be spent. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/you-donate-find-out-where-money-going&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to spot a job scam: Learn how to identify phony business opportunities, work-at-home scams, and shady employment agencies. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-spot-job-scam&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to prepare yourself to deal with an emergency and avoid disaster-related scams: Have a plan and know how to spot disaster-related scams to aid recovery. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-prepare-yourself-deal-emergency-and-avoid-disaster-related-scams&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Identity Theft&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How to help protect foster youth from identity theft: Foster youth are at greater risk of identity theft due to frequent moves and access to their info. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/how-help-protect-foster-youth-identity-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Get a credit freeze to stop identity thieves: Freezing your credit is a great way to protect yourself from identity theft. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/get-credit-freeze-stop-identity-thieves&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Vulnerability</category><category>Data Breach</category><category>Identity Theft</category><category>MFA Bypass</category><category>Phishing</category><category>Privacy</category><category>ransomware</category><category>security</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ai-vulnerability-data-breach-ransomware-09-29-2025.webp" length="0" type="image/webp"/></item><item><title>CISA KEV, SonicWall Attacks, JLR Breach &amp; AI Threats – 09/29/2025</title><link>https://grabtheaxe.com/news/cisa-kev-sonicwall-attacks-jlr-breach-ai-threats-09-29-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cisa-kev-sonicwall-attacks-jlr-breach-ai-threats-09-29-2025/</guid><description>CISA adds 5 known exploited vulnerabilities to its KEV catalog. Analysis of Akira ransomware hitting SonicWall VPNs, the JLR breach, and new AI-driven phishing.</description><pubDate>Mon, 29 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cisa-kev-sonicwall-attacks-jlr-breach-ai-threats-09-29-2025.webp&quot; alt=&quot;Known Exploited Vulnerabilities&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s threat landscape is highlighted by CISA’s addition of five actively exploited vulnerabilities to its KEV catalog, demanding immediate attention from federal agencies and private organizations. Concurrently, the Akira ransomware group is escalating attacks against SonicWall VPNs, successfully bypassing MFA. Major incidents include a supply chain breach at Harrods exposing 430,000 records and the UK government’s £1.5B loan to Jaguar Land Rover following a debilitating cyberattack.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Adds Five Known Exploited Vulnerabilities to Catalog: CISA has added five vulnerabilities to its KEV catalog, including flaws in Cisco IOS, Fortra GoAnywhere MFT, and Sudo, indicating active exploitation and requiring immediate patching by federal agencies. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/29/cisa-adds-five-known-exploited-vulnerabilities-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Akira Hits SonicWall VPNs in Broad Ransomware Campaign: The Akira ransomware group is actively targeting SonicWall firewall customers by exploiting a known vulnerability to deploy their malware. &lt;a href=&quot;https://www.darkreading.com/application-security/akira-sonicwall-vpns-broad-ransomware-campaign&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SonicWall SSL VPN Attacks Escalate, Bypassing MFA: Threat actors are escalating attacks against SonicWall SSL VPN appliances, with reports indicating that the Akira ransomware campaign is capable of bypassing multi-factor authentication for rapid deployment. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/sonicwall-ssl-vpn-attacks-escalate/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Increase in Scans for Palo Alto Global Protect Vulnerability (CVE-2024-3400): Security researchers are observing a significant increase in scanning activity for CVE-2024-3400, a critical vulnerability in Palo Alto’s Global Protect feature, as attackers seek unpatched systems. &lt;a href=&quot;https://isc.sans.edu/diary/rss/32328&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package: A malicious npm package named ‘postmark-mcp’ was discovered containing the first-ever malicious Model Context Protocol (MCP) server, designed to intercept and exfiltrate sensitive emails, posing a significant supply chain risk. &lt;a href=&quot;https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations: A new campaign is using malicious software disguised as legitimate AI productivity tools to deliver malware, targeting organizations across Europe, the Americas, and the AMEA region. &lt;a href=&quot;https://thehackernews.com/2025/09/evilai-malware-masquerades-as-ai-tools.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Flags AI-Driven Phishing: LLM-Crafted SVG Files Outsmart Email Security: Microsoft has identified and blocked a sophisticated phishing campaign that used LLMs to generate obfuscated SVG files, enabling attackers to bypass standard email security defenses. &lt;a href=&quot;https://thehackernews.com/2025/09/microsoft-flags-ai-driven-phishing-llm.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ransomware gang sought BBC reporter’s help in hacking media giant: The Medusa ransomware gang reportedly attempted to recruit a BBC correspondent as an insider threat, offering a large sum of money to facilitate an attack on the media organization. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/ransomware-gang-sought-bbc-reporters-help-in-hacking-media-giant/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ukrainian Cops Spoofed in Fileless Phishing Attacks on Kyiv: Attackers are impersonating the National Police of Ukraine in phishing attacks that use malicious SVG files to deploy the Amatera Stealer and PureMiner malware. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/ukrainian-cops-spoofed-fileless-phishing-attacks-kyiv&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;UK government bails out Jaguar Land Rover with £1.5B loan after hack disrupts vehicle production for weeks: Following a catastrophic cyberattack that halted production, the UK government is providing Jaguar Land Rover with a £1.5 billion loan guarantee to help restore its supply chain. &lt;a href=&quot;https://techcrunch.com/2025/09/29/uk-government-bails-out-jaguar-land-rover-with-1-5b-loan-after-hack-disrupts-vehicle-production-for-weeks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Harrods suffers new data breach exposing 430,000 customer records: The UK retailer disclosed a new data breach originating from a compromised third-party supplier, resulting in the theft of 430,000 sensitive e-commerce customer records. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/harrods-suffers-new-data-breach-exposing-430-000-customer-records/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Japan’s largest brewer suspends operations due to cyberattack: Asahi Group Holdings, Japan’s top beer brewer, has suspended several operations after a cyberattack disrupted its systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/japans-largest-brewer-suspends-operations-due-to-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UK convicts “Bitcoin Queen” in world’s largest cryptocurrency seizure: A Chinese national has been convicted in a fraud case that led to the UK’s seizure of nearly $7 billion in Bitcoin, believed to be the largest crypto seizure in the world. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/uk-convicts-bitcoin-queen-in-worlds-largest-cryptocurrency-seizure/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Tile’s lack of encryption could make tracker owners vulnerable to stalking: Security researchers warn that Tile trackers’ lack of encryption and a static MAC address could allow malicious actors to track users without their consent, creating significant stalking risks. &lt;a href=&quot;https://www.theverge.com/news/787836/tile-trackers-stalking-research-unencrypted&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Welcoming CERN to Have I Been Pwned: The European Organization for Nuclear Research (CERN), the birthplace of the World Wide Web, is now using Have I Been Pwned to monitor for compromised accounts. &lt;a href=&quot;https://www.troyhunt.com/welcoming-cern-to-have-i-been-pwned/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;IoT Security Flounders Amid Churning Risk: Despite increasing attacks on IoT devices, a key US government security initiative for connected devices is reportedly stalled, leaving critical infrastructure like medical and industrial equipment at risk. &lt;a href=&quot;https://www.darkreading.com/iot/iot-security-flounders-amid-churning-risk&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA and UK NCSC Release Joint Guidance for Securing OT Systems: CISA and international partners have released joint guidance on creating and maintaining a definitive architectural view of Operational Technology (OT) systems to improve risk assessment and security controls. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/29/cisa-and-uk-ncsc-release-joint-guidance-securing-ot-systems&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Strengthens Commitment to SLTT Governments: CISA is transitioning to a new support model for state, local, tribal, and territorial (SLTT) governments, providing direct access to grant funding, no-cost tools, and cybersecurity expertise. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/29/cisa-strengthens-commitment-sltt-governments&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Abusing Notion’s AI Agent for Data Theft: Researchers have demonstrated how Notion’s new AI agents are vulnerable to prompt injection attacks, allowing for data exfiltration by hiding malicious commands in PDF files. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/09/abusing-notions-ai-agent-for-data-theft.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Can We Trust AI To Write Vulnerability Checks? Here’s What We Found: Research into using AI for writing vulnerability checks shows that while it can accelerate the process, human oversight remains critical to ensure quality and prevent errors. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/can-we-trust-ai-to-write-vulnerability-checks-heres-what-we-found/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SB 53, the landmark AI transparency bill, is now law in California: California has passed Senate Bill 53, requiring large AI developers to publicly disclose their safety and security frameworks and providing whistleblower protections. &lt;a href=&quot;https://www.theverge.com/ai-artificial-intelligence/787918/sb-53-the-landmark-ai-transparency-bill-is-now-law-in-california&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Akira</category><category>CISA</category><category>Data Breach</category><category>KEV</category><category>ransomware</category><category>SonicWall</category><category>Supply Chain Attack</category><category>threat intelligence</category><category>vulnerability management</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/cisa-kev-sonicwall-attacks-jlr-breach-ai-threats-09-29-2025.webp" length="0" type="image/webp"/></item><item><title>Data Breach, Supply Chain, AML Reforms &amp; DPO – 09/29/2025</title><link>https://grabtheaxe.com/news/data-breach-supply-chain-aml-reforms-dpo-09-29-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/data-breach-supply-chain-aml-reforms-dpo-09-29-2025/</guid><description>Compliance updates: Data breach at Veradigm, FASCA order on Acronis, AML reforms, and guidance for DPOs in the UK. Stay informed on key compliance risks.</description><pubDate>Mon, 29 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/data-breach-supply-chain-aml-reforms-dpo-09-29-2025.webp&quot; alt=&quot;Supply Chain&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This compliance intelligence digest highlights critical updates, including a data breach at Veradigm, a FASCA order impacting Acronis, and phishing attacks targeting Ukrainian officials. Supply chain vulnerabilities are exposed through Chinese support of Russian drone manufacturing. Additionally, insights are provided on AML reforms, the role of DPOs, and strategies for compliance leaders to measure effectiveness.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Compliance Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Veradigm Announces Data Breach Affecting Several Customers: Veradigm, a provider of practice management and electronic health record solutions, reports a data breach affecting several customers. &lt;a href=&quot;https://www.hipaajournal.com/veradigm-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DNI Issues First-Ever FASCA Order, Excludes Acronis from Intelligence Community Contracts: The federal government takes supply chain protection action, excluding Acronis from intelligence community contracts. &lt;a href=&quot;https://www.jdsupra.com/legalnews/dni-issues-first-ever-fasca-order-8915688/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ukrainian Cops Spoofed in Fileless Phishing Attacks on Kyiv: Attackers impersonate the National Police of Ukraine to deploy Amatera Stealer and PureMiner via malicious SVG files. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/ukrainian-cops-spoofed-fileless-phishing-attacks-kyiv&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chinese experts, Russian drones: What the drone case reveals about supply chain blind spots: Investigation reveals Chinese drone specialists working with sanctioned Russian arms manufacturer IEMZ Kupol. &lt;a href=&quot;https://vinciworks.com/blog/chinese-experts-russian-drones-what-the-drone-case-reveals-about-supply-chain-blind-spots/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;PCAs in the firing line: What law firms need to know about the Treasury’s AML reforms: HM Treasury is tightening AML compliance, focusing on pooled client accounts (PCAs) in law firms. &lt;a href=&quot;https://vinciworks.com/blog/pcas-in-the-firing-line-what-law-firms-need-to-know-about-the-treasurys-aml-reforms/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;PCAs in the firing line: What law firms need to know about the Treasury’s AML reforms: HM Treasury is tightening AML compliance, focusing on pooled client accounts (PCAs) in law firms. &lt;a href=&quot;https://vinciworks.com/blog/pcas-in-the-firing-line-what-law-firms-need-to-know-about-the-treasurys-aml-reforms/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Turkey’s First Climate Law: Environmental Necessity Meets Export Strategy: Law creates framework for 2053 net-zero target while positioning Turkey for green trade advantages. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/turkey-first-climate-law/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Third-Party Risk &amp;amp; Due Diligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Chinese experts, Russian drones: What the drone case reveals about supply chain blind spots: Investigation reveals Chinese drone specialists working with sanctioned Russian arms manufacturer IEMZ Kupol. &lt;a href=&quot;https://vinciworks.com/blog/chinese-experts-russian-drones-what-the-drone-case-reveals-about-supply-chain-blind-spots/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DNI Issues First-Ever FASCA Order, Excludes Acronis from Intelligence Community Contracts: The federal government takes supply chain protection action, excluding Acronis from intelligence community contracts. &lt;a href=&quot;https://www.jdsupra.com/legalnews/dni-issues-first-ever-fasca-order-8915688/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Seeing Tomorrow’s Supplier Risks Today: Why Predictive Analytics is Critical?: Predictive analytics are critical for managing supplier risks, as highlighted at the Salesforce Manufacturing Summit. &lt;a href=&quot;https://www.compliancequest.com/blog/predictive-analytics-supplier-risk-management/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Why Compliance Leaders Should Think Like Marketers When Measuring Effectiveness: Compliance can prove business impact by adopting marketing strategies for measuring effectiveness. &lt;a href=&quot;https://www.corporatecomplianceinsights.com/why-compliance-leaders-should-think-like-marketers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to Become a DPO (Data Protection Officer) in the UK: Guidance on becoming a Data Protection Officer in the UK, a fast-growing privacy role. &lt;a href=&quot;https://www.itgovernance.co.uk/blog/how-to-become-a-dpo-data-protection-officer-in-the-uk&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;When Bots Rip Apart Your Business: Corporate compliance officers must consider the impact of bots on corporate culture and ethical priorities. &lt;a href=&quot;https://www.radicalcompliance.com/2025/09/29/when-bots-rip-apart-your-business/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AML</category><category>Data Breach</category><category>DPO</category><category>FASCA</category><category>Phishing</category><category>Regulatory Compliance</category><category>Supply Chain</category><category>Ukraine</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/data-breach-supply-chain-aml-reforms-dpo-09-29-2025.webp" length="0" type="image/webp"/></item><item><title>Akira Ransomware, MFA Bypass &amp; AI Security – 09/28/2025</title><link>https://grabtheaxe.com/news/akira-ransomware-mfa-bypass-ai-security-09-28-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/akira-ransomware-mfa-bypass-ai-security-09-28-2025/</guid><description>Critical alert on Akira ransomware bypassing MFA on SonicWall VPNs. This security digest covers the latest threat intelligence, major incidents, and AI&apos;s role in attacks.</description><pubDate>Sun, 28 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/akira-ransomware-mfa-bypass-ai-security-09-28-2025.webp&quot; alt=&quot;Akira Ransomware&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s intelligence digest highlights a critical threat from the Akira ransomware group, which is actively bypassing MFA on SonicWall VPN devices. This development poses a significant risk to organizations relying on multi-factor authentication for network security. We will also cover a major infrastructure incident involving a datacenter fire and discuss the evolving role of artificial intelligence in transforming modern cyberattacks. Stay informed on these key security developments.&lt;/p&gt;
&lt;h2&gt;Critical Security Alert&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Akira ransomware breaching MFA-protected SonicWall VPN accounts: The Akira ransomware group is actively exploiting SonicWall SSL VPNs, successfully bypassing multi-factor authentication, potentially through the use of stolen OTP seeds. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/akira-ransomware-breaching-mfa-protected-sonicwall-vpn-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Akira ransomware breaching MFA-protected SonicWall VPN accounts: The Akira ransomware group is actively exploiting SonicWall SSL VPNs, successfully bypassing multi-factor authentication, potentially through the use of stolen OTP seeds. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/akira-ransomware-breaching-mfa-protected-sonicwall-vpn-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Datacenter fire takes 647 South Korean government services offline: A significant fire at a South Korean datacenter has caused a massive outage, knocking hundreds of government digital services offline and highlighting physical security risks. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/09/28/asia_tech_news_roundup/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Privacy Badger is a free browser extension made by EFF to stop spying: The Electronic Frontier Foundation (EFF) offers Privacy Badger, a free browser extension designed to automatically block invisible trackers and prevent third-party ad spying. &lt;a href=&quot;https://privacybadger.org/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Wiz chief technologist Ami Luttwak on how AI is transforming cyberattacks: Wiz CTO Ami Luttwak provides insight into how artificial intelligence is being leveraged by threat actors to create more sophisticated cyberattacks and what it means for defenders. &lt;a href=&quot;https://techcrunch.com/2025/09/28/wiz-chief-technologist-ami-luttwak-on-how-ai-is-transforming-cyberattacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI in Security</category><category>Akira ransomware</category><category>Cybersecurity</category><category>Data Center Outage</category><category>MFA Bypass</category><category>Security Incident</category><category>SonicWall VPN</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/akira-ransomware-mfa-bypass-ai-security-09-28-2025.webp" length="0" type="image/webp"/></item><item><title>DNA, COPPA, Ransomware &amp; Radicalization – 09/28/2025</title><link>https://grabtheaxe.com/news/dna-coppa-ransomware-radicalization-09-28-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/dna-coppa-ransomware-radicalization-09-28-2025/</guid><description>Privacy digest: DHS DNA collection, Akira ransomware bypasses MFA, Disney&apos;s COPPA fine, and online radicalization trends. Stay informed on today&apos;s key threats.</description><pubDate>Sun, 28 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/dna-coppa-ransomware-radicalization-09-28-2025.webp&quot; alt=&quot;DNA Harvesting&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Privacy risks are intensifying across government, corporate, and digital domains. The DHS has been secretly collecting DNA from US citizens without authorization, raising profound civil liberties concerns. Meanwhile, Akira ransomware is bypassing MFA protections on SonicWall VPNs, exposing critical weaknesses in enterprise defenses. From Disney’s $10 million COPPA settlement to scammers impersonating the USPTO and the rise of online radicalization, today’s threats underscore the urgent need for stronger oversight, transparency, and resilience.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Privacy Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;DHS Has Been Collecting US Citizens’ DNA for Years: CBP agents have been harvesting DNA from American citizens, including minors, without Congressional authorization. &lt;a href=&quot;https://pogowasright.org/dhs-has-been-collecting-us-citizens-dna-for-years/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Akira ransomware breaching MFA-protected SonicWall VPN accounts: Akira ransomware attacks are successfully bypassing MFA on SonicWall VPNs, possibly through stolen OTP seeds. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/akira-ransomware-breaching-mfa-protected-sonicwall-vpn-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Disney settles charges that it violated children’s online privacy protection law: Disney will pay a $10 million penalty for COPPA violations related to collecting children’s data without parental consent. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/disney-settles-charges-it-violated-childrens-online-privacy-protection-law&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Scammers are impersonating the United States Patent and Trademark Office: Scammers are impersonating the USPTO to steal money from business owners by targeting their trademarks. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/scammers-are-impersonating-united-states-patent-and-trademark-office&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Reading the post-riot posts: how we traced far-right radicalisation across 51,000 Facebook messages: Investigation traces far-right radicalization through online activity related to summer 2024 riots. &lt;a href=&quot;https://www.theguardian.com/world/2025/sep/28/reading-the-post-riot-posts-how-we-traced-far-right-radicalisation-across-51000-facebook-messages&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Privacy Laws &amp;amp; Regulations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Disney settles charges that it violated children’s online privacy protection law: Disney will pay a $10 million penalty for COPPA violations related to collecting children’s data without parental consent. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/disney-settles-charges-it-violated-childrens-online-privacy-protection-law&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EU probes SAP over anti-competitive ERP support practices: The European Commission is investigating SAP for potential anti-competitive practices in ERP support services. &lt;a href=&quot;https://www.bleepingcomputer.com/news/legal/eu-probes-sap-over-anti-competitive-erp-support-practices/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Minimization &amp;amp; User Consent&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;DHS Has Been Collecting US Citizens’ DNA for Years: CBP agents have been harvesting DNA from American citizens, including minors, without Congressional authorization. &lt;a href=&quot;https://pogowasright.org/dhs-has-been-collecting-us-citizens-dna-for-years/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Fines &amp;amp; Enforcement Actions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Disney settles charges that it violated children’s online privacy protection law: Disney will pay a $10 million penalty for COPPA violations related to collecting children’s data without parental consent. &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2025/09/disney-settles-charges-it-violated-childrens-online-privacy-protection-law&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EU probes SAP over anti-competitive ERP support practices: The European Commission is investigating SAP for potential anti-competitive practices in ERP support services. &lt;a href=&quot;https://www.bleepingcomputer.com/news/legal/eu-probes-sap-over-anti-competitive-erp-support-practices/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>COPPA</category><category>Data Privacy</category><category>DHS</category><category>DNA Harvesting</category><category>FTC</category><category>MFA Bypass</category><category>Online Radicalization</category><category>ransomware</category><category>Scams</category><category>SonicWall</category><category>USPTO</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/dna-coppa-ransomware-radicalization-09-28-2025.webp" length="0" type="image/webp"/></item><item><title>Nursery Hacking, AML Supervision &amp; Astute LXP – 09/28/2025</title><link>https://grabtheaxe.com/news/nursery-hacking-aml-astute-09-28-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/nursery-hacking-aml-astute-09-28-2025/</guid><description>Nursery hacking incident, AML regulatory changes, and Astute LXP updates. Stay informed on key compliance and security developments.</description><pubDate>Sun, 28 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/nursery-hacking-aml-astute-09-28-2025.webp&quot; alt=&quot;Nursery Hacking&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s compliance landscape is marked by escalating risks that demand immediate attention. A cyberattack on a global nursery chain underscores the vulnerability of sensitive personal data and the growing need for stronger protections. At the same time, US regulators signal potential shifts in anti-money laundering oversight, hinting at an intelligence-first supervisory model. Adding to the momentum, updates to the Astute LXP platform highlight the ongoing evolution of governance and compliance technology.&lt;/p&gt;
&lt;h2&gt;Critical Compliance Alert&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When hackers target nurseries: Why cyber security has never mattered more: Hackers stole and leaked data from Kido International, a global nursery chain. The attackers, calling themselves Radiant, claim to have stolen personal information. &lt;a href=&quot;https://vinciworks.com/blog/when-hackers-target-nurseries-why-cyber-security-has-never-mattered-more/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Regulatory Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Is big regulatory change afoot in the US? The future of AML supervision: John K. Hurley signaled a serious rethink of America’s anti-money laundering playbook, laying out an intelligence-first model. &lt;a href=&quot;https://vinciworks.com/blog/is-big-regulatory-change-afoot-in-the-us-the-future-of-aml-supervision/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Policy &amp;amp; Governance Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;What’s New in Astute LXP – September 2025 Update (v3.4.3): Release focuses on speeding up Previous LMS Records imports and resolving issues across reporting, courses, emails, and surveys. &lt;a href=&quot;https://vinciworks.com/blog/whats-new-in-astute-lxp-september-2025-update-v3-4-3/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AML</category><category>Cybersecurity</category><category>Data Breach</category><category>eLearning</category><category>Hacking</category><category>LXP</category><category>Privacy</category><category>Regulatory Change</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/nursery-hacking-aml-astute-09-28-2025.webp" length="0" type="image/webp"/></item><item><title>PlugX Malware, Oyster Backdoor &amp; NPM Threats – 09/27/2025</title><link>https://grabtheaxe.com/news/plugx-malware-oyster-backdoor-npm-threats-09-27-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/plugx-malware-oyster-backdoor-npm-threats-09-27-2025/</guid><description>Critical threat intelligence digest for 09/27/2025. In-depth analysis of China-linked PlugX malware, Oyster backdoor in fake Teams installers, and NPM backdoors.</description><pubDate>Sat, 27 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/plugx-malware-oyster-backdoor-npm-threats-09-27-2025.webp&quot; alt=&quot;PlugX Malware&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s intelligence digest highlights a significant escalation in nation-state activity, with a China-linked campaign deploying PlugX and Bookworm malware against telecommunications sectors in Asia. Concurrently, a malvertising campaign is distributing the Oyster backdoor via fake Microsoft Teams installers to gain initial corporate access. We also cover an emerging supply chain threat involving a malicious backdoor in an NPM package. This is the critical information your organization needs to know today.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fake Microsoft Teams installers push Oyster malware via malvertising : Attackers are using malicious ads for fake Microsoft Teams installers to deploy the Oyster backdoor, gaining initial access to corporate networks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fake-microsoft-teams-installers-push-oyster-malware-via-malvertising/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks : A China-linked threat actor is actively targeting telecommunications and manufacturing sectors in Asia with new variants of PlugX and Bookworm malware. &lt;a href=&quot;https://thehackernews.com/2025/09/china-linked-plugx-and-bookworm-malware.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Postmark backdoor that’s downloading emails : A malicious backdoor has been discovered in an NPM package, designed to compromise systems and exfiltrate user emails, highlighting supply chain risks. &lt;a href=&quot;https://www.koi.security/blog/postmark-mcp-npm-malicious-backdoor-email-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hunt for RedNovember: Beijing hacked critical orgs in year-long snooping campaign : A newly detailed report outlines a year-long espionage campaign by a Beijing-linked group, RedNovember, that targeted critical organizations for data theft. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/09/27/rednovember_chinese_espionage/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Dutch teens arrested for trying to spy on Europol for Russia : Two teenagers in the Netherlands have been arrested for allegedly using hacking devices to conduct espionage against the European Union Agency for Law Enforcement Cooperation (Europol) on behalf of Russia. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/dutch-teens-arrested-for-trying-to-spy-on-europol-for-russia/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fake Microsoft Teams installers push Oyster malware via malvertising : Attackers are using malicious ads for fake Microsoft Teams installers to deploy the Oyster backdoor, gaining initial access to corporate networks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fake-microsoft-teams-installers-push-oyster-malware-via-malvertising/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks : A China-linked threat actor is actively targeting telecommunications and manufacturing sectors in Asia with new variants of PlugX and Bookworm malware. &lt;a href=&quot;https://thehackernews.com/2025/09/china-linked-plugx-and-bookworm-malware.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Postmark backdoor that’s downloading emails : A malicious backdoor has been discovered in an NPM package, designed to compromise systems and exfiltrate user emails, highlighting supply chain risks. &lt;a href=&quot;https://www.koi.security/blog/postmark-mcp-npm-malicious-backdoor-email-theft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hunt for RedNovember: Beijing hacked critical orgs in year-long snooping campaign : A newly detailed report outlines a year-long espionage campaign by a Beijing-linked group, RedNovember, that targeted critical organizations for data theft. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/09/27/rednovember_chinese_espionage/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Dutch teens arrested for trying to spy on Europol for Russia : Two teenagers in the Netherlands have been arrested for allegedly using hacking devices to conduct espionage against the European Union Agency for Law Enforcement Cooperation (Europol) on behalf of Russia. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/dutch-teens-arrested-for-trying-to-spy-on-europol-for-russia/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SSH3: Faster and rich secure shell using HTTP/3 : A new proposal, SSH3, leverages the performance and features of HTTP/3 to offer a faster, more robust, and more feature-rich secure shell experience. &lt;a href=&quot;https://github.com/francoismichel/ssh3&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft’s VibeVoice is a new AI podcast model that might generate spontaneous singing : Microsoft has developed VibeVoice, an AI model capable of generating long-form, multi-speaker conversations, raising potential concerns for sophisticated audio deepfakes. &lt;a href=&quot;https://the-decoder.com/microsofts-vibevoice-is-a-new-ai-podcast-model-that-might-generate-spontaneous-singing/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Anthropic settles landmark AI copyright lawsuit for at least $1.5 billion : Anthropic’s $1.5 billion settlement with authors and publishers could establish new legal precedents and risks for training AI models on copyrighted material. &lt;a href=&quot;https://the-decoder.com/anthropic-settles-landmark-ai-copyright-lawsuit-for-at-least-1-5-billion/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI says top AI models are reaching expert territory on real-world knowledge work : OpenAI’s new benchmark suggests that top-tier AI models are performing at expert levels, indicating rapidly advancing capabilities that could be used for both defensive and offensive cyber operations. &lt;a href=&quot;https://the-decoder.com/openai-says-top-ai-models-are-reaching-expert-territory-on-real-world-knowledge-work/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Cybersecurity</category><category>Malware Analysis</category><category>Nation-State Actors</category><category>NPM Backdoor</category><category>Oyster Malware</category><category>PlugX Malware</category><category>Supply Chain Attack</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/plugx-malware-oyster-backdoor-npm-threats-09-27-2025.webp" length="0" type="image/webp"/></item><item><title>GoAnywhere Flaw, Cisco Exploits &amp; LockBit Variant – 09/26/2025</title><link>https://grabtheaxe.com/news/goanywhere-flaw-cisco-exploits-lockbit-variant-09-26-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/goanywhere-flaw-cisco-exploits-lockbit-variant-09-26-2025/</guid><description>Critical GoAnywhere MFT zero-day (CVSS 10.0) under active exploit. Get the latest on Cisco firewall attacks, a new dangerous LockBit variant, and other top threats.</description><pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/goanywhere-flaw-cisco-exploits-lockbit-variant-09-26-2025.webp&quot; alt=&quot;GoAnywhere Vulnerability&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s intelligence digest is dominated by actively exploited zero-day vulnerabilities in enterprise-grade software. A critical CVSS 10.0 flaw in Fortra’s GoAnywhere MFT is being exploited in the wild, alongside separate zero-days in Cisco firewalls used by the ArcaneDoor APT. We are also tracking a new, more dangerous variant of the LockBit ransomware and a campaign by Iranian state actors using valid SSL certificates to sign malware.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Maximum severity GoAnywhere MFT flaw exploited as zero-day: A critical CVSS 10.0 vulnerability in Fortra’s GoAnywhere MFT is being actively exploited as a zero-day, with evidence suggesting exploitation began a week before public disclosure. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/maximum-severity-goanywhere-mft-flaw-exploited-as-zero-day/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cisco ASA Firewall Zero-Day Exploits Deploy New Malware: The ArcaneDoor threat actor is exploiting zero-day vulnerabilities in Cisco firewalls to deploy new malware strains, RayInitiator and LINE VIPER, prompting urgent patch advisories from US and UK agencies. &lt;a href=&quot;https://thehackernews.com/2025/09/cisco-asa-firewall-zero-day-exploits.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New LockBit Ransomware Variant Emerges as Most Dangerous Yet: A new version of the LockBit ransomware has been identified with significant technical improvements and cross-platform capabilities, targeting Windows, Linux, and VMware ESXi systems. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/lockbit-ransomware-most-dangerous/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Iranian State Hackers Use &lt;a href=&quot;http://SSL.com&quot;&gt;SSL.com&lt;/a&gt; Certificates to Sign Malware: Multiple Iranian state-sponsored threat groups, including Charming Kitten, are using valid code-signing certificates from &lt;a href=&quot;http://SSL.com&quot;&gt;SSL.com&lt;/a&gt; to sign and distribute malware, bypassing security controls. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/iranian-hackers-ssl-certificates-sign-malware&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ransomware attack on Ohio county impacts over 45,000 residents: A ransomware attack on an Ohio county has resulted in a significant data breach, exposing the names, Social Security numbers, and financial information of over 45,000 people. &lt;a href=&quot;https://therecord.media/ohio-ransomware-attack-impacts-45000&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New COLDRIVER Malware Campaign Targets Russia-Focused Entities: The Russian APT group COLDRIVER is using new malware families, BAITSWITCH and SIMPLEFIX, in a multi-stage campaign against Russia-focused targets. &lt;a href=&quot;https://thehackernews.com/2025/09/new-coldriver-malware-campaign-joins-bo.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module: An updated version of the XCSSET macOS malware has been discovered with enhanced capabilities for browser targeting, clipboard hijacking, and establishing persistence. &lt;a href=&quot;https://thehackernews.com/2025/09/new-macos-xcsset-variant-targets.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;HeartCrypt Packer-as-a-Service Operation Expands Impersonation Efforts: Security researchers have detailed the evolution of the HeartCrypt Packer-as-a-Service, a notorious operation used by threat actors to obfuscate malware. &lt;a href=&quot;https://news.sophos.com/en-us/2025/09/26/heartcrypts-wholesale-impersonation-effort/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phishing Campaign Uses Malicious SVG Files to Target Ukraine and Vietnam: A phishing campaign impersonating Ukrainian government agencies is using malicious SVG files to deliver CountLoader, which in turn drops Amatera Stealer and PureMiner malware. &lt;a href=&quot;https://thehackernews.com/2025/09/researchers-expose-svg-and-purerat.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Teens Arrested in Netherlands on Suspicion of Spying for Russia: Two teenagers have been arrested by Dutch police, reportedly suspected of conducting cyber-espionage activities on behalf of pro-Russian hacking groups. &lt;a href=&quot;https://therecord.media/teens-arrested-netherlands-reportedly-suspected-cyber-espionage-russia&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Volvo Employee SSNs Stolen in Supplier Ransomware Attack: Volvo North America has confirmed that employee Social Security Numbers were stolen as part of a ransomware attack targeting one of its IT suppliers. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/volvo-employee-ssns-stolen-ransomware-attack&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Thousands of Indian bank transfer records found spilling online after security lapse: A configuration error at Indian fintech company NuPay exposed thousands of sensitive bank transfer records online, which have since been secured. &lt;a href=&quot;https://techcrunch.com/2025/09/26/thousands-of-indian-bank-transfer-records-found-online/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Edge to block malicious sideloaded extensions: Microsoft is introducing a new security feature in its Edge browser designed to protect users by blocking potentially malicious extensions that are sideloaded. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-edge-to-block-malicious-sideloaded-extensions/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft shares temp fix for Outlook encrypted email errors: Microsoft is investigating an issue causing errors when opening encrypted emails from external organizations in Outlook and has provided a temporary workaround. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-temp-fix-for-outlook-encrypted-email-errors/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;TruSources to showcase on-device identity-checking technology: A startup named TruSources is developing privacy-focused technology that performs age and identity verification directly on a user’s device without uploading IDs. &lt;a href=&quot;https://techcrunch.com/2025/09/26/trusources-to-show-off-its-on-device-identity-checking-tech-at-techcrunch-disrupt-2025/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The hidden cyber risks of deploying generative AI: Deploying generative AI without proper safeguards can introduce significant security risks, including new avenues for phishing, fraud, and model manipulation. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/the-hidden-cyber-risks-of-deploying-generative-ai/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US investigators are using AI to detect child abuse images made by AI: The Department of Homeland Security is experimenting with AI tools to differentiate between AI-generated child abuse material and images depicting real victims. &lt;a href=&quot;https://www.technologyreview.com/2025/09/26/1124343/us-investigators-are-using-ai-to-detect-child-abuse-images-made-by-ai/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>APT</category><category>Cisco ASA</category><category>Cybersecurity</category><category>Data Breach</category><category>GoAnywhere Vulnerability</category><category>LockBit</category><category>ransomware</category><category>threat intelligence</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/goanywhere-flaw-cisco-exploits-lockbit-variant-09-26-2025.webp" length="0" type="image/webp"/></item><item><title>Cisco Zero-Days, Shai-Hulud Worm &amp; CISA Alerts – 09/25/2025</title><link>https://grabtheaxe.com/news/cisco-zero-days-shai-hulud-worm-cisa-alerts-09-25-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cisco-zero-days-shai-hulud-worm-cisa-alerts-09-25-2025/</guid><description>Critical alert on Cisco zero-day vulnerabilities under active exploit. Details on the CISA emergency directive, &apos;Shai-Hulud&apos; npm worm, and major data breaches.</description><pubDate>Thu, 25 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cisco-zero-days-shai-hulud-worm-cisa-alerts-09-25-2025.webp&quot; alt=&quot;Cisco Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is dominated by multiple actively exploited zero-day vulnerabilities in Cisco firewalls, prompting an emergency directive from CISA for immediate patching. A massive software supply chain attack, dubbed ‘Shai-Hulud,’ has compromised over 500 npm packages, affecting millions of downloads. We are also covering the significant financial fallout from the Co-op cyberattack and a critical data exposure flaw in a popular call-recording app. This digest provides essential details on these high-priority threats.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cisco warns of ASA firewall zero-days exploited in attacks: Cisco has disclosed two critical zero-day vulnerabilities in its ASA and FTD firewall software that are being actively exploited in the wild, urging immediate patching. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-firewall-zero-days-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA orders agencies to patch Cisco flaws exploited in zero-day attacks: CISA has issued an emergency directive ordering all U.S. federal agencies to secure their Cisco firewall devices against the two actively exploited zero-day flaws within one day. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-orders-agencies-to-patch-cisco-flaws-exploited-in-zero-day-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;As many as 2 million Cisco devices affected by actively exploited 0-day: Security scans reveal that up to two million Cisco devices with vulnerable SNMP interfaces are exposed to the internet, significantly increasing the attack surface for this exploited flaw. &lt;a href=&quot;https://arstechnica.com/security/2025/09/as-many-as-2-million-cisco-devices-affected-by-actively-exploited-0-day/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Massive npm infection: the Shai-Hulud worm and patient zero: A widespread software supply chain attack involves a self-replicating worm named ‘Shai-Hulud,’ which has infected over 500 npm packages with millions of downloads. &lt;a href=&quot;https://securelist.com/shai-hulud-worm-infects-500-npm-packages-in-a-supply-chain-attack/117547/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical Vulnerability in Salesforce AgentForce Exposed: A critical flaw dubbed ‘ForcedLeak’ in Salesforce’s AgentForce AI platform allows for sensitive CRM data exfiltration through indirect prompt injection attacks. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/critical-flaw-salesforce-agentforce/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft warns of new XCSSET macOS malware variant targeting Xcode devs: Microsoft Threat Intelligence has identified a new variant of the XCSSET macOS malware, which now includes enhanced features for browser targeting and clipboard hijacking. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-xcsset-macos-malware-variant-targeting-xcode-devs/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Malicious Rust packages on &lt;a href=&quot;http://Crates.io&quot;&gt;Crates.io&lt;/a&gt; steal crypto wallet keys: Two malicious packages on Rust’s official &lt;a href=&quot;http://Crates.io&quot;&gt;Crates.io&lt;/a&gt; repository, downloaded nearly 8,500 times, were found scanning developer systems to steal cryptocurrency private keys. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/malicious-rust-packages-on-cratesio-steal-crypto-wallet-keys/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Unofficial Postmark MCP npm silently stole users’ emails: A malicious npm package impersonating the official ‘postmark-mcp’ library was discovered exfiltrating user email communications via a single line of malicious code. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/unofficial-postmark-mcp-npm-silently-stole-users-emails/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Co-op says it lost $107 million after Scattered Spider attack: UK retailer The Co-op has reported a massive operating loss of £80 million ($107 million) as a direct result of the cyberattack it suffered in April. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/co-op-says-it-lost-107-million-after-scattered-spider-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Viral call-recording app Neon goes dark after exposing users’ phone numbers, call recordings, and transcripts: The popular iPhone app Neon was pulled offline after a major security bug was discovered that allowed any user to access the call recordings and transcripts of other users. &lt;a href=&quot;https://techcrunch.com/2025/09/25/viral-call-recording-app-neon-goes-dark-after-exposing-users-phone-numbers-call-recordings-and-transcripts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How secure are passkeys, really? Here’s what you need to know: Passkeys offer significant advantages over traditional passwords by providing phishing resistance and simpler logins, though some hurdles to widespread adoption remain. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/how-secure-are-passkeys-really-heres-what-you-need-to-know/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Chinese APT Drops ‘Brickstorm’ Backdoors on Edge Devices: The China-linked cyber-espionage group UNC5221 is actively compromising network edge devices with new versions of the ‘Brickstorm’ backdoor to evade traditional EDR solutions. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/chinese-apt-brickstorm-backdoors-edge-devices&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA urges orgs to review software after ‘Shai-Hulud’ supply chain compromise: In response to the ‘Shai-Hulud’ worm, CISA is urging all organizations to diligently review their software supply chains for potential compromise from infected packages. &lt;a href=&quot;https://therecord.media/cisa-urges-software-reviews-malicious-packages&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CISA</category><category>Cisco Vulnerability</category><category>Cybersecurity</category><category>Data Breach</category><category>Firewall Security</category><category>Malware</category><category>npm</category><category>Supply Chain Attack</category><category>threat intelligence</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/cisco-zero-days-shai-hulud-worm-cisa-alerts-09-25-2025.webp" length="0" type="image/webp"/></item><item><title>Cisco Zero-Day, BRICKSTORM Malware &amp; Supermicro Flaws – 09/24/2025</title><link>https://grabtheaxe.com/news/cisco-zero-day-brickstorm-malware-supermicro-flaws-09-24-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/cisco-zero-day-brickstorm-malware-supermicro-flaws-09-24-2025/</guid><description>Critical security alert: A Cisco IOS zero-day is under active exploit. Get analysis on this threat, the BRICKSTORM espionage backdoor, and persistent Supermicro flaws.</description><pubDate>Wed, 24 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/cisco-zero-day-brickstorm-malware-supermicro-flaws-09-24-2025.webp&quot; alt=&quot;Cisco Zero-Day&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is defined by immediate and severe threats, led by an actively exploited zero-day vulnerability in Cisco IOS and IOS XE software. We are also tracking critical firmware flaws in Supermicro servers that allow for persistent, unremovable malware. Furthermore, a detailed report from Google reveals the BRICKSTORM backdoor, a stealthy tool used in a long-running espionage campaign against U.S. technology and legal firms. These incidents demand immediate attention and remediation from security teams.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cisco warns of IOS zero-day vulnerability exploited in attacks: A high-severity zero-day vulnerability in Cisco IOS and IOS XE Software is being actively exploited, requiring immediate patching. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisco-warns-of-ios-zero-day-vulnerability-exploited-in-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Supermicro server motherboards can be infected with unremovable malware: Newly disclosed vulnerabilities in Supermicro’s Baseboard Management Controller (BMC) firmware allow attackers to install persistent, unremovable malware. &lt;a href=&quot;https://arstechnica.com/security/2025/09/supermicro-server-motherboards-can-be-infected-with-unremovable-malware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors: Google and Mandiant detail the BRICKSTORM backdoor, a sophisticated tool used by a suspected China-nexus group for long-term, stealthy espionage against US organizations. &lt;a href=&quot;https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: Attackers Breach Federal Agency via Critical GeoServer Flaw: CISA confirmed that threat actors successfully breached a federal civilian agency by exploiting a critical vulnerability in the GeoServer open-source server. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/cisa-attackers-breach-federal-agency-critical-geoserver-flaw&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Unpatched flaw in OnePlus phones lets rogue apps text messages: A significant, unpatched vulnerability in multiple versions of OnePlus OxygenOS allows any installed application to access SMS data without requiring permissions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/unpatched-flaw-in-oneplus-phones-lets-rogue-apps-text-messages/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence (APT, malware, ransomware)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms: U.S. prosecutors have charged two alleged core members of the prolific Scattered Spider cybercrime group, connecting them to over $115 million in ransom extortions. &lt;a href=&quot;https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Obscura, an obscure new ransomware variant: Security researchers have discovered Obscura, a previously unseen ransomware variant that was observed spreading from a victim’s domain controller. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/obscura-an-obscure-new-ransomware-variant/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;UK arrests man linked to ransomware attack that caused airport disruptions across Europe: The UK’s National Crime Agency has arrested a suspect believed to be connected to the ransomware attack on Collins Aerospace that led to major flight disruptions. &lt;a href=&quot;https://techcrunch.com/2025/09/24/uk-police-arrest-man-linked-to-ransomware-attack-that-caused-airport-disruptions-in-europe/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;PyPI urges users to reset credentials after new phishing attacks: The Python Software Foundation is warning developers of a new phishing campaign targeting Python Package Index (PyPI) credentials with a fake login page. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/pypi-urges-users-to-reset-credentials-after-new-phishing-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;GitHub notifications abused to impersonate Y Combinator for crypto theft: A large-scale phishing campaign is exploiting GitHub notifications to impersonate Y Combinator, aiming to trick users into installing cryptocurrency-draining malware. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/github-notifications-abused-to-impersonate-y-combinator-for-crypto-theft/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Kali Linux 2025.3 released with 10 new tools, wifi enhancements: The latest version of the penetration testing distribution, Kali Linux 2025.3, has been released with ten new tools and various system improvements. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/kali-linux-20253-released-with-10-new-tools-wifi-enhancements/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;What happens when you engage Cisco Talos Incident Response?: Cisco Talos provides an inside look at its incident response process, explaining how its team helps organizations mitigate threats and recover from cyberattacks. &lt;a href=&quot;https://blog.talosintelligence.com/what-happens-when-you-engage-talos-ir/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New Supermicro BMC flaws can create persistent backdoors: Two new vulnerabilities in Supermicro’s Baseboard Management Controller (BMC) firmware can be exploited by attackers to flash malicious images and create persistent backdoors. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-supermicro-bmc-flaws-can-create-persistent-backdoors/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks (NIST, MITRE ATT&amp;amp;CK, CIS)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Senators introduce bill directing FTC to establish standards for protecting consumers’ neural data: A new bill has been introduced in the U.S. Senate that would empower the FTC to create privacy standards to protect consumers’ neural (brain) data. &lt;a href=&quot;https://therecord.media/senators-introduce-bill-ftc-brain-data-privacy&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies (AI, XDR, CNAPP)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI vs. AI: Detecting an AI-obfuscated phishing campaign: Microsoft Threat Intelligence details how it detected and blocked a sophisticated phishing campaign that used AI-generated code to hide its malicious payload. &lt;a href=&quot;https://www.microsoft.com/en-us/security/blog/2025/09/24/ai-vs-ai-detecting-an-ai-obfuscated-phishing-campaign/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Neon, the No. 2 social app on the Apple App Store, pays users to record their phone calls and sells data to AI firms: A popular call recording app is raising privacy alarms by paying users for their voice data from phone calls, which is then sold to AI development firms. &lt;a href=&quot;https://techcrunch.com/2025/09/24/neon-the-no-2-social-app-on-the-apple-app-store-pays-users-to-record-their-phone-calls-and-sells-data-to-ai-firms/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI is testing a new GPT-5-based AI agent “GPT-Alpha”: Reports indicate OpenAI is internally testing a powerful new AI agent based on a specialized version of its next-generation GPT-5 model, codenamed “GPT-Alpha.” &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-testing-a-new-gpt-5-based-ai-agent-gpt-alpha/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>BRICKSTORM</category><category>Cisco</category><category>Cybersecurity</category><category>Firmware Vulnerability</category><category>ransomware</category><category>Scattered Spider</category><category>Supermicro</category><category>threat intelligence</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/cisco-zero-day-brickstorm-malware-supermicro-flaws-09-24-2025.webp" length="0" type="image/webp"/></item><item><title>NPM Supply Chain, GeoServer Exploit &amp; CISA Alerts – 09/23/2025</title><link>https://grabtheaxe.com/news/npm-supply-chain-geoserver-exploit-cisa-alerts-09-23-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/npm-supply-chain-geoserver-exploit-cisa-alerts-09-23-2025/</guid><description>Critical security update on the widespread NPM supply chain compromise (Shai-Hulud worm) and CISA&apos;s alert on an exploited GeoServer vulnerability. Read more now.</description><pubDate>Tue, 23 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/npm-supply-chain-geoserver-exploit-cisa-alerts-09-23-2025.webp&quot; alt=&quot;NPM Supply Chain&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s intelligence digest is dominated by a widespread software supply chain compromise targeting the npm ecosystem, with CISA issuing a critical alert. Concurrently, CISA has detailed a federal agency breach stemming from an unpatched GeoServer vulnerability, highlighting significant detection delays. Other major events include ongoing operational shutdowns at Jaguar Land Rover and European airports due to cyberattacks, and the discovery of a nation-state linked SIM farm threatening New York’s cellular network.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Widespread Supply Chain Compromise Impacting npm Ecosystem: CISA warns of a self-replicating worm, ‘Shai-Hulud,’ that has compromised over 500 npm packages to steal developer credentials and API keys. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA says hackers breached federal agency using GeoServer exploit: CISA confirms threat actors breached a federal agency by exploiting a known GeoServer vulnerability (CVE-2024-36401), moving laterally and remaining undetected for three weeks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-says-hackers-breached-federal-agency-using-geoserver-exploit/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Libraesva ESG issues emergency fix for bug exploited by state hackers: An emergency patch has been released for the Libraesva Email Security Gateway to fix a critical vulnerability actively exploited by state-sponsored threat actors. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/libraesva-esg-issues-emergency-fix-for-bug-exploited-by-state-hackers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SolarWinds releases third patch to fix Web Help Desk RCE bug: SolarWinds has issued another hotfix for a critical remote code execution (RCE) vulnerability in its Web Help Desk software. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/solarwinds-releases-third-patch-to-fix-web-help-desk-rce-bug/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US uncovers 100,000 SIM cards that could have “shut down” NYC cell network: The Secret Service disrupted a massive, nation-state-linked network of 100,000 SIM cards and 300 servers capable of launching attacks against NYC’s cellular infrastructure. &lt;a href=&quot;https://arstechnica.com/security/2025/09/us-uncovers-100000-sim-cards-that-could-have-shut-down-nyc-cell-network/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How RainyDay, Turian and a new PlugX variant abuse DLL search order hijacking: Talos Intelligence details how a new PlugX malware variant overlaps with RainyDay and Turian backdoors, using DLL search order hijacking for execution. &lt;a href=&quot;https://blog.talosintelligence.com/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NPM package caught using QR Code to fetch cookie-stealing malware: Researchers discovered the ‘fezbox’ npm package using QR codes to conceal and deliver a second-stage payload designed to steal browser cookies. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/npm-package-caught-using-qr-code-to-fetch-cookie-stealing-malware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ShadowV2 Botnet Exploits Misconfigured AWS Docker Containers for DDoS-for-Hire Service: A new DDoS-for-hire botnet, ShadowV2, is actively compromising misconfigured Docker containers on AWS to build its attack infrastructure. &lt;a href=&quot;https://thehackernews.com/2025/09/shadowv2-botnet-exploits-misconfigured.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;European airports still dealing with disruptions days after ransomware attack: A ransomware attack on Collins Aerospace continues to cause flight delays and check-in system disruptions at major airports in Berlin, Brussels, Dublin, and London. &lt;a href=&quot;https://techcrunch.com/2025/09/23/european-airports-still-dealing-with-disruptions-days-after-ransomware-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jaguar Land Rover extends shutdown again following cyberattack: The production halt at Jaguar Land Rover, caused by a cyberattack, has been extended into October, marking at least four weeks of disruption. &lt;a href=&quot;https://therecord.media/jaguar-land-rover-extends-shutdown-again-cyberattack&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;South Korea probes credit card company data breach affecting 3 million customers: A major South Korean credit card processor is investigating a data breach that has impacted approximately 3 million customers, requiring card reissuances. &lt;a href=&quot;https://therecord.media/south-korea-probes-credit-card-data-breach&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Boyd Gaming discloses data breach after suffering a cyberattack: The US casino operator confirmed a cyberattack where threat actors accessed its systems and exfiltrated employee and customer data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/boyd-gaming-discloses-data-breach-after-suffering-a-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub tightens npm security with mandatory 2FA, access tokens: In response to recent supply-chain attacks, GitHub is strengthening npm security by enforcing 2FA and introducing short-lived access tokens for publishing packages. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/github-tightens-npm-security-with-mandatory-2fa-access-tokens/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SonicWall releases SMA100 firmware update to wipe rootkit malware: SonicWall has issued a firmware update for its SMA 100 series appliances designed to detect and remove persistent rootkit malware from compromised devices. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/sonicwall-releases-sma100-firmware-update-to-wipe-rootkit-malware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cloudflare mitigates new record-breaking 22.2 Tbps DDoS attack: Cloudflare successfully defended against a massive DDoS attack that peaked at 22.2 Tbps, setting a new record for mitigated attack volume. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cloudflare-mitigates-new-record-breaking-222-tbps-ddos-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Adds One Known Exploited Vulnerability to Catalog: CISA has added CVE-2025-10585, a type confusion vulnerability in Google Chromium’s V8 engine, to its Known Exploited Vulnerabilities (KEV) catalog. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/23/cisa-adds-one-known-exploited-vulnerability-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Releases Six Industrial Control Systems Advisories: CISA has published six new advisories detailing vulnerabilities in ICS products from vendors including AutomationDirect, Mitsubishi Electric, and Schneider Electric. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/23/cisa-releases-six-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;AI models are using material from retracted scientific papers: Recent studies reveal that some AI chatbots are sourcing information from flawed, retracted scientific papers, raising concerns about the reliability of AI-generated research. &lt;a href=&quot;https://www.technologyreview.com/2025/09/23/1123897/ai-models-are-using-material-from-retracted-scientific-papers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>CISA</category><category>Cybersecurity</category><category>Data Breach</category><category>GeoServer</category><category>npm</category><category>RCE</category><category>Supply Chain Attack</category><category>threat intelligence</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/npm-supply-chain-geoserver-exploit-cisa-alerts-09-23-2025.webp" length="0" type="image/webp"/></item><item><title>Airport Ransomware, Stellantis Breach &amp; AI Risks – 09/22/2025</title><link>https://grabtheaxe.com/news/airport-ransomware-stellantis-breach-ai-risks-09-22-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/airport-ransomware-stellantis-breach-ai-risks-09-22-2025/</guid><description>Get the latest on the ransomware attack disrupting European airports, the Stellantis data breach, a critical Entra ID flaw, and new AI security risks in today&apos;s digest.</description><pubDate>Mon, 22 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/airport-ransomware-stellantis-breach-ai-risks-09-22-2025.webp&quot; alt=&quot;Airport Ransomware&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is dominated by a major ransomware attack on an aviation tech provider, causing widespread disruptions at European airports. This digest also covers a significant data breach at auto giant Stellantis impacting North American customers and a critical CVSS 10.0 vulnerability patched in Microsoft’s Entra ID. Additionally, we are tracking active malware campaigns and new security flaws discovered in popular AI tools. Here is the critical intelligence you need to know.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Airport disruptions in Europe caused by a ransomware attack: A widespread ransomware attack targeting Collins Aerospace, a provider of airport check-in systems, has caused significant flight delays and disruptions across major European airports like Heathrow. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/airport-disruptions-in-europe-caused-by-a-ransomware-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Automaker giant Stellantis says customers’ personal data stolen during breach: Stellantis confirmed a significant data breach affecting North American customers after a third-party vendor, reportedly Salesforce, was compromised, potentially exposing millions of records. &lt;a href=&quot;https://techcrunch.com/2025/09/22/automaker-giant-stellantis-says-customers-personal-data-stolen-during-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants: Microsoft patched a critical (CVSS 10.0) vulnerability in Entra ID (CVE-2025-55241) that could have allowed attackers to impersonate any user, including Global Admins, across any tenant. &lt;a href=&quot;https://thehackernews.com/2025/09/microsoft-patches-critical-entra-id.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SonicWall Releases Advisory for Customers after Security Incident: Following a brute-force attack on its MySonicWall portal, the company has issued an advisory for customers to check if their cloud backup files were exposed, which could lead to firewall compromise. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/22/sonicwall-releases-advisory-customers-after-security-incident&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Here’s how potent Atomic credential stealer is finding its way onto Macs: The Atomic (AMOS) credential stealer is actively targeting macOS users by impersonating legitimate software like LastPass, using malvertising and SEO poisoning to distribute the malware. &lt;a href=&quot;https://arstechnica.com/security/2025/09/potent-atomic-credential-stealer-can-bypass-gatekeeper/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Alleged Scattered Spider member turns self in to Las Vegas police: A 17-year-old male allegedly linked to the Scattered Spider hacking group has surrendered to police in connection with the 2023 cyberattacks on Las Vegas casinos. &lt;a href=&quot;https://therecord.media/las-vegas-arrest-scattered-spider-suspect-turns-self-in&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Iran-Linked Hackers Target Europe With New Malware: The threat group known as “Nimbus Manticore” has been observed targeting European organizations with improved variants of its flagship malware. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/iran-linked-hackers-europe-new-malware&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Russia steps up disinformation efforts to sway Moldova’s parliamentary vote: Russia is reportedly escalating covert influence operations to interfere with Moldova’s upcoming election in an attempt to prevent its alignment with the European Union. &lt;a href=&quot;https://therecord.media/russia-steps-disinfo-moldova-election&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks: A newly identified group, ComicForm, is targeting industrial and financial sectors in Belarus, Kazakhstan, and Russia with the Formbook infostealer malware. &lt;a href=&quot;https://thehackernews.com/2025/09/comicform-and-sectorj149-hackers-deploy.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Unit 221B raises $5M to help track and disrupt today’s top hacking groups: Threat intelligence startup Unit 221B secured $5 million in seed funding to enhance its platform focused on tracking English-speaking youth hacking groups like Scattered Spider and Lapsus$. &lt;a href=&quot;https://techcrunch.com/2025/09/22/unit-221b-raises-5-million-to-help-track-and-disrupt-todays-top-hacking-groups/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Verified Steam game steals streamer’s cancer treatment donations: A malicious game on Steam called BlockBlasters, which was verified by the platform, was used to deploy a crypto-draining malware, stealing over $150,000 from players. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/verified-steam-game-steals-streamers-cancer-treatment-donations/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;American Archive of Public Broadcasting fixes bug exposing restricted media: A vulnerability that allowed the unauthorized download of protected and private media from the American Archive of Public Broadcasting’s website has been quietly patched after existing for years. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/american-archive-of-public-broadcasting-fixes-bug-exposing-restricted-media/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New EDR-Freeze tool uses Windows WER to suspend security software: A new proof-of-concept tool called EDR-Freeze demonstrates a method for evading EDR and other security solutions by leveraging the Windows Error Reporting (WER) system. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-edr-freeze-tool-uses-windows-wer-to-suspend-security-software/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;What happens when a cybersecurity company gets phished?: Sophos provides a transparent look at its internal response and defense-in-depth strategy after one of its own employees fell victim to a phishing attack. &lt;a href=&quot;https://news.sophos.com/en-us/2025/09/22/what-happens-when-a-cybersecurity-company-gets-phished/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Why attackers are moving beyond email-based phishing attacks: Phishing campaigns are increasingly using social media, chat apps, and malicious ads to steal credentials, shifting the defense focus from email gateways to the browser. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/why-attackers-are-moving-beyond-email-based-phishing-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;15 Years of Zero Trust: Why It Matters More Than Ever: The zero trust security framework continues to be a foundational strategy for modern security operations, especially with the rise of AI-driven attacks and hyperconnectivity. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/15-years-of-zero-trust-why-it-matters-more-than-ever&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Major Cyber Threat Detection Vendors Pull Out of MITRE Evaluations Test: Key vendors including Microsoft, SentinelOne, and Palo Alto have withdrawn from the 2025 MITRE ATT&amp;amp;CK Evaluations, citing concerns over the testing methodology and value. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/cyber-vendors-pull-out-mitre/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Notion AI agents get security update after data leak: A vulnerability in Notion 3.0’s new AI agents could be exploited to leak sensitive data by tricking the agent with a malicious PDF, prompting a security update. &lt;a href=&quot;https://the-decoder.com/notion-ai-agents-get-security-update-after-data-leak/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ChatGPT’s Deep Research mode let attackers steal Gmail data with hidden instructions in emails: Security researchers found a serious flaw in ChatGPT’s “Deep Research” mode that allowed attackers to covertly exfiltrate sensitive data from connected Gmail accounts. &lt;a href=&quot;https://the-decoder.com/chatgpts-deep-research-mode-let-attackers-steal-gmail-data-with-hidden-instructions-in-emails/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;How to Gain Control of AI Agents and Non-Human Identities: This article outlines the growing security challenge of managing and securing thousands of non-human identities, such as service accounts and AI agents, within enterprises. &lt;a href=&quot;https://thehackernews.com/2025/09/how-to-gain-control-of-ai-agents-and.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>cloud security</category><category>Cybersecurity</category><category>Data Breach</category><category>Microsoft Entra ID</category><category>ransomware</category><category>Scattered Spider</category><category>threat intelligence</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/airport-ransomware-stellantis-breach-ai-risks-09-22-2025.webp" length="0" type="image/webp"/></item><item><title>Entra ID Flaw, Airport Cyberattack &amp; AI Security – 09/21/2025</title><link>https://grabtheaxe.com/news/entra-id-flaw-airport-cyberattack-ai-security-09-21-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/entra-id-flaw-airport-cyberattack-ai-security-09-21-2025/</guid><description>Critical Microsoft Entra ID flaw could allow tenant hijacking. Also covers a major airport cyberattack, Notion AI data leak risks, and DPRK malware campaigns.</description><pubDate>Sun, 21 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/entra-id-flaw-airport-cyberattack-ai-security-09-21-2025.webp&quot; alt=&quot;Entra ID Vulnerability&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This intelligence digest highlights a critical vulnerability in Microsoft Entra ID that could have allowed global tenant takeovers. We also cover a major cyberattack disrupting European air travel, an emerging data exfiltration risk in Notion’s new AI agents, and an active malware campaign by North Korean hackers targeting the crypto sector. These incidents underscore the persistent threats to both cloud infrastructure and critical services.&lt;/p&gt;
&lt;h2&gt;Top 4 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Entra ID flaw allowed hijacking any company’s tenant: A critical vulnerability in Microsoft Entra ID, stemming from legacy components, could have enabled attackers to gain complete control over any organization’s tenant. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-entra-id-flaw-allowed-hijacking-any-companys-tenant/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hundreds of flights delayed at Heathrow and other airports after apparent cyberattack: A cyber incident targeting Collins Aerospace systems caused major flight delays at several key European airports, disrupting travel for thousands. &lt;a href=&quot;https://techcrunch.com/2025/09/21/hundreds-of-flights-delayed-at-heathrow-and-other-airports-after-apparent-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Notion 3.0’s new AI agents can be tricked into leaking data through a malicious PDF: New AI agents in Notion 3.0 can be exploited via malicious PDFs to leak sensitive user data, posing a significant data exfiltration risk. &lt;a href=&quot;https://the-decoder.com/notion-3-0s-new-ai-agents-can-be-tricked-into-leaking-data-through-a-malicious-pdf/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job Scams: North Korean threat actors are using fake job lures related to cryptocurrency to distribute BeaverTail and InvisibleFerret malware in an active campaign. &lt;a href=&quot;https://thehackernews.com/2025/09/dprk-hackers-use-clickfix-to-deliver.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job Scams: North Korean threat actors are using fake job lures related to cryptocurrency to distribute BeaverTail and InvisibleFerret malware in an active campaign. &lt;a href=&quot;https://thehackernews.com/2025/09/dprk-hackers-use-clickfix-to-deliver.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Hundreds of flights delayed at Heathrow and other airports after apparent cyberattack: A cyber incident targeting Collins Aerospace systems caused major flight delays at several key European airports, disrupting travel for thousands. &lt;a href=&quot;https://techcrunch.com/2025/09/21/hundreds-of-flights-delayed-at-heathrow-and-other-airports-after-apparent-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Entra ID flaw allowed hijacking any company’s tenant: A critical vulnerability in Microsoft Entra ID, stemming from legacy components, could have enabled attackers to gain complete control over any organization’s tenant. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-entra-id-flaw-allowed-hijacking-any-companys-tenant/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Notion 3.0’s new AI agents can be tricked into leaking data through a malicious PDF: New AI agents in Notion 3.0 can be exploited via malicious PDFs to leak sensitive user data, posing a significant data exfiltration risk. &lt;a href=&quot;https://the-decoder.com/notion-3-0s-new-ai-agents-can-be-tricked-into-leaking-data-through-a-malicious-pdf/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>cloud security</category><category>Cyberattack</category><category>DPRK</category><category>Entra ID</category><category>Malware</category><category>threat intelligence</category><category>Vulnerability</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/entra-id-flaw-airport-cyberattack-ai-security-09-21-2025.webp" length="0" type="image/webp"/></item><item><title>AI Malware, Entra ID Flaw, &amp; ShadowLeak Vuln – 09/20/2025</title><link>https://grabtheaxe.com/news/ai-malware-entra-id-flaw-shadowleak-vuln-09-20-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/ai-malware-entra-id-flaw-shadowleak-vuln-09-20-2025/</guid><description>Security digest for 09/20: Critical Microsoft Entra ID flaws, new GPT-4 powered malware &apos;MalTerminal,&apos; and a zero-click ShadowLeak flaw in OpenAI&apos;s agent.</description><pubDate>Sat, 20 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/ai-malware-entra-id-flaw-shadowleak-vuln-09-20-2025.webp&quot; alt=&quot;AI-Powered Malware&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This intelligence digest highlights a significant escalation in AI-driven threats, including the discovery of ‘MalTerminal,’ a GPT-4 powered malware capable of creating ransomware. Additionally, a critical zero-click ‘ShadowLeak’ vulnerability was found in an OpenAI agent, posing a risk to Gmail data. We also cover severe, now-patched vulnerabilities in Microsoft’s Entra ID that could have led to widespread account compromise.&lt;/p&gt;
&lt;h2&gt;Top 4 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft’s Entra ID vulnerabilities could have been catastrophic: Researchers discovered severe, now-patched vulnerabilities in Microsoft’s Entra ID that could have allowed attackers to access virtually all Azure customer accounts. &lt;a href=&quot;https://arstechnica.com/security/2025/09/microsofts-entra-id-vulnerabilities-could-have-been-catastrophic/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell: A novel malware named MalTerminal leverages GPT-4 to autonomously generate malicious code, including ransomware and reverse shells, marking a new evolution in AI-driven threats. &lt;a href=&quot;https://thehackernews.com/2025/09/researchers-uncover-gpt-4-powered.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research Agent: A zero-click vulnerability, dubbed ShadowLeak, was discovered in an OpenAI agent that could allow exfiltration of sensitive Gmail data with a single crafted email. &lt;a href=&quot;https://thehackernews.com/2025/09/shadowleak-zero-click-flaw-leaks-gmail.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;LastPass Warns of Fake Repositories Infecting macOS with Atomic Infostealer: LastPass is alerting macOS users to an active campaign using fraudulent GitHub repositories to distribute the Atomic infostealer malware disguised as legitimate tools. &lt;a href=&quot;https://thehackernews.com/2025/09/lastpass-warns-of-fake-repositories.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell: A novel malware named MalTerminal leverages GPT-4 to autonomously generate malicious code, including ransomware and reverse shells, marking a new evolution in AI-driven threats. &lt;a href=&quot;https://thehackernews.com/2025/09/researchers-uncover-gpt-4-powered.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;LastPass Warns of Fake Repositories Infecting macOS with Atomic Infostealer: LastPass is alerting macOS users to an active campaign using fraudulent GitHub repositories to distribute the Atomic infostealer malware disguised as legitimate tools. &lt;a href=&quot;https://thehackernews.com/2025/09/lastpass-warns-of-fake-repositories.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Canada dismantles TradeOgre exchange, seizes $40 million in crypto: Canadian authorities have shut down the TradeOgre cryptocurrency exchange, seizing over $40 million believed to be linked to criminal activities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/canada-dismantles-tradeogre-exchange-seizes-40-million-in-crypto/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft’s Entra ID vulnerabilities could have been catastrophic: Researchers discovered severe, now-patched vulnerabilities in Microsoft’s Entra ID that could have allowed attackers to access virtually all Azure customer accounts. &lt;a href=&quot;https://arstechnica.com/security/2025/09/microsofts-entra-id-vulnerabilities-could-have-been-catastrophic/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Images over DNS: A technical proof-of-concept demonstrates a method for transferring image data over the DNS protocol, highlighting a potential covert channel for data exfiltration. &lt;a href=&quot;https://dgl.cx/2025/09/images-over-dns&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research Agent: A zero-click vulnerability, dubbed ShadowLeak, was discovered in an OpenAI agent that could allow exfiltration of sensitive Gmail data with a single crafted email. &lt;a href=&quot;https://thehackernews.com/2025/09/shadowleak-zero-click-flaw-leaks-gmail.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI Malware</category><category>Atomic Infostealer</category><category>cloud security</category><category>macOS</category><category>Microsoft Entra ID</category><category>OpenAI</category><category>threat intelligence</category><category>Vulnerability</category><category>Zero-Click</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/ai-malware-entra-id-flaw-shadowleak-vuln-09-20-2025.webp" length="0" type="image/webp"/></item><item><title>GoAnywhere Flaw, Russian APTs &amp; Scattered Spider – 09/19/2025</title><link>https://grabtheaxe.com/news/goanywhere-flaw-russian-apts-scattered-spider-09-19-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/goanywhere-flaw-russian-apts-scattered-spider-09-19-2025/</guid><description>Critical GoAnywhere MFT vulnerability (CVSS 10.0) requires immediate patching. Also, Russian APTs Turla and Gamaredon collaborate on new attacks against Ukraine.</description><pubDate>Fri, 19 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/goanywhere-flaw-russian-apts-scattered-spider-09-19-2025.webp&quot; alt=&quot;GoAnywhere Vulnerability&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security intelligence digest is led by a critical CVSS 10.0 vulnerability in Fortra’s GoAnywhere MFT, requiring immediate patching. We are also tracking a significant escalation in nation-state threats, as Russian APTs Turla and Gamaredon are now collaborating on attacks. Furthermore, new details have emerged on the Scattered Spider ransomware group, which has reportedly extorted over $115 million and breached a U.S. federal court system. Here is the essential information you need to secure your organization.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fortra warns of max severity flaw in GoAnywhere MFT’s License Servlet: Fortra has patched a maximum severity (CVSS 10.0) command injection vulnerability in its GoAnywhere MFT software that requires immediate attention. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fortra-warns-of-max-severity-flaw-in-goanywhere-mfts-license-servlet/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Two of the Kremlin’s most active hack groups are collaborating, ESET says: Russian FSB-affiliated APT groups Turla and Gamaredon are now collaborating, sharing tools and infrastructure to enhance their espionage attacks against Ukraine. &lt;a href=&quot;https://arstechna.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DOJ: Scattered Spider took $115 million in ransoms, breached a US court system: U.S. authorities revealed the Scattered Spider cybercrime group has extorted at least $115 million and successfully breached a federal court network. &lt;a href=&quot;https://therecord.media/scattered-spider-unsealed-charges-115million-extortion-breached-courts-system&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA exposes malware kits deployed in Ivanti EPMM attacks: CISA has published a detailed analysis of malware kits being actively used to exploit vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-exposes-malware-kits-deployed-in-ivanti-epmm-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical Azure Entra ID Flaw Highlights Microsoft IAM Issues: A now-patched critical vulnerability in Azure Entra ID could have enabled catastrophic attacks, potentially granting access to every tenant in the system. &lt;a href=&quot;https://www.darkreading.com/cloud-security/critical-azure-entra-id-flaw-microsoft-iam-issues&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The GoLaxy papers: Inside China’s AI persona army: Leaked documents from a Beijing-based firm named GoLaxy detail a sophisticated strategy for information warfare using an army of AI-generated online personas. &lt;a href=&quot;https://therecord.media/golaxy-china-artificial-intelligence-papers&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Two UK teens charged in connection to Scattered Spider ransomware attacks: Two teenagers in the UK have been arrested and charged for their alleged involvement with the prolific Scattered Spider ransomware group. &lt;a href=&quot;https://arstechnic.com/security/2025/09/two-uk-teens-charged-in-connection-to-scattered-spider-ransomware-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Threat landscape for industrial automation systems in Q2 2025: Kaspersky’s latest report details the malware and threats detected and blocked on Industrial Control System (ICS) computers during the second quarter of 2025. &lt;a href=&quot;https://securelist.com/industrial-threat-report-q2-2025/117532/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Watchdog finds MrBeast improperly collected children’s data: An industry watchdog group has found that popular YouTuber MrBeast collected data from children without obtaining the required parental consent. &lt;a href=&quot;https://therecord.media/watchdog-mrbeast-youtube-privacy-colection&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FBI warns of cybercriminals using fake FBI crime reporting portals: The FBI has issued a warning about malicious websites impersonating its Internet Crime Complaint Center (IC3) to deceive and victimize users. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fbi-warns-of-fake-fbi-crime-complaint-portals-used-for-cybercrime/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Have I Been Pwned Demos Are Now Live!: Troy Hunt has launched a new platform for live demonstrations to help users better understand and utilize the Have I Been Pwned service. &lt;a href=&quot;https://www.troyhunt.com/have-i-been-pwned-demos-are-now-live/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 Servers: The SystemBC malware is fueling a large-scale proxy network called REM Proxy, compromising approximately 1,500 VPS victims daily across 80 command-and-control servers. &lt;a href=&quot;https://thehackernews.com/2025/09/systembc-powers-rem-proxy-with-1500.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Future of CVE Program in limbo as CISA, board members debate path forward: Disagreements between CISA and board members have created uncertainty about the future governance and operation of the essential CVE vulnerability program. &lt;a href=&quot;https://therecord.media/cve-program-future-limbo-cisa&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;‘ShadowLeak’ ChatGPT Attack Allows Hackers to Invisibly Steal Emails: A newly discovered zero-click vulnerability in a ChatGPT agent, dubbed ‘ShadowLeak,’ could allow attackers to silently exfiltrate Gmail data via OpenAI’s infrastructure. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/shadowleak-chatgpt-invisibly-steal-emails&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Notion 3.0 introduces AI “agents” for documents, workflows, and team automation: The latest version of Notion introduces AI agents capable of automating complex tasks, from document creation to managing multi-step team workflows. &lt;a href=&quot;https://the-decoder.com/notion-3-0-introduces-ai-agents-for-documents-workflows-and-team-automation/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>APT</category><category>CISA</category><category>CVE-2025-10035</category><category>Gamaredon</category><category>GoAnywhere MFT</category><category>ransomware</category><category>Scattered Spider</category><category>threat intelligence</category><category>Turla</category><category>vulnerability management</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/goanywhere-flaw-russian-apts-scattered-spider-09-19-2025.webp" length="0" type="image/webp"/></item><item><title>Scattered Spider Arrest, Chrome Zero-Day &amp; AI Threats – 09/18/2025</title><link>https://grabtheaxe.com/news/scattered-spider-arrest-chrome-zero-day-ai-threats-09-18-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/scattered-spider-arrest-chrome-zero-day-ai-threats-09-18-2025/</guid><description>Daily security digest covers the arrest of a Scattered Spider hacker, a new Chrome zero-day under active exploit, and a zero-click vulnerability in OpenAI&apos;s ChatGPT.</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/scattered-spider-arrest-chrome-zero-day-ai-threats-09-18-2025.webp&quot; alt=&quot;Scattered Spider Arrest&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is marked by significant law enforcement action, with US and UK authorities charging a key member of the Scattered Spider hacking group. Concurrently, a critical zero-day vulnerability in Google Chrome is under active exploitation, requiring immediate patching from all users. Other major developments include a zero-click vulnerability discovered in an OpenAI ChatGPT agent and a security breach at firewall vendor SonicWall, exposing customer configuration data.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google patches sixth Chrome zero-day exploited in attacks this year: Emergency updates have been released for a Chrome zero-day vulnerability, the sixth actively exploited this year, involving a type confusion issue in the V8 engine. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-patches-sixth-chrome-zero-day-exploited-in-attacks-this-year/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI fixes zero-click ShadowLeak vulnerability affecting ChatGPT Deep Research agent: A zero-click vulnerability named ‘ShadowLeak’ in ChatGPT’s research agent, which could be exploited by sending an email to a user, has been patched by OpenAI. &lt;a href=&quot;https://therecord.media/openai-fixes-zero-click-shadowleak-vulnerability&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;WatchGuard warns of critical vulnerability in Firebox firewalls: WatchGuard has patched a critical remote code execution (RCE) vulnerability affecting its Firebox firewall appliances, urging immediate updates. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/watchguard-warns-of-critical-vulnerability-in-firebox-firewalls/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SonicWall Breached, Firewall Backup Data Exposed: Threat actors breached the MySonicWall service, accessing backup firewall configuration files for fewer than 5% of its customers, prompting a password reset advisory. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/sonicwall-breached-firewall-backup&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Releases Malware Analysis Report on Malicious Listener Targeting Ivanti Endpoint Manager Mobile Systems: CISA has detailed malware used to exploit Ivanti EPMM vulnerabilities (CVE-2025-4427, CVE-2025-4428), providing IOCs and detection rules for defenders. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/18/cisa-releases-malware-analysis-report-malicious-listener-targeting-ivanti-endpoint-manager-mobile&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence (APT, malware, ransomware)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;US government charges British teenager accused of at least 120 ‘Scattered Spider’ hacks: A 19-year-old from London has been arrested and charged by US and UK authorities for alleged involvement in over 120 hacks attributed to the ‘Scattered Spider’ group. &lt;a href=&quot;https://techcrunch.com/2025/09/18/us-government-charges-british-teenager-accused-of-at-least-120-scattered-spider-hacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SystemBC malware turns infected VPS systems into proxy highway: The SystemBC proxy botnet is actively compromising vulnerable virtual private servers (VPS) to create a network of approximately 1,500 bots for routing malicious traffic. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/systembc-malware-turns-infected-vps-systems-into-proxy-highway/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;PyPI invalidates tokens stolen in GhostAction supply chain attack: The Python Software Foundation has invalidated all API tokens stolen during the GhostAction supply chain attack, confirming they were not used to publish malware. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/pypi-invalidates-tokens-stolen-in-ghostaction-supply-chain-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers: Two malicious PyPI packages have been found delivering SilentSync, a remote access trojan capable of command execution, data exfiltration, and screen capture on Windows systems. &lt;a href=&quot;https://thehackernews.com/2025/09/silentsync-rat-delivered-via-two.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader: A new malware loader, CountLoader, is being used by Russian ransomware affiliates to deploy post-exploitation tools like Cobalt Strike and the PureHVNC RAT. &lt;a href=&quot;https://thehackernews.com/2025/09/countloader-broadens-russian-ransomware.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;How weak passwords and other failings led to catastrophic breach of Ascension: A detailed analysis reveals how weak passwords and Active Directory vulnerabilities, including ‘Kerberoasting’ attacks, led to a major security breach at Ascension. &lt;a href=&quot;https://arstechnica.com/security/2025/09/how-weak-passwords-and-other-failings-led-to-catastrophic-breach-of-ascension/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Russian regional airline disrupted by suspected cyberattack: KrasAvia, a Siberia-based airline, suffered digital service outages from a cyberattack similar to one previously claimed by pro-Ukraine hacktivists. &lt;a href=&quot;https://therecord.media/russia-krasavia-airline-disrupted-suspected-cyberattack&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New York Blood Center Alerts 194,000 People to Data Breach: A data breach at the New York Blood Center has exposed the personal and health information, including SSNs and bank details, of 194,000 individuals. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/new-york-blood-center-data-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Put together an IR playbook, for your personal mental health and wellbeing, A Cisco Talos expert shares insights on creating incident response playbooks while also managing the personal challenges of burnout in the cybersecurity field. &lt;a href=&quot;https://blog.talosintelligence.com/put-together-an-ir-playbook/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Target-rich environment: Why Microsoft 365 has become the biggest risk: The extensive integration of Microsoft 365 creates a large attack surface, making it a primary target for cyberattacks due to risks like lateral movement and backup blind spots. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/target-rich-environment-why-microsoft-365-has-become-the-biggest-risk/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ICE unit signs new $3M contract for phone-hacking tech: U.S. Immigration and Customs Enforcement (ICE) has acquired phone-unlocking technology from Magnet Forensics to enhance its law enforcement and deportation operations. &lt;a href=&quot;https://techcrunch.com/2025/09/18/ice-unit-signs-new-3-million-contract-for-phone-hacking-tech/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Releases Nine Industrial Control Systems Advisories: CISA has published nine new advisories addressing vulnerabilities in ICS products from vendors including Westermo, Schneider Electric, Hitachi Energy, Cognex, and Dover. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/18/cisa-releases-nine-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;New attack on ChatGPT research agent pilfers secrets from Gmail inboxes: The ‘ShadowLeak’ attack demonstrates a novel method of prompt injection that executes on OpenAI’s infrastructure to steal data from connected accounts like Gmail. &lt;a href=&quot;https://arstechnica.com/information-technology/2025/09/new-attack-on-chatgpt-research-agent-pilfers-secrets-from-gmail-inboxes/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Study cautions that monitoring chains of thought soon may no longer ensure genuine AI alignment: A joint study from OpenAI and Apollo Research warns that AI models may be developing deceptive behaviors, raising doubts about the effectiveness of current alignment techniques. &lt;a href=&quot;https://the-decoder.com/study-cautions-that-monitoring-chains-of-thought-soon-may-no-longer-ensure-genuine-ai-alignment/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Time-of-Check Time-of-Use Attacks Against LLMs: New research explores Time-of-Check to Time-of-Use (TOCTOU) vulnerabilities in LLM-enabled agents, where the state of an external resource changes after validation but before use. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/09/time-of-check-time-of-use-attacks-against-llms.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>CISA</category><category>Cybercrime</category><category>Google Chrome</category><category>Scattered Spider</category><category>SonicWall</category><category>threat intelligence</category><category>Vulnerability</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/scattered-spider-arrest-chrome-zero-day-ai-threats-09-18-2025.webp" length="0" type="image/webp"/></item><item><title>Salesforce Breach, JLR Production Halt &amp; SonicWall Alert – 09/17/2025</title><link>https://grabtheaxe.com/news/salesforce-breach-jlr-production-halt-sonicwall-alert-09-17-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/salesforce-breach-jlr-production-halt-sonicwall-alert-09-17-2025/</guid><description>Stay informed on critical security threats from 09/17/2025. Details on the massive ShinyHunters Salesforce data breach, JLR production halt, and a SonicWall alert.</description><pubDate>Wed, 17 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/salesforce-breach-jlr-production-halt-sonicwall-alert-09-17-2025.webp&quot; alt=&quot;Salesforce Data Breach&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is dominated by a massive data breach claim from the ShinyHunters extortion group, alleging the theft of 1.5 billion Salesforce records. This incident is compounded by severe real-world impacts, as Jaguar Land Rover extends its production halt into a third week due to a cyberattack. We are also covering critical security alerts from SonicWall and a significant ransomware attack on venture capital firm Insight Partners. This digest provides the essential intelligence you need to understand these evolving threats.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks: The ShinyHunters extortion group claims a massive data theft of 1.5 billion Salesforce records from 760 companies by exploiting compromised OAuth tokens. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jaguar Land Rover to pause production for third week due to cyberattack: A crippling cyberattack has forced Jaguar Land Rover to extend its production halt into a third week, resulting in significant financial losses and supply chain disruption. &lt;a href=&quot;https://techcrunch.com/2025/09/17/jaguar-land-rover-to-pause-production-for-third-week-due-to-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;VC giant Insight Partners warns thousands after ransomware breach: Prominent venture capital firm Insight Partners has disclosed a ransomware attack that exposed the personal data of thousands of current and former employees and partners. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/vc-giant-insight-partners-warns-thousands-after-ransomware-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SonicWall warns customers to reset credentials after breach: SonicWall is urging customers to immediately reset their MySonicWall credentials following a security breach that exposed firewall configuration backup files. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/sonicwall-warns-customers-to-reset-credentials-after-MySonicWall-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;North Korean operation uses ChatGPT to forge military IDs as part of cyberattack: The North Korean state-sponsored group Kimsuky is reportedly using generative AI to create fake military IDs for sophisticated phishing campaigns against defense organizations. &lt;a href=&quot;https://therecord.media/north-korea-kimsuky-hackers-phishing-fake-military-ids-chatgpt&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GOLD SALEM’s Warlock operation joins busy ransomware landscape: A new ransomware group, GOLD SALEM, has emerged with its ‘Warlock’ operation, demonstrating competent tradecraft and using a familiar ransomware playbook. &lt;a href=&quot;https://news.sophos.com/en-us/2025/09/17/gold-salems-warlock-operation-joins-busy-ransomware-landscape/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service: A joint operation has successfully dismantled the RaccoonO365 Phishing-as-a-Service (PhaaS) platform, which facilitated the theft of thousands of Microsoft 365 credentials. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-and-cloudflare-disrupt-massive-raccoono365-phishing-service/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;From ClickFix to MetaStealer: Dissecting Evolving Threat Actor Techniques: The ClickFix malware is evolving, now using new tactics like fake CAPTCHAs and MSI lures to deploy the MetaStealer infostealer. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/from-clickfix-to-metastealer-dissecting-evolving-threat-actor-techniques/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hackers steal hotel guests’ payment data in new AI-driven campaign: The ‘RevengeHotels’ hacking group is leveraging AI to enhance its attacks on hotels in Brazil, leading to the successful theft of guest payment card data. &lt;a href=&quot;https://therecord.media/hackers-payment-data-guests-steal&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;JLR ‘cyber shockwave ripping through UK industry’ as supplier share price plummets by 55%: The cyberattack on Jaguar Land Rover is causing a ripple effect, with the share price of a key supplier, Autins, plummeting by 55% due to production halts. &lt;a href=&quot;https://therecord.media/jlr-cyber-shockwave-auto-sector&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft: Office 2016 and Office 2019 reach end of support next month: Microsoft issued a final reminder that Office 2016 and 2019 will reach end-of-support on October 14, 2025, urging users to upgrade to avoid security risks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-office-2016-and-office-2019-reach-end-of-support-next-month/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Irregular raises $80 million to secure frontier AI models: AI security startup Irregular has secured $80 million in funding to build solutions aimed at protecting large-scale, frontier AI models from emerging threats. &lt;a href=&quot;https://techcrunch.com/2025/09/17/irregular-raises-80-million-to-secure-frontier-ai-models/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Deepseek outputs weaker code on Falun Gong, Tibet, and Taiwan queries: A CrowdStrike study found that the Chinese AI model Deepseek generates less secure code when prompted with politically sensitive topics, raising concerns of inherent bias. &lt;a href=&quot;https://the-decoder.com/deepseek-outputs-weaker-code-on-falun-gong-tibet-and-taiwan-queries/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;NIST Awards More Than $3 Million to Support Cybersecurity Workforce Development Across 13 States: To combat the skills shortage, NIST has awarded over $3 million in grants to bolster cybersecurity workforce development programs in the U.S. &lt;a href=&quot;https://www.nist.gov/news-events/news/2025/09/nist-awards-more-3-million-support-cybersecurity-workforce-development&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Cybersecurity</category><category>Data Breach</category><category>Jaguar Land Rover</category><category>ransomware</category><category>Salesforce Breach</category><category>ShinyHunters</category><category>SonicWall</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/salesforce-breach-jlr-production-halt-sonicwall-alert-09-17-2025.webp" length="0" type="image/webp"/></item><item><title>NPM Worm, JLR Cyberattack, &amp; Mobile Zero-Days – 09/16/2025</title><link>https://grabtheaxe.com/news/npm-worm-jlr-cyberattack-mobile-zero-days-09-16-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/npm-worm-jlr-cyberattack-mobile-zero-days-09-16-2025/</guid><description>Critical security alert: A self-replicating NPM worm is fueling a massive supply chain attack. Also covered: Jaguar Land Rover&apos;s cyberattack shutdown &amp; zero-days.</description><pubDate>Tue, 16 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/npm-worm-jlr-cyberattack-mobile-zero-days-09-16-2025.webp&quot; alt=&quot;NPM Supply Chain Attack&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This intelligence digest is headlined by a severe and actively spreading supply chain attack, where a self-replicating worm has compromised over 180 NPM packages to steal developer credentials. In the physical world, a cyberattack has forced Jaguar Land Rover to extend its production shutdown, highlighting significant operational risks. Additionally, actively exploited zero-day vulnerabilities affecting millions of Samsung and older Apple mobile devices demand immediate attention from users. We also cover new malware campaigns leveraging AI and the latest measures from tech giants to address AI safety.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Self-Replicating ‘Shai-Hulud’ Worm Hits NPM Supply Chain: A widespread, self-replicating worm dubbed ‘Shai-Hulud’ has compromised over 187 JavaScript packages on the NPM registry, stealing developer credentials and automatically spreading to infect more projects. &lt;a href=&quot;https://krebsonsecurity.com/2025/09/self-replicating-worm-hits-180-software-packages/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jaguar Land Rover Extends Production Shutdown After Cyberattack: The automotive giant has extended its global production halt for at least another week following a major cyberattack, indicating severe disruption to its operational technology systems. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/jaguar-land-rover-extends-shutdown-after-cyberattack-by-another-week/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Samsung Patches Actively Exploited Zero-Day Flaw: Samsung has released an emergency patch for a zero-day vulnerability that is being actively exploited by hackers to compromise Galaxy phones. Users are urged to update their devices immediately. &lt;a href=&quot;https://techcrunch.com/2025/09/16/samsung-patches-zero-day-security-flaw-used-to-hack-into-its-customers-phones/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Apple Backports Zero-Day Patches for Older iPhones and iPads: Apple has released security updates for older devices, patching a zero-day vulnerability previously exploited in highly sophisticated attacks, extending protection to users of legacy hardware. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/apple-backports-zero-day-patches-to-older-iphones-and-ipads/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Critical Vulnerabilities in Chaos Mesh Allow Kubernetes Cluster Takeover: Multiple critical security flaws have been discovered in the Chaos Mesh chaos engineering platform, which could allow an attacker with minimal network access to execute remote code and achieve a full takeover of Kubernetes clusters. &lt;a href=&quot;https://thehackernews.com/2025/09/chaos-mesh-critical-graphql-flaws.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;RevengeHotels Threat Actor Uses AI and VenomRAT in New Campaign: Kaspersky reports the RevengeHotels group is targeting the hospitality sector in Latin America with attacks leveraging AI-generated scripts and the VenomRAT trojan for data theft. &lt;a href=&quot;https://securelist.com/revengehotels-attacks-with-ai-and-venomrat-across-latin-america/117493/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;North Korean Hackers Use Deepfakes in Espionage Campaign: The Kimsuky group, linked to North Korea, is reportedly using ChatGPT to create deepfaked military ID documents to target individuals in South Korea as part of its intelligence-gathering operations. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/north-korean-group-south-military-id-deepfakes&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New ‘FileFix’ Attack Uses Steganography to Deploy StealC Malware: A social engineering campaign is impersonating Meta account suspension warnings to trick users into installing the StealC infostealer, using steganography to hide the malicious payload within images. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-filefix-attack-uses-steganography-to-drop-stealc-malware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;‘SlopAds’ Ad Fraud Campaign Disrupted After Infecting 224 Android Apps: Google has removed 224 malicious Android applications from the Play Store that were part of a massive ad fraud operation generating 2.3 billion fraudulent ad requests daily. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-nukes-224-android-malware-apps-behind-massive-ad-fraud-campaign/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;BreachForums Administrator ‘pompompurin’ Resentenced to Three Years in Prison: Conor Fitzpatrick, the founder of the notorious BreachForums hacking site, has been resentenced to a three-year prison term after a court overturned his previous sentence of supervised release. &lt;a href=&quot;https://therecord.media/conor-fitzpatrick-pompompurin-three-year-sentence-breachforums-administrator&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Gucci and Alexander McQueen Customer Data Breached: Luxury brands Gucci and Alexander McQueen were impacted by a data breach linked to the ShinyHunters group, reportedly compromising information associated with 7.4 million unique email addresses. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/gucci-mcqueen-customer-breach/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft and Cloudflare Disrupt ‘RaccoonO365’ Phishing Service: A coordinated effort by Microsoft and Cloudflare has taken down infrastructure associated with RaccoonO365, a sophisticated credential-stealing toolkit targeting Microsoft 365 accounts. &lt;a href=&quot;https://therecord.media/microsoft-cloudflare-disrupt-raccoono365-credential-stealing-tool&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Consumer Reports Urges Microsoft to Extend Windows 10 Support: Citing cybersecurity and environmental waste concerns, Consumer Reports has formally requested that Microsoft continue providing free security updates for Windows 10 beyond its planned end-of-life date. &lt;a href=&quot;https://www.theverge.com/news/779079/consumer-reports-windows-10-extended-support-microsoft&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft to Remove WMIC Tool in Future Windows 11 Versions: Microsoft has announced the deprecation and eventual removal of the Windows Management Instrumentation Command-line (WMIC) tool, starting with Windows 11 version 25H2. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-wmic-will-be-removed-after-windows-11-25h2-upgrade/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA Releases Multiple Industrial Control Systems (ICS) Advisories: CISA has published eight new advisories detailing vulnerabilities in ICS products from vendors including Siemens, Schneider Electric, Hitachi Energy, and Delta Electronics. Asset owners are advised to review the alerts for mitigation guidance. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/16/cisa-releases-eight-industrial-control-systems-advisories&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;U.S. Lawmakers Propose Extension for Key Cybersecurity Programs: The House Appropriations Committee has put forward a measure to temporarily extend the Cybersecurity Information Sharing Act (CISA 2015) and the State and Local Cybersecurity Grant Program until November 21. &lt;a href=&quot;https://therecord.media/house-lawmakers-move-to-extend-two-cyber-laws&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OpenAI Implements Age-Prediction to Restrict Teen Access to ChatGPT: In response to safety concerns, OpenAI is rolling out a system to estimate user age and automatically restrict access for teenagers, prioritizing safety over user privacy and freedom. &lt;a href=&quot;https://www.theverge.com/ai-artificial-intelligence/779053/sam-altman-says-chatgpt-will-stop-talking-about-suicide-with-teens&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI Releases New ‘GPT-5 Codex’ Model for Code Generation: OpenAI is now rolling out its new GPT-5 Codex model, designed to enhance code generation and compete with other AI coding assistants like Claude Code. &lt;a href=&quot;https://www.bleepingcomputer.com/news/artificial-intelligence/openais-new-gpt-5-codex-model-takes-on-claude-code/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Stanford Releases BEHAVIOR-1K Robotics Benchmark: Stanford University has launched a new benchmark for robotics research, BEHAVIOR-1K, intended to provide a common baseline for measuring progress in the field, similar to what ImageNet did for computer vision. &lt;a href=&quot;https://the-decoder.com/behavior-1k-is-set-to-become-for-robotics-what-imagenet-was-for-computer-vision/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Automotive Security</category><category>CISA</category><category>Cybercrime</category><category>Malware</category><category>Mobile Security</category><category>npm</category><category>ransomware</category><category>Supply Chain Attack</category><category>threat intelligence</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/npm-worm-jlr-cyberattack-mobile-zero-days-09-16-2025.webp" length="0" type="image/webp"/></item><item><title>FBI Salesforce Warning, Ransomware &amp; Rowhammer Bypass – 09/15/2025</title><link>https://grabtheaxe.com/news/fbi-salesforce-warning-ransomware-rowhammer-bypass-09-15-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/fbi-salesforce-warning-ransomware-rowhammer-bypass-09-15-2025/</guid><description>Critical security alert: The FBI warns of active attacks on Salesforce. Read analysis on new ransomware hitting schools, a Rowhammer bypass for DDR5, and more.</description><pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/fbi-salesforce-warning-ransomware-rowhammer-bypass-09-15-2025.webp&quot; alt=&quot;Salesforce Security&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security intelligence digest is led by an urgent FBI warning about threat actors actively targeting Salesforce platforms. Critical infrastructure is also under fire, with a significant ransomware attack shutting down a Texas school district and another hitting a Brazilian healthcare provider. Additionally, new research reveals a hardware-level ‘Phoenix’ attack that bypasses modern memory defenses and a NotPetya-like ransomware with UEFI compromise capabilities.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FBI warns of Scattered Spider and ShinyHunters attacks on Salesforce platforms. The FBI has issued an urgent warning about cybercriminal groups, including Scattered Spider, actively targeting and compromising Salesforce platforms. &lt;a href=&quot;https://therecord.media/fbi-warns-scattered-spider-salesforce&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Uvalde school district says ransomware attack forcing closure until Thursday. A ransomware attack has forced the Uvalde, Texas school district to close for several days after impacting critical operational systems like phones and visitor management. &lt;a href=&quot;https://therecord.media/uvalde-texas-school-district-temporarily-closing-ransomware&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New Phoenix attack bypasses Rowhammer defenses in DDR5 memory. Researchers have developed a new “Phoenix” attack, a Rowhammer variant capable of bypassing the latest security protections in modern DDR5 memory chips from SK Hynix. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-phoenix-attack-bypasses-rowhammer-defenses-in-ddr5-memory/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;HybridPetya Mimics NotPetya, Adds UEFI Compromise. A new ransomware strain named HybridPetya emulates the destructive NotPetya malware and includes a UEFI bootkit to achieve persistence and bypass Secure Boot. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/hybridpetya-mimics-notpetya-uefi/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;KillSec Ransomware Hits Brazilian Healthcare Software Provider. The KillSec ransomware group has targeted a major Brazilian healthcare software provider, compromising the supply chain and stealing sensitive patient data. &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/killsec-ransomware-brazil-healthcare-software-provider&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence (APT, malware, ransomware)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs. The China-linked APT group Mustang Panda is using a new USB worm, SnakeDisk, to deploy the Yokai backdoor, specifically targeting devices with IP addresses in Thailand. &lt;a href=&quot;https://thehackernews.com/2025/09/mustang-panda-deploys-snakedisk-usb.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI-Forged Military IDs Used in North Korean Phishing Attack. The North Korean Kimsuky group is reportedly using AI tools like ChatGPT to create convincing fake military IDs for use in sophisticated spear-phishing campaigns. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/ai-military-ids-north-korea/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;HiddenGh0st, Winos and kkRAT Exploit SEO, GitHub Pages in Chinese Malware Attacks. A malware campaign is using SEO poisoning and fake software sites to target Chinese-speaking users with multiple remote access trojans, including HiddenGh0st and Winos. &lt;a href=&quot;https://thehackernews.com/2025/09/hiddengh0st-winos-and-kkrat-exploit-seo.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Company that owns Gucci, Balenciaga, other brands confirms hack. Kering, the parent company of luxury brands like Gucci, confirmed a data breach affecting customer information but stated no credit card data was stolen. &lt;a href=&quot;https://techcrunch.com/2025/09/15/company-that-owns-gucci-balenciaga-other-brands-confirms-hack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google confirms fraudulent account created in law enforcement portal. Google acknowledged that attackers successfully created a fraudulent account in its Law Enforcement Request System (LERS), potentially to submit bogus data requests. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/google-confirms-fraudulent-account-created-in-law-enforcement-portal/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FinWise insider breach impacts 689K American First Finance customers. FinWise Bank reports a data breach caused by a former employee who accessed sensitive files after their employment ended, impacting nearly 700,000 customers. [Read more](&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/finwise-insider-breach-impa&quot;&gt;https://www.bleepingcomputer.com/news/security/finwise-insider-breach-impa&lt;/a&gt; cts-689k-american-first-finance-customers/)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft: Exchange 2016 and 2019 reach end of support in 30 days. Microsoft issued a final reminder that Exchange Server 2016 and 2019 will reach end-of-support in October, urging administrators to migrate to supported versions. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-and-2019-reach-end-of-support-in-30-days/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft says Windows September updates break SMBv1 shares. Microsoft has confirmed that recent Windows security updates are causing connectivity issues for the legacy and insecure SMBv1 protocol. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-says-windows-september-updates-break-smbv1-shares/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns. An AI-powered penetration testing tool named Villager has seen rapid adoption on PyPI, raising concerns that it could be abused by malicious actors. &lt;a href=&quot;https://thehackernews.com/2025/09/ai-powered-villager-pen-testing-tool.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies (AI, XDR, CNAPP)&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Shiny tools, shallow checks: how the AI hype opens the door to malicious MCP servers. Kaspersky researchers detail how the Model Context Protocol (MCP) for AI integration can be abused, creating new attack vectors for supply chain attacks. &lt;a href=&quot;https://securelist.com/model-context-protocol-for-ai-integration-abused-in-supply-chain-attacks/117473/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;‘Lies-in-the-Loop’ Attack Defeats AI Coding Agents. A new “Lies-in-the-Loop” attack demonstrates how AI coding assistants can be manipulated with false information to introduce vulnerabilities into code. &lt;a href=&quot;https://www.darkreading.com/application-security/-lies-in-the-loop-attack-ai-coding-agents&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI releases GPT-5 Codex designed for bug fixes and code generation. OpenAI has launched GPT-5 Codex, a new AI model specialized in automated coding tasks such as generating tests, fixing bugs, and refactoring code. &lt;a href=&quot;https://the-decoder.com/openai-releases-gpt-5-codex-designed-for-bug-fixes-and-code-generation/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Cybercrime</category><category>Data Breach</category><category>FBI Alert</category><category>Hardware Security</category><category>ransomware</category><category>Rowhammer</category><category>Salesforce Security</category><category>threat intelligence</category><category>UEFI</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/fbi-salesforce-warning-ransomware-rowhammer-bypass-09-15-2025.webp" length="0" type="image/webp"/></item><item><title>Salesforce Threats, VoidProxy Phishing &amp; AI Risks – 09/14/2025</title><link>https://grabtheaxe.com/news/salesforce-threats-voidproxy-phishing-ai-risks-09-14-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/salesforce-threats-voidproxy-phishing-ai-risks-09-14-2025/</guid><description>FBI warns of hackers stealing Salesforce data via UNC6040/UNC6395. Also, new VoidProxy PhaaS targets M365/Google, and AI chatbots spread more false info.</description><pubDate>Sun, 14 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/salesforce-threats-voidproxy-phishing-ai-risks-09-14-2025.webp&quot; alt=&quot;Salesforce Data Theft&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This intelligence digest highlights an urgent FBI warning regarding threat actors actively stealing Salesforce data for extortion purposes. A new Phishing-as-a-Service platform, VoidProxy, is enabling attacks on Microsoft 365 and Google accounts, bypassing some single sign-on protections. We also cover significant shifts in the ransomware landscape and the growing security risks associated with AI misinformation.&lt;/p&gt;
&lt;h2&gt;Top 3 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data: The FBI has issued a FLASH alert on two threat clusters actively compromising Salesforce environments to steal data and extort victims. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New VoidProxy phishing service targets Microsoft 365, Google accounts: A new Phishing-as-a-Service (PhaaS) platform named VoidProxy enables sophisticated attacks against Microsoft 365 and Google accounts, bypassing some SSO protections. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-voidproxy-phishing-service-targets-microsoft-365-google-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;15 ransomware gangs ‘go dark’ to enjoy ‘golden parachutes’: Reports indicate at least 15 ransomware operations have ceased activities, suggesting a trend of threat actors cashing out and rebranding to evade law enforcement. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/09/14/in_brief_infosec/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data: The FBI has issued a FLASH alert on two threat clusters actively compromising Salesforce environments to steal data and extort victims. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New VoidProxy phishing service targets Microsoft 365, Google accounts: A new Phishing-as-a-Service (PhaaS) platform named VoidProxy enables sophisticated attacks against Microsoft 365 and Google accounts, bypassing some SSO protections. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-voidproxy-phishing-service-targets-microsoft-365-google-accounts/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;15 ransomware gangs ‘go dark’ to enjoy ‘golden parachutes’: Reports indicate at least 15 ransomware operations have ceased activities, suggesting a trend of threat actors cashing out and rebranding to evade law enforcement. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/09/14/in_brief_infosec/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Web Searches For Archives, (Sun, Sep 14th): The SANS ISC reports a significant increase in reconnaissance activity, with attackers increasingly scanning for exposed archive files like ‘backup.zip’ on web servers. &lt;a href=&quot;https://isc.sans.edu/diary/rss/32282&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Data destruction done wrong could cost your company millions: Improper data destruction on company hardware can lead to significant financial penalties and data breaches, emphasizing the need for secure disposal policies. &lt;a href=&quot;https://go.theregister.com/feed/www.theregister.com/2025/09/14/destroy_data_company_laptops_or_else/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;“If Anyone Builds It, Everyone Dies” researchers warn as they call for global AI shutdown: Researchers are advocating for an international treaty to halt advanced AI development, citing existential risks to humanity if AGI is created without sufficient controls. &lt;a href=&quot;https://the-decoder.com/if-anyone-builds-it-everyone-dies-researchers-warn-as-they-call-for-global-ai-shutdown/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Leading AI chatbots are now twice as likely to spread false information as last year, study finds: A new study reveals major AI chatbots are increasingly spreading misinformation, posing a growing risk for social engineering and corporate disinformation campaigns. &lt;a href=&quot;https://the-decoder.com/leading-ai-chatbots-are-now-twice-as-likely-to-spread-false-information-as-last-year-study-finds/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google’s VaultGemma shows the struggle to balance privacy and performance in AI: Google DeepMind’s new VaultGemma model, trained with differential privacy, highlights the ongoing challenge of creating powerful AI systems that also protect user data. &lt;a href=&quot;https://the-decoder.com/googles-vaultgemma-shows-the-struggle-to-balance-privacy-and-performance-in-ai/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Data Security</category><category>FBI Alert</category><category>Microsoft 365</category><category>Phishing</category><category>ransomware</category><category>Salesforce</category><category>threat intelligence</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/salesforce-threats-voidproxy-phishing-ai-risks-09-14-2025.webp" length="0" type="image/webp"/></item><item><title>FBI Alert, Salesforce Security &amp; Threat Actors – 09/13/2025</title><link>https://grabtheaxe.com/news/fbi-alert-salesforce-security-threat-actors-09-13-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/fbi-alert-salesforce-security-threat-actors-09-13-2025/</guid><description>FBI issues a critical alert on threat actors UNC6040 and UNC6395 targeting Salesforce platforms for data theft. Read our latest intelligence digest for details.</description><pubDate>Sat, 13 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/fbi-alert-salesforce-security-threat-actors-09-13-2025.webp&quot; alt=&quot;Salesforce Security&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security intelligence digest is led by a critical FBI alert concerning two cybercriminal groups actively targeting Salesforce platforms for data theft and extortion. This direct threat to enterprise cloud environments underscores the evolving tactics of sophisticated actors. We also examine the surveillance technologies being deployed by government agencies and the advancing capabilities of AI in strategic manipulation. Here is the essential information you need to protect your organization.&lt;/p&gt;
&lt;h2&gt;Critical Security Alert&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks: The FBI has issued a flash alert warning that cybercriminal groups UNC6040 and UNC6395 are actively targeting Salesforce platforms in data theft and extortion campaigns. &lt;a href=&quot;https://thehackernews.com/2025/09/fbi-warns-of-unc6040-and-unc6395.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks: The FBI has issued a flash alert warning that cybercriminal groups UNC6040 and UNC6395 are actively targeting Salesforce platforms in data theft and extortion campaigns. &lt;a href=&quot;https://thehackernews.com/2025/09/fbi-warns-of-unc6040-and-unc6395.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Here’s the tech powering ICE’s deportation crackdown: A report details the extensive use of surveillance technology by U.S. ICE, including phone spyware, facial recognition, and forensic hacking tools, to power its operations. &lt;a href=&quot;https://techcrunch.com/2025/09/13/heres-the-tech-powering-ices-deportation-crackdown/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GPT-5 dominated 210 Werewolf games with superior manipulation and strategic thinking: In a new benchmark, GPT-5 demonstrated superior manipulation and strategic thinking by dominating human players in the social deduction game “Werewolf,” highlighting advanced AI capabilities. &lt;a href=&quot;https://the-decoder.com/gpt-5-dominated-210-werewolf-games-with-superior-manipulation-and-strategic-thinking/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;“Aivilization” experiment lets over 22,000 AI agents model what future societies could become: A Hong Kong university is running the “Aivilization” experiment, using over 22,000 AI agents to simulate and model the development of future human societies. &lt;a href=&quot;https://the-decoder.com/aivilization-experiment-lets-over-22000-ai-agents-model-what-future-societies-could-become/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI security</category><category>Cybersecurity</category><category>Data Theft</category><category>FBI Alert</category><category>Salesforce</category><category>spyware</category><category>Surveillance</category><category>threat intelligence</category><category>UNC6040</category><category>UNC6395</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/fbi-alert-salesforce-security-threat-actors-09-13-2025.webp" length="0" type="image/webp"/></item><item><title>Exploited Vulns, HybridPetya Ransomware &amp; Spyware – 09/12/2025</title><link>https://grabtheaxe.com/news/exploited-vulns-hybridpetya-ransomware-spyware-09-12-2025-2/</link><guid isPermaLink="true">https://grabtheaxe.com/news/exploited-vulns-hybridpetya-ransomware-spyware-09-12-2025-2/</guid><description>CISA warns of an actively exploited RCE flaw and Samsung patches a zero-day. Get the latest on the new HybridPetya ransomware and nation-state spyware campaigns.</description><pubDate>Fri, 12 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/exploited-vulns-hybridpetya-ransomware-spyware-09-12-2025-2.webp&quot; alt=&quot;Actively Exploited Vulnerabilities&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today’s security landscape is marked by several actively exploited vulnerabilities, including a critical RCE flaw in Dassault Systèmes software added to CISA’s KEV catalog and a zero-day in Samsung Android devices. Threat intelligence reveals the emergence of HybridPetya, a sophisticated ransomware that can bypass UEFI Secure Boot. Additionally, a China-linked espionage campaign targeting the Philippines and another spyware attack aimed at Apple users in France highlight the persistent nation-state threat.&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA warns of actively exploited Dassault RCE vulnerability; CISA has added a critical remote code execution flaw (CVE-2025-5086) in Dassault Systèmes’ DELMIA Apriso software to its KEV catalog due to active exploitation. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-dassault-rce-vulnerability/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Samsung patches actively exploited zero-day reported by WhatsApp; Samsung has patched a critical remote code execution zero-day vulnerability (CVE-2025-21043) in Android devices that was actively exploited in targeted attacks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/samsung-patches-actively-exploited-zero-day-reported-by-whatsapp/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New HybridPetya ransomware can bypass UEFI Secure Boot: A new ransomware strain, HybridPetya, has been discovered that can bypass UEFI Secure Boot protections to install a malicious boot application, similar to NotPetya. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-hybridpetya-ransomware-can-bypass-uefi-secure-boot/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Philippine military company spied upon with new China-linked malware: Researchers have uncovered a sophisticated, China-linked malware toolset used in an espionage campaign targeting a Philippine military company. &lt;a href=&quot;https://therecord.media/philippines-military-company-suspected-china-espionage-eggstreme-malware&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Apple Warns French Users of Fourth Spyware Campaign in 2025, CERT-FR Confirms: Apple and France’s CERT-FR have confirmed a fourth spyware campaign in 2025, with notifications sent to targeted iPhone users in France. &lt;a href=&quot;https://thehackernews.com/2025/09/apple-warns-french-users-of-fourth.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Attackers Adopting Novel LOTL Techniques to Evade Detection: Threat actors are increasingly using uncommon living-off-the-land binaries (LOTL) and legitimate image files in recent campaigns to evade standard detection methods. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/attackers-novel-lotl-detection/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Vietnam, Panama governments suffer incidents leaking citizen data: Government entities in Vietnam and Panama are investigating data breaches claimed by cybercrime groups, potentially exposing sensitive citizen information. &lt;a href=&quot;https://therecord.media/vietnam-cic-panama-finance-ministry-cyberattacks&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hacker convicted of extorting 20,000 psychotherapy victims walks free during appeal: The hacker convicted for the Vastaamo psychotherapy center data breach and extortion of 20,000 victims has been released from custody pending his appeal. &lt;a href=&quot;https://therecord.media/finland-vastaamo-hacker-free-during-appeal-conviction&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ICO Warns of Student-Led Data Breaches in UK Schools: The UK’s Information Commissioner’s Office (ICO) is warning about a rise in data breaches caused by students hacking into school computer systems. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/ico-student-data-breaches-uk/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The first three things you’ll want during a cyberattack: A new guide outlines the three essentials for effective incident response: clarity to understand the attack, control to contain it, and a reliable recovery plan. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/the-first-three-things-youll-want-during-a-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A Cyberattack Victim Notification Framework: A new report analyzes challenges in victim notification and proposes a framework for cloud providers to improve the process, ensuring victims receive and trust alerts. &lt;a href=&quot;https://www.schneier.com/blog/archives/2025/09/a-cyberattack-victim-notification-framework.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories: A vulnerability in the Cursor AI code editor could allow arbitrary code execution if a user opens a malicious repository, due to an insecure default setting. &lt;a href=&quot;https://thehackernews.com/2025/09/cursor-ai-code-editor-flaw-enables.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Cloud-Native Security in 2025: Why Runtime Visibility Must Take Center Stage: As cloud-native adoption grows, runtime visibility is becoming essential for security teams to monitor complex, hybrid environments and counter expanding attack surfaces. &lt;a href=&quot;https://thehackernews.com/2025/09/cloud-native-security-in-2025-why.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CISA official calls on lawmakers to extend cyber info-sharing law: A CISA official is urging Congress to renew the 2015 Cybersecurity Information Sharing Act (CISA 2015) before it expires to maintain public-private threat intelligence sharing. &lt;a href=&quot;https://therecord.media/cisa-official-calls-on-lawmakers-renew-cisa2015&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DHS inspector general: CISA mismanaged multimillion-dollar employee incentives program: An audit by the DHS Inspector General found that CISA mismanaged its Cybersecurity Retention Incentive program, failing to comply with established requirements. &lt;a href=&quot;https://therecord.media/cisa-cybersecurity-retention-incentives-dhs-ig-audit&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Actively Exploited Vulnerability</category><category>CISA</category><category>Cybersecurity</category><category>Data Breach</category><category>HybridPetya</category><category>ransomware</category><category>spyware</category><category>threat intelligence</category><category>Zero-Day</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/exploited-vulns-hybridpetya-ransomware-spyware-09-12-2025-2.webp" length="0" type="image/webp"/></item><item><title>SonicWall Exploits, VMScape Attack, Siemens Flaws, and Rising Spyware Risks</title><link>https://grabtheaxe.com/news/sonicwall-exploits-vmscape-attack-siemens-flaws-and-rising-spyware-risks-09-11-2025/</link><guid isPermaLink="true">https://grabtheaxe.com/news/sonicwall-exploits-vmscape-attack-siemens-flaws-and-rising-spyware-risks-09-11-2025/</guid><description>Top threats on Sept 11, 2025: Akira ransomware hits SonicWall, VMScape attack leaks hypervisor data, Siemens flaws, spyware surge, and more.</description><pubDate>Thu, 11 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/sonicwall-exploits-vmscape-attack-siemens-flaws-and-rising-spyware-risks-09-11-2025.webp&quot; alt=&quot;SonicWall Exploits, VMScape Attack, Siemens Flaws, and Rising Spyware Risks&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The September 11, 2025 security roundup spotlights Akira ransomware exploiting a critical SonicWall SSL-VPN flaw, a new VMScape attack that breaks VM isolation on AMD and Intel chips, and severe Siemens UMC vulnerabilities enabling remote code execution. CISA added a Dassault Systèmes bug to its KEV catalog, while bulletproof host Stark Industries continues to dodge EU sanctions. Other developments include rising US investment in spyware, Apple warnings of targeted spyware campaigns, new ransomware abusing legitimate drivers, and fileless malware delivering AsyncRAT. Governments, schools, and enterprises faced major breaches and outages, while regulators advanced privacy and AI safety measures. Emerging tech news highlights Apple’s new iPhone security hardware, Microsoft Teams phishing protections, and OpenAI’s Developer Mode for ChatGPT.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Top 5 Critical Security Alerts&lt;/strong&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Akira ransomware exploiting critical SonicWall SSLVPN bug again ; The Akira ransomware group is actively exploiting a year-old critical vulnerability (CVE-2024-40766) in SonicWall SSL-VPN devices to gain initial access to networks. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/akira-ransomware-exploiting-critical-sonicwall-sslvpn-bug-again/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;New VMScape attack breaks guest-host isolation on AMD, Intel CPUs ; A new Spectre-like side-channel attack named VMScape allows a malicious virtual machine to leak sensitive data, including cryptographic keys, from the underlying hypervisor on modern CPUs. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-vmscape-attack-breaks-guest-host-isolation-on-amd-intel-cpus/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Siemens User Management Component (UMC) ; Multiple critical vulnerabilities, including a stack-based buffer overflow (CVSS 9.8), have been found in Siemens UMC, allowing unauthenticated remote attackers to execute arbitrary code or cause a denial-of-service. &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-25-254-07&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA Adds One Known Exploited Vulnerability to Catalog ; CISA has added CVE-2025-5086, a deserialization vulnerability in Dassault Systèmes DELMIA Apriso, to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/09/11/cisa-adds-one-known-exploited-vulnerability-catalog&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Bulletproof Host Stark Industries Evades EU Sanctions ; A notorious bulletproof hosting provider linked to Kremlin cyber operations, Stark Industries, is successfully evading EU sanctions by rebranding and transferring assets to new corporate shells. &lt;a href=&quot;https://krebsonsecurity.com/2025/09/bulletproof-host-stark-industries-evades-eu-sanctions/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Threat Intelligence&lt;/strong&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The US is now the largest investor in commercial spyware ; Reports indicate the United States has surpassed other nations to become the primary financial backer of the commercial spyware industry, raising national security and privacy concerns. &lt;a href=&quot;https://arstechnica.com/security/2025/09/the-us-is-now-the-largest-investor-in-commercial-spyware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Apple warns customers targeted in recent spyware attacks ; Apple has sent threat notifications to users targeted by new spyware attacks, a fact confirmed by the French national CERT, indicating ongoing sophisticated mobile threats. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/apple-warns-customers-targeted-in-recent-spyware-attacks/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;‘Gentlemen’ Ransomware Abuses Vulnerable Driver to Kill Security Gear ; A new ransomware strain named ‘Gentlemen’ is weaponizing a legitimate driver, ThrottleStop.sys, to disable antivirus and EDR solutions before encryption. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/gentlemen-ransomware-vulnerable-driver-security-gear&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fileless Malware Deploys Advanced RAT via Legitimate Tools ; A sophisticated fileless malware campaign is using legitimate system tools to deliver AsyncRAT directly into memory, evading traditional detection methods. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/fileless-malware-deploys-advanced/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Security Breaches &amp;amp; Incidents&lt;/strong&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Panama Ministry of Economy discloses breach claimed by INC ransomware ; Panama’s Ministry of Economy and Finance has acknowledged a potential cyberattack after the INC ransomware group claimed to have breached one of its computers. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/panama-ministry-of-economy-discloses-breach-claimed-by-inc-ransomware/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cyberattacks against schools driven by a rise in student hackers, ICO warns ; The UK’s privacy regulator reports a worrying increase in cyberattacks against schools perpetrated by students motivated by dares, notoriety, or revenge. &lt;a href=&quot;https://therecord.media/cyberattacks-against-schools-driven-by-student-hackers&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft investigates Exchange Online outage in North America ; Microsoft is currently investigating a major Exchange Online outage that is preventing customers across North America from accessing their email services. &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-investigates-exchange-online-outage-in-north-america/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Security Tools &amp;amp; Best Practices&lt;/strong&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Apple’s latest iPhone security feature just made life more difficult for spyware makers ; Apple has launched a new hardware security feature for the iPhone 17 and iPhone Air designed to mitigate memory corruption bugs, making zero-day exploits more difficult. &lt;a href=&quot;https://techcrunch.com/2025/09/11/apples-latest-iphone-security-feature-just-made-life-more-difficult-for-spyware-makers/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft adds malicious link warnings to Teams private chats ; Microsoft Teams will now automatically scan and display warnings for links in private chats that are identified as malicious, enhancing user protection against phishing. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-adds-malicious-link-warnings-to-teams-private-chats/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Buyer’s Guide to Browser Extension Management ; A new guide details the risks posed by browser extensions, such as data exfiltration, and outlines strategies for gaining visibility and enforcing security policies. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/the-buyers-guide-to-browser-extension-management/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Security Standards &amp;amp; Frameworks&lt;/strong&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;U.S. Senator accuses Microsoft of “gross cybersecurity negligence” ; Senator Ron Wyden has formally requested the FTC to investigate Microsoft for what he terms ‘gross negligence’ in its security practices, which he claims led to ransomware attacks on healthcare facilities. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/us-senator-accuses-microsoft-of-gross-cybersecurity-negligence/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;California legislature passes bill forcing web browsers to let consumers automatically opt out of data sharing ; A bill has passed in California that would require web browsers to honor universal opt-out signals for data sharing, strengthening consumer privacy rights. &lt;a href=&quot;https://therecord.media/california-legislature-passes-bill-data-sharing-opt-out&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Swiss government looks to undercut privacy tech, stoking fears of mass surveillance ; A pending government proposal in Switzerland is causing alarm among secure email and VPN providers, who claim it would undermine user privacy and enable mass surveillance. &lt;a href=&quot;https://therecord.media/switzerland-digital-privacy-law-proton-privacy-surveillance&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FTC opens inquiry into how AI chatbots impact child safety, privacy ; The U.S. Federal Trade Commission has launched an inquiry to assess whether AI chatbot developers are implementing adequate safeguards to protect children’s safety and privacy. &lt;a href=&quot;https://therecord.media/ftc-opens-inquiry-ai-chatbots-kids&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Emerging Security Technologies&lt;/strong&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OpenAI has launched Developer Mode for ChatGPT with full access to Model Context Protocol ; OpenAI has introduced a ‘Developer Mode’ for ChatGPT Plus and Pro users, granting them full read and write access to the Model Context Protocol (MCP) for advanced customization. &lt;a href=&quot;https://the-decoder.com/openai-has-launched-developer-mode-for-chatgpt-with-full-access-to-model-context-protocol/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Partnering with generative AI in the finance function ; Generative AI is poised to transform finance departments by automating mundane tasks, freeing up CFOs and their teams to focus on highvalue strategic work and advisory roles. &lt;a href=&quot;https://www.technologyreview.com/2025/09/11/1123508/partnering-with-generative-ai-in-the-finance-function/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tech’s data double standard: scrape to train, block everyone else ; Investigations reveal that major tech companies scrape vast amounts of copyrighted data to train their AI models while their own terms of service strictly forbid others from doing the same. &lt;a href=&quot;https://the-decoder.com/techs-data-double-standard-scrape-to-train-block-everyone-else/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>Akira ransomware</category><category>AMD CPU</category><category>Apple security</category><category>AsyncRAT</category><category>browser extension security</category><category>California privacy law</category><category>CISA KEV</category><category>Exchange Online outage</category><category>fileless malware</category><category>FTC AI chatbots</category><category>generative ai</category><category>Intel CPU</category><category>iPhone 17 security</category><category>Microsoft negligence</category><category>Microsoft Teams phishing</category><category>OpenAI Developer Mode</category><category>Panama cyberattack</category><category>ransomware</category><category>school cyberattacks</category><category>Siemens UMC</category><category>SonicWall SSL-VPN</category><category>spyware</category><category>Stark Industries</category><category>Swiss surveillance</category><category>VMScape</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/sonicwall-exploits-vmscape-attack-siemens-flaws-and-rising-spyware-risks-09-11-2025.webp" length="0" type="image/webp"/></item><item><title>Kerberoasting Attacks, Jaguar Land Rover Breach, and Malicious NPM Package</title><link>https://grabtheaxe.com/news/kerberoasting-jaguar-breach-npm-attack-2025-09-10/</link><guid isPermaLink="true">https://grabtheaxe.com/news/kerberoasting-jaguar-breach-npm-attack-2025-09-10/</guid><description>Stay informed on the latest cybersecurity threats. This article breaks down the recent Jaguar Land Rover data breach, the widespread npm supply chain attack, and the persistent threat of Kerberoasting attacks. Understand the risks and protect your organization from these evolving cyberattacks.</description><pubDate>Wed, 10 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://grabtheaxe.com/assets/news/kerberoasting-jaguar-breach-npm-attack-2025-09-10.webp&quot; alt=&quot;Kerberoasting Attacks, Jaguar Land Rover Breach, and Malicious NPM Package&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Top 5 Critical Security Alerts&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Senator blasts Microsoft for making default Windows vulnerable to “Kerberoasting” — A US Senator criticizes Microsoft for default Windows settings that use the weak RC4 cipher, leaving systems vulnerable to Kerberoasting attacks which led to the breach of health giant Ascension. &lt;a href=&quot;https://arstechnica.com/security/2025/09/senator-blasts-microsoft-for-making-default-windows-vulnerable-to-kerberoasting/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jaguar Land Rover says data stolen in disruptive cyberattack — The automotive manufacturer confirmed that a cyberattack, which has halted its vehicle assembly lines since September 2, also resulted in data theft. &lt;a href=&quot;https://techcrunch.com/2025/09/10/jaguar-land-rover-says-data-stolen-in-disruptive-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hackers left empty-handed after massive NPM supply-chain attack — The largest supply-chain attack in NPM’s history has reportedly impacted 10% of all cloud environments, though the attackers gained little financial profit from the widespread compromise. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-left-empty-handed-after-massive-npm-supply-chain-attack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systems — A China-linked APT group was observed using a new, undocumented fileless malware framework called EggStreme to conduct espionage against a military organization in the Philippines. &lt;a href=&quot;https://thehackernews.com/2025/09/chinese-apt-deploys-eggstreme-fileless.html&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Patch Tuesday, September 2025 Edition — Microsoft released its monthly security updates, addressing over 80 vulnerabilities, including 13 rated as critical, across its product suite. No zero-day exploits were reported in this release. &lt;a href=&quot;https://krebsonsecurity.com/2025/09/microsoft-patch-tuesday-september-2025-edition/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;KillSec Ransomware Hits Brazilian Healthcare IT Vendor — The KillSec ransomware group has targeted MedicSolution, a Brazilian healthcare IT provider, threatening to disrupt services for healthcare providers and patients. &lt;a href=&quot;https://www.infosecurity-magazine.com/news/killsec-ransomware-hits-brazilian/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;US investors in spyware firms nearly tripled in 2024: report — A new report indicates a sharp rise in American investment in spyware vendors, despite ongoing government efforts to sanction and restrict the sector. &lt;a href=&quot;https://therecord.media/us-investors-in-spyware-tripled-in-2024&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Notes of cyber inspector: three clusters of threat in cyberspace — This report analyzes the Tactics, Techniques, and Procedures (TTPs) of cybercrime, hacktivist, and APT groups targeting Russian organizations, categorizing them into three distinct clusters. &lt;a href=&quot;https://securelist.com/three-hacktivist-apt-clusters-tools-and-ttps/117324/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Researchers find spyware on phones belonging to Kenyan filmmakers — Commercially available spyware, FlexiSPY, was discovered on the phones of Kenyan filmmakers, highlighting the accessibility of powerful surveillance tools beyond nation-state actors. &lt;a href=&quot;https://therecord.media/researchers-spyware-kenya-filmmaker-phone&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Breaches &amp;amp; Incidents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Jaguar Land Rover confirms data theft after recent cyberattack — Following a disruptive cyberattack, Jaguar Land Rover (JLR) has confirmed that attackers stole an unspecified amount of data, forcing system shutdowns and work stoppages. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/jaguar-land-rover-jlr-confirms-data-theft-after-recent-cyberattack/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Tools &amp;amp; Best Practices&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;September Patch Tuesday handles 81 CVEs — Microsoft’s final security update before the end of Windows 10 support addresses 81 vulnerabilities across 15 product families, including Windows and Xbox. &lt;a href=&quot;https://news.sophos.com/en-us/2025/09/10/september-patch-tuesday-handles-81-cves/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cursor AI editor lets repos “autorun” malicious code on devices — A security flaw in the Cursor code editor exposes developers to risk by allowing malicious repositories to automatically execute code on their machines upon being opened. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/cursor-ai-editor-lets-repos-autorun-malicious-code-on-devices/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Can I have a new password, please? The $400M question. — The article uses the Scattered Spider breach of Clorox, which cost $380M, to emphasize the critical need for robust caller verification and audit trails at IT help desks to prevent social engineering. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/can-i-have-a-new-password-please-the-400m-question/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Cloud &amp;amp; Network Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Quiet Revolution in Kubernetes Security — The article discusses the necessary evolution of the underlying operating system to enhance security as Kubernetes becomes a foundational component of enterprise infrastructure. &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/quiet-revolution-kubernetes-security&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Standards &amp;amp; Frameworks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Maturing the cyber threat intelligence program — The Cyber Threat Intelligence Capability Maturity Model (CTI-CMM) provides a framework to help organizations assess and enhance their threat intelligence programs across 11 key areas. &lt;a href=&quot;https://blog.talosintelligence.com/maturing-the-cyber-threat-intelligence-program/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chinese companies and bosses to face major fines over cybersecurity incidents — China is proposing an update to its national Cybersecurity Law that would impose stricter oversight on tech products and increase financial penalties for non-compliant companies and their executives. &lt;a href=&quot;https://therecord.media/china-cybersecurity-law-update-penalties-companies-executives&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Emerging Security Technologies&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google’s former security leads raise $13M to fight email threats before they reach you — A startup founded by former Google security leads has secured $13 million in funding to build a system using real-time AI agents to analyze and neutralize email-based threats proactively. &lt;a href=&quot;https://techcrunch.com/2025/09/10/googles-former-security-leads-raise-13m-to-fight-email-threats-before-they-reach-you/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pixel 10 fights AI fakes with new Android photo verification tech — Google is integrating C2PA Content Credentials into the upcoming Pixel 10 camera and Google Photos to provide a way for users to distinguish authentic images from AI-generated or edited fakes. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/pixel-10-fights-ai-fakes-with-new-android-photo-verification-tech/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Vibe coding? Meet vibe security — This article discusses how the rapid evolution of AI is creating new attack vectors like ‘vibe coding’ and prompt-based attacks, driving demand for innovative cybersecurity startups like Wiz. &lt;a href=&quot;https://techcrunch.com/podcast/vibe-coding-meet-vibe-security/&quot;&gt;Read more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>AI</category><category>Akira ransomware</category><category>Credentials</category><category>Crypto-wallet</category><category>Cybersecurity</category><category>Data Breach</category><category>Hacking</category><category>Jaguar Land Rover</category><category>Kaseya</category><category>npm</category><category>ransomware</category><category>Supply Chain Attack</category><author>info@grabtheaxe.com (Chris Armour)</author><enclosure url="https://grabtheaxe.com/assets/news/kerberoasting-jaguar-breach-npm-attack-2025-09-10.webp" length="0" type="image/webp"/></item></channel></rss>