CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (5 November 2025)

Published: Loading…

At a Glance

  • European police dismantled a €600 million crypto fraud network and arrested nine suspects.
  • Microsoft and researchers uncovered SesameOp malware abusing OpenAI’s API for covert control.
  • Multiple WordPress flaws were exploited to hijack admin accounts.
  • Apple and Google issued critical security patches, while researchers detailed Teams vulnerabilities enabling message impersonation.
  • A new cybercrime alliance emerged, merging Scattered Spider, LAPSUS$, and ShinyHunters operations.

Summary

Europol and Eurojust led a coordinated operation across Cyprus, Spain, and Germany, dismantling a cryptocurrency fraud network responsible for stealing more than €600 million. Nine suspects were arrested for running fake investment platforms and laundering proceeds through complex international transfers.

Microsoft disclosed a new backdoor named SesameOp, which abuses the OpenAI Assistants API as a covert command-and-control channel to evade detection. The malware, also documented by independent researchers, uses the API to store and relay attacker commands.

Two critical WordPress vulnerabilities were actively exploited this week. Attackers targeted the Post SMTP plugin and JobMonster theme, compromising administrator accounts on hundreds of thousands of sites and enabling complete takeover of affected installations.

Apple released iOS and macOS updates patching over 100 vulnerabilities, including 19 flaws in WebKit discovered partly by Google’s AI-driven “Big Sleep” system. Google also pushed November Android updates addressing critical remote code execution issues in the platform’s System component.

Researchers from Check Point detailed four now-fixed vulnerabilities in Microsoft Teams that allowed attackers to impersonate users, forge messages, and alter chat histories. These flaws were patched following responsible disclosure in March.

A newly formed cybercrime alliance has combined the operations of Scattered Spider, LAPSUS$, and ShinyHunters. The group has established multiple Telegram channels to coordinate data theft and extortion campaigns, signalling a more unified threat landscape.

Today’s advisories highlighted critical vulnerabilities in Apple, Android, VMware, Tenable, and the Linux kernel, several of which allow remote code execution or privilege escalation. CISA added two actively exploited flaws to its KEV catalogue, while multiple vendors — notably OpenStack, Golang, and OpenSSL — issued coordinated patches addressing systemic security weaknesses.

Highlights of the day:

  • Microsoft uncovers backdoor abusing OpenAI API for covert control: new espionage malware “SesameOp” uses OpenAI’s Assistants API as a hidden command channel to execute encrypted tasks, evading standard network defences.
  • Android fixes critical flaw allowing remote code execution: November 2025 security update resolves a System component bug affecting Android 13–16 that could permit remote code execution without user interaction.
  • Check Point exposes Teams flaws enabling identity spoofing: four critical vulnerabilities, including CVE-2024-38197, allowed attackers to impersonate executives and manipulate Teams messages before Microsoft issued fixes.
  • Scattered LAPSUS$ Hunters unify major cybercrime groups: Trustwave reports Scattered Spider, ShinyHunters, and LAPSUS$ have formed a joint Extortion-as-a-Service operation using Telegram for coordination and publicity.
  • Critical flaw exposes 400,000 WordPress sites to account takeover: Wordfence found a CVSS 9.8 vulnerability in the Post SMTP plugin letting unauthenticated attackers access email logs and reset admin passwords.

Highlights of the Day

Microsoft uncovers backdoor abusing OpenAI API for covert control

Microsoft researchers have identified a new espionage-focused backdoor, “SesameOp”, which exploits the OpenAI Assistants API as a covert command-and-control channel. The malware uses legitimate API communications to issue encrypted commands and return results, evading detection and traditional network defences. Microsoft and OpenAI have jointly disabled the attacker’s API key and continue investigating the misuse.

Android fixes critical flaw allowing remote code execution

Google has released the November 2025 Android Security Bulletin, addressing multiple vulnerabilities, including a critical flaw in the System component that could allow remote code execution without user interaction. Devices running Android versions 13 to 16 are affected, with patches issued through the 2025-11-01 security update level.

Check Point exposes Teams flaws enabling identity spoofing

Check Point Research identified four critical vulnerabilities in Microsoft Teams that allowed attackers to impersonate executives, alter messages and notifications, and forge caller identities. Both guest users and insiders could exploit these flaws to deceive employees and disrupt corporate communications. Microsoft confirmed and fixed the issues, tracking one as CVE-2024-38197.

Scattered LAPSUS$ Hunters unify major cybercrime groups

Trustwave researchers have identified a new alliance of three notorious cybercriminal groups — Scattered Spider, ShinyHunters, and LAPSUS$ — operating collectively as “Scattered LAPSUS$ Hunters.” The group runs an Extortion-as-a-Service operation using Telegram as its hub, combining social engineering, exploit development, and public intimidation to amplify its reputation and reach. Analysts say it marks a rare consolidation of mature cybercrime brands under a unified structure.

Critical flaw exposes 400,000 WordPress sites to account takeover

Wordfence researchers have disclosed a critical vulnerability in the Post SMTP WordPress plugin affecting more than 400,000 sites. The flaw, rated CVSS 9.8, allows unauthenticated attackers to access email logs containing password reset links, enabling full account takeover. Exploitation began in early November, though a patch was released on 29 October in version 3.6.1.

Source: Wordfence

Daily Coverage

Vulnerabilities
CVE-2025-11371Centrestack 16.10.10408.56683 (High)CVE-2025-48703Webpanel 0.9.8.1205 (Critical)CVE-2024-38197CVE-2023-20198Allen-Bradley_Stratix_5200_Firmware 17.12.02 (Critical)CVE-2025-11953The Metro Development Server, Which Is Opened By The React Native Community Cli, Binds To External Interfaces By Default. The Server Exposes An Endpoint That Is Vulnerable To Os Command Injection. This Allows Unauthenticated Network Attackers To Send A Post Request To The Server And Run Arbitrary Executables. On Windows, The Attackers Can Also Execute Arbitrary Shell Commands With Fully Controlled Arguments.CVE-2025-9900A Flaw Was Found In Libtiff. This Vulnerability Is A "Write-What-Where" Condition, Triggered When The Library Processes A Specially Crafted Tiff Image File. By Providing An Abnormally Large Image Height Value In The File's Metadata, An Attacker Can Trick The Library Into Writing Attacker-Controlled Color Data To An Arbitrary Memory Location. This Memory Corruption Can Be Exploited To Cause A Denial Of Service (Application Crash) Or To Achieve Arbitrary Code Execution With The Permissions Of The…CVE-2025-12428CVE-2025-12429CVE-2025-12430CVE-2025-12431
Threat Groups
LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.