Europol and Eurojust led a coordinated operation across Cyprus, Spain, and Germany, dismantling a cryptocurrency fraud network responsible for stealing more than €600 million. Nine suspects were arrested for running fake investment platforms and laundering proceeds through complex international transfers.
Microsoft disclosed a new backdoor named SesameOp, which abuses the OpenAI Assistants API as a covert command-and-control channel to evade detection. The malware, also documented by independent researchers, uses the API to store and relay attacker commands.
Two critical WordPress vulnerabilities were actively exploited this week. Attackers targeted the Post SMTP plugin and JobMonster theme, compromising administrator accounts on hundreds of thousands of sites and enabling complete takeover of affected installations.
Apple released iOS and macOS updates patching over 100 vulnerabilities, including 19 flaws in WebKit discovered partly by Google’s AI-driven “Big Sleep” system. Google also pushed November Android updates addressing critical remote code execution issues in the platform’s System component.
Researchers from Check Point detailed four now-fixed vulnerabilities in Microsoft Teams that allowed attackers to impersonate users, forge messages, and alter chat histories. These flaws were patched following responsible disclosure in March.
A newly formed cybercrime alliance has combined the operations of Scattered Spider, LAPSUS$, and ShinyHunters. The group has established multiple Telegram channels to coordinate data theft and extortion campaigns, signalling a more unified threat landscape.
Today’s advisories highlighted critical vulnerabilities in Apple, Android, VMware, Tenable, and the Linux kernel, several of which allow remote code execution or privilege escalation. CISA added two actively exploited flaws to its KEV catalogue, while multiple vendors — notably OpenStack, Golang, and OpenSSL — issued coordinated patches addressing systemic security weaknesses.
Highlights of the day:
- Microsoft uncovers backdoor abusing OpenAI API for covert control: new espionage malware “SesameOp” uses OpenAI’s Assistants API as a hidden command channel to execute encrypted tasks, evading standard network defences.
- Android fixes critical flaw allowing remote code execution: November 2025 security update resolves a System component bug affecting Android 13–16 that could permit remote code execution without user interaction.
- Check Point exposes Teams flaws enabling identity spoofing: four critical vulnerabilities, including CVE-2024-38197, allowed attackers to impersonate executives and manipulate Teams messages before Microsoft issued fixes.
- Scattered LAPSUS$ Hunters unify major cybercrime groups: Trustwave reports Scattered Spider, ShinyHunters, and LAPSUS$ have formed a joint Extortion-as-a-Service operation using Telegram for coordination and publicity.
- Critical flaw exposes 400,000 WordPress sites to account takeover: Wordfence found a CVSS 9.8 vulnerability in the Post SMTP plugin letting unauthenticated attackers access email logs and reset admin passwords.