Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (4 November 2025)
Published: Loading…
At a Glance
- Hackers stole over $120 million from the Balancer DeFi protocol in one of the year’s largest crypto heists.
- Microsoft identified the SesameOp malware exploiting OpenAI’s API for covert command-and-control.
- Malicious SleepyDuck extension on Open VSX backdoored developers through an Ethereum-based channel.
- Former cybersecurity professionals were indicted for conducting BlackCat ransomware attacks.
- CISA and NSA issued new guidance for securing Microsoft Exchange Servers.
- Cargo theft surged as cybercriminals used remote monitoring tools to hijack shipments.
Summary
Hackers stole more than $120 million from the Balancer DeFi protocol by exploiting vulnerabilities in its v2 liquidity pools, marking one of the largest cryptocurrency thefts of the year. Reports indicate significant financial losses across decentralised finance networks following the incident.
Microsoft researchers revealed a new backdoor malware called SesameOp, which abuses the OpenAI Assistants API for command-and-control operations. The malware uses AI integration to mask its communications, complicating detection.
A malicious VSCode extension named SleepyDuck was found on the Open VSX registry, embedding a remote access trojan that communicates via Ethereum smart contracts. It initially appeared as a legitimate Solidity development tool before being weaponised in a later version.
Three former employees of cybersecurity companies DigitalMint and Sygnia have been indicted for allegedly executing BlackCat ransomware attacks on several U.S. firms. The individuals reportedly extorted victims while working as negotiators or incident responders.
The Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) released new joint guidelines for securing Microsoft Exchange Servers. The recommendations include configuration baselines and patching practices to prevent ongoing exploitation.
Cybercriminals have increasingly turned to remote monitoring and management (RMM) tools to facilitate cargo theft. Researchers reported that organised crime groups are collaborating with hackers to infiltrate logistics networks and hijack physical shipments.
Today’s advisories highlight multiple high-severity flaws across core infrastructure, notably in the Linux kernel, Microsoft Windows, and Redis, with one Windows zero-day confirmed as actively exploited via malicious .LNK files. Additional updates address critical code-execution risks in Chrome/Edge, OpenSSL, and X.Org/Xwayland, indicating a broad focus on patching essential runtime and cryptographic components.
Highlights of the day:
- Android/BankBot-YNRK trojan hits banking apps: new Android malware mimics trusted apps, abuses accessibility services, and targets over 70 banking and cryptocurrency platforms with credential theft and remote control capabilities.
- Cybercriminals exploit RMM tools for cargo theft: attackers use legitimate remote management software like ScreenConnect to infiltrate logistics firms, hijack shipments, and coordinate physical theft through organised crime networks.
- Ransomware negotiators charged with extortion: two employees from DigitalMint and Sygnia allegedly launched ransomware attacks on clients, stealing over $1 million while posing as trusted intermediaries.
- SleepyDuck malware hides in Open VSX extension: malicious Solidity extension downloaded 14,000 times installs a remote access trojan using Ethereum smart contracts to maintain control after takedowns.
- Balancer DeFi exploit drains $100 million: hackers exploited access control flaws in the Balancer protocol, stealing Ethereum-based assets and triggering emergency shutdowns across connected blockchain platforms.
Highlights of the Day
Android/BankBot-YNRK Trojan Targets Banking and Crypto Apps
Researchers have uncovered a sophisticated Android trojan, dubbed Android/BankBot-YNRK, capable of full remote control of infected devices. The malware impersonates legitimate apps like Google News, abuses accessibility services for privilege escalation, and targets over 70 banking and cryptocurrency applications. It employs persistence mechanisms, anti-analysis features, and extensive command-and-control functions to steal credentials and perform fraudulent transactions.
Cybercriminals Exploit RMM Tools to Steal Real-World Cargo
Proofpoint has identified a series of cyber campaigns targeting trucking and logistics companies, where attackers deploy remote monitoring and management (RMM) tools to gain access to corporate systems and facilitate physical cargo theft. The operations, active since early 2025, involve compromised load board accounts and phishing tactics to install legitimate RMM software such as ScreenConnect and SimpleHelp, allowing criminals to hijack shipments and sell stolen goods through organised crime networks.
Ransomware Negotiators Indicted for Running Their Own Attacks
Two cybersecurity professionals from DigitalMint and Sygnia have been charged with conducting ransomware attacks while employed to help victims negotiate ransoms. The FBI alleges the men extorted over $1 million from a Florida medical firm and attempted further attacks on several companies across the United States. Both firms have dismissed the employees and are cooperating with investigators.
SleepyDuck Malware Found in Open VSX Code Extension
Researchers have uncovered a new remote access trojan dubbed SleepyDuck hidden in a fake Solidity extension on the Open VSX marketplace, downloaded over 14,000 times before being updated with malicious code. The malware gathers system data, evades sandboxes, and maintains control through an Ethereum smart contract that dynamically updates its command-and-control address if blocked.
Over $100 Million Stolen in Balancer DeFi Exploit
Hackers have stolen more than $100 million in cryptocurrency from the decentralised finance protocol Balancer, exploiting a flaw in its access controls. The attack, which primarily affected Ethereum-based assets, prompted emergency responses from connected platforms including Berachain, Gnosis, and Sonic, as Balancer moved to pause affected pools and investigate the breach.
Daily Coverage