CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (4 November 2025)

Published: Loading…

At a Glance

  • Hackers stole over $120 million from the Balancer DeFi protocol in one of the year’s largest crypto heists.
  • Microsoft identified the SesameOp malware exploiting OpenAI’s API for covert command-and-control.
  • Malicious SleepyDuck extension on Open VSX backdoored developers through an Ethereum-based channel.
  • Former cybersecurity professionals were indicted for conducting BlackCat ransomware attacks.
  • CISA and NSA issued new guidance for securing Microsoft Exchange Servers.
  • Cargo theft surged as cybercriminals used remote monitoring tools to hijack shipments.

Summary

Hackers stole more than $120 million from the Balancer DeFi protocol by exploiting vulnerabilities in its v2 liquidity pools, marking one of the largest cryptocurrency thefts of the year. Reports indicate significant financial losses across decentralised finance networks following the incident.

Microsoft researchers revealed a new backdoor malware called SesameOp, which abuses the OpenAI Assistants API for command-and-control operations. The malware uses AI integration to mask its communications, complicating detection.

A malicious VSCode extension named SleepyDuck was found on the Open VSX registry, embedding a remote access trojan that communicates via Ethereum smart contracts. It initially appeared as a legitimate Solidity development tool before being weaponised in a later version.

Three former employees of cybersecurity companies DigitalMint and Sygnia have been indicted for allegedly executing BlackCat ransomware attacks on several U.S. firms. The individuals reportedly extorted victims while working as negotiators or incident responders.

The Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) released new joint guidelines for securing Microsoft Exchange Servers. The recommendations include configuration baselines and patching practices to prevent ongoing exploitation.

Cybercriminals have increasingly turned to remote monitoring and management (RMM) tools to facilitate cargo theft. Researchers reported that organised crime groups are collaborating with hackers to infiltrate logistics networks and hijack physical shipments.

Today’s advisories highlight multiple high-severity flaws across core infrastructure, notably in the Linux kernel, Microsoft Windows, and Redis, with one Windows zero-day confirmed as actively exploited via malicious .LNK files. Additional updates address critical code-execution risks in Chrome/Edge, OpenSSL, and X.Org/Xwayland, indicating a broad focus on patching essential runtime and cryptographic components.

Highlights of the day:

  • Android/BankBot-YNRK trojan hits banking apps: new Android malware mimics trusted apps, abuses accessibility services, and targets over 70 banking and cryptocurrency platforms with credential theft and remote control capabilities.
  • Cybercriminals exploit RMM tools for cargo theft: attackers use legitimate remote management software like ScreenConnect to infiltrate logistics firms, hijack shipments, and coordinate physical theft through organised crime networks.
  • Ransomware negotiators charged with extortion: two employees from DigitalMint and Sygnia allegedly launched ransomware attacks on clients, stealing over $1 million while posing as trusted intermediaries.
  • SleepyDuck malware hides in Open VSX extension: malicious Solidity extension downloaded 14,000 times installs a remote access trojan using Ethereum smart contracts to maintain control after takedowns.
  • Balancer DeFi exploit drains $100 million: hackers exploited access control flaws in the Balancer protocol, stealing Ethereum-based assets and triggering emergency shutdowns across connected blockchain platforms.

Highlights of the Day

Android/BankBot-YNRK Trojan Targets Banking and Crypto Apps

Researchers have uncovered a sophisticated Android trojan, dubbed Android/BankBot-YNRK, capable of full remote control of infected devices. The malware impersonates legitimate apps like Google News, abuses accessibility services for privilege escalation, and targets over 70 banking and cryptocurrency applications. It employs persistence mechanisms, anti-analysis features, and extensive command-and-control functions to steal credentials and perform fraudulent transactions.

Source: CYFIRMA

Cybercriminals Exploit RMM Tools to Steal Real-World Cargo

Proofpoint has identified a series of cyber campaigns targeting trucking and logistics companies, where attackers deploy remote monitoring and management (RMM) tools to gain access to corporate systems and facilitate physical cargo theft. The operations, active since early 2025, involve compromised load board accounts and phishing tactics to install legitimate RMM software such as ScreenConnect and SimpleHelp, allowing criminals to hijack shipments and sell stolen goods through organised crime networks.

Source: Proofpoint

Ransomware Negotiators Indicted for Running Their Own Attacks

Two cybersecurity professionals from DigitalMint and Sygnia have been charged with conducting ransomware attacks while employed to help victims negotiate ransoms. The FBI alleges the men extorted over $1 million from a Florida medical firm and attempted further attacks on several companies across the United States. Both firms have dismissed the employees and are cooperating with investigators.

SleepyDuck Malware Found in Open VSX Code Extension

Researchers have uncovered a new remote access trojan dubbed SleepyDuck hidden in a fake Solidity extension on the Open VSX marketplace, downloaded over 14,000 times before being updated with malicious code. The malware gathers system data, evades sandboxes, and maintains control through an Ethereum smart contract that dynamically updates its command-and-control address if blocked.

Over $100 Million Stolen in Balancer DeFi Exploit

Hackers have stolen more than $100 million in cryptocurrency from the decentralised finance protocol Balancer, exploiting a flaw in its access controls. The attack, which primarily affected Ethereum-based assets, prompted emergency responses from connected platforms including Berachain, Gnosis, and Sonic, as Balancer moved to pause affected pools and investigate the breach.

Daily Coverage

Vulnerabilities
CVE-2025-43429CVE-2025-11953The Metro Development Server, Which Is Opened By The React Native Community Cli, Binds To External Interfaces By Default. The Server Exposes An Endpoint That Is Vulnerable To Os Command Injection. This Allows Unauthenticated Network Attackers To Send A Post Request To The Server And Run Arbitrary Executables. On Windows, The Attackers Can Also Execute Arbitrary Shell Commands With Fully Controlled Arguments.CVE-2024-36350A Transient Execution Vulnerability In Some Amd Processors May Allow An Attacker To Infer Data From Previous Stores, Potentially Resulting In The Leakage Of Privileged Information.CVE-2024-36357A Transient Execution Vulnerability In Some Amd Processors May Allow An Attacker To Infer Data In The L1D Cache, Potentially Resulting In The Leakage Of Sensitive Information Across Privileged Boundaries.CVE-2024-26700Linux_Kernel 6.1.82 (Medium)CVE-2025-38727In The Linux Kernel, The Following Vulnerability Has Been Resolved: Netlink: Avoid Infinite Retry Looping In Netlink_Unicast() Netlink_Attachskb() Checks For The Socket's Read Memory Allocation Constraints. Firstly, It Has: Rmem < Read_Once(Sk->Sk_Rcvbuf) To Check If The Just Increased Rmem Value Fits Into The Socket's Receive Buffer. If Not, It Proceeds And Tries To Wait For The Memory Under: Rmem + Skb->Truesize > Read_Once(Sk->Sk_Rcvbuf) The Checks Don't Cover The Case When Skb->Tru…CVE-2023-52593Linux_Kernel 6.1.77 (Medium)CVE-2024-26896Linux_Kernel 6.1.83 (Medium)CVE-2025-55315Asp.net_Core 2.3.6 (Critical)CVE-2025-11371Centrestack 16.10.10408.56683 (High)
Threat Groups
LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.