Australian authorities sentenced a 44-year-old man for operating an evil twin WiFi network at airports to steal traveller data. The court imposed a term of seven years and four months.
Microsoft reported that recent Windows 11 updates can make the password sign-in option invisible on the lock screen, although the function itself remains operational.
A security engineer uncovered more than 17,000 exposed secrets across public GitLab repositories. The scan covered 5.6 million repositories spanning over 2,800 domains.
Asahi confirmed a ransomware incident that may have exposed data belonging to 1.5 million individuals. The organisation stated that the breach involved personal information but not payment details.
ReversingLabs researchers identified vulnerable bootstrap scripts in legacy PyPI packages that create a domain-takeover risk. Additional supply-chain concerns emerged as PostHog confirmed the Shai-Hulud 2.0 worm compromised its JavaScript software development kits.
Threat researchers observed 197 malicious npm packages linked to North Korean actors spreading an updated OtterCookie variant. The packages accumulated more than 31,000 downloads.
The French Football Federation disclosed a breach caused by a compromised account granting access to management software. British telecom provider Brsk separately investigated claims of a breach involving more than 230,000 customer files.
GrapheneOS announced a shift away from OVHcloud due to concerns regarding French privacy policies. BitSight reported abuse of calendar subscriptions for phishing, malware and social-engineering delivery.
Researchers documented a prompt-injection method using poetic formatting to jailbreak large language models.
The UK Office for Budget Responsibility brought in former NCSC chief Ciaran Martin after a budget forecast appeared online prematurely. Further disclosures covered MS Teams guest-access bypass behaviour and a cyberattack against crypto exchange Upbit shortly after its acquisition by Naver.
Highlights of the day:
- French Football Federation reports major data breach: a compromised account exposed personal details of millions of licensed players, prompting notification of national authorities and system remediation.
- Calendar subscription abuse affects millions of Apple devices: more than 4 million iOS and macOS systems continue syncing to abandoned or hijacked calendar domains used to deliver unsolicited events with links or attachments.
- North Korean npm campaign expands with nearly 200 new packages: malicious uploads distribute an updated OtterCookie variant through typosquatted tools and cloned crypto projects targeting Web3 developers.
- Scan of public GitLab repositories uncovers 17,000 live secrets: analysis of 5.6 million repositories revealed widespread exposure of active credentials, including Google Cloud Platform keys and GitLab tokens.
- WA man jailed for airport ‘evil twin’ WiFi attacks: a Perth court sentenced him to more than seven years for deploying fake WiFi networks, harvesting credentials, and accessing victims’ online accounts.