CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (29 November 2025)

Published: Loading…

At a Glance

  • Australian authorities sentenced an airport WiFi attacker, while major organisations in France, Japan and the UK disclosed data breaches.
  • Researchers reported extensive secret exposure on GitLab and new supply-chain risks in Python and npm ecosystems.
  • North Korean actors expanded malicious npm activity, and Microsoft warned of a Windows 11 password display issue.
  • Additional reports described phishing via calendar subscriptions and a bypass affecting Microsoft Teams guest protections.

Summary

Australian authorities sentenced a 44-year-old man for operating an evil twin WiFi network at airports to steal traveller data. The court imposed a term of seven years and four months.

Microsoft reported that recent Windows 11 updates can make the password sign-in option invisible on the lock screen, although the function itself remains operational.

A security engineer uncovered more than 17,000 exposed secrets across public GitLab repositories. The scan covered 5.6 million repositories spanning over 2,800 domains.

Asahi confirmed a ransomware incident that may have exposed data belonging to 1.5 million individuals. The organisation stated that the breach involved personal information but not payment details.

ReversingLabs researchers identified vulnerable bootstrap scripts in legacy PyPI packages that create a domain-takeover risk. Additional supply-chain concerns emerged as PostHog confirmed the Shai-Hulud 2.0 worm compromised its JavaScript software development kits.

Threat researchers observed 197 malicious npm packages linked to North Korean actors spreading an updated OtterCookie variant. The packages accumulated more than 31,000 downloads.

The French Football Federation disclosed a breach caused by a compromised account granting access to management software. British telecom provider Brsk separately investigated claims of a breach involving more than 230,000 customer files.

GrapheneOS announced a shift away from OVHcloud due to concerns regarding French privacy policies. BitSight reported abuse of calendar subscriptions for phishing, malware and social-engineering delivery.

Researchers documented a prompt-injection method using poetic formatting to jailbreak large language models.

The UK Office for Budget Responsibility brought in former NCSC chief Ciaran Martin after a budget forecast appeared online prematurely. Further disclosures covered MS Teams guest-access bypass behaviour and a cyberattack against crypto exchange Upbit shortly after its acquisition by Naver.

Highlights of the day:

  • French Football Federation reports major data breach: a compromised account exposed personal details of millions of licensed players, prompting notification of national authorities and system remediation.
  • Calendar subscription abuse affects millions of Apple devices: more than 4 million iOS and macOS systems continue syncing to abandoned or hijacked calendar domains used to deliver unsolicited events with links or attachments.
  • North Korean npm campaign expands with nearly 200 new packages: malicious uploads distribute an updated OtterCookie variant through typosquatted tools and cloned crypto projects targeting Web3 developers.
  • Scan of public GitLab repositories uncovers 17,000 live secrets: analysis of 5.6 million repositories revealed widespread exposure of active credentials, including Google Cloud Platform keys and GitLab tokens.
  • WA man jailed for airport ‘evil twin’ WiFi attacks: a Perth court sentenced him to more than seven years for deploying fake WiFi networks, harvesting credentials, and accessing victims’ online accounts.

Highlights of the Day

French Football Federation Reports Major Data Breach

The French Football Federation disclosed unauthorised access to its administrative platform used by football clubs across France. Attackers accessed a compromised account and obtained personal details of millions of registered players, including contact information and licence numbers. The federation notified national authorities and secured the affected system.

Calendar Subscriptions Expose Millions of Devices to Abuse

Bitsight research revealed that more than 4 million iOS and macOS devices continue to sync with abandoned or hijacked calendar subscription domains. These domains can deliver crafted iCalendar files that insert unsolicited events containing links or attachments, creating opportunities for large-scale social engineering or malware delivery. The investigation identified more than a thousand domains tied to notification-scam networks and compromised websites feeding users into these subscriptions.

Source: Bitsight

North Korean Operation Expands npm Supply-Chain Intrusions

Socket researchers report that the Contagious Interview campaign has added nearly 200 further malicious npm packages, using typosquatted utilities and cloned crypto projects to deliver updated OtterCookie malware. Investigators traced several packages to a removed GitHub account that linked GitHub, Vercel, and a separate command-and-control server into a unified delivery chain targeting blockchain and Web3 developers.

Source: Socket

Scan of Public GitLab Repositories Uncovers 17,000 Live Secrets

A security engineer scanned 5.6 million public GitLab repositories and identified more than 17,000 verified active secrets linked to 2,804 organisations. The findings showed a higher density of exposed credentials on GitLab than on Bitbucket, with leaked Google Cloud Platform keys and GitLab tokens among the most common. The researcher used automated tooling and large-scale triage processes to disclose the exposed credentials to affected organisations.

WA Man Jailed for Airport ‘Evil Twin’ WiFi Attacks

Australian Federal Police reported that a West Australian man received a seven-year, four-month sentence for creating fake WiFi networks to capture travellers’ credentials and accessing women’s online accounts. Investigators linked his activity to airports in multiple cities and identified thousands of stolen images, videos and personal details on seized devices. He pleaded guilty to a range of cybercrime, data access and evidence-destruction offences.

Daily Coverage

Vulnerabilities
CVE-2025-38616In The Linux Kernel, The Following Vulnerability Has Been Resolved: Tls: Handle Data Disappearing From Under The Tls Ulp Tls Expects That It Owns The Receive Queue Of The Tcp Socket. This Cannot Be Guaranteed In Case The Reader Of The Tcp Socket Entered Before The Tls Ulp Was Installed, Or Uses Some Non-Standard Read Api (Eg. Zerocopy Ones). Replace The Warn_On() And A Buggy Early Exit (Which Leaves Anchor Pointing To A Freed Skb) With Real Error Handling. Wipe The Parsing State And Tell The R…CVE-2025-66034Fonttools 4.60.2 (Medium)CVE-2025-13402
Threat Groups
Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.