A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Russian court sentences notorious card fraud ringleader ‘Flint’ and 25 associates
Cambodia extradites alleged cyber scam linchpin to China as crackdown intensifies
Drift Protocol exploited for $286 million in suspected DPRK-linked attack
European Commission cloud breach: a supply-chain compromise
Cyber attack on the Left Party
Malware
Infiniti Stealer: a new macOS infostealer using ClickFix and Python/Nuitka
axios Compromised: npm Supply Chain Attack via Dependency Injection
Axios compromised: hijacked maintainer account pushes malicious npm versions
A laughing RAT: CrystalX combines spyware, stealer, and prankware features
Hacking
Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
Nicholas Carlini – Black-hat LLMs | [un]prompted 2026
MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)
New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released
Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets
Double Agents: Exposing Security Blind Spots in GCP Vertex AI
ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime
Intelligence and Information Warfare
TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
Hacked Hospitals, Hidden Spyware: Iran Conflict Shows How Digital Fight Is Ingrained in Warfare
Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
BlueNoroff | How DPRK’s macOS RustBucket Seeks to Evade Analysis and Detection
Iran-linked hackers claim breach of Israeli air defence contractor PSK Wind
Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets
Cybersecurity
Apple Now Sending Critical Security Alerts to iPhones Running iOS 17 and Earlier
Forecasting Future Outbreaks A Behavioral and Predictive Approach to Proactive Cyber Risk Management
Nearly half a million Lloyds Banking Group customers affected by personal data glitch
Claude Code’s source code appears to have leaked: here’s what we know
What’s Really Running Inside Your Free VPN: A Mysterium VPN Research
After fighting malware for decades, this cybersecurity veteran is now hacking drones
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Source: SecurityAffairs
Source Link: https://securityaffairs.com/190368/breaking-news/security-affairs-newsletter-round-571-by-pierluigi-paganini-international-edition.html